ChurchLibrary

Data Processing Addendum

Last updated: July 24, 2026

This Data Processing Addendum ("DPA") supplements the ChurchLibrary Terms of Service or other written agreement governing Customer's use of the Service (the "Agreement") between Customer and Church of the Highlands, Inc., through ChurchLibrary ("Provider"). This DPA applies to the extent Provider processes Customer Personal Data on behalf of Customer in connection with the Service.

Capitalized terms not defined in this DPA have the meanings given in the Agreement. If this DPA conflicts with the Agreement regarding processing of Customer Personal Data, this DPA controls.

1. Definitions

"Applicable Data Protection Law" means privacy, data-protection, and data-security laws applicable to the processing of Customer Personal Data under the Agreement.

"Customer Personal Data" means personal data or personal information contained in Customer Content or otherwise processed by Provider on Customer's behalf in connection with the Service.

"Controller," "Business," "Processor," "Service Provider," "Personal Data," "Personal Information," "Process," and similar terms have the meanings given under Applicable Data Protection Law, as applicable.

"Subprocessor" means a third party engaged by Provider to process Customer Personal Data on Customer's behalf.

2. Roles and Scope

As between the parties, Customer determines the purposes and means of processing Customer Personal Data submitted to the Service and acts as Controller or Business, as applicable. Provider acts as Processor or Service Provider when processing Customer Personal Data on Customer's behalf, except for limited processing for which Provider independently determines purposes and means, such as account administration, security, fraud prevention, legal compliance, and management of its own business records.

The subject matter, duration, nature, purpose, data categories, and data subjects are described in Annex A.

3. Processing Instructions

Provider will process Customer Personal Data only on Customer's documented instructions, including as necessary to provide the Service under the Agreement, unless Applicable Data Protection Law requires otherwise. The Agreement, Customer's use and configuration of the Service, and Customer's lawful instructions constitute documented instructions.

If Provider believes an instruction violates Applicable Data Protection Law, Provider may notify Customer and suspend the affected processing while the parties address the issue.

4. Customer Responsibilities

Customer is responsible for ensuring that its instructions and submission of Customer Personal Data comply with Applicable Data Protection Law, including providing required notices, establishing an appropriate legal basis, obtaining required consents or permissions, responding to individuals, and limiting data submitted to what is lawful and appropriate.

Customer acknowledges that sermon and ministry content may reveal religious beliefs and may include information about speakers, congregants, or other individuals. Customer is responsible for determining whether submission and processing of such information is appropriate and lawful.

5. Confidentiality

Provider will ensure that persons authorized to process Customer Personal Data are subject to appropriate confidentiality obligations and are permitted to access Customer Personal Data only as reasonably necessary for their responsibilities.

6. Security

Provider will maintain reasonable and appropriate administrative, technical, and organizational safeguards designed to protect Customer Personal Data against unauthorized or unlawful access, acquisition, alteration, disclosure, destruction, or loss. The current categories of safeguards are described in Annex B.

Customer is responsible for secure configuration of its workspace, Authorized User access, credentials, and permissions.

7. Security Incidents

Provider will notify Customer without undue delay after confirming a breach of security resulting in unauthorized access to, acquisition of, or disclosure of Customer Personal Data for which notice to Customer is required under Applicable Data Protection Law ("Security Incident").

Provider will provide information reasonably available to it to assist Customer in meeting legally required notification obligations and will take reasonable steps to contain, investigate, and remediate the Security Incident. Notice of a Security Incident is not an admission of fault or liability.

Unsuccessful attempts or events that do not result in unauthorized access to Customer Personal Data, such as scans, pings, failed login attempts, or blocked attacks, are not Security Incidents for purposes of this DPA.

8. Subprocessors

Customer authorizes Provider to engage Subprocessors to process Customer Personal Data as necessary to provide the Service. Provider will impose data-protection obligations on Subprocessors appropriate to the nature of the services they provide.

Current categories and principal Subprocessors are listed in Annex C. Provider may update its Subprocessors as the Service evolves. If required by Applicable Data Protection Law or a separately agreed enterprise process, Provider will provide reasonable notice of a new Subprocessor and consider a timely objection based on reasonable data-protection grounds. If the parties cannot resolve a valid objection, either party may terminate the affected Service as their exclusive remedy for the objection.

9. Assistance with Individual Rights

Taking into account the nature of processing, Provider will provide reasonable assistance to Customer with requests by individuals to exercise rights under Applicable Data Protection Law. If Provider receives a request concerning Customer Personal Data for which Customer is responsible, Provider may direct the requester to Customer or forward the request to Customer, unless law requires Provider to respond directly.

10. Regulatory and Compliance Assistance

Taking into account the nature of processing and information available to Provider, Provider will provide reasonable assistance with legally required data-protection impact assessments, consultations with regulators, and compliance inquiries relating to Provider's processing of Customer Personal Data.

Provider will make information reasonably necessary to demonstrate compliance with this DPA available to Customer. Any audit or inspection rights required by Applicable Data Protection Law will be exercised on reasonable advance notice, during normal business hours, in a manner designed to minimize disruption, and subject to reasonable confidentiality and security requirements. The parties will first seek to satisfy audit requests through existing reports, certifications, questionnaires, or other documentation when reasonably sufficient.

11. Return and Deletion

Upon termination of the Service or a valid Customer request, Provider will return or delete Customer Personal Data in accordance with the Agreement and available Service functionality, unless Applicable Data Protection Law requires retention.

Deletion from active systems may occur over a commercially reasonable period. Residual copies may remain in routine backups, security logs, legal holds, fraud-prevention records, and other limited systems until overwritten or deleted under ordinary retention practices, provided such data remains protected and is not used for unrelated purposes.

12. U.S. State Privacy Terms

To the extent Provider processes Customer Personal Data subject to a U.S. state privacy law that regulates service providers, processors, or contractors:

  • Provider will process Customer Personal Data only for the business purposes and services specified in the Agreement, this DPA, and Customer's documented instructions;
  • Provider will not sell Customer Personal Data or share it for cross-context behavioral advertising;
  • Provider will not retain, use, or disclose Customer Personal Data outside the direct business relationship with Customer except as permitted by Applicable Data Protection Law;
  • Provider will not combine Customer Personal Data received from or on behalf of Customer with personal information received from another person or collected from Provider's own interactions with an individual except as permitted by Applicable Data Protection Law;
  • Provider will provide the same level of privacy protection required of processors, service providers, or contractors under Applicable Data Protection Law, as applicable; and
  • Customer may take reasonable and appropriate steps to help ensure Provider uses Customer Personal Data consistently with Customer's obligations under Applicable Data Protection Law.

13. International Transfers

If Customer Personal Data is transferred from a jurisdiction that requires a lawful transfer mechanism to a country not recognized as providing adequate protection, the parties will cooperate in good faith to implement an appropriate lawful mechanism, such as applicable standard contractual clauses or another recognized transfer mechanism, to the extent legally required.

14. Transfer or Assignment of ChurchLibrary

This DPA may be assigned or transferred together with the Agreement to an affiliate, subsidiary, successor, purchaser, or other entity that acquires, assumes ownership of, or operates all or substantially all of ChurchLibrary or the assets or business associated with the Service, including through an internal restructuring, reorganization, merger, consolidation, sale, or transfer of assets. A permitted assignee that assumes the Service may succeed to Provider's applicable rights and obligations under this DPA.

If a transfer results in a material change to processing practices or the identity of the responsible processor where notice is required by law, Provider or its successor will provide appropriate notice.

15. Liability and General Terms

The liability limitations, indemnities, governing law, venue, and other general terms in the Agreement apply to this DPA unless Applicable Data Protection Law requires otherwise. This DPA terminates when Provider no longer processes Customer Personal Data on Customer's behalf, except for provisions that by their nature survive.