Back to homeNexclesia

Privacy Policy

Last updated: September 2026

Who we are and our role

Nexclesia provides church-management software to churches and religious organisations (our "Customers"). This policy explains what personal data we handle, why, who we share it with, and the choices and rights available to the people whose data we process.

For the data a church puts into the service about its members, visitors, donors and children, the church is the data controller and Nexclesia is a data processor acting on the church's documented instructions. Nexclesia is the controller for the limited data we hold about church administrators' accounts and about visitors to our own marketing website.

Each church is responsible for having a lawful basis (including any required consent — see "Children's data" and "Communications") for the personal data it collects, and for giving its own people an appropriate privacy notice. This policy does not replace legal advice; Customers should confirm their obligations under the Nigeria Data Protection Act 2023 (NDPA), the NDPR and any other law that applies to them.

Information we process

Depending on the features a church uses, the service may process:

  • Administrator and staff accounts: name, email, phone, role and login credentials (passwords are stored only as a secure one-way hash).
  • Member records: names, contact details, home address, gender, date of birth, marital status, occupation, photo, emergency contact, family relationships, group and department membership, attendance, and administrator-defined custom fields.
  • Religious and spiritual data: church membership itself, plus records such as salvation/rededication decisions, baptism, discipleship and ministry progress, and prayer requests. This is special-category data and is inherent to the service.
  • Children's data: for churches using the Children's Ministry module — a child's name, full date of birth, gender, optional photo, school/grade, health and safety information (allergies, medical notes, dietary needs, special needs, emergency instructions), guardian and authorised-pickup details, custody/pickup restrictions, and a check-in/check-out custody record. See “Children's data”.
  • Pastoral and care data: care cases (e.g. hospitalisation, bereavement, counselling, financial hardship, family or emergency situations) and pastoral notes, which may include health and other sensitive information.
  • Visitor and first-timer data: name, contact details, how they heard about the church, interests, follow-up notes and communication history.
  • Financial and giving data: donation and payment records, receipts, funds, cash counts, a double-entry accounting ledger, uploaded bank statements, subscription and billing records, and each church's own settlement bank-account details. We do not receive or store full card numbers (see “Payments”).
  • Communications: the content and delivery status of emails and SMS messages sent through the service, and email opt-out records.
  • Uploaded files: images, documents and media uploaded to member/child profiles, church branding, events, media libraries and custom forms.
  • Technical and usage data: IP address (sometimes stored only as a one-way hash), device and browser information, activity and audit logs, and cookies (see “Cookies and analytics”).

How we collect it

Personal data reaches the service in several ways:

  • Entered by church staff in the administrator dashboard, or imported in bulk by the church.
  • Entered by members and leaders in the member portal.
  • Submitted through public, no-login pages a church chooses to publish — visitor sign-up, member self-registration, online giving, custom forms, and children's-ministry family registration. Member self-registration creates a portal login and emails a set-up link.
  • Generated automatically as people use the service — attendance check-ins, logs, and cookies.

Where a church publishes a public form, the church is responsible for the notice and consent shown to the people who fill it in, including obtaining verifiable parental consent before collecting a child's information.

How we use it and our legal bases

We use personal data to:

  • Provide the service to the church — the dashboard, member portal, check-in, giving and finance, communications, events, care and children's-ministry features (processing to perform our contract, and on the church's instructions as its processor).
  • Send transactional messages such as account set-up links, password resets and receipts, and — where the church enables them — welcome and reminder messages on the church's behalf.
  • Keep the service secure, prevent abuse and fraud, and diagnose problems (our and our Customers' legitimate interests).
  • Meet legal, accounting and tax obligations.

We do not sell personal data, and we do not use member, donor or children's data for advertising or to train our own models.

Children's data

Churches that use the Children's Ministry module process personal data about minors, including full date of birth, health and safety information, and custody/safeguarding details. This is sensitive data and we treat it with particular care.

The church is the controller of this data and must obtain verifiable consent from a parent or legal guardian before collecting or entering a child's information, and must provide its own child-appropriate privacy notice. We process children's data only to provide the module to the church (for example, secure check-in and pickup verification).

Because much of this information exists for child-safety reasons, some records (such as guardian, authorised-pickup and pickup-restriction history, and access audit trails) are retained even after they are revoked, and are not routinely deleted. Children do not receive their own login and are excluded from directories, broadcasts and our AI features. A parent or guardian who wishes to access, correct or delete a child's information should contact the church.

AI features

Some optional features use a third-party large-language-model (AI) provider to power the administrator AI assistant, generate summaries and insights, and help parse uploaded bank statements. These features are read-only: they cannot change your data, and are limited by each user's permissions.

When an administrator uses these features, the relevant data is sent to the active AI provider to produce the response. Depending on the feature this can include member or visitor names and details, pastoral or communication content, aggregate church statistics, or the contents of an uploaded bank statement. Children's data is excluded from the AI assistant.

The AI provider processes this data to return a result; its own handling of that data is governed by its terms. AI output can be inaccurate and is provided to assist, not replace, human judgement. If your church does not want AI processing, ask us and it can be left disabled.

Payments

Payments — subscription fees, SMS credits, online giving and paid event tickets — are processed by Paystack. Card, bank and USSD details are entered on Paystack's own hosted checkout and are never transmitted to or stored by us; we store only the resulting transaction record (amount, reference, status and, where applicable, the giver's identity).

For member giving and event tickets, funds settle directly to the church's own bank account through the church's Paystack account; we do not hold or take a share of congregants' donations. To enable settlement, a church's bank-account and business details are shared with Paystack. A payer's IP address is stored as a one-way hash to help prevent fraud and abuse on public giving pages.

Communications and your choices

The service sends two kinds of message on a church's behalf: transactional messages (such as set-up links, password resets and receipts) that are necessary to operate an account, and non-transactional messages (such as broadcasts, newsletters and welcome or reminder messages) that a church chooses to send.

Email broadcasts include an unsubscribe link, and an unsubscribe is honoured for that church's future broadcasts. To stop other messages, or to opt out of SMS, contact the church that holds your data; you can also use your mobile network's Do-Not-Disturb service for SMS. Because the church controls its own messaging, please direct message-preference requests to the church in the first instance.

Cookies and analytics

We use a small number of strictly-necessary cookies to keep you signed in and to remember your current view — for example the session cookie and a branch-selection cookie. These are required for the service to work.

We also use analytics to understand how our site and app are used. Vercel Analytics is cookieless. Where Google Analytics is enabled, it sets analytics cookies and shares usage signals with Google; you can opt out using Google's browser opt-out or your browser's cookie controls. We are expanding our cookie controls, and where the law requires consent for non-essential cookies we will obtain it.

Who we share data with

We share data only with the service providers ("sub-processors") that help us run the service — for example hosting and database, payment processing, email and SMS delivery, AI features, error diagnostics and analytics. Each is bound to protect the data and to use it only on our instructions. We may also disclose data where required by law, to protect our rights or safety, or in connection with a business transfer. We never sell personal data.

Churches can request our current list of sub-processors and a Data Processing Agreement by contacting us.

International transfers

Our database and much of our infrastructure are hosted in the United States, and several of our sub-processors are located outside Nigeria. This means personal data — including member, financial and children's data — is transferred to and processed in other countries.

Where we transfer data internationally, we rely on the transfer mechanisms available under the NDPA and applicable law and on our sub-processors' contractual and security commitments to protect it.

Security

Data is encrypted in transit (TLS) and at rest. Access within the service is restricted by role-based permissions and per-church data isolation, sensitive actions are logged, and we keep regular backups (retained for about 30 days). No system is perfectly secure, but we take reasonable technical and organisational measures to protect personal data, and we expect churches to keep their own credentials secure and to grant access only to those who need it.

How long we keep it

We keep a church's data for as long as its account is active. When a church closes its account, deletion is scheduled after a 30-day grace period (during which it can be cancelled), after which the church's data is permanently removed from our live systems; residual copies may persist in encrypted backups for up to about 30 days more.

Some records are kept longer where we have a legal or operational reason: financial and accounting records (including the giving ledger) are retained for accounting and legal-compliance purposes and may be immutable by design; audit and security logs are retained; and certain children's-safeguarding records are retained as described above. Within an active account, deleting a member usually deactivates the record; a permanent member deletion detaches (rather than erases) their historical giving so financial totals stay accurate.

Your rights

Subject to applicable law (including the NDPA, and the GDPR where it applies), individuals have rights to access, correct, delete, restrict or object to the processing of their personal data, and to data portability.

Because each church controls its members' data, members and visitors should exercise these rights with their church, which can action most requests directly in the service. Churches can export their data and request account deletion from within the service. We support churches in responding to such requests. Note that our current data export and erasure tools operate at the church level; we are continuing to improve individual-level self-service.

If you have a concern we have not resolved, you may contact us at privacy@nexclesia.io, and you have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC) or your local supervisory authority.

Changes to this policy

We may update this policy as the service and the law change. We will revise the date above and, for material changes, take reasonable steps to notify Customers.

Contact

Questions or requests about this policy? Email privacy@nexclesia.io. Churches can also request a Data Processing Agreement.

See also our Terms of Service.