GDPR & security

Churches hold some of the most sensitive data in the voluntary sector — children’s records, giving, pastoral notes. Here is exactly how we protect it.

UK data residency
Your church's data is stored in the UK or EEA and never moved outside it without an adequacy decision or IDTA clauses in place.
Encrypted in transit and at rest
TLS on every connection, encryption at rest on the database and backups. Provider keys you enter — Stripe, Twilio, Resend — are separately encrypted with a key held outside the database.
Least-privilege roles
Giving needs the Finance role. Pastoral notes are visible only to the group the author chose. Children's records are limited to the Children team. Most volunteers need none of these.
Audit logging
Safeguarding-sensitive events — child check-in and check-out, changes to a child's record, exports of personal data — are written to a log your administrators can review.
Tenant isolation
Every church lives on its own subdomain, and every database query is scoped to that church. One church can never read another's records.
One-click subject access
A subject access request that used to mean a week of spreadsheets is an export button on the person's record — every field, note, donation and message we hold for them.

The questions a trustee will ask

Who is the controller and who is the processor?

Your church is the controller of its records — it decides what to collect and why. ChurchHub is the processor, acting on your instructions. That split is set out in full in our privacy policy, and a data processing agreement is available for your records.

How is consent tracked?

Consent is recorded per person and per channel, with the date it was given. Communications respect it automatically: someone who has withdrawn email consent is excluded from email sends, with no reliance on anyone remembering.

What about children's data?

Children's records support guardians, medical and allergy notes and photo-consent flags. Access is limited to the Children team, check-in and check-out are logged with the leader's name, and pick-up codes exist so a child is only released to the right adult.

How do we handle an erasure request?

Delete the person's record and it is removed from the live database immediately and purged from backups within 35 days. Where Gift Aid has been claimed, the donation record must be retained for seven years to meet HMRC rules — the person's contact details are erased and the financial record is anonymised.

Can we get our data out?

Any time, while your subscription is active — per person, per module, or the whole database as CSV. There is no export fee and no notice period.

Reporting a vulnerability

If you believe you have found a security issue, email security@chhub.app. We acknowledge reports within one working day and will keep you updated until it is resolved. Please give us a reasonable window to fix an issue before disclosing it publicly — we will never take legal action against someone who reports a genuine problem in good faith.

For the legal detail, see our privacy policy, terms of use and cookie policy.

Data protection your trustees can sign off

Start a 30-day trial and show them the audit log yourself.

Start free trial