This is the same data agreement we sign with any church whose team needs one in writing. It is published here so you can read it before you ask. A signable Word copy is available — email security@visiongenesisai.com.
Between Vision Genesis Partners ("Provider," operating AskMyChurch) and your church ("Church"), attached to and governed by your service agreement.
1. Roles. The Church controls its data. Provider processes it only to run the Church's assistant: answering visitor questions from the Church's published content, routing crisis messages to help lines and the Church's own contacts, and reporting anonymous usage to the Church.
2. What Provider processes. (a) The Church's published content: website pages, sermons, podcasts, and documents the Church supplies or makes public. (b) Visitor questions and the assistant's answers, retained per Annex A. (c) Contact details a visitor chooses to share, delivered to the Church. Provider does not process membership rolls, giving records, counseling notes, or attendance lists, and the assistant cannot answer from data it never ingests.
3. No training, no sale. Neither Provider nor its AI subprocessors use the Church's content or its visitors' messages to train models. Provider does not sell or share data for advertising. Ever, not as a tier.
4. Sensitive messages. Messages the assistant detects as sensitive or pastoral are stored as an anonymous category and count only; the words are discarded at write time. Crisis messages are answered by a hard-coded referral (988, Crisis Text Line, the Church's own care contacts) before any AI model receives them.
5. Subprocessors. Annex B lists every subprocessor. Provider gives the Church 30 days' notice before adding one, and the Church may object in writing on reasonable data-protection grounds.
6. Security. Provider maintains the measures in Annex A and will not weaken them during the term.
7. Breach notice. Provider notifies the Church of a confirmed personal-data breach affecting the Church's data without undue delay and no later than 72 hours after confirmation, with what is known: what happened, whose data, what Provider is doing, and what the Church should do.
8. Deletion and return. During the term, the Church can export its content and correct or remove sources at any time from its dashboard. On termination, Provider deletes the Church's content and conversation data within 30 days, except records law requires Provider to keep (billing).
9. Assistance. Provider gives the Church reasonable help answering data-subject requests and completing the Church's own assessments, at no charge for anything answerable from Annex A and this DPA.
10. Audit. Once per year, on 30 days' notice, the Church may send a written security questionnaire, and Provider answers within 15 business days. On-site or technical audits: only where law requires, scoped, at the Church's cost.
11. Data location. Data is processed and stored on Cloudflare's global network. Provider does not promise a specific country of storage. Regional residency is a custom term, priced separately.
12. Liability. This DPA shares the liability cap of the service agreement; it does not create a separate pool.
Everything here is what the system verifiably does today. The full detail, with mechanisms, is on our security page.
Version 1 · Last reviewed: August 18, 2026. For a signable Word copy, email security@visiongenesisai.com.