Skip to content

Privacy policy

How SundayAssist processes personal data for sundayassist.com, our legacy websites and SundayAssist hosted products.

Last updated: 10 October 2026

Introduction

This privacy policy describes how SundayAssist ("we", "us") processes personal data when you use sundayassist.com, proweave.app, edgeweave.io, hosted applications such as SundayAssist Connect, and related services (together, the "Services").

Effective date: 30 August 2026. Read this policy together with our Terms of service.

This policy also covers the standalone WorshipAssist workspace and its companion apps. Availability of native companion apps is stated separately on our product pages.

1. Data controller and contact

The controller responsible for personal data we process as a controller is SundayAssist, KvK 71817042, VAT NL025074519B01.

Registered address: Varenstraat 19, 2681 GN Monster, The Netherlands.

Contact (privacy, general and product enquiries): [email protected] or our contact page.

Data Protection Officer: We do not currently appoint a Data Protection Officer under Article 37 GDPR. For data-protection questions, use [email protected].

2. When we are controller and when we are processor

We act as controller, among other things, for: visitors to our marketing sites; messages you send via contact forms; account and billing data for our customer relationship; our own security, abuse prevention, and service analytics consistent with this policy; and transactional emails we send as part of operating the Services.

We act as processor on behalf of subscribing organisations for much of the content in organisation workspaces (for example roster, scheduling, and volunteer communications entered by the organisation). The organisation is typically the controller for that data; we process it on its instructions via use of the product and, where applicable, a Data Processing Agreement (Article 28 GDPR) available on request at [email protected]. Individuals should contact their organisation first for access or deletion of workspace data where appropriate; we assist organisations as required by law.

3. Personal data we process

Depending on your role, we may process:

WorshipAssist processes account and workspace membership, shared songs and setlists, author/source information, changes and the information needed to use a band session or invitation. Membership of a church music team may reveal religious belief. Applicable workspace permissions and invitations determine access. Share only necessary information and content that recipients are authorised to access.

  • Account and authentication: email address, name, profile fields from your identity provider where used, session and security-related data.
  • Organisation / roster data: names, contact details, notes, assignments, availability, identifiers your organisation configures, and similar planning data.
  • Files: attachments and profile images (avatars) uploaded to the service.
  • Billing: billing contact details and payment-related metadata. Card payments are handled by Stripe; we do not store full card numbers.
  • SundayAssist Presenter licence activation: account and entitlement identifiers, a random installation identifier, product version, activation and last successful licence-check times, and the signed offline licence issued to that installation. We do not use a network MAC address as the installation identifier.
  • Email and messaging: addresses and content needed to send operational or organisation-triggered messages, such as roster summaries or invitations; organisation email-policy settings and evidence references; invitation acceptance, delivery-attempt records, and organisation-specific unsubscribe preferences.
  • Optional calendar integration: if enabled, OAuth tokens and calendar metadata needed to connect Google Calendar or similar providers.
  • Optional Canva integration: if enabled, encrypted OAuth tokens and transient authorization state, Canva user/team and display-name metadata, presentation metadata, and user-requested PDF or MP4 export jobs. SundayAssist Presenter saves exports in the local collection. Imports requested in SundayAssist Connect are stored as private organisation media and follow the media retention choices below.
  • Optional periodic SundayAssist Presenter diagnostics: when you enable this setting, SundayAssist Presenter sends limited operational information: app version, platform, architecture, distribution channel, interface language, time running while opted in, startup/recovery indicators, selected feature categories, and temporary random report and session identifiers. At most one report is successfully sent per 24 hours. Reports contain no account or organisation identifiers, names, contact details, presentation content, audio, file paths or free-text logs. They are not linked to website visits or customer accounts.
  • Technical and security: IP address, browser and device information, logs, audit records, diagnostics, and abuse-prevention data.
  • Realtime presence (when in use): display name, avatar reference, and session-related metadata to show who is active in the product.
  • Website contact form: name, email, message text, and similar fields you submit. Forms are submitted securely to our backend for delivery by email.
  • Website and product usage analytics (with consent): when you accept analytics cookies on our marketing sites, we record pseudonymous events such as page views, button clicks, demo plays, download attempts, homepage experiment version, and a choice from the fixed Pastor, Worship leader, Planner, Tech team, or Volunteer role buttons. The role choice adapts product information and is not linked to an account or accepted as free text. For installable web apps we may also record fixed product, offer/action/result, and browser-method values; QR contents, setup codes, session identifiers, and participant names are never included in those events. We store a salted daily hash derived from your IP address and browser user agent; we do not store the raw IP address in this analytics table. We use a country routing header where available. If it is unavailable, our server may send the request IP to IPinfo solely to resolve a two-letter country code; we store only that country result. We also store browser locale and time zone, page path, event name, and referring hostname without its path, query, or fragment. These coarse signals are not treated as precise location. We do not use cross-site tracking or sell this data.
  • Optional SundayAssist Presenter online backup: automatic backup starts off. After you review the size and confirm, selected decks, portable SundayAssist Presenter preferences, library content and linked media can be uploaded as private backups scoped to your account and organisation. Backup metadata includes a random computer identifier, computer label, timestamps, sizes and file checksums. Credentials, sign-in tokens and device-pairing state are excluded.
  • Campaign measurement (with analytics consent): campaign links may supply source, medium and campaign labels. We remember the first consented campaign for up to 30 days and may attach it to an installer request, a download email submission or a newly created customer account. A new church or first paid purchase can inherit that account’s acquisition campaign. Private internal activity reports and founder emails can include supplied email addresses, church names, versions and purchased plans. They do not expose named browsing histories. Download and account records are not newsletter consent.

Special categories: Where organisations use the Services in a religious context, some roster or notes data may reveal religious belief or other special categories under GDPR Article 9. The organisation is responsible for establishing a lawful basis; we process such data only as needed to provide the Services under the organisation's instructions.

4. Purposes and legal bases (GDPR Article 6)

We process personal data for the purposes below, on the following legal bases:

  • Providing and operating the Services — performance of a contract with you or your organisation, or steps prior to entering a contract; including hosting, authentication, delivering features you request, and customer support.
  • Security, integrity, and abuse prevention — legitimate interests in keeping the Services secure and reliable, balanced against your rights.
  • Billing and accounting — performance of a contract and legal obligations (for example tax and invoicing rules).
  • Responding to enquiries — legitimate interests and, where relevant, steps prior to a contract.
  • Compliance with law — legal obligation, including lawful requests from public authorities subject to appropriate review.
  • Optional analytics storage — on our marketing websites we record first-party marketing analytics events only when you enable Analytics in our cookie settings. Processing is based on consent (Article 6(1)(a) GDPR). You can withdraw consent at any time through Cookie settings in the footer; events are not collected or replayed after rejection.
  • Optional periodic SundayAssist Presenter diagnostics — with your consent, to assess release quality, platform and language support, and feature use. The setting starts disabled and is separate from website analytics or written feedback. You can withdraw consent in SundayAssist Presenter under Settings → Privacy & Permissions. This stops collection and pending reports; reports already received cannot be recalled through the switch.

Where Article 9 GDPR applies to special categories, organisations using the Services must ensure an appropriate Article 9 basis; we process only as necessary to deliver the product they configure.

4a. Organisation emails and invitations

Before sending organisation emails through SundayAssist Connect, an owner or administrator records the organisation’s legal basis, the source of contact details or existing relationship, an evidence reference, and the organisation’s privacy notice and contact. The organisation must also assess any applicable Article 9 condition for data that reveals religious beliefs. These settings record its assessment; they do not establish a lawful basis or prove the recipient’s consent. The organisation remains responsible for its processing and applicable email rules.

The first invitation and subsequent organisation emails identify the sending organisation and include the source or relationship it has recorded, the stated processing basis, its privacy notice, its privacy contact and an unsubscribe link. This information is included outside editable email templates. The organisation’s own notice must describe its actual processing; this SundayAssist policy does not replace that notice.

You can stop invitations, reminders, roster summaries, availability requests and other SundayAssist Connect notifications from an organisation without an account. Open the unsubscribe link and confirm; opening or scanning the link alone does not change your preference. Unsubscribe controls supported by your email application can also submit the request. The preference applies to your email address within that organisation, including duplicate directory or guest records. Editing a profile, resending an invitation or accepting organisation access does not turn these emails back on.

Unsubscribing does not delete your profile, decline an assignment or close an account. Login or recovery emails you request remain available; billing and security messages have separate purposes. Receiving an invitation to join an organisation does not itself grant new membership or access to its data: you must accept it, including when you already have a SundayAssist account.

4b. Finding an organisation and requesting access

Organisations can choose to appear in the SundayAssist Connect or WorshipAssist search directory. Listings expose their organisation name, chosen public town or area and country, not member identities or private contact details. Each product is opted into separately. You can search without signing in. Sending a join request requires a verified SundayAssist account. The organisation provides a public privacy notice for its processing; it is linked before you request access.

If you ask to join, we use your name, verified account email, stated country of residence, selected organisation and product, request status, and the time, language and version of your explicit consent to handle that request. The receipt also identifies the organisation and the privacy-notice link presented at the time; it is not a saved copy of the organisation’s external page. We record confirmation of the displayed minimum age, not your date of birth. A church or worship-team request may reveal religious affiliation. Before submission, you explicitly agree to share the request with the selected organisation’s authorised organisers for assessment and, if approved, to create or link the profile and account access you requested. This optional request processing relies on consent under Article 6(1)(a) GDPR and, where it reveals religious beliefs, explicit consent under Article 9(2)(a). The organisers decide whether to approve it. Their own notice must explain the lawful grounds, purposes and retention of any continuing membership or workspace access; request consent is not unlimited permission for later processing. The request itself grants no access, and it is not used for advertising or religious-interest profiling.

This optional flow is initially available for supported EU/EEA, United States and Canadian country selections. Both the organisation’s country and your stated residence must qualify. Direct requests have a consistent product age limit of 16 across these supported countries. This is a product rollout policy, not a universal legal age. Unsupported regions and younger users can contact an organiser about an invitation and, where needed, parental or guardian consent. Country selection does not promise storage in that country; the international-transfer information below applies. We may prefill an editable region suggestion from available account or browser hints; correct it if it does not describe your residence.

You can withdraw and delete your request or download your retained request data in the same screen. A change to your email does not require you to verify it again to exercise these controls while signed in to the same account. Unanswered requests expire after 30 days; processing a decision clears the request’s name and email and keeps its status and account/organisation link for seven days. Expired records are removed by scheduled cleanup, which can take until a subsequent run. Withdrawing after approval deletes the request record but does not remove an already-approved membership or its People record; contact the organisation about leaving and the retention of membership data. Consent to assess a request does not authorise unrelated future processing. Search rate limits use an hourly rotating keyed hash derived from the request IP; the rate-limit store contains no raw IP, account identity, query or target organisation. Submission counters contain account, action and time, not search terms or a target organisation. Both expire after two days through cleanup. A functional routing hint can retain only your chosen organisation, region and local return route through sign-in, including confirmation in a new tab of the same browser, so you do not have to search again. It is valid for 15 minutes and cleared on use, expiry checks or account sign-out/switch; no request consent, search terms or contact details are stored in it.

5. Subprocessors

We use service providers who process data on our instructions. The following are key categories (specific vendors may change; we will update this policy or provide notice as appropriate):

ProviderRoleNotes
SupabaseAuthentication, database, file storage, realtime channels, Edge Functions, and consent-gated website analytics eventsHosts application data for our production environment in the London (United Kingdom) region. We use Supabase's data-processing terms and applicable transfer safeguards where relevant.
IPinfoCountry-level IP geolocation for consent-gated website analyticsReceives a request IP only when our hosting path does not provide a country header. We request and retain only the resulting country code in our analytics data. See ipinfo.io/privacy-policy.
StripePayments and customer billing portalProcesses payment data under Stripe's terms — see stripe.com/privacy.
ResendTransactional email and contact-form deliveryWe use resend.com to send email on our behalf; Resend processes message metadata and content as needed to deliver mail. See Resend's privacy policy.
GoogleOptional Calendar OAuth and YouTube embedded mediaCalendar data is processed only if an organisation or user enables the integration. YouTube connects only after a visitor enables External media or opens YouTube directly; Google may act as an independent controller for that visit.
CanvaOptional presentation importCanva account identifiers, design metadata, requested exports, and OAuth credentials are processed only when a user connects Canva. Credentials remain encrypted in our backend; disconnecting or deleting the SundayAssist account removes them. SundayAssist Presenter copies remain in the local collection. SundayAssist Connect imports are stored as private organisation media until their retention period ends or they are deleted.

5a. Google Calendar data, sharing and local AI

Connecting Google Calendar is optional. SundayAssist Connect uses Google account identity and email to identify the connected account, calendar names, identifiers, time zones and access roles to let you choose a calendar, and event data to preview and import the events you select. Event data can include titles, descriptions, dates, times and identifiers. Imported SundayAssist Connect events retain the title, dates, times and Google identifiers needed for planning and synchronisation.

Import only reads the selected calendar. If you choose Import + sync, SundayAssist Connect also creates and updates events in your selected writable Google calendar and deletes linked Google events when the corresponding SundayAssist Connect event is unpublished or removed. SundayAssist Connect controls the titles and times it publishes; this is not automatic merging of edits made in Google. Switching the sync calendar can remove linked events from the old calendar and recreate eligible events in the new one.

We share, transfer or disclose Google user data only as needed for the calendar and planning features you enable, with the following recipients:

  • Supabase: processes Google OAuth credentials, connected-account and calendar settings, imported event records and sync jobs on our behalf through its hosted database and Edge Functions. Google credentials are kept in backend storage and are not exposed to other SundayAssist Connect users.
  • Google: receives authorisation and token requests and, when sync is enabled, event titles, dates, times and technical identifiers needed to create, update or delete events. People who can access the destination calendar may see those events according to its Google sharing settings, including public visibility if you chose a public calendar.
  • Your organisation and the people you share with: imported events become organisation planning records. Authorised organisers, invited participants and members can see the relevant event information according to SundayAssist Connect permissions and the invitations or publications your organisation enables. Exports and connected SundayAssist Presenter workflows can also copy event information to devices or recipients your organisation chooses.
  • Resend and email recipients: when your organisation sends invitations, reminders or other operational emails about an imported event, the event information included in those messages, such as its title and time, is processed by Resend for delivery and disclosed to the intended recipients. Google OAuth credentials are not included.
  • Support, security and legal disclosures: access by SundayAssist staff or service providers is limited to what is needed for the service. Human access to Google data is permitted only with your explicit agreement for the specific data, for necessary security investigations, or to comply with applicable law. Any disclosure to authorities is limited to applicable legal requirements.

Google data is not sold, shared with advertising platforms or data brokers, used for personalised advertising, or supplied to AI providers for training or secondary purposes. We do not use raw, aggregated, anonymised or derived Google user data to create, train or improve general-purpose AI or machine-learning models.

Local/offline models: SundayAssist’s optional speech and music assistance runs local inference on the user’s device. Local models are AI, but they do not send their input to the model provider. The SundayAssist Connect Google Calendar integration does not use AI or send Google Calendar data to these models or to third-party AI services. Calendar connection and sync themselves use our hosted backend; they are not an offline-only service.

Limited Use: SundayAssist’s use and transfer of information received from Google APIs, including raw and derived Google Workspace data, will adhere to the Google API Services User Data Policy and the Google Workspace API User Data and Developer Policy, including the Limited Use requirements.

Retention and removal: we retain the connection credentials and settings while the organisation keeps Google Calendar connected. Disconnect in SundayAssist Connect Settings → Integrations → Google Calendar to remove the stored connection, credentials and pending sync jobs and stop future access through that connection; we also request revocation from Google. You can independently revoke access in your Google Account connections settings. Disconnecting does not erase events already imported into SundayAssist Connect or events already written to Google. Remove SundayAssist Connect copies through the event controls or request deletion through your organisation or [email protected]; remove remaining Google copies in Google Calendar. Related audit and delivery records follow the retention periods in section 7.

6. Cookies and local storage

Our settings cover cookies and similar technologies such as localStorage, sessionStorage, web beacons, and embedded third-party content. Optional categories are disabled by default.

Required storage is always active and is limited to operating features you request: storing your consent record, session security, payment checkout, and short-lived release or issue-list caches. The consent record is stored in localStorage and is renewed after approximately twelve months.

Preferences is optional. If enabled, localStorage may remember your selected language and, only if you enter it, your optional download email preference. Disabling Preferences removes those stored values.

Analytics is optional. If enabled, a pseudonymous identifier is stored in sessionStorage under pw_analytics_session_id to group first-party events within one browser session. We do not send or later replay analytics events that occur before consent. Disabling Analytics stops events and removes that session identifier.

External media is optional. YouTube frames are not loaded until you enable this category. We use YouTube's privacy-enhanced embed domain, but loading or opening a video still connects to Google and may allow Google to store or access information under its own policies.

We do not use advertising cookies or cross-site tracking on the marketing sites. You can change or withdraw any optional choice at any time through Cookie settings in the footer; withdrawing consent is as easy as granting it.

The SundayAssist Connect web interface may store a short-lived functional preference (for example a sidebar_state cookie, on the order of one week) to remember UI layout. This is strictly necessary for the interface and does not track you across unrelated sites.

With Analytics enabled, a campaign link can also set the optional proweave_campaign cookie for 30 days. On proweave.app this cookie is shared with SundayAssist Connect through the .proweave.app domain. It remembers campaign labels, not a unique visitor identifier. Disabling Analytics removes it and stops new browser attribution.

7. Retention

We retain personal data only as long as necessary for the purposes above and to meet legal, tax, and accounting requirements. Organisations may delete or export data using in-product controls where available.

Configured maintenance removes additional audit-event details and the linked account identifier from entries older than 730 days. Summaries and other actor fields can remain identifiable, so this is not full anonymisation of the audit log. The same maintenance process deletes volunteer access tokens more than 90 days after expiry and directory records archived for more than 395 days. These are configured cleanup thresholds; contact support for information about the maintenance process and any remaining records.

SundayAssist Connect’s delivery-attempt records are scheduled for deletion once they are more than 90 days old. We retain the organisation, email address and registration time needed to honour an unsubscribe preference even if a directory or guest record is deleted. Removing a person therefore does not reset their email preference. Requests concerning these records can be made through the organisation’s privacy contact.

Contact-form and mailbox content is kept for the time needed to handle your request and ordinary business follow-up unless a longer period is required by law.

Raw website analytics events are retained for up to fourteen months, then deleted or aggregated for reporting. Download analytics events follow a similar operational retention window.

A Canva connection is retained until the user disconnects Canva or deletes the SundayAssist account. We then remove the stored credentials and attempt to revoke Canva consent. Disconnecting does not delete imported copies. Local copies are controlled by the user. SundayAssist Connect service attachment references expire 30 days after the service ends. Shared files remain while another service reference is valid or Keep in SundayAssist Connect is enabled. Up to 10 GB per organisation can be kept beyond service expiry within its shared 50 GB cloud allowance. Releasing a kept file with no service references queues it for deletion; deleting the organisation removes its retained media too.

Periodic SundayAssist Presenter diagnostic reports are scheduled for deletion after 90 days by an hourly task; deletion can take until the next run. The reporting view covers the latest 30 days and stores no indefinite aggregate history. Separate abuse-prevention records use an hourly rotating hash derived from the request IP, are not attached to reports, and expire after two hours before the next cleanup. Infrastructure access logs are managed separately.

SundayAssist Presenter backups share the organisation’s 50 GB Complete allowance with SundayAssist Connect media. We keep the latest two completed backups per computer, for up to five computers per account and organisation. Saved copies remain until replaced or deleted; deleting the account or organisation queues its copies for storage cleanup. Turning off automatic backup does not delete existing copies. While organisation membership remains, the account can restore its saved backups after Complete ends.

The private Pulse activity log removes contact fields after 90 days; completed notification bodies are also cleared after 90 days. Business deduplication keys remain to prevent repeated purchase alerts. Founder emails already delivered remain subject to their recipients’ mailbox retention.

For song or setlist transfers, we record the authorised actor and the rights declaration confirmed for the action. Exported files can be retained outside SundayAssist; revoking access does not remove copies already held by recipients. The organisation and recipient remain responsible for applicable rights and retention obligations. Contact your organisation or [email protected] about deletion of workspace data and associated audit records.

WorshipAssist in-app deletion requests record the authenticated account ID, the account email address at receipt, a reference, status and response deadline. Access is restricted to handling the request. The case remains available while it is open, including if the Auth account is erased before completion is confirmed. Case contact email and account ID are scheduled for removal 90 days after the later of resolution and sending the outcome; the non-contact case reference and dates remain as an operational record. This does not change separate retention duties for shared workspace or statutory records.

8. International transfers

Data may be processed in the Netherlands (our company), the United Kingdom (including our primary application hosting in London), elsewhere in the European Economic Area, and in other locations where subprocessors operate. Transfers from the EEA to the UK rely on applicable adequacy decisions or appropriate safeguards. Where personal data is transferred outside the EEA or UK without adequacy, we implement appropriate safeguards such as Standard Contractual Clauses (and the UK Addendum or International Data Transfer Agreement where relevant), as offered by our vendors.

For information about the current transfer safeguards and subprocessors, or a copy of the applicable safeguards, contact [email protected]. We may redact unrelated confidential information while providing the information needed to understand the protection of your data.

9. Your rights

Under the GDPR and applicable local law you may have the right to access, rectify, erase, restrict or object to processing, and data portability where applicable, and to withdraw consent where processing is based on consent. You may lodge a complaint with a supervisory authority. In the Netherlands this is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).

For workspace data controlled by your organisation, contact the organisation first. The product may offer organisation export, organisation deletion, administrator account deletion, and person-level deletion subject to role rules; see in-app settings or your administrator.

To exercise rights against SundayAssist as controller, contact [email protected]. We may need to verify your identity.

For account deletion and privacy requests, contact [email protected]. You can also initiate account deletion in WorshipAssist under My account after signing in. If ownership or billing prevents immediate deletion, the app lets you submit a deletion request and view its reference, status and response deadline. Shared data and ownership require review before changes are made. Submitting a request does not itself erase data, transfer a workspace or cancel a subscription; completion requires confirmation of the outcome.

10. Children

The Services are not directed at children. Organisations must not use the Services to process children's personal data in violation of applicable child-protection laws.

11. Security

We implement technical and organisational measures appropriate to the risk, including access controls and encryption in transit. No method of transmission or storage is completely secure.

SundayAssist Connect limits event editing to owners, administrators and editors by default. An administrator or editor can enable Collaboration for an individual event so its invitees, including guests, can also edit the service, assignments and files. With Collaboration disabled, invitees can read the event and respond to their own invitation; other people’s invitation statuses and contact details are excluded from the event roster response. Organisation-level permissions remain separate from this event setting.

12. Third-party sites and embedded content

Our sites may link to or embed third-party content. YouTube embeds remain blocked until you enable External media; following an external link takes you to the third party directly. Those parties have their own policies, and we are not responsible for their independent practices.

13. Changes

We may update this policy. We will revise the "Last updated" date and, where required, provide additional notice.