Privacy at congrega
Your data. Clearly handled.
This notice explains in plain language which personal data is processed when you visit our website or use congrega — and which rights you have.
Last updated: 21 August 2026
No marketing tracking
No analytics, advertising, or social media trackers.
Necessary storage only
No cookies on the website; only essential storage in the app.
Two operating modes
Online on EU servers or local on your own hardware.
Controller
The controller under the General Data Protection Regulation (GDPR) for this website and direct communications with us is:
Scope and data protection roles
This privacy notice applies to congrega.org, the online application operated by us, and direct communications with us.
congrega Online
Where a congregation uses congrega Online and determines the purposes and means of processing its application data, that congregation is the controller. We generally process this data on documented instructions as a processor. Details are governed by a data processing agreement under Article 28 GDPR.
congrega Local
With congrega Local, application data is processed on the congregation’s own hardware. We have no access during normal operation unless temporary access is granted for a specific support or maintenance case.
Visiting the website
When you access this website, your browser sends technically necessary information to the web server. This may include:
- IP address
- date and time of access
- requested page or file and amount of data transferred
- referrer URL, if transmitted
- browser, operating system, and device type
Purpose and legal basis
Processing is necessary to deliver the website, maintain its stability and security, and prevent attacks. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure and reliable operation of our service.
We do not use audience analytics, advertising networks, social media pixels, or user profiling on this website.
Using the application
The data processed in congrega depends on how each congregation configures and uses it. The following categories may typically be involved:
- Account and profile data
- e.g. name, email address, congregation, role, and permissions
- Organisation data
- e.g. groups, districts, assignments, dates, and responsibilities
- Territory data
- e.g. territory boundaries, assignments, returns, progress, and do-not-call records — the latter may also concern people who do not use congrega; they are entered by the congregation acting as controller
- Ministry and planning data
- e.g. reports, availabilities, and assignments
- Third-party contact data
- e.g. profiles of public speakers and contact persons of other congregations with name, phone number, and email address
- Location and device data
- e.g. temporary live locations during an active territory session and device push tokens
- Usage and log data
- e.g. sign-in times, changes, and security-related events
- Content
- e.g. notes, responses, and uploaded documents where those features are used
Sensitive data
Some information may reveal religious affiliation and may therefore constitute special-category data under Article 9 GDPR. The controller decides whether and on what legal basis such data is entered. congrega is designed to restrict access through roles and permissions.
Purposes of processing
- Providing and administering user accounts
- Organising territories, assignments, meetings, and ministry
- Synchronising and making approved content available offline
- Support, error analysis, and protection against misuse and unauthorised access
For processing performed on instructions, the congregation determines the legal bases. We process our own contract and contact data where necessary to perform a contract or take pre-contractual steps (Article 6(1)(b) GDPR), and to ensure system security based on legitimate interests (Article 6(1)(f) GDPR). No solely automated decision-making, including profiling, takes place.
Mobile app and map services
When you use the iOS and Android apps and the map features, the following services and processing operations apply in addition:
- Map display
- Territory maps load map tiles directly from the OpenStreetMap Foundation’s servers. Your device’s IP address and the requested map sections are transmitted to this provider. The Leaflet map library is bundled with the app and is not loaded from an external service. No account or application data is transferred.
- Address search and geocoding
- Address data for territories is retrieved via our server from services such as Nominatim (OpenStreetMap), Overpass, and official address registers. These requests originate from our server and contain no link to your user account.
- Push notifications
- Notifications are delivered via Firebase Cloud Messaging (Google, Android) and the Apple Push Notification service (iOS). A push token for your device and the minimal notification payload are transmitted. No other push broker is used. Notifications can be disabled per category in the app.
- Location sharing
- The app shares your live location with your team only during an active territory session — and only while you are inside the territory or within a radius of roughly 500 metres. Outside of that, no location is transmitted. Sharing ends with the session.
- App lock
- The optional unlock via Face ID or fingerprint is evaluated entirely on your device. Biometric data never leaves your device and never reaches our servers.
The app contains no analytics or advertising SDKs, no third-party crash reporting, and no payment features. The system does not send emails; password resets are handled by your congregation’s administrators.
Contacting us
If you contact us by email, we process your contact details and message to respond. The legal basis is Article 6(1)(b) GDPR where the request relates to a contract or pre-contractual steps, and otherwise Article 6(1)(f) GDPR. Our legitimate interest is responding appropriately to your enquiry.
Email is generally not transmitted with end-to-end encryption. Please do not send confidential content by email unless necessary.
Recipients and third countries
We disclose personal data only where necessary to provide the service, where required by law, or where another legal basis applies. Current recipients are in particular: our hosting provider Hetzner Online GmbH (Gunzenhausen, Germany) for operating the application and database, Google (Firebase Cloud Messaging) and Apple (Apple Push Notification service) for delivering push notifications, and — directly from the device — the OpenStreetMap Foundation for map display.
Under our operating model, production data for congrega Online is processed on servers within the European Union. congrega Local stores application data on the congregation’s own hardware. A current list of sub-processors is provided in the data processing agreement.
When push notifications are delivered via Google and Apple and when map tiles are retrieved, a transfer to third countries, in particular the USA, cannot be ruled out. Such transfers take place only in accordance with Articles 44 et seq. GDPR, in particular on the basis of an adequacy decision (such as the EU-US Data Privacy Framework) or appropriate safeguards such as standard contractual clauses.
Open the data processing agreementRetention and deletion
We retain personal data only for as long as required for its purpose or by statutory retention obligations. In particular, we use these criteria:
- Server logs
- only for the period required to operate the service and detect attacks; longer where necessary to investigate a security incident
- Contact enquiries
- until finally resolved; beyond that only where related to a contract or required by law
- Contract and billing data
- for the contract term and then in line with statutory retention periods
- Application data in congrega Online
- on instruction and according to the deletion periods agreed with the controller; after contract termination data is deleted or returned unless retention is legally required
- Security logs (audit log)
- for the duration of the congregation’s contract; they contain only names and changed fields, never the underlying content
Data security
We take appropriate technical and organisational measures to protect personal data against loss, alteration, and unauthorised access. These include encrypted transmission, role-based access, logging of security-relevant events, backups, and regular updates. Safeguards are developed in line with the state of the art.
Your data protection rights
Where the legal requirements are met, you have the following rights in particular:
- Access to your processed data (Article 15 GDPR)
- Rectification of inaccurate data (Article 16 GDPR)
- Erasure of your data (Article 17 GDPR)
- Restriction of processing (Article 18 GDPR)
- Data portability (Article 20 GDPR)
- Objecting to processing based on legitimate interests (Article 21 GDPR)
- Withdrawing consent with future effect (Article 7(3) GDPR)
For data managed by a congregation in congrega, please contact that congregation first. It is generally the controller. You may still contact us at any time if you are unsure.
Changes to this privacy notice
We update this privacy notice when our service, the services we use, or legal requirements change. The version published on this page applies.
Still unsure?
Questions about privacy?
Write to us. We will gladly explain what happens to your data and who is responsible for your request.
Send an email