Vine & Branch
  • Features
  • Pricing
  • Contact
Get Started
← Back to Privacy Policy

Data Processing Agreement

This Data Processing Agreement ("DPA") is entered into as of the date the Church accepts the Terms of Service.
Version: 1.0  ·  Effective: June 2026

This Data Processing Agreement forms part of the Terms of Service between the parties identified below and governs the processing of personal data by Vine and Branch Software, LLC on behalf of the Church in connection with the Vine and Branch church management platform ("Service").

1. Parties

Data Controller (the Church):

Church Legal Name: [CHURCH NAME]

Address: [CHURCH ADDRESS]

Authorized Representative: [NAME AND TITLE]

Contact Email: [EMAIL ADDRESS]

Data Processor:

Vine and Branch Software, LLC

Contact: legal@vineandbranch.app

The Church is the "Data Controller" with respect to personal data of its members, staff, visitors, and other individuals whose information is stored in the Service. Vine and Branch Software, LLC is the "Data Processor" that processes such data on the Church's instructions.

2. Subject Matter and Duration

This DPA applies to all processing of personal data that Vine and Branch Software, LLC performs on behalf of the Church in connection with the Service, from the date of acceptance of the Terms of Service until:

  • termination of the Terms of Service; or
  • deletion or return of all personal data as described in Section 9 below, whichever is later.

3. Nature and Purpose of Processing

Vine and Branch Software, LLC processes personal data solely to provide the Service to the Church, which includes the following purposes:

  • Storing and managing member profiles, contact information, and household records
  • Recording and displaying sermons, attendance, volunteer assignments, and giving records
  • Sending email, SMS, and push notifications on the Church's behalf
  • Maintaining audit logs for the Church's security and compliance purposes
  • Processing online gifts and donations (payment instrument tokenization handled by third-party payment processors; Vine and Branch does not store raw card numbers)
  • Providing pastoral care tools, including encrypted notes, prayer requests, and care workflows
  • Children's check-in, attendance tracking, and background check workflow management
  • Generating reports and analytics for church administrators

Processing is performed on behalf of and under the instructions of the Church. Vine and Branch Software, LLC will not process personal data for any other purpose without the Church's prior written consent, except where required by applicable law.

4. Categories of Data Subjects and Personal Data

Data Subjects

  • Church members and regular attendees
  • Visitors, guests, and prospective members
  • Church staff and volunteers
  • Children enrolled in children's ministry programs
  • Donors (including non-members)

Categories of Personal Data

  • Identity data: Full name, date of birth, gender, profile photo
  • Contact data: Email address, phone number, mailing address
  • Household data: Family relationships, household composition
  • Financial data: Donation history, fund allocations, giving statements (not raw payment credentials)
  • Attendance and service data: Service attendance records, volunteer assignments, check-in history
  • Spiritual and pastoral data: Prayer requests, pastoral care notes, discipleship progress, sacramental records (baptism, marriage) — stored with field-level encryption
  • Children's data: Child name, age, room assignment, medical and allergy notes (encrypted), security codes, guardian information
  • Background check data: Background check status and results (encrypted) where applicable
  • Communications data: Email/SMS engagement records, notification preferences
  • Technical data: IP addresses, browser user-agent, session audit logs

Special Category Data

To the extent the Church uses the Service to store health or medical information (e.g., children's allergy information or pastoral counseling notes that may reveal health conditions), such data is treated as sensitive and stored with AES-128 field-level encryption. The Church, as Data Controller, is responsible for ensuring it has an appropriate legal basis for processing any special category data.

5. Obligations of the Data Processor (Vine and Branch Software, LLC)

Vine and Branch Software, LLC agrees to:

  1. Process only on instructions. Process personal data only on the documented instructions of the Church, unless required to do so by applicable law. In such a case, Vine and Branch Software, LLC will notify the Church before processing, unless prohibited by law.
  2. Confidentiality. Ensure that all personnel authorized to process personal data are bound by appropriate confidentiality obligations.
  3. Security. Implement appropriate technical and organizational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access (see Section 11).
  4. Sub-processors. Not engage sub-processors without the Church's general or specific prior authorization, and flow down equivalent data protection obligations to any approved sub-processor (see Section 8).
  5. Data subject rights. Assist the Church, by appropriate technical and organizational measures, in responding to requests from individuals exercising their rights under applicable data protection law, including rights of access, correction, deletion, restriction, and portability.
  6. Breach notification. Notify the Church without undue delay — and in any event within 72 hours of becoming aware — of any personal data breach, including information required under applicable law (see Section 12).
  7. Data protection impact assessments. Provide reasonable assistance to the Church in conducting data protection impact assessments and prior consultations with supervisory authorities where required.
  8. Deletion or return. At the Church's choice, delete or return all personal data to the Church after the end of the provision of the Service, and delete existing copies unless applicable law requires storage.
  9. Audit cooperation. Make available to the Church all information necessary to demonstrate compliance with this DPA and allow for and contribute to audits conducted by the Church or a mandated auditor (see Section 13).

6. Obligations of the Data Controller (the Church)

The Church agrees to:

  1. Comply with all applicable data protection laws in its use of the Service, including ensuring it has a valid legal basis for processing each category of personal data.
  2. Provide individuals with required privacy notices at the point of collection of their personal data.
  3. Obtain any required consents for special category processing (e.g., health information, children's data) before entering such data into the Service.
  4. Keep access credentials secure and manage user accounts and role permissions appropriately, including promptly revoking access for departing staff or volunteers.
  5. Not instruct Vine and Branch Software, LLC to process personal data in a way that would violate applicable law.
  6. Promptly notify Vine and Branch Software, LLC of any suspected security breach or unauthorized access to the Service.

7. Sub-processors

The Church provides general authorization for Vine and Branch Software, LLC to engage the following sub-processors as of the effective date of this DPA. Vine and Branch Software, LLC will notify the Church of any intended addition or replacement of sub-processors with at least 14 days' notice, giving the Church opportunity to object.

Sub-processor Purpose Location DPA / Privacy
MongoDB, Inc.
(MongoDB Atlas)
Primary database hosting and storage United States (AWS us-east-1) mongodb.com/legal/dpa
Sinch Email AB
(Mailjet)
Transactional and bulk email delivery EU / United States mailjet.com/legal/dpa
Twilio, Inc. SMS delivery (church communications) United States twilio.com/legal/dpa

Each sub-processor is bound by contractual data protection obligations no less protective than those set out in this DPA.

8. Data Retention and Deletion

Vine and Branch Software, LLC will retain personal data for the duration of the Church's active subscription. Upon termination of the Terms of Service:

  • The Church may request a full data export (ZIP archive) from the App Settings panel within 30 days of termination.
  • Vine and Branch Software, LLC will purge all personal data from production systems within 90 days of account closure, except where a longer retention period is required by law.
  • Aggregate or anonymized data from which no individual can be identified may be retained for product improvement purposes.
  • Certain technical data (such as security audit logs) may be retained for up to 12 months in accordance with Vine and Branch Software, LLC's security obligations.

The Church may at any time request deletion of specific records or of its entire data set through the data export and deletion features in the Service, or by written request to privacy@vineandbranch.app.

9. Security Measures

Vine and Branch Software, LLC maintains appropriate technical and organizational security measures, including:

  • Encryption in transit: All connections to the Service are encrypted using TLS 1.2 or higher. HTTP Strict Transport Security (HSTS) is enforced.
  • Encryption at rest: Sensitive fields (pastoral care notes, children's medical/allergy information, background check data) are encrypted at the application layer using Fernet (AES-128 with HMAC-SHA256) before storage.
  • Credential security: Passwords are stored using bcrypt one-way hashing. Vine and Branch Software, LLC never stores plaintext passwords.
  • Access controls: Role-based access controls limit data access to authorized personnel. Administrative functions require explicitly assigned permissions.
  • Brute-force protection: Login rate limiting (5 failed attempts triggers a 15-minute account lockout) and anomaly detection for unusual login patterns.
  • Multi-factor authentication: Optional TOTP-based MFA for administrator accounts; churches may require MFA for all admin roles.
  • Audit logging: Comprehensive, tamper-evident audit logs record all create/update/delete operations and authentication events with user identity and timestamp.
  • Infrastructure: The Service runs in isolated containers with restricted network access. Database access is restricted by IP allowlist.
  • Vulnerability management: Dependencies are monitored for known vulnerabilities and updated regularly.

Vine and Branch Software, LLC reviews and updates these measures periodically in light of evolving threats and technological developments.

10. Personal Data Breach Notification

In the event of a personal data breach affecting Church data, Vine and Branch Software, LLC will:

  • Notify the Church's designated contact without undue delay and, where feasible, within 72 hours of becoming aware of the breach (in accordance with Art. 33 GDPR and comparable US state privacy law requirements).
  • Provide a written incident report including: a description of the nature of the breach; the categories and approximate number of data subjects affected; the categories and approximate number of personal data records affected; the likely consequences of the breach; and the measures taken or proposed to address the breach.
  • Cooperate with the Church in any required notifications to supervisory authorities or affected data subjects.

The Church, as Data Controller, retains primary responsibility for notifying affected individuals and relevant regulatory authorities in accordance with applicable law.

11. International Data Transfers

The Service is hosted and operated in the United States. If the Church is located in the European Economic Area (EEA), the United Kingdom, or another jurisdiction with restrictions on cross-border data transfers:

  • Transfers of personal data to the United States are made pursuant to the EU Standard Contractual Clauses (Module 2: Controller-to-Processor) adopted by the European Commission on 4 June 2021, which are hereby incorporated by reference into this DPA.
  • For UK-based churches, the International Data Transfer Addendum to the EU Standard Contractual Clauses (UK IDTA) issued by the UK Information Commissioner's Office applies.
  • A copy of the applicable Standard Contractual Clauses is available upon request at legal@vineandbranch.app.

Most churches using this Service are located in the United States. If your church has members residing in the EEA or you are uncertain about your transfer obligations, please consult with a qualified data protection advisor.

12. Audit Rights

Vine and Branch Software, LLC will provide the Church with all information reasonably necessary to demonstrate compliance with this DPA. The Church (or its mandated auditor, subject to appropriate confidentiality obligations) may conduct audits of Vine and Branch Software, LLC's data processing activities upon no less than 30 days' written notice, no more than once per 12-month period, and during normal business hours. Vine and Branch Software, LLC reserves the right to charge reasonable costs for supporting audits that go beyond making standard documentation available.

In lieu of an on-site audit, Vine and Branch Software, LLC may provide the Church with the results of an independent third-party security assessment or SOC 2 report, where available, as reasonable evidence of compliance.

13. Termination

This DPA terminates automatically upon termination of the Terms of Service. Provisions relating to confidentiality (Section 5.2), deletion of data (Section 8), and governing law (Section 15) survive termination. Upon termination, Vine and Branch Software, LLC will cease processing personal data and proceed with deletion as described in Section 8.

14. Limitation of Liability

Each party's liability under this DPA is subject to the limitations of liability set out in the Terms of Service. Nothing in this DPA is intended to limit either party's liability to data subjects or supervisory authorities under applicable data protection law.

15. Governing Law and Jurisdiction

This DPA is governed by the laws of the State of Florida, United States, without regard to its conflict of law provisions, except to the extent that applicable data protection law (including the GDPR, UK GDPR, or US state privacy laws) requires otherwise. The parties irrevocably submit to the exclusive jurisdiction of the courts of Hillsborough County, Florida for resolution of any dispute arising under this DPA.

Where EU Standard Contractual Clauses apply (Section 11), the governing law and jurisdiction provisions of those Clauses take precedence to the extent required by applicable law.

16. Entire Agreement; Order of Precedence

This DPA, together with the Terms of Service and Privacy Policy, constitutes the entire agreement between the parties regarding the processing of personal data under the Service. In the event of any conflict between this DPA and the Terms of Service with respect to the processing of personal data, this DPA shall prevail.

17. Execution

By accepting the Terms of Service, the Church agrees to this DPA. Where a signed copy is required for the Church's records, the parties may execute this agreement manually below.

Data Controller (the Church)

 
Signature
[NAME]
Printed Name
[TITLE]
Title
[CHURCH NAME]
Organization
[DATE]
Date

Data Processor (Vine and Branch Software, LLC)

 
Signature
 
Printed Name
Authorized Representative
Title
Vine and Branch Software, LLC
Organization
[DATE]
Date

Questions about this DPA? Contact us at legal@vineandbranch.app.

Vine & Branch

Church Management Software © 2026 Vine and Branch Software LLC

Privacy Policy  ·  Data Processing Agreement  ·  Terms of Service