Last updated · 20 August 2025
Privacy policy.
Who we are
The Purpose Center Church (“the Church”, “we”, “us”, “our”) is committed to respecting and protecting your privacy in accordance with the Data Protection Act, 2019 and related regulations in Kenya. We are a registered Data Controller and hold a valid Data Controller Certificate issued by the Office of the Data Protection Commissioner (ODPC).
This Privacy Policy explains how we collect, use, disclose, store and secure your personal data when you interact with us through all church-related activities and events, including but not limited to Rhema Feast, worship services, seminars, conferences, workshops, missions and other events hosted or organized by the Church or our website.
1. What is personal data?
“Personal Data” refers to any information that can identify you directly or indirectly. This includes, but is not limited to:
- Full name, national ID or passport details
- Contact details (phone number, email, address)
- Date of birth and gender
- Payment or donation information
- Emergency contacts
- Health-related information voluntarily shared with us (for example accessibility needs, or other medical considerations)
- Photos, videos, or recordings taken during church services or events
2. When do we collect your personal data?
We collect your personal data when:
- You register for church events, including Rhema Feast and other annual gatherings.
- You attend church services, prayer meetings, small groups, or other ministry activities.
- You sign up for volunteer programs, outreach missions, or discipleship programs.
- You make donations or tithes to the Church.
- You communicate with us via email, website, social media, or phone.
- You consent to participate in media coverage (for example photos, videos, testimonials).
3. What personal data might we collect?
Depending on the context, we may collect:
- Identity Data: full name, national ID, passport number, date of birth.
- Contact Data: address, phone number, email address.
- Financial Data: tithe or donation records, payment confirmations.
- Health Data: only when necessary for event planning, medical preparedness, accessibility, or safety during church activities.
- Media Data: photos, video recordings, or livestreams captured during events and services.
To note
We do not collect or process sensitive data such as political opinions, criminal history, or biometric data unless absolutely necessary and with your explicit consent.
4. Purposes for collecting your personal data
Your data is collected solely for lawful purposes, including:
- Event planning and management: to facilitate smooth registration and participation at events such as Rhema Feast, to plan for medical, accessibility, and security needs, and to send reminders, tickets, or schedules.
- Communication and updates: to provide information about upcoming services, conferences, and other church-related events, and to share important updates or changes regarding planned events or activities.
- Security and access control: to ensure safety at church premises and events, and to control access to restricted areas at large gatherings such as Rhema Feast.
- Ministry engagement: to connect you with discipleship groups, prayer chains, and volunteer opportunities, and to invite you to future Ruach (Purpose Centre), Rhema Feast and JKM Global Church events and initiatives (opt-in only).
- Financial administration: to process tithes, donations, and offerings securely, and to issue receipts and comply with legal or tax reporting obligations.
- Post-event follow-up: to share sermon notes, recordings, devotionals, or feedback surveys, and to improve future church activities and programs.
5. Legal grounds for processing personal data
Our processing of your information is always lawful. Typically, this means one of the following applies:
- Consent: you have given explicit permission, especially for sensitive information (for example health details, payment details, biometrics) or for promotional communications. You may withdraw consent at any time.
- Contractual or performance: processing is necessary to fulfill a service you requested or a membership agreement.
- Legitimate interests: for non-sensitive uses, such as sending church newsletters or improving our facilities, we rely on our legitimate interest in serving our community, provided it does not override your rights.
- Legal obligations: we process certain data to comply with laws, such as financial record-keeping.
6. Sharing and disclosure of personal data
Your personal data is kept confidential and shared only as necessary:
- Within the Church: authorized staff and volunteers who need your information to perform their duties, such as pastors, administrators, or event leaders. All such persons are trained on privacy and are bound to protect confidentiality.
- Service providers: we may engage trusted third-party service providers to help run our operations, for example event service providers, legal support, IT support, accounting firms, or website hosting. These providers are contractually bound with contracts and NDAs to process your data only on our instructions and to keep it secure.
- Legal requests: we will disclose personal information if required by law, such as a court order, government agency, or law enforcement, to protect rights or public safety.
- Community communications: with your permission, we may share your contact information with other church members or ministries, for example a small group contact list, but only if you have agreed to it.
- Photos and media: we sometimes take photos or videos during church events for outreach or communication. These may be used on our website or social media. You will always be informed when photographs are being taken and can let us know if you prefer not to be included.
- No marketing sale: we will never sell or rent your personal data to any marketing or advertising company.
7. Data security
We have implemented technical, administrative, and physical security measures to protect your personal data, including:
- Secure servers and encrypted databases.
- Restricted staff access to sensitive data.
- Regular audits to ensure compliance with data protection laws.
8. Cross-border data transfers
We do not routinely transfer personal data outside Kenya. If we were to use an international service, such as Google Forms for registrations, note that data may be processed on servers abroad. Kenyan law forbids transferring data outside the country unless there are adequate safeguards or your consent. We will only engage such services when necessary and will ensure any cross-border transfer complies with the law, for example by obtaining your consent and ensuring the provider meets data protection standards.
9. Data retention
We will keep your personal data only as long as necessary for the purposes we collected it and as required by law. Under the Data Protection Act, data must not be kept in a form which permits identification of data subjects for longer than is necessary.
For example, we may keep donation records for the number of years required by tax regulations, but we will regularly review and securely delete or anonymize older records that are no longer needed.
10. Your data protection rights
You have several rights regarding your personal data under Kenyan law. These include the right to:
- Be informed: you can ask us to explain what data we collect about you and why.
- Access: request a copy of the personal data we hold about you.
- Correction: have us rectify inaccurate or incomplete data, for example correcting a wrong address.
- Deletion or erasure: request deletion of your data if it is no longer needed or is being processed unlawfully.
- Object to processing: object to certain types of processing, for example direct communications, if you have a valid reason.
- Restrict processing: ask us to suspend processing your data in certain situations, for example while a dispute is resolved.
- Withdraw consent: if you have consented to processing, for example for sensitive data or for marketing, you can withdraw that consent at any time. Withdrawal will not affect processing already done.
- Complain: lodge a complaint with the Office of the Data Protection Commissioner (ODPC) if you believe your data has been mishandled.
11. Children's privacy
We do not seek to collect personal data from children without parental consent. If you provide information about a minor, for example in a program registration or Sunday school, we will assume you have the authority to do so. Parents or guardians can contact us to review, correct, or delete their child's data at any time. Our goal is to handle any minors' information with the same care and legal compliance as for adults.
12. Data Protection Officer
For all privacy-related queries or to exercise your rights, you may contact our Data Protection Officer at ruachsouthchurch@gmail.com or +254 716 341 739.
13. Frequently asked questions
Why do you need my data?
We need your data to serve you better as part of the church community. For example, we use your contact info to send you service updates or prayer requests, and we use event sign-up info to arrange seating or food. Health information, if provided, lets us make events accessible, for example providing ramps or medical support, and keep you safe. Collecting this data is necessary for carrying out our mission and legal responsibilities.
Is my sensitive information protected?
Yes. Sensitive details like health or special needs, and biometrics, are handled with strict confidentiality. We only ask for such information if it is truly needed, so we will obtain your explicit consent before collecting it and use it only for the stated purpose. We do not share your sensitive data with anyone outside the church officials who need it to provide assistance.
Who has access to my information?
Only authorized church personnel, staff or volunteers, who need the information to perform their duties. For example, our administrative team may access your contact details to send newsletters, and event coordinators may see mobility needs for seating. All such personnel are required to keep your data confidential. We do not share your information with unrelated third parties.
Do you ever share my data with others or transfer it abroad?
We do not sell or give your personal data to marketers. We may share data with trusted service providers who operate on our behalf, such as an email service or accounting, under confidentiality obligations. As noted above, we generally process and store your data within Kenya. If we use an international service, for example Google Forms, it means data may go through servers outside Kenya. Kenyan law prohibits such transfers unless there are safeguards or your consent. In practice, we minimize any cross-border sharing and only do so with appropriate consent.
How is my data kept safe?
We use industry-standard security measures. Personal records are kept on secure servers and locked filing systems. We limit database access with strong passwords, and we regularly update our systems and train staff on data protection. While we strive for strong security, please remember that no system is perfect. If a breach occurs, we will act promptly to contain it and notify affected individuals.
How long will you keep my data?
Only as long as needed. The law requires that data not be kept longer than necessary. In practice, we keep active member records and communication info for as long as you participate in church activities. Some records, like donation receipts, are kept for a fixed period required by law. We periodically purge or anonymize data that is no longer needed.
Can I see or change my data?
Yes. You have the right to access your data and request corrections. If you notice any errors, please let us know so we can fix them. You can also ask us to delete your data if it is inaccurate or no longer needed. To make such requests, contact us.
What if I do not want to provide some information?
Providing certain information may be optional, for example filling out a survey. However, some data is necessary for participation. For example, if you wish to attend an event, we may require your name and contact details to register you and ensure your safety. If you refuse to provide mandatory information, we may not be able to enroll you in certain services. In all cases, we will notify you when data is optional or mandatory at the point of collection.
How can I withdraw consent or complain?
If you previously gave consent, for example to receive email updates, and later change your mind, you can withdraw that consent at any time by contacting us. This will stop any future processing that relied on that consent. If you believe we have violated your privacy rights, you have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC).
14. Policy updates
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. Updates will be published on our official website.