Data Processing Addendum

Updated 16 August 2026

This addendum sits on top of the Terms when a church uses Miqra to store personal data of members, guests, and staff. It is written for NDPA 2023. It is an operational DPA, not a signed counsel opinion.

Roles

The church is the controller of member profiles, families, first-timers, attendance, giving, pastoral notes, sermons, messages, and website content it publishes.

Pypapi Technologies Limited (with SonsHub Media as co-operator of Miqra) is the processor of that set.

For platform login accounts, billing contacts, and audit logs we keep as operator, we are controller. That is covered by the Privacy policy, not this DPA.

Instructions

We process church-held data only to provide the modules the church switched on, to keep backups needed for that service, and to follow the church's in-product actions (export, delete, role change).

We will not use church member lists to advertise third-party products. Platform ads to members are not offered.

Security measures

We isolate tenants in the database layer, require a permission on API routes, transmit over HTTPS, store sessions in httpOnly cookies, and keep amounts as integer kobo.

Personnel at the operator who can see tenant data are limited to work that cannot be done in the tenant workspace. Access is logged.

Sub-processors

We use infrastructure, email/SMS, Paystack, and object storage as needed to run those jobs. A current list can be requested from the published mailbox. We will not add a sub-processor that takes over the whole member database without telling church admins.

Helping the church with rights requests

The product includes export and deletion tools for member records. If a data subject writes to us about church-held data, we will point them at the church and, if needed, pass the request to the church admin on file.

Breach notice

If we confirm a breach of church-held personal data, we will notify the church admin on file without undue delay, with the facts we have: what happened, which records, and what we are doing. The church decides how it notifies the NDPC or its members. Write to contact@usemiqra.app.

Return and deletion

When a church leaves Miqra, it should export first. After the retention in the Privacy policy, we delete tenant data we no longer have a legal reason to keep, including processor copies, except backups that age out on their schedule.