Addeum

Data Processing Addendum (draft)

Draft for counsel. This page is an operational overview for procurement — not a signed contract. Your order form / master agreement controls. Effective draft date 30 July 2026 (version 2026-07-30).

Roles

  • Church / organization — controller of congregation and ministry personal data processed in the Addeum product.
  • Addeum — processor (and, for our own marketing/CRM leads, an independent controller — see Site Privacy Policy).

What we process for you

When you use Addeum under a customer agreement, we process personal data you and your staff enter or import — for example member records, attendance, giving metadata, volunteer schedules, and communications content — solely to provide the services described in that agreement and your documented instructions.

Our commitments (summary)

  • Process product data only on documented instructions (the product configuration and agreement).
  • Apply appropriate technical and organizational measures (schema-per-tenant isolation, RBAC, encryption in transit, managed encryption at rest, audit logging, AI PII redaction on supported paths).
  • Assist with data-subject requests to the extent the product tools allow (export / deletion workflows) and as required by applicable law.
  • Notify you of personal-data breaches affecting your tenant without undue delay as required by law and your agreement.
  • Delete or return product data at end of services per the agreement (subject to legal retention).

Product subprocessors (indicative)

We may engage the categories below. Exact vendors and regions are confirmed in your security review / DPA schedule. Email enquiry@addeum.life for the current schedule.

  • Cloud infrastructure host (e.g. AWS / GCP / Azure via operator)Host application, databases, object storage, and backups (As specified in the customer agreement / DPA)
  • Managed PostgreSQL providerPrimary operational datastore (control + tenant schemas) (As specified in the customer agreement / DPA)
  • Email / SMS providers (when enabled by the church)Transactional and ministry communications you configure (Provider-dependent)
  • Payment processors (e.g. Stripe / PayPal when enabled)Online giving and billing you enable (Provider-dependent)
  • Optional LLM providers (self-hosted path preferred)AI features after PII redaction on supported paths (As configured per tenant / agreement)

International transfers

Where product data is transferred outside your country, we use appropriate safeguards required by applicable law (for example SCCs or an equivalent mechanism) as set out in the final DPA.

How to get a signable DPA

Contact enquiry@addeum.life during procurement. Related pages: Trust Center, Privacy, Terms.