Security
Data processing
Epimely is built for church-owned pastoral-care data. This page explains the practical processing model for churches evaluating privacy, retention, exports, and data-processing addendum requests.
Controller and processor
The church controls the people records, care requests, notes, forms, tasks, and other content it puts into Epimely. Stuart Technologies operates Epimely as a processor on the church's behalf: we use that data to provide, secure, support, and maintain the service.
Purpose limitation
We do not sell church data, use pastoral records for advertising, or share one church's data with another church. Operational access is limited to what is needed to maintain the service, investigate support requests, secure the platform, or meet a legal obligation.
Retention and deletion
Churches decide how long pastoral-care records should remain in their account. Epimely keeps account data while the church maintains an account, supports record deletion where the product exposes it, and can process account-deletion requests. Encrypted backups cycle out over time.
Exports
Authorized administrators can export church data from the app where exports are available. Export actions are security-sensitive and should be handled under the church's own confidentiality and retention policies.
DPA requests
Churches that require a signed data-processing addendum can request one from [email protected]. See also the sub-processors page and Privacy Policy.