Data policy
Effective date: 2026-09-30
This policy explains the practical handling of workspace records. It supplements the Privacy notice and Terms of use; it is not a substitute for an executed data processing agreement or international transfer clauses.
Famplified LLC · Oklahoma, United States10125 Beaupre Dr, Arcadia, OK 73007, United States
info@email.famplified.com
1. Organization control and minimization
The organization decides what records to create, who is authorized, and how long records are needed. Collect only relevant information and review it for accuracy and necessity. Restrict sensitive prayer and care information to appropriate staff. Use anonymized descriptions when possible. A workspace may support several congregations, but administrators must ensure permissions match the actual organizational relationships and confidentiality requirements. The platform’s organization boundary does not establish a separate permission boundary for each congregation inside that workspace.
2. Service providers
The production architecture uses Amazon Web Services for hosting, authentication, databases, private files, operational logs, and transactional email. Stripe supports paid checkout and subscription management when configured. These providers receive information appropriate to their function; payment providers may also act independently for their own legal and fraud-prevention duties. Ministry narratives are not included in routine notification emails. External links and provider-hosted pages have their own terms and privacy notices. Request the current contracted provider, location, and subprocessor details before onboarding regulated data. Any required subprocessor authorization, change notice, and objection process must be documented in the parties’ processing agreement.
3. Access, security, and incidents
The platform checks organization membership, roles, module access, and record visibility on the server. Private attachments require an authorized request and a short-lived download link. The infrastructure is designed for encryption in transit and at rest, audit records, and backups; these measures depend on proper deployment and operation. Protect shared devices, remove departed team members promptly, and report suspected incidents to info@email.famplified.com. We will investigate and notify affected controllers without undue delay where required; controllers remain responsible for assessing notices to individuals and regulators, including the GDPR’s 72-hour supervisory-authority requirement where applicable. No security certification or suitability for regulated medical records is asserted.
4. Export, retention, and deletion
Authorized exports include supported CSV records and a structured JSON workspace export. Export availability follows access permissions; files are downloaded separately. Archiving hides or closes work but is not erasure. Deletion of an entire account, workspace, attachment versions, or backups currently requires a verified support request and an agreed operational process. We will explain any legal retention exception, applicable timing, and backup constraints rather than promise instant removal. Backup copies are not used for ordinary activity and must be handled under the agreed lifecycle; any restoration must reapply completed deletion instructions. Organizations should set review schedules, export needed records before cancellation, and document retention decisions.
5. Consent records and withdrawal
Service-term acceptance records identify the account, notice version, time, and selected language. Public prayer forms ask separately for explicit permission to process the submitted sensitive information and optional permission for public sharing. Consent boxes start unchecked. Keep your private withdrawal receipt; anyone with its secret link can withdraw the request. Withdrawal removes the public listing and replaces the active request text with a minimal withdrawal record. It does not automatically erase staff notes, attachments, audit evidence, backups, exports, or copies held outside the platform. Contact the organization or Famplified LLC for a broader rights or deletion request. Staff must not republish a withdrawn submission or treat consent as permission for unrelated purposes.
6. Regulated-data onboarding
Before using the service for data subject to EU or UK restrictions, contact info@email.famplified.com to confirm the controller and processor roles, processing instructions, categories of individuals and data, provider locations, retention schedule, security measures, rights assistance, and incident contacts. Complete the required data processing agreement and, when applicable, the appropriate EU standard contractual clause modules or other lawful transfer safeguards. Assess whether a data protection impact assessment, representative, or data protection officer is required. These are operational and contractual requirements, not outcomes guaranteed by accepting a website policy. We can provide available information to support that assessment; do not upload affected data until the necessary arrangements are in place.