VotrexOne

Data Processing Addendum

Last updated: July 20, 2026

This Data Processing Addendum ("DPA") forms part of the agreement between VotrexStudio LLC ("VotrexStudio", "we", "us") and the church or organization that uses VotrexOne (the "Church", "you") (the "Agreement"). It governs our processing of Personal Data on the Church's behalf. Where this DPA conflicts with the Terms of Service on a data-protection matter, this DPA controls.

This DPA is offered to all VotrexOne customers and is incorporated into the Agreement. A church that requires a countersigned copy for its records may request one at [email protected].

1. Definitions

"Personal Data", "Processing", "Controller", "Processor", "Data Subject", and "Personal Data Breach" have the meanings given in applicable data protection law. "Applicable Data Protection Law" means all laws applicable to the processing of Personal Data under the Agreement, including the EU General Data Protection Regulation (GDPR), the UK GDPR, and the California Consumer Privacy Act as amended by the CPRA (the "CCPA"). "Sub-processor" means a third party engaged by VotrexStudio to process Personal Data.

2. Roles of the parties

As between the parties, the Church is the Controller (or a Processor acting on behalf of a third-party controller) of the Personal Data it maintains in its VotrexOne account, and VotrexStudio is the Processor. Under the CCPA, VotrexStudio acts as a Service Provider. VotrexStudio processes Personal Data only on behalf of the Church.

3. Scope and instructions

VotrexStudio will process Personal Data only: (a) to provide, secure, and support VotrexOne; (b) as described in the Agreement and this DPA; and (c) on the Church's further documented instructions. VotrexStudio will inform the Church if, in its opinion, an instruction infringes Applicable Data Protection Law. VotrexStudio does not sell or share Personal Data, does not retain, use, or disclose it for any purpose other than performing the Service, and does not use it for its own commercial purposes or for advertising.

4. Details of processing

See Annex A for the subject matter, duration, nature and purpose of processing, the categories of Data Subjects, and the categories of Personal Data.

5. Confidentiality

VotrexStudio ensures that personnel authorized to process Personal Data are bound by appropriate confidentiality obligations.

6. Security

VotrexStudio implements appropriate technical and organizational measures designed to protect Personal Data, taking into account the state of the art and the nature of the data. These include encryption of data at rest, TLS in transit, per-Church tenant isolation, field-level encryption of connected-account tokens, encrypted offsite backups, two-factor authentication for staff, and least-privilege, logged operator access. Card payment data is processed by Stripe, a PCI-DSS Level 1 certified provider, and does not touch VotrexStudio's systems. Further detail is on our Security page.

7. Sub-processors

The Church authorizes VotrexStudio to engage the Sub-processors listed in Annex B. VotrexStudio imposes data-protection obligations on each Sub-processor that are no less protective than those in this DPA and remains responsible for their performance. VotrexStudio will provide notice of any new Sub-processor, and the Church may object on reasonable data-protection grounds.

8. Data Subject requests

Taking into account the nature of the processing, VotrexStudio will assist the Church by appropriate technical and organizational measures, insofar as possible, to respond to requests from Data Subjects to exercise their rights (including access, rectification, erasure, restriction, portability, and objection under the GDPR, and the rights to know, delete, correct, and opt out under the CCPA). If VotrexStudio receives a request directly from a Data Subject regarding a Church's data, it will, unless legally prohibited, direct the request to the Church.

9. Assistance

Taking into account the nature of processing and the information available to it, VotrexStudio will assist the Church in ensuring compliance with its obligations regarding security of processing, personal data breach notification, and data protection impact assessments.

10. Personal Data Breach

VotrexStudio will notify the Church without undue delay after becoming aware of a Personal Data Breach affecting the Church's Personal Data, provide the information reasonably available to it, and take reasonable steps to mitigate and remediate.

11. Deletion or return of data

On termination or expiry of the Agreement, VotrexStudio will, at the Church's choice, delete or return the Church's Personal Data within a reasonable period, and delete existing copies except where retention is required by law. See our Data Deletion page.

12. Audits

VotrexStudio will make available to the Church information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Church or its mandated auditor, subject to reasonable notice, confidentiality, and frequency limits, or by providing available third-party attestations.

13. International transfers

VotrexStudio is based in the United States and processes Personal Data in the United States. Where the Church transfers Personal Data that is subject to the GDPR or UK GDPR, the parties will rely on an appropriate transfer mechanism, such as the applicable Standard Contractual Clauses, which the parties agree to enter into as required by Applicable Data Protection Law.

14. CCPA

With respect to Personal Information subject to the CCPA, VotrexStudio is a Service Provider. It certifies that it understands the restrictions in CCPA § 1798.140, will comply with them, and will not sell or share Personal Information, or retain, use, or disclose it outside the direct business relationship or for any purpose other than performing the Service, except as permitted by the CCPA.

15. General

This DPA is incorporated into and subject to the Agreement, including its provisions on liability and governing law. If any provision is found unenforceable, the remainder stays in effect.

Annex A — Details of processing

Annex B — Sub-processors

Sub-processorPurpose
StripePayment processing for online giving and subscriptions.
CloudflareContent delivery, TLS, network protection, and encrypted offsite backup storage (R2).
Anthropic (Claude)AI selection of clip-worthy sermon segments and draft social copy.
ResendTransactional and church-branded email delivery.
Google Firebase Cloud MessagingMobile push notifications.
Google / YouTube APIPublishing clips to a Church's own YouTube channel, when connected.
Meta / Facebook Graph APIPublishing clips to a Church's own Facebook Page, when connected.
MapboxAddress autocomplete and maps for location fields.
GIPHYOptional GIF search in messaging (search terms only).
PexelsOptional stock-photo search for event artwork.
bible-api.comLooking up public-domain Scripture passages.

Contact

Data protection contact: [email protected]
VotrexStudio LLC — VotrexOne

Security · Privacy Policy · DPA · Terms of Service · Data Deletion · DMCA
© 2026 VotrexStudio LLC · VotrexOne