Data Protection & Regulatory Compliance
AsoreOnline is built on a foundation of trust, privacy, and technical rigor. Learn how we safeguard church data, uphold statutory compliance, and maintain enterprise security standards.
Compliant by Design
We understand the sensitive nature of pastoral records, member tithes, and children check-in details. Our platform complies with the Data Protection Act (Act 843) and international security standards to ensure your ministry operates safely in the digital age.
Data Protection & Governance
Compliant with the Ghana Data Protection Act, 2012 (Act 843) and international data governance frameworks.
- Strict multi-tenant software architecture ensuring complete data segregation between churches.
- Data collected is processed solely for providing management services to subscriber churches.
- Churches retain 100% legal ownership of their member, financial, and attendance records.
- Opt-in and explicit consent workflows for member communications and children check-in records.
Security Infrastructure & Encryption
Enterprise-grade security controls maintaining strict confidentiality and integrity.
- Encryption in Transit: All endpoints use TLS 1.3/HTTPS encryption with HTTP Strict Transport Security (HSTS).
- Data Isolation: Application-layer tenant validation header (x-church-id) enforced on every API transaction.
- Access Controls: Strict Role-Based Access Control (RBAC) ensuring staff see only assigned domain data.
- Credential Protection: Bcrypt salted password hashing; JWT tokens with configurable expiration.
Data Retention & Rights (DPO / Data Subject Rights)
Empowering church administrators and members with complete control over their personal data.
- Right to Access & Export: Administrators can export membership and financial records in standard formats (XLSX, CSV, PDF).
- Right to Erasure: Soft and hard deletion options for member profiles upon formal request.
- Account Closure Retention: Data retained for 30 days post-cancellation before permanent purges from active databases.
- Audit Logging: Security and financial transaction logs retained for compliance reconciliation.
Third-Party Sub-Processors & Infrastructure
Strictly vetted third-party vendors adhering to industry security and privacy standards.
- Paystack / Mono: PCI-DSS compliant payment gateways processing subscriptions and member tithes/donations.
- Arkesel / Resend: Telecom and email partners for transactional SMS and email delivery.
- Cloudflare / AWS R2: Global CDN, Web Application Firewall (WAF), and encrypted cloud storage.
- Sentry & Monitoring: Anonymized error logging and system uptime tracking.
Frequently Asked Compliance Questions
Clear answers regarding data sovereignty, storage, and privacy rights.
Who owns our church data?
Your church owns all data entered into AsoreOnline. AsoreOnline operates as a Data Processor, while your church serves as the Data Controller under applicable data protection laws.
Can members request their data to be deleted?
Yes. Church administrators can delete or anonymize member records directly from the portal. Inquiries sent directly to AsoreOnline regarding church member data are routed to the designated church administrator.
How are financial records handled?
Payment details (card numbers, mobile money PINs) are processed directly by PCI-DSS compliant partners like Paystack and Mono. AsoreOnline never stores raw card credentials or payment PINs.
How do I request a Data Processing Agreement (DPA)?
Registered churches can request a signed DPA tailored to their organizational needs by emailing our compliance team at privacy@asoreonline.com.
Have questions regarding regulatory compliance, security audits, or data protection officer (DPO) requests?
Contact our Data Protection Office at privacy@asoreonline.com