Data Processing Agreement
Version 1.0 · Last updated 4 September 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service (the "Agreement") between Kingdom Metrics Inc, 378 Northlake Blvd #246, North Palm Beach, FL 33408, USA ("Kingdom Metrics", the "Processor"; UK ICO registration ZC189018) and the customer church that has accepted the Agreement (the "Customer", the "Controller").
It applies wherever Kingdom Metrics processes Personal Data on the Customer's behalf in providing the attendance-measurement service (the "Service"). For UK customers, the UK GDPR and the Data Protection Act 2018 (as amended, including by the Data (Use and Access) Act 2025) are the applicable "Data Protection Laws"; for other jurisdictions, the equivalent applicable laws. Terms such as Personal Data, processing, Controller, Processor and personal data breach have the meanings given in the Data Protection Laws.
Riders for customers in New Zealand (Privacy Act 2020) and South Africa (POPIA) are provided to those customers at contracting and form part of this DPA for them. Prospective customers may request them at [email protected].
1. Roles
1.1 The Customer is the Controller of Congregation Data and Staff Data (defined in Annex A). Kingdom Metrics is the Processor and processes such data only on the Customer's documented instructions, which are: (a) this DPA, (b) the Agreement, and (c) the Customer's configuration of the Service (schedules, venues, camera placement, validation actions).
1.2 Kingdom Metrics acts as an independent controller only for: (a) the Customer's own account, billing, and business-contact data; and (b) its public website. These are covered by the Kingdom Metrics Privacy Policy, not this DPA.
1.3 Model training. Use of Congregation Data (capture images) to improve Kingdom Metrics' detection models is excluded by default for capture images from venues outside the United States and occurs only with the Customer's express written opt-in for the venue(s) concerned, recorded in the Service. Derived, non-identifying numeric data (point coordinates, counts, statistical profiles) is not Congregation Data and may be retained and used to operate and improve the Service.
1.4 Aggregated insights. Kingdom Metrics may use aggregated, anonymised statistics derived from the Service, never images, never data identifying any individual, and never identifying the Customer without its consent, for service improvement and for published industry insights (for example, cross-customer attendance trends). The Customer may opt out of inclusion in published aggregate insights at any time by notice to [email protected], recorded as a flag on its account.
1.5 UK representative. Kingdom Metrics' representative in the United Kingdom under Article 27 UK GDPR is Prighter Ltd (20 Mortlake High Street, London SW14 8JN), which can be contacted through kingdommetrics.com/uk-representative. The representative is mandated to be addressed by the ICO and by data subjects on all matters concerning the processing described in this DPA, in addition to Kingdom Metrics.
2. Subject matter, nature, and purpose
Detailed in Annex A. In short: scheduled still-image captures of the Customer's worship venue(s) are processed by computer-vision models to produce aggregate attendance counts. The Service does not perform facial recognition, identification, or tracking of individuals, and produces no individual-level profiles. Images necessarily include photographs of identifiable congregants and visitors, including children; in a worship context these may reveal religious belief and are treated with the safeguards appropriate to special-category data.
3. Controller obligations
The Customer warrants that it: (a) has a lawful basis under Article 6 and an applicable Article 9 condition for the capture of congregation imagery in its venue(s); (b) provides transparency to congregants (signage at venue entrances and/or notice in its own privacy information, naming attendance measurement and Kingdom Metrics as processor; Kingdom Metrics provides template signage text on request); (c) will not instruct processing that violates Data Protection Laws.
4. Processor obligations (Article 28(3))
Kingdom Metrics shall:
- (a) process Congregation Data only on documented instructions (section 1.1), including with regard to international transfers (section 9), unless required otherwise by law (in which case it will inform the Customer unless legally prohibited);
- (b) ensure persons authorised to process the data are bound by confidentiality (all Kingdom Metrics personnel are under written confidentiality obligations);
- (c) implement the technical and organisational measures in Annex B;
- (d) engage sub-processors only per section 7 and Annex C;
- (e) assist the Customer, insofar as possible, in responding to data-subject requests (section 6);
- (f) assist the Customer with Articles 32 to 36 (security, breach notification, DPIAs; Kingdom Metrics provides a DPIA support pack describing the Service's data flows on request);
- (g) delete or return Personal Data at the end of the Agreement (section 8);
- (h) make available information necessary to demonstrate compliance and allow audits (section 10);
- (i) immediately inform the Customer if, in Kingdom Metrics' opinion, an instruction infringes Data Protection Laws.
5. Personal-data breach
5.1 Kingdom Metrics shall notify the Customer without undue delay and in any event within 72 hours of becoming aware of a personal-data breach affecting Congregation Data or Staff Data, with the information required by Article 33(3) (nature, categories and approximate numbers, likely consequences, measures taken), supplemented in phases as investigation continues. Initial notification is not delayed pending completion of the investigation.
5.2 "Becoming aware" means having a reasonable degree of certainty that a security incident has compromised Personal Data. The 72-hour outer bound matches the incident-notification commitment on our security page; the Customer's own regulatory notification period runs from the Customer's awareness.
6. Data-subject rights assistance
6.1 Kingdom Metrics routes any data-subject request it receives directly to the Customer within 5 business days and does not respond substantively except on the Customer's instruction.
6.2 On instruction, Kingdom Metrics will: locate and permanently delete a specific capture image (the derived attendance count for that service, which identifies no one, is retained unless the Customer asks for it to be removed as well); provide a copy of stored images and counts for a specified venue and period; or restrict processing for a venue or schedule (disable capture).
6.3 Complaints: under section 164A of the Data Protection Act 2018, the Customer owns congregant complaints; Kingdom Metrics acknowledges any complaint it receives about its own controller processing within 30 days via [email protected].
7. Sub-processors
7.1 The Customer grants general written authorisation for the sub-processors in Annex C. Kingdom Metrics gives at least 30 days' notice of intended additions or replacements (email to the Customer's primary contact); the Customer may object on reasonable data-protection grounds, in which case the parties cooperate on a resolution and the Customer may terminate the affected Service if none is found.
7.2 Kingdom Metrics imposes data-protection obligations on each sub-processor materially equivalent to this DPA and remains liable for their performance.
8. Retention, deletion, and return
8.1 Capture images are retained per the retention schedule in Annex A. For venues in the United Kingdom this is a rolling 90 days, after which images are permanently deleted from primary storage; residual copies in system snapshots expire within 7 days (Annex B, item 5). Derived numeric data (counts, coordinates, aggregate statistics) is retained for the life of the Agreement as it does not identify individuals.
8.2 On termination, at the Customer's choice, Kingdom Metrics returns (as an export of stored capture images and attendance data for the Customer's venues) and/or deletes all Congregation Data and Staff Data within 30 days of the effective termination date (subject to the same snapshot tail), and certifies deletion on written request. Kingdom Metrics retains Personal Data after that only to the extent, and for as long as, applicable law requires (for example, billing and tax records).
9. International transfers
9.1 The Service is operated from the United States. For UK customers, the transfer of Personal Data to Kingdom Metrics is a restricted transfer under UK GDPR Chapter V, and the parties execute the ICO International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses (Annex D), which forms part of this DPA and prevails over it in case of conflict.
9.2 Kingdom Metrics maintains the supplementary measures in Annex B (encryption in transit and at rest, access controls) in support of the transfer risk assessment.
10. Audit
10.1 Kingdom Metrics makes available on request: this DPA's annexes kept current, its ICO registration, security-measure documentation, and questionnaire responses.
10.2 The Customer may audit (itself or via a mandated auditor that is bound by confidentiality and is not a competitor of Kingdom Metrics) no more than once per 12 months on 30 days' notice, during business hours, without access to other customers' data. Kingdom Metrics may first meet an audit request with the information in section 10.1 where that reasonably answers it. The Customer bears the cost of any audit, including Kingdom Metrics' reasonable time and expenses in supporting it; findings are confidential.
11. Liability
Liability under this DPA is subject to the limitation of liability in the Agreement, except that for claims arising from Kingdom Metrics' breach of this DPA or of Data Protection Laws, Kingdom Metrics' total liability to the Customer is limited to the fees paid by the Customer under the Agreement in the 12 months before the event giving rise to the claim. Nothing in this DPA limits liability that cannot be limited by law.
12. Term and remedies
12.1 This DPA is effective for the duration of the Agreement plus the deletion period in section 8.
12.2 If Kingdom Metrics is in material breach of this DPA and does not cure the breach within 30 days of written notice, the Customer may suspend the affected processing or terminate the Agreement.
13. Order of precedence and governing law
13.1 This DPA prevails over the Agreement for data-protection matters; Annex D (transfer instrument) prevails over this DPA.
13.2 For customers in the United Kingdom this DPA is governed by the laws of England and Wales. For other customers it is governed by the law governing the Agreement, except where a jurisdiction rider provides otherwise.
Annex A: Details of processing
| Item | Description |
|---|---|
| Subject matter | Automated attendance measurement for worship services |
| Duration | Term of the Agreement plus the section 8 deletion period |
| Nature | Scheduled still-image capture from Customer-sited cameras; encrypted relay transport; computer-vision person detection producing point coordinates and counts; optional human validation by Customer staff; aggregate reporting; optional one-time import of the Customer's historical attendance totals (aggregate counts, non-personal) |
| Purpose | Producing aggregate attendance counts and trends for the Customer |
| Data subjects | Congregants and visitors present in the venue (including children); Customer staff and volunteers (portal accounts) |
| Personal data: Congregation Data | Venue photographs including identifiable individuals (no names attached; no facial recognition performed). Context (worship service) may reveal religious belief; handled as sensitive |
| Personal data: Staff Data | Portal account name, email, role; validation actions |
| Special category | Religious belief, by inference from presence at worship (images only; never extracted as a data point) |
| Retention: images | Venues in the United Kingdom: rolling 90 days, then permanent deletion (section 8.1). Other venues: the retention period configured for the Customer (minimum 7 days); where none is configured, the term of the Agreement |
| Retention: derived counts and coordinates | Life of the Agreement (non-identifying) |
| Frequency | Per Customer-configured schedule (typically weekly services) |
Annex B: Technical and organisational measures
- Encryption in transit: TLS on all public endpoints; mutual TLS between internal services; camera transport over the manufacturer's encrypted relay protocol.
- Encryption at rest: AES-256-GCM volume encryption on database and object storage; camera and WiFi credentials additionally encrypted application-side via isolated secrets.
- Access control: role-based access (admin vs customer); customer-facing views are scoped to the Customer's own venues and data; images are served only through an authenticated proxy (no public or presigned URLs); production host access restricted to named operators via SSH keys.
- Monitoring: centralised structured logging with secret-scrubbing; automated alerting; access and deploy audit trails.
- Backups: database backups retained approximately 30 days, the offsite copy held in Google Workspace storage under Google's at-rest encryption; capture images are excluded from offsite backup by design; storage snapshots expire on a bounded schedule (at most 7 days).
- Data minimisation: no facial recognition; no identity extraction; counts and coordinates are the work product; camera framing reviewed at placement to cover seating areas only.
- Personnel: small named-operator team; written confidentiality obligations; production changes gated by automated safety checks.
Annex C: Sub-processors
Sub-processors are listed here by category. The current named list is provided to customers at contracting and to prospective customers on request ([email protected]). Additions or replacements are notified at least 30 days in advance (section 7.1).
| Category | Purpose | Personal data touched | Location |
|---|---|---|---|
| Edge network, TLS and web hosting | Serving the website, portal and API | Traffic metadata; portal and API traffic in transit | USA / global |
| Business email and offsite backup storage | Email to Customer contacts; database backup copies | Email content; database backup copies (no capture images) | USA |
| Payment processing | Billing | Billing contact and payment records | USA |
| SMS and voice notifications | Operational notifications | Contact phone numbers, message content | USA |
| Internal operations messaging | Alerts and support tooling | Operational alerts; live venue stills requested by operators for troubleshooting and camera placement (may include people present); uploaded files retained per the provider's workspace retention | USA |
| Camera manufacturer's encrypted relay | Camera transport | Encrypted capture transport | Global |
| Cloud computer-vision inference | Person detection | Capture images processed transiently during inference; not retained by the provider and not used for the provider's own training; being replaced by Kingdom Metrics' own GPU infrastructure | USA |
The Customer's own church-management system (for example Planning Center or Church Metrics) receives aggregate counts at the Customer's direction and is the Customer's vendor, not a sub-processor.
Annex D: International transfer instrument
For UK customers, the ICO International Data Transfer Agreement (or the UK Addendum to the EU Standard Contractual Clauses) executed between the parties forms part of this DPA and prevails over it in case of conflict.
Changes and contact
Version 1.0, September 2026: first published version. Material changes are notified to the Customer's primary contact; sub-processor changes follow section 7.1. Questions: [email protected].