Ekklesia
Effective date: 16 July 2026
This Privacy Policy explains how Nylank Technologies ("Nylank", "we", "us", or "our") collects, uses, shares, and protects personal data when you use the Ekklesia church administration platform (the "Service"), which is operated by Nylank Technologies. It is designed to comply with the Nigeria Data Protection Act, 2023 (NDPA), applicable regulations issued under it (including related NDPR instruments), and, where applicable, the EU GDPR and UK GDPR.
Nylank Technologies operates the Ekklesia church administration platform. In this Privacy Policy, references to "Ekklesia", "we", "us", and "our" mean Nylank Technologies in its capacity as operator of the Service, unless the context clearly refers to the product brand.
Contact for general support: support@ekklesia.it.com. Privacy Contact: support@ekklesia.it.com with the subject line "Privacy" (a dedicated privacy mailbox may be published here when available).
Our primary public application domains include app.ekklesia.it.com and related Organization subdomains or custom domains configured by churches. The Service may also include related applications and APIs.
Nylank Technologies operates from Nigeria. Registered company name (including any corporate suffix), incorporation details, and registered address will be provided on request or updated on this page when published.
Most Church Data (member profiles, attendance, pastoral notes you choose to store, event assignments, giving records entered by the church, etc.) is processed on behalf of the Organization. In that capacity the Organization typically determines the purposes of processing (controller / data controller under the NDPA and other applicable laws) and Nylank Technologies processes data under the Organization's instructions (processor).
Nylank Technologies acts as an independent controller for platform account data needed to operate the Service itself—for example authentication credentials, security logs, billing or plan metadata, Platform Operator accounts, abuse prevention, and limited product analytics that do not replace the church's own ministry records.
If you are a member of a church using Ekklesia, many privacy requests (correction of ministry records, deletion of church-held profile fields) should be directed first to your church administrators. We will assist Organizations in fulfilling valid requests.
Organizations are responsible for ensuring the accuracy of data they upload or enter into the Service, and for obtaining any consents or other lawful bases required for that data.
Depending on how you use the Service, we may process:
Account data: name, email, phone number, password hashes, organization membership, and roles/permissions.
Profile and ministry data entered by you or your Organization: addresses, dates of birth, family links, team or volunteer assignments, attendance, notes (including pastoral or ministry notes the Organization chooses to store), support tickets, and similar records.
Media and files: church logos, uploaded documents or attachments, and other files the Organization stores in the Service.
Visitor and check-in data: visitor details and optional consent to receive church updates.
Children's program data: child profiles linked to guardians, check-in/check-out events, and related safety information entered by the Organization.
Communications metadata: notification preferences, delivery status, bounce/complaint signals for email.
Technical and security data: IP address, device/browser information, approximate location derived from network data, cookies or similar technologies, security/audit logs, and API or service usage records generated by operating the platform.
Product analytics data: feature usage, navigation patterns, crash or error reports, and performance metrics used to improve the Service (not to monitor pastoral care content for marketing).
Payment or plan data if paid features apply (processed via our payment providers as applicable).
Provide, authenticate, and secure the Service.
Enable Organization administration, member tools, events, notifications, and support.
Send transactional emails (verification, password reset, invitations, operational notices).
Send or allow church-initiated communications consistent with consent and preferences.
Monitor abuse, spam, fraud, and security incidents.
Improve reliability, performance, and product features through limited product analytics (feature usage, crashes, and performance), based on our legitimate interests in operating and improving the Service where that basis applies.
Comply with legal obligations and enforce our Terms.
We rely on one or more of: performance of a contract (providing the Service you requested); legitimate interests (securing and improving the platform, preventing abuse, and limited product analytics); consent (where required for optional marketing or certain cookies); and legal obligation.
Organizations are responsible for establishing a lawful basis for Church Data they upload or instruct us to process—including consent or other bases for member communications and children's data under the NDPA and other applicable laws.
We do not use personal data to make solely automated decisions that produce legal or similarly significant effects concerning individuals.
We do not sell personal data.
We share personal data with service providers (processors) who help us operate the Service, under confidentiality and data-processing terms. These may include:
Hosting and infrastructure providers.
Email delivery providers.
File storage providers.
Monitoring and security tooling.
Payment processors (where paid features apply).
Customer support tooling (where used).
Separately from processor sharing, we may disclose information when required to comply with applicable law, court orders, or lawful government requests; to protect the rights, safety, and security of Nylank Technologies, our users, or others; or to investigate fraud, abuse, or security incidents.
Platform Operators (Nylank staff with control-plane access) may access tenant information only on a need-to-know basis for support, security, maintenance, billing, or legal compliance. Such access is logged where feasible and is subject to confidentiality obligations. Access is exceptional and controlled—not routine browsing of pastoral records.
Within an Organization, Administrators and authorized roles can access Member and Church Data according to role-based permissions configured in the workspace.
A current list of material subprocessors is available upon request at support@ekklesia.it.com (subject line "Subprocessors").
The Service and our providers may process data in countries other than where you live. Where required by applicable law (including GDPR where it applies), we use appropriate safeguards such as contractual protections or equivalent transfer mechanisms for cross-border transfers.
We retain personal data for as long as needed to provide the Service, fulfill Organization instructions, resolve disputes, enforce agreements, and meet legal or security requirements.
After Organization closure or a validated deletion request, we delete or anonymize personal data from active systems within a commercially reasonable period (typically aiming to complete primary deletion promptly after closure processing is finished), except where retention is required by law or needed for security, fraud prevention, or dispute handling.
Residual copies may remain in access-restricted backups for a limited additional period until those backups are rotated or purged in the ordinary course. Operational backups are not a user archive; restoration of specific records is not guaranteed.
Organizations should export or retain copies of important records as needed for their own compliance. Specific retention timelines for particular data types may be confirmed on request where we publish operational schedules.
We implement reasonable administrative, technical, and organizational measures designed to protect personal data, including HTTPS encrypted transport, password hashing, role-based access controls within Organizations, monitoring, and audit logging for sensitive platform and finance actions where implemented. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Please use strong unique passwords and protect your devices.
Subject to applicable law (including the NDPA and GDPR where they apply), you may have the right to request access, correction, deletion, restriction, portability, or objection to certain processing, and to withdraw consent where processing is consent-based.
Members should usually contact their church Administrators for Church Data requests. You may also contact our Privacy Contact at support@ekklesia.it.com with the subject line "Privacy". We may need to verify your identity.
Where Nylank Technologies acts solely as a processor for Church Data, we may be unable to respond to a request directly and will refer it to the relevant Organization (or assist that Organization in responding).
You may have the right to lodge a complaint with a supervisory authority (for example Nigeria's data protection authority under the NDPA framework, or your local EU/UK authority if GDPR applies).
Ekklesia includes features for children's ministry (such as kids profiles and check-in). Those features are intended for use by churches and guardians, not for children creating their own platform accounts.
We do not knowingly permit children to create independent accounts on the Service unless specifically enabled by an Organization in a manner that is legally appropriate under applicable law.
Organizations are responsible for obtaining all permissions and parental or guardian consents required under applicable law before collecting or processing children's personal information through the Service, and must only enter children's data for legitimate ministry and safety purposes. Contact the Organization or our Privacy Contact for questions about children's records.
We use cookies and similar technologies in these categories:
Essential cookies: authentication, security, session management, and load balancing required for the Service to function.
Preference cookies: remembering settings such as UI preferences where used.
Analytics cookies: limited product-usage measurement where used to understand how the Service performs.
Where required by law, we will request consent for non-essential cookies. You can usually control cookies through your browser settings; blocking essential cookies may prevent parts of the Service from working.
Platform emails are controlled by Nylank Technologies as operator of Ekklesia. These include transactional messages needed to operate your account (for example verification, password reset, invitations, and security or service notices).
Church emails and member notifications are controlled by the Organization. Churches decide who receives ministry or event communications, subject to their own consent practices and in-product notification preferences where available. Visitor feedback flows may capture consent for church updates where offered.
Email footers include links to our Terms and this Privacy Policy. Contact our Privacy Contact for questions about platform-level communication preferences we control.
If we become aware of a personal data breach affecting Church Data, we will notify affected Organizations where required by applicable law and will cooperate with them as reasonably necessary to meet their own notification obligations.
If Nylank Technologies is involved in a merger, acquisition, corporate reorganization, financing, or sale of assets (including a transfer of the Ekklesia Service to an affiliate or successor), personal data may be transferred as part of that transaction, subject to appropriate confidentiality and continued protection consistent with this Privacy Policy (or notice of material changes).
We may update this Privacy Policy from time to time. The effective date at the top of this page will change when we do. Significant changes may also be communicated in-product or by email where appropriate.
Legal entity: Nylank Technologies (operator of Ekklesia).
Privacy Contact: support@ekklesia.it.com (subject line "Privacy"). General support and in-app support tickets are also available in Organization workspaces where enabled.
Also see our Terms & Conditions.