1. Scope and roles
In short: Your church controls the personal data in its content. We process it only to run Displayte for you, as you instruct.
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between Displayte, a sole proprietorship (“Displayte,” “we”) and the church using the Service (“you”). It applies when we process personal data contained in Your Content (as defined in the Terms), or about the people your church invites, on your behalf (“Customer Personal Data”). For Customer Personal Data, you are the controller (or a processor acting for a controller), and we are your processor. Terms such as “personal data,” “processing,” “controller” and “processor” have the meanings given in the EU General Data Protection Regulation (“GDPR”) and its UK equivalent; where US state law applies, “service provider” and “business” have the meanings in that law.
2. The processing
- Subject matter and purpose: providing the Service to you: storing, processing and showing your church’s content on its screens, and managing the people who use it.
- Duration: for as long as the Terms are in effect, and until deletion under section 9.
- Nature: hosting, storage, conversion and compression for playback, transmission to your church’s Apple TVs, and display in the web app.
- Types of personal data: images and video of people; names and other information shown in content; and, for the people your church invites, names, email addresses and roles.
- Data subjects: people who appear or are named in your church’s content, which may include members, visitors, staff, volunteers and children; and the people your church invites to use the Service.
- Special categories: content may incidentally reveal religious belief, since it’s shown in a church. You’re responsible for having a lawful basis for that processing; we protect it as described in section 5.
3. Your instructions
We process Customer Personal Data only on your documented instructions, which are the Terms, this DPA and your use and configuration of the Service, unless the law requires otherwise; if it does, we’ll tell you before processing, unless the law forbids that. If we believe an instruction breaks data protection law, we’ll tell you. You’re responsible for the lawfulness of the instructions you give and of the Customer Personal Data you provide, including any consent needed from the people shown.
4. Confidentiality
Everyone we authorize to process Customer Personal Data is bound by confidentiality, and has access only as far as needed to provide, support or secure the Service.
5. Security
We maintain technical and organizational measures appropriate to the risk, including:
- encryption of data in transit (TLS) and at rest;
- separation of every church’s data, enforced by row-level security in the database, with tests that one church can never read or change another’s;
- private file storage, reached only through short-lived signed links;
- checks on every uploaded file’s real type before it can reach a screen, and a closed list of accepted formats;
- individual, rotating credentials for each Apple TV, which your church can withdraw at any time;
- multi-factor authentication and least-privilege access for our staff to production systems;
- security review of every change to sign-in, data access, storage, uploads and the TV connection, and a monthly review of the whole Service; and
- encrypted daily backups of the database.
Our Security page describes these measures further. We may update them, but never in a way that lowers the overall level of protection.
6. Subprocessors
You authorize us to use the subprocessors listed on our Subprocessors page. We impose on each one, by written contract, data protection obligations at least as protective as this DPA, and remain responsible for their performance. We’ll give at least 30 days’ notice, by updating that page and emailing your account’s owners, before adding or replacing a subprocessor of Customer Personal Data. If you object on reasonable data protection grounds, we’ll work with you in good faith to find an alternative; if we can’t, you may end the affected part of the Service.
7. Requests from people
Your church can find, change and delete its content in the Service itself. If we receive a request about Customer Personal Data directly from a person, we’ll pass it to you without responding ourselves, unless the law requires otherwise. We’ll give you reasonable help to respond to such requests, and with data protection impact assessments and consultations with authorities, taking into account the nature of the processing.
8. Personal data breaches
We’ll notify you without undue delay, and in any case within 72 hours, after becoming aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data. We’ll tell you what we know about it, what we’re doing, and what you may need to do, and keep you updated as we learn more.
9. Deletion at the end
We delete Customer Personal Data as the Terms and our Privacy Policy describe. Your church’s files, and every copy made for its screens, are deleted 30 days after its plan ends; its account and records, including its people, are kept so it can start again, until an owner deletes the church. A deleted church can be brought back for 7 days; then its data is deleted, except counts that identify no one and payment records kept at Stripe. Backup copies expire within a further 7 days. Before then, an owner can ask us for a copy of your church’s files (the versions we keep for its screens). We may keep data only where the law requires us to, and then only for that purpose.
10. Information and audits
We’ll make available the information reasonably needed to show that we meet this DPA, including by answering your written security questions. If that isn’t enough to meet an obligation you have under data protection law, you may audit our compliance, once a year, with at least 30 days’ notice, during business hours, at your own cost, and in a way that doesn’t compromise other customers’ data or our security.
11. International transfers
We process Customer Personal Data in the United States and in the other countries our subprocessors use. Where GDPR, UK or Swiss law applies to a transfer to a country without an adequacy decision, the Standard Contractual Clauses adopted by the European Commission in Decision 2021/914 (Module Two, controller to processor, or Module Three, processor to processor, as applicable) are incorporated into this DPA by reference, with the UK Addendum and Swiss amendments where needed. For those clauses, the details in section 2 form Annex I, the measures in section 5 form Annex II, the governing law and courts are those of Ireland, and the optional docking clause and clause 11’s optional language don’t apply.
12. US state privacy laws
Where the California Consumer Privacy Act or a similar US state law applies, we are your service provider (or processor). We won’t sell or share Customer Personal Data; won’t retain, use or disclose it for any purpose other than providing the Service, or outside our direct business relationship with you; and won’t combine it with personal data we receive from others, except as those laws allow. We’ll tell you if we can no longer meet these obligations.
13. General
The limits on liability in the Terms apply to this DPA. If this DPA conflicts with the Terms on the processing of Customer Personal Data, this DPA wins. Questions about this DPA: support@displayte.com.