iConfirm Church Data Protection Addendum — v2
Reviewed — ready for use 2026-08-23
Effective date: 2026-08-23
This Data Protection Addendum ("DPA") forms part of the Church Service Agreement between BIBS Specialty Services, Inc. ("BIBS") and the Church identified in the order ("Church"). Capitalized terms not defined here have the meanings in the Agreement.
1. Scope and roles
This DPA governs personal information processed through the Church account, including information about Parents, Students, and Leaders ("Covered Data").
The parties' roles depend on the processing activity:
- BIBS acts as the operator of iConfirm and directly provides Parents the child-privacy notice, obtains and records Parent consent, manages Parent/Student accounts, and responds to Parent rights under COPPA and other applicable law.
- For Church organization administration, attendance, progress, and Student-designated shared content, BIBS processes Covered Data to provide the contracted Service and Church determines its own authorized Leaders and lawful confirmation-program use.
- Each Party acts independently for its own legal compliance, security, billing, dispute, and recordkeeping obligations.
Where applicable law uses "controller," "processor," "business," "service provider," or similar terms, the Parties will be treated according to their actual functions above rather than a label alone.
Church is not treated as a FERPA-covered school, and this DPA is not a FERPA or Illinois SOPPA agreement, unless the Parties sign a separate written amendment after counsel confirms those laws apply to the specific Church/program.
2. Processing details
Duration
The subscription term plus the retrieval, deletion, legal-retention, and backup periods stated in the Agreement, Privacy Policy, and written retention schedule.
Nature and purpose
Account creation, authentication, Parent authorization, confirmation lessons, attendance, progress/completion, Student private work, Student-directed sharing, support, email, subscription administration, security, exports, privacy requests, retention/deletion, and legal compliance.
Data subjects
Parents, Students (including children under 13), Church Leaders, Church representatives, and authorized support contacts.
Data categories
- Parent names, verified emails, account IDs, consent and subscription records;
- Student names/nicknames, Parent/Church associations, hashed PINs, progress, attendance, completion, reflections, surveys, visibility choices, and activity records;
- Leader names, verified emails, roles, Church association, and activity/access records;
- shared content and Church exports;
- transaction identifiers and limited payment/subscription metadata;
- communications and support/privacy requests; and
- IP address, device/browser data, session/authentication data, and security/server logs.
No photo uploads are permitted at launch. The DPA and related notices must be reviewed before enabling them.
3. Processing restrictions
BIBS will:
- process Covered Data only to provide, secure, support, and improve the Service under the Agreement; follow valid Parent rights; comply with law; and carry out documented, lawful instructions consistent with the privacy boundary;
- not sell or rent Covered Data;
- not use Covered Data for targeted advertising or another party's independent marketing;
- not use real Student-generated content to train AI or language models;
- not disclose private Student reflections or surveys to Church or Leaders;
- not combine Covered Data with information received from other parties for advertising or unrelated profiling; and
- notify Church if an instruction would require BIBS to violate law or the Parent/Student privacy boundary.
Church may not instruct BIBS to disclose private Student content, provide/reset Student credentials, impersonate a Student, or override Parent rights.
4. Church obligations
Church will:
- authorize and supervise only appropriate Leaders;
- notify BIBS promptly when Leader access must be revoked;
- not submit child data before Parent authorization;
- use Covered Data only for the confirmation program and safeguarding/legal duties;
- secure and minimize exports;
- delete exported shared content where feasible after a Student revokes sharing and Church receives notice;
- comply with applicable privacy and child-safety law; and
- notify BIBS promptly of suspected unauthorized use or disclosure.
5. Confidentiality and access
BIBS will limit Covered Data access to persons who need it for an authorized function and are subject to confidentiality. The sole authorized operator currently has privileged database access. Private reflections are plaintext at the database layer, protected by provider encryption at rest, TLS in transit, and application access controls; they are not end-to-end encrypted.
BIBS has completed a two-Church tenant-isolation test suite, confirming that no ordinary Leader path in any participating Church exposes another Church's data or another Leader's private Student content. Testing confirmed that an ordinary Leader role — including a Leader who is also BIBS's operator, as tested against the original St. Paul pilot configuration — cannot retrieve private reflections or surveys through any available in-app Leader path. iConfirm supports multiple participating Churches on this basis.
6. Security
BIBS will maintain a written information-security program appropriate to the sensitivity of children's information, including:
- a designated security owner;
- periodic risk assessment;
- role-based access and tenant separation;
- MFA for privileged provider accounts where available;
- encryption in transit and provider encryption at rest;
- secure PIN hashing and Parent-controlled resets;
- service-provider diligence and written protections;
- vulnerability, authorization, and recovery testing;
- incident response; and
- purpose-bound retention and secure deletion.
Status: the production database runs on a backup-capable plan with automatic backups active. MFA on the hosting account and a synthetic-data restore test remain unverified — do not represent to Church or Parents that a tested restore capability exists until that test has run and passed.
7. Service providers
Church authorizes these current subprocessors:
| Subprocessor | Function | Data generally involved |
|---|---|---|
| Supabase | Database, authentication, and storage | Account, Student, content, consent, progress, and technical information |
| Vercel | Hosting and delivery | Requests, application data in transit, and server/security logs |
| Resend | Transactional email | Recipient email, message contents, delivery metadata |
| Stripe | Payments and subscriptions | Payer, payment, subscription, discount, and transaction information |
BIBS will maintain a current list and use service providers only under terms requiring appropriate confidentiality, security, use restrictions, and deletion. BIBS will give at least 30 days' notice of a material new subprocessor when reasonably practicable. If Church reasonably objects on data-protection grounds, the Parties will work in good faith on mitigation; if none is reasonably available, Church may terminate the affected Service before the change takes effect.
[FILING NEEDED, not a document change] BIBS has not yet obtained and filed each subprocessor's written data-processing assurance (16 C.F.R. §312.8(c)). All four publish a standard DPA; downloading and filing them is a paperwork task, logged separately.
8. Individual and Parent requests
BIBS will receive Parent review, export, correction, deletion, refusal, and consent-withdrawal requests at office@iconfirm.app from the verified Parent account email. BIBS will verify and fulfill requests as required by law. Church will reasonably assist and will not interfere with Parent rights.
If a request concerns an export held only by Church, Church will respond as applicable and notify BIBS. Neither Party will disclose Covered Data to a requester before reasonable verification.
9. Security incidents
A "Security Incident" is unauthorized access to, acquisition, use, disclosure, alteration, loss, or destruction of Covered Data, excluding unsuccessful attempts that do not compromise security.
Each Party will notify the other without undue delay after confirming a Security Incident affecting the other Party's data or obligations. BIBS's notice will include, as available, the nature of the incident, affected information and persons, likely consequences, containment/remediation, and a contact. Updates may be provided as the investigation develops.
The Parties will cooperate on required notices. No Party will identify the other publicly or notify on the other's behalf without authorization unless law requires it. Allocation of notification costs follows responsibility for the incident, subject to the Agreement's liability terms.
BIBS will notify Church without undue delay and in no case later than 72 hours after confirming a Security Incident affecting Church's data, giving BIBS time to complete an initial multi-state breach analysis before that notice goes out.
10. Retention, return, and deletion
While paid access remains active, BIBS retains Covered Data needed to provide the Service. After paid access ends, ordinary Student use is intended to lock by day 5 while export remains available through day 90. Student Content is then deleted from active systems and applicable backups under BIBS's control.
BIBS may retain minimal consent, billing, security, dispute, and legal-hold records for their specific lawful purpose. Church must retrieve permitted organization exports during the available period and delete Covered Data no longer needed.
Church has no right to receive private Student content at termination. A Student transfer between Churches requires a verified manual request and must not expose private content to the former or new Church.
11. Information and review
On reasonable written request, BIBS will provide information reasonably necessary to demonstrate compliance, such as current subprocessors, relevant policies, and summary test evidence, subject to confidentiality and security limitations.
Church may request a compliance discussion no more than annually unless a confirmed incident or regulator requires more. Reviews must avoid access to another tenant's information, private Student content, privileged material, or security details that would create risk.
12. Government requests
BIBS will evaluate legal demands for Covered Data, disclose only what it reasonably believes is legally required, and notify affected parties when legally permitted. Nothing in this DPA promises that reflections are privileged or immune from legal process.
13. Conflict, term, and survival
This DPA controls conflicts concerning data protection. It remains effective while BIBS processes Covered Data under the Agreement. Confidentiality, use restrictions, security-incident cooperation, and deletion obligations survive as necessary to fulfill their purpose.
Signatures
BIBS Specialty Services, Inc.
By/name/title/date: [INSERT]
Church
Legal name: [INSERT]
By/name/title/date: [INSERT]
