Privacy notice

Your data, protected by design.

This page explains what FFWPU Manager collects, how it is used and how it is protected. It is maintained by the FFWPU Africa administration and is provided as an app-owned notice — not a formal certification.

Role-based access

You only see records permitted by your role and assigned scope (region, nation or church).

Row-level security

Every protected table enforces access rules server-side — not just in the browser.

Audit logs

Approvals, role changes, finance decisions, imports and exports are recorded.

Information we collect

To administer membership, FFWPU Manager stores the information you provide during registration and profile completion, including your name, contact details, location (region, nation, city, church), blessing status, membership category, emergency contact, and any documents you upload.

Administrators additionally record attendance, financial transactions, allowances, asset records and announcements. These records are linked to your profile only where relevant (for example, an attendance record for a session you attended).

How we use your information

  • Verify your membership and produce your member ID card.
  • Record and report attendance at programs and worship sessions.
  • Manage donations, allowances and expenses for your church, nation or region.
  • Send you announcements and notifications relevant to your scope.
  • Produce internal leadership dashboards and administrative reports.

We do not sell your data and we do not share it with third parties for marketing.

Who can see your data

Members can only view and edit their own profile, documents, notifications, support requests and attendance history. Administrators can only see records within the region, nation or church assigned to their role. Only Super Admin can assign roles and change critical system settings.

How your data is protected

  • Authentication is provided by our managed identity provider; passwords are never stored by the app.
  • All traffic between your device and the platform is encrypted in transit (HTTPS).
  • Every protected table enforces row-level security policies server-side.
  • Uploaded documents are stored in private buckets and accessible only to authorized roles.
  • Sensitive administrative actions run through server-side checks and are written to an audit log.

Lawful basis and consent

Each category of processing has a stated lawful basis. Membership administration rests on performance of a contract, accounting records on legal obligation, and religious affiliation data on your explicit consent under Article 9 of the GDPR. Photographs, newsletters and health or family information are optional and rest on consent alone.

Signed-in users can review every notice, see which version they accepted and withdraw any optional consent from the in-app Consent Centre. Withdrawal affects future use of your data and does not undo processing already carried out lawfully.

Where your data is stored

Member records are hosted in the European Union. A current list of the processors and sub-processors we rely on, what each one does and where it stores data, is published on our subprocessor list. We do not sell your data and we do not share it with third parties for marketing.

Data retention

We keep each category of record only as long as it is needed. Membership and attendance records are retained for the duration of membership and a defined period afterwards; financial and accounting records are retained for the statutory period required by law; support messages, notifications and audit entries follow shorter schedules. The full retention schedule is maintained inside the platform and enforced by scheduled review.

Your rights

You have the right of access, rectification, erasure, restriction, objection and data portability. Signed-in users can exercise these directly from the in-app Privacy Centre: download a complete structured copy of your data instantly, or submit a rectification, erasure, restriction or objection request. We respond to every request within one month.

Where we erase your data we remove or pseudonymise your personal details; financial and accounting entries are kept in pseudonymised form where the law requires them to be retained.

Contact and complaints

Privacy requests are handled by our data protection contact. Raise a request from the in-app Privacy Centre or Support module after signing in, or contact your national or regional office directly. If you are not satisfied with how we handle your request, you may lodge a complaint with your national data protection supervisory authority.

This notice is maintained by the FFWPU Africa administration and may be updated as the platform evolves. Continued use of the platform after an update constitutes acceptance of the revised notice. Return to the home page or read about the platform.