Information Officer
Our Information Officer is responsible for making sure we follow POPIA and PAIA. You can reach them through the contact form; choose the subject “Information Officer”. We'll respond within 30 days, as the law requires.
Our standards
- Lawful and minimal: we only collect what we need for a clear purpose, and tell you why.
- Consent: we ask before sending the weekly letter, using photos, or keeping functional cookies, and you can withdraw any time.
- Quality: you can update your details any time, and members confirm their membership every four months.
- Openness: our privacy policy explains what we collect and who sees it.
- Security safeguards: see below.
- Your participation: you can see, correct or delete your information.
Security measures
- All traffic is encrypted (HTTPS/TLS), with strict security headers.
- The admin dashboard needs a Google sign-in and a one-time code emailed to the church account, and every admin action is logged.
- Uploaded files are checked for type and size and stored privately. They're never public links.
- Sign-in sessions are secure, http-only cookies that expire.
- Forms are protected against spam and abuse with rate limits.
- Database backups and point-in-time recovery are kept on Cloudflare.
How long we keep information
- Members: while you're a member, and up to 2 years after you leave or revoke membership.
- Event registrations and proof of payment: up to 5 years (financial records).
- Prayer requests and messages: up to 2 years.
- Complaints: up to 5 years.
- Email delivery logs: 90 days. Security logs and expired sign-in codes are deleted automatically.
Your requests (PAIA)
To see what we hold about you, or to correct or delete it, use the contact form or, if you're signed in, your profile. We may ask you to confirm your identity first. Requests for your own information are free.
If something goes wrong
If we ever suspect a security compromise affecting your information, we'll notify the Information Regulator and the people affected as soon as reasonably possible, as section 22 of POPIA requires, and explain what we're doing about it.
Service providers
We use Cloudflare (hosting, database, file storage, email) and Google (sign-in) as operators. They process information only on our instructions, under agreements that protect it to a standard similar to POPIA.
The Information Regulator
If you're unhappy with how we've handled your information, you can complain to the Information Regulator of South Africa: inforeg.org.za.