Legal · Data Processing Addendum

Data Processing Addendum (DPA).

This DPA governs how LoveSync processes personal data on behalf of organisational customers — churches, employers, NGOs, schools, and other institutional partners who bring LoveSync to their community. It supplements the standard LoveSync Terms of Service for organisational customers.

01

1. Parties and scope

This DPA is entered into between the organisational customer (“you”, the “Data Controller”) and LoveSync (the “Data Processor”) with respect to personal data processed under the LoveSync Terms of Service.

It applies whenever LoveSync processes personal data on your behalf — that is, when your organisation is bringing LoveSync to a defined membership (a cohort, a seat pool, or a private group) and you determine the purposes and means of that processing.

Where LoveSync processes personal data for its own purposes (e.g. direct-to-consumer members, platform operation, safeguarding), LoveSync acts as an independent controller and this DPA does not apply — the LoveSync Privacy Policy governs instead.

02

2. Definitions

“Personal Data”, “Processing”, “Controller”, “Processor”, and “Data Subject” have the meanings given in the GDPR, the UK GDPR, or equivalent local law that applies to your jurisdiction.

“Sub-processor” means any third party engaged by LoveSync to process Personal Data under this DPA.

“Restricted Transfer” means a transfer of Personal Data outside the jurisdiction of origin that requires safeguards under applicable data-protection law.

“SCCs” means the Standard Contractual Clauses adopted by the European Commission and the UK Information Commissioner’s Office for international data transfers.

03

3. Subject matter, duration, nature, and purpose

Subject matter: the provision of the LoveSync platform to your organisation’s members under the LoveSync Terms of Service.

Duration: for as long as your organisation holds an active LoveSync organisational agreement, plus the retention periods set out in this DPA.

Nature and purpose: to deliver the six rooms of LoveSync (Learn, Counsel, Celebrate & give, Events, Services, Community), to process payments and payouts, to maintain safeguarding and moderation, and to support your organisation with cohort-level (anonymised) reporting.

Categories of data subjects: members of your organisation who create or activate LoveSync accounts under your seat plan.

Categories of Personal Data: identity data (name, email, phone); profile data (preferences, love language, relationship status); practice data (rituals, prompts, shared-space content); counselling data (bookings, session data — subject to counsellor privacy rules); payment data (invoices, ledger records); technical data (device, session, telemetry).

04

4. Your obligations as Controller

You warrant that you have a lawful basis under applicable data-protection law for engaging LoveSync as a Processor and for the categories of Personal Data described above.

You are responsible for the accuracy, quality, and legality of any Personal Data you provide directly to LoveSync (e.g. member lists, seat assignments) and for obtaining necessary consents from your members before enrolling them.

You will respond to Data Subject requests where the Data Subject engages you directly. LoveSync will support you with reasonable technical assistance as described in § 8.

05

5. LoveSync’s obligations as Processor

LoveSync processes Personal Data only on your documented instructions, including with respect to Restricted Transfers, unless a legal obligation requires otherwise (in which case LoveSync will notify you before processing, unless the law prohibits notification).

LoveSync ensures that persons authorised to process Personal Data are bound by written confidentiality obligations.

LoveSync implements appropriate technical and organisational measures to protect Personal Data (§ 7).

LoveSync respects the conditions in § 6 for engaging sub-processors and will notify you of any intended addition or replacement.

LoveSync assists you, taking into account the nature of processing, in fulfilling your obligations to respond to Data Subject requests (§ 8) and to meet Articles 32–36 GDPR (or equivalent) — security, breach notification, DPIAs, and prior consultation.

06

6. Sub-processors

You give LoveSync general written authorisation to engage sub-processors, subject to the following conditions: (a) LoveSync maintains an up-to-date list of sub-processors on request; (b) LoveSync notifies you at least 30 days before adding or replacing a sub-processor for the categories of Personal Data you provide; (c) each sub-processor is bound by written terms substantially equivalent to this DPA.

You may object to a proposed new sub-processor on reasonable data-protection grounds within 14 days of notification. Where the objection cannot be resolved, either party may terminate the affected part of the service with pro-rata refund of prepaid fees.

07

7. Security of processing

LoveSync implements and maintains appropriate technical and organisational measures to protect Personal Data — including encryption of Personal Data in transit and at rest for sensitive fields, access controls on a need-to-know basis, an append-only audit log for security-relevant actions, formal incident response and breach notification procedures, and regular security testing.

Additional detail is available on request under NDA, including our SOC 2 status, penetration test summaries, and sub-processor security assessments.

08

8. Assistance with Data Subject requests

Where a Data Subject exercises rights of access, rectification, erasure, portability, restriction, or objection, LoveSync will provide the technical means for you to fulfil those requests directly through the organisational admin console.

Where a request cannot be fulfilled through the admin console, LoveSync will assist you with reasonable technical support at no additional cost, within one calendar month of your written request, or within the shorter period required by applicable law.

09

9. Personal Data breach notification

LoveSync will notify you without undue delay, and in any event within 72 hours of becoming aware, of any Personal Data breach affecting your Personal Data. The notification will describe the nature of the breach, the categories and approximate number of Data Subjects and records concerned, likely consequences, and measures taken or proposed.

Where full information is not available within 72 hours, LoveSync will provide an initial notification and follow-up detail as it becomes available. LoveSync will support you with any onward notifications you must make to supervisory authorities or Data Subjects.

10

10. International data transfers

Where LoveSync’s processing involves a Restricted Transfer of Personal Data, we rely on an approved safeguard under applicable law — typically the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, or an equivalent recognised mechanism.

Where you require the SCCs to apply between us, they are incorporated into this DPA by reference and take precedence over any conflicting term.

11

11. Audit rights

LoveSync will make available to you all information necessary to demonstrate compliance with this DPA, including access to relevant audit reports (e.g. SOC 2 Type II).

Where you have specific concerns that available audit materials do not adequately address, you may audit LoveSync’s compliance on reasonable prior written notice (not less than 30 days), during business hours, at your expense, subject to reasonable confidentiality undertakings. Repeat audits within a 12-month period may be reasonably declined unless required by law or triggered by a specific incident.

12

12. Return and deletion of Personal Data

On termination of your organisational agreement, LoveSync will, at your choice, return or delete all Personal Data processed on your behalf, and delete any existing copies unless law requires further storage.

Members whose accounts continue as direct-to-consumer LoveSync members after termination are not affected by this clause — their Personal Data continues to be processed by LoveSync as an independent controller under our Privacy Policy.

13

13. Liability and order of precedence

Liability under this DPA is subject to the limitation of liability in the LoveSync Terms of Service or in your organisational agreement, whichever applies.

In case of conflict between this DPA, the LoveSync Terms of Service, and any organisational agreement between us, the following order of precedence applies: (i) mandatory data-protection law; (ii) this DPA; (iii) any organisational agreement; (iv) the LoveSync Terms of Service.

14

14. Changes to this DPA

LoveSync may update this DPA from time to time to reflect changes in applicable law, sub-processor arrangements, or platform architecture. Material changes will be notified to you at least 30 days in advance.

Where you object to a material change on reasonable data-protection grounds, we will discuss in good faith. If we cannot resolve the objection, either party may terminate the affected part of the service with pro-rata refund of prepaid fees.

15

15. Contact

Data Protection Officer: [email protected]

Legal notices: [email protected]

For questions about this DPA specifically: [email protected]