iConfirm Church Data Protection Addendum — v2

Reviewed — ready for use 2026-08-23
Effective date: 2026-08-23

This Data Protection Addendum ("DPA") forms part of the Church Service Agreement between BIBS Specialty Services, Inc. ("BIBS") and the Church identified in the order ("Church"). Capitalized terms not defined here have the meanings in the Agreement.

1. Scope and roles

This DPA governs personal information processed through the Church account, including information about Parents, Students, and Leaders ("Covered Data").

The parties' roles depend on the processing activity:

Where applicable law uses "controller," "processor," "business," "service provider," or similar terms, the Parties will be treated according to their actual functions above rather than a label alone.

Church is not treated as a FERPA-covered school, and this DPA is not a FERPA or Illinois SOPPA agreement, unless the Parties sign a separate written amendment after counsel confirms those laws apply to the specific Church/program.

2. Processing details

Duration

The subscription term plus the retrieval, deletion, legal-retention, and backup periods stated in the Agreement, Privacy Policy, and written retention schedule.

Nature and purpose

Account creation, authentication, Parent authorization, confirmation lessons, attendance, progress/completion, Student private work, Student-directed sharing, support, email, subscription administration, security, exports, privacy requests, retention/deletion, and legal compliance.

Data subjects

Parents, Students (including children under 13), Church Leaders, Church representatives, and authorized support contacts.

Data categories

No photo uploads are permitted at launch. The DPA and related notices must be reviewed before enabling them.

3. Processing restrictions

BIBS will:

Church may not instruct BIBS to disclose private Student content, provide/reset Student credentials, impersonate a Student, or override Parent rights.

4. Church obligations

Church will:

5. Confidentiality and access

BIBS will limit Covered Data access to persons who need it for an authorized function and are subject to confidentiality. The sole authorized operator currently has privileged database access. Private reflections are plaintext at the database layer, protected by provider encryption at rest, TLS in transit, and application access controls; they are not end-to-end encrypted.

BIBS has completed a two-Church tenant-isolation test suite, confirming that no ordinary Leader path in any participating Church exposes another Church's data or another Leader's private Student content. Testing confirmed that an ordinary Leader role — including a Leader who is also BIBS's operator, as tested against the original St. Paul pilot configuration — cannot retrieve private reflections or surveys through any available in-app Leader path. iConfirm supports multiple participating Churches on this basis.

6. Security

BIBS will maintain a written information-security program appropriate to the sensitivity of children's information, including:

Status: the production database runs on a backup-capable plan with automatic backups active. MFA on the hosting account and a synthetic-data restore test remain unverified — do not represent to Church or Parents that a tested restore capability exists until that test has run and passed.

7. Service providers

Church authorizes these current subprocessors:

SubprocessorFunctionData generally involved
SupabaseDatabase, authentication, and storageAccount, Student, content, consent, progress, and technical information
VercelHosting and deliveryRequests, application data in transit, and server/security logs
ResendTransactional emailRecipient email, message contents, delivery metadata
StripePayments and subscriptionsPayer, payment, subscription, discount, and transaction information

BIBS will maintain a current list and use service providers only under terms requiring appropriate confidentiality, security, use restrictions, and deletion. BIBS will give at least 30 days' notice of a material new subprocessor when reasonably practicable. If Church reasonably objects on data-protection grounds, the Parties will work in good faith on mitigation; if none is reasonably available, Church may terminate the affected Service before the change takes effect.

[FILING NEEDED, not a document change] BIBS has not yet obtained and filed each subprocessor's written data-processing assurance (16 C.F.R. §312.8(c)). All four publish a standard DPA; downloading and filing them is a paperwork task, logged separately.

8. Individual and Parent requests

BIBS will receive Parent review, export, correction, deletion, refusal, and consent-withdrawal requests at office@iconfirm.app from the verified Parent account email. BIBS will verify and fulfill requests as required by law. Church will reasonably assist and will not interfere with Parent rights.

If a request concerns an export held only by Church, Church will respond as applicable and notify BIBS. Neither Party will disclose Covered Data to a requester before reasonable verification.

9. Security incidents

A "Security Incident" is unauthorized access to, acquisition, use, disclosure, alteration, loss, or destruction of Covered Data, excluding unsuccessful attempts that do not compromise security.

Each Party will notify the other without undue delay after confirming a Security Incident affecting the other Party's data or obligations. BIBS's notice will include, as available, the nature of the incident, affected information and persons, likely consequences, containment/remediation, and a contact. Updates may be provided as the investigation develops.

The Parties will cooperate on required notices. No Party will identify the other publicly or notify on the other's behalf without authorization unless law requires it. Allocation of notification costs follows responsibility for the incident, subject to the Agreement's liability terms.

BIBS will notify Church without undue delay and in no case later than 72 hours after confirming a Security Incident affecting Church's data, giving BIBS time to complete an initial multi-state breach analysis before that notice goes out.

10. Retention, return, and deletion

While paid access remains active, BIBS retains Covered Data needed to provide the Service. After paid access ends, ordinary Student use is intended to lock by day 5 while export remains available through day 90. Student Content is then deleted from active systems and applicable backups under BIBS's control.

BIBS may retain minimal consent, billing, security, dispute, and legal-hold records for their specific lawful purpose. Church must retrieve permitted organization exports during the available period and delete Covered Data no longer needed.

Church has no right to receive private Student content at termination. A Student transfer between Churches requires a verified manual request and must not expose private content to the former or new Church.

11. Information and review

On reasonable written request, BIBS will provide information reasonably necessary to demonstrate compliance, such as current subprocessors, relevant policies, and summary test evidence, subject to confidentiality and security limitations.

Church may request a compliance discussion no more than annually unless a confirmed incident or regulator requires more. Reviews must avoid access to another tenant's information, private Student content, privileged material, or security details that would create risk.

12. Government requests

BIBS will evaluate legal demands for Covered Data, disclose only what it reasonably believes is legally required, and notify affected parties when legally permitted. Nothing in this DPA promises that reflections are privileged or immune from legal process.

13. Conflict, term, and survival

This DPA controls conflicts concerning data protection. It remains effective while BIBS processes Covered Data under the Agreement. Confidentiality, use restrictions, security-incident cooperation, and deletion obligations survive as necessary to fulfill their purpose.

Signatures

BIBS Specialty Services, Inc.
By/name/title/date: [INSERT]

Church
Legal name: [INSERT]
By/name/title/date: [INSERT]