Privacy Notice
Effective 23 July 2026 · Version 2026-07-v1
This notice explains how Kharis Church ("we", "us", "the church") collects and uses your personal data when you use Kairos, our internal church administration platform. It is written to comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Kharis Church is the data controller for personal data processed in Kairos. If you have any questions about this notice, or you want to exercise any of the rights described below, please contact us at privacy@kharis.org.
1. Who this notice applies to
This notice applies to members of Kharis Church who create an account in Kairos, to people whose information is entered into Kairos by our leaders (for example first-time visitors captured on a welcome form, or children whose parents provide information on their behalf), and to anyone who submits information through a public Kairos form.
2. What personal data we collect
2.1 Information you give us at sign-up
- Full name (first, middle, last) and any preferred honorific
- Email address and phone number
- Date of birth and gender
- Home and (optionally) secondary postal address
- The Kharis Church branch you attend
- Emergency contact name, relationship and phone number
- A password (stored only as a one-way cryptographic hash)
2.2 Information you can add later
- A profile photo
- Marital status, occupation, prior church background
- Notification preferences
2.3 Information generated by your church activity
- Service and fellowship attendance records
- Fellowship group membership and any leadership role you hold
- Department membership, rota assignments and uniform sizes
- New believer discipleship pipeline stage, if applicable, along with mentor session notes taken by your mentor
- Form submissions you make (for example: baptism application, testimony, altar-call response, baby dedication, declarative forms)
- Prayer requests, follow-up notes, or safeguarding notes recorded by a leader in connection with pastoral care
- Records of the consents you have given or withdrawn, and the versions of this notice and our Terms & Conditions you have accepted
2.4 Technical information
- Sign-in timestamps, session tokens and the browser you used
- IP address and coarse device information, used only to secure your account against unauthorised access
- Error reports automatically generated if part of Kairos fails while you are using it
2.5 Special category and safeguarding data
Where a form asks you to disclose information about your health, a disability, a child in your care, or a safeguarding concern, that information is treated with extra care. We collect it only where it is necessary for the pastoral and safeguarding responsibilities of the church, and access is restricted to leaders with a lawful reason to see it.
3. Why we use your data and our legal basis
Under UK GDPR we can only process your data if we have a lawful basis for doing so. We rely on the following bases:
| Purpose | Lawful basis |
|---|---|
| Administering church membership, allowing you to sign in, and contacting you about services and fellowship groups you are part of | Legitimate interests of the church in caring for its members |
| Recording attendance, tracking discipleship progress, and co-ordinating rotas | Legitimate interests of the church in running services and ministries |
| Pastoral care, prayer follow-up and safeguarding of vulnerable people (including children under 16) | Legitimate interests, and where relevant our legal obligations under safeguarding law |
| Sending you optional newsletters, event invitations, or outreach communications | Your explicit consent |
| Protecting Kairos against fraud and abuse, and keeping audit logs | Legitimate interests in maintaining a secure platform |
We do not use your data for automated decision-making that significantly affects you, and we do not sell your data to anyone.
4. Who we share your data with
Your data is visible inside Kharis Church to leaders whose role requires it. Access is scoped so that leaders only see the data for the people and areas they are responsible for.
We share data with the following third parties who help us run Kairos:
- Cloudflare, Inc. — hosts the Kairos website, application server, database gateway and image storage
- PlanetScale, Inc. — runs the Postgres database that stores your member record. Data is stored in the UK / EEA
- Amazon Web Services, Inc. — sends transactional emails. Region: EU (London / Frankfurt)
- Sentry, Inc. — receives error reports when Kairos fails, so we can diagnose and fix issues
These providers act as data processors: they process your data only under our instructions and are bound by contract to protect it.
We may also disclose data where we are legally required to do so — for example in response to a safeguarding investigation, a court order, or a request from a UK regulator.
5. How long we keep your data
| Data type | Retention |
|---|---|
| Active member records | For as long as you remain a member |
| Archived member records | Up to 6 years after you leave |
| Records about children under 16 | In line with our safeguarding policy |
| Attendance records | 3 years on a rolling basis |
| Consent records | Lifetime of account plus 6 years |
| Sign-in logs and error reports | Up to 90 days, then automatically deleted |
6. Your rights
Under UK GDPR you have the right to:
- Access your personal data (a "subject access request")
- Correct data that is inaccurate or incomplete
- Erase your data ("the right to be forgotten"), except where we are required to keep it for safeguarding or legal reasons
- Restrict how we process your data while a query is being resolved
- Portability — receive a machine-readable export of the data you gave us
- Object to processing carried out on the basis of our legitimate interests
- Withdraw consent at any time, where we relied on consent
To exercise any of these rights, email us at privacy@kharis.org. We will respond within one calendar month.
If you believe we have handled your data unlawfully, you can complain to the UK Information Commissioner's Office at ico.org.uk. We would encourage you to raise the issue with us first so that we can put it right.
7. Children and young people
Kharis Church takes the safeguarding of children very seriously. If you are under 16, please ask a parent or guardian to complete Kairos-related forms on your behalf. Children's records are created and managed by a parent or a designated safeguarding lead, and their visibility inside Kairos is restricted to leaders whose role requires them to see it.
8. Cookies and tracking
Kairos uses a single first-party cookie to keep you signed in during a session. We do not use advertising cookies, we do not run third-party analytics that track you across the web, and we do not share your usage patterns with marketing platforms.
9. Security
Passwords are stored as one-way cryptographic hashes and cannot be read by anyone, including us. Data in transit is protected by TLS. Access to Kairos administration is gated by role-based permissions and audit-logged.
10. Changes to this notice
When we make a material change to this notice we will bump its version and ask you to review and accept it the next time you sign in. Minor typo-level changes may be made without prompting.
11. Contact us
Kharis Church — privacy@kharis.org
Draft for review
This document is an initial draft written from what Kairos actually collects and how it is stored. It has not yet been reviewed by Kharis Church leadership or a data-protection professional. Please treat it as a starting point rather than a settled policy.