Privacy Policy

Last updated 2 September 2026

Ekklesia is a platform for discovering and attending events run by churches and faith-based organisations. This policy explains what personal data we collect, why we collect it, the legal bases we rely on, and the choices you have. It applies to our website at ekklesiaevents.com and to our iOS and Android apps.

You can browse events on Ekklesia without an account. You only need to sign in if you want to RSVP to an event, save events, or publish events as an organisation.

1. Who we are

Ekklesia is operated by David Taribo, a sole trader trading as Ekklesia Events, based at 76 Millard Road, Deptford, London SE8 3GB, United Kingdom. David Taribo is the data controller for the personal data described in this policy. In this policy, “Ekklesia” refers to the platform and apps operated under that trading name.

We are registered with the UK Information Commissioner’s Office as a data controller.

You can reach us about anything in this policy, including to exercise your rights, at david@ekklesiaevents.com. We aim to acknowledge within two working days.

2. Data we collect

Account details. Your name, email address and password. Passwords are stored only as salted hashes; we never see or store the plaintext.

Activity on the platform. Events you save, RSVPs and tickets you hold, the organisations you belong to, and your chosen location for finding nearby events.

Images you upload. Event cover images, organisation logos and profile pictures.

Communications. Messages you send us, including reports you submit about content or other users, and our correspondence with you.

Technical and security data. Your IP address and device or browser user agent, recorded alongside security-relevant actions such as sign-in attempts and content reports, so we can investigate abuse.

Diagnostic data. Not currently collected. We do not use a crash reporting or analytics SDK in our apps. Our servers keep operational error logs, which may incidentally include the technical and security data described above. If we introduce crash reporting, we will update this policy before doing so.

Payment records. Not currently collected. Ekklesia does not process payments at this time and every event on the platform is free. If and when paid ticketing launches, we will collect the order, amount and status of your transactions, and we will update this policy before that happens. Card details would in any case be entered directly with our payment processor and would never reach our servers.

3. Information about religious beliefs

Ekklesia lists events run by churches and faith-based organisations. Because of this, the fact that you have RSVP’d to a particular event may reveal something about your religious or philosophical beliefs. Under UK and EU data protection law that is a special category of personal data, which carries extra protection.

We rely on your explicit consent to process this information. You give that consent when you create an account, and you can withdraw it at any time by deleting your account or by contacting us at david@ekklesiaevents.com. Withdrawing consent does not affect processing carried out before you withdrew it, but it does mean we can no longer hold your RSVP history.

You can browse the whole platform without giving this consent, because browsing does not require an account and we do not record who views which event.

We have an appropriate policy document in place governing our processing of special category data, as required by the Data Protection Act 2018. You can request a copy from david@ekklesiaevents.com.

4. How we use your data, and our legal bases

What we doCreate and maintain your account, authenticate youWhyTo give you access to the serviceLegal basisPerformance of a contract with you
What we doTake and confirm RSVPs, issue and validate ticketsWhyTo deliver the core service you asked forLegal basisPerformance of a contract with you
What we doRecord that you are attending a faith-based eventWhyInherent in taking an RSVPLegal basisExplicit consent (Article 9(2)(a))
What we doShow you events relevant to your chosen locationWhyTo make the service usefulLegal basisPerformance of a contract with you
What we doSend transactional email — RSVP confirmations, password resets, event changesWhyTo keep you informed about bookings you madeLegal basisPerformance of a contract with you
What we doSend push notifications about your bookingsWhyTo keep you informedLegal basisYour consent, given at the OS permission prompt
What we doInvestigate abuse, fraud and security incidents; moderate contentWhyTo keep the platform safe for everyoneLegal basisOur legitimate interests in running a safe platform
What we doDiagnose faults and improve reliabilityWhyTo keep the service workingLegal basisOur legitimate interests in maintaining the service
What we doRetain financial and tax recordsWhyBecause the law requires itLegal basisLegal obligation
What we doRespond to legal requestsWhyBecause the law requires itLegal basisLegal obligation

We do not sell your personal data. We do not use it for advertising, behavioural profiling, or automated decision-making that produces legal or similarly significant effects.

5. Device permissions

The mobile app can add an event to your calendar and open a venue in your maps app. Both actions happen only when you tap them, and both hand off to your device’s own system apps. We do not read your calendar, your contacts or your location, and the app does not request background location access.

If you allow push notifications, you can turn them off at any time in your device settings.

6. Who we share data with

Service providers acting on our behalf. We share the minimum necessary with:

  • Vercel — application and website hosting
  • Neon — database hosting
  • Backblaze B2 — storage of uploaded images
  • Resend — sending account and RSVP emails
  • Expo — delivering push notifications to your device
  • Stripe — payment processing (inactive; will apply only when paid ticketing launches)

Each of these is bound by a written data processing agreement and may only use your data on our instructions.

Event organisers. When you RSVP to an event, the organisation running that event receives your name and email address so it can manage attendance. From that point the organisation is an independent data controller of your information and its own privacy practices apply, not ours. We tell you which organisation will receive your details before you confirm an RSVP. If you want your data removed from an organiser’s records, contact the organiser directly; we will help you get in touch if you need us to.

Legal disclosures. We may disclose data where we are legally required to, or where it is necessary to establish, exercise or defend legal claims, or to protect someone’s vital interests.

We do not share your data with anyone else.

7. International transfers

Some of our service providers process data outside the UK and the European Economic Area, including in the United States. Where that happens, we rely on:

  • the UK Government’s adequacy regulations or the European Commission’s adequacy decisions, where these cover the country in question; or
  • the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses together with the UK Addendum, supported by a transfer risk assessment.

You can request details of the safeguards applying to a specific transfer at david@ekklesiaevents.com.

8. How long we keep data

DataAccount details and profileRetentionUntil you delete your account
DataRSVPs, tickets and saved eventsRetentionUntil you delete your account
DataImages you uploadRetentionUntil you or your organisation delete them, or until account deletion
DataSecurity logs (IP, user agent)Retention12 months from the event recorded
DataTrust and safety records (reports, moderation actions)Retention3 years from the action, in de-identified form after account deletion
DataFinancial and tax recordsRetention6 years from the end of the relevant accounting period, as required by UK tax law (not currently applicable — no payments are processed)
DataSupport correspondenceRetention2 years from last contact

9. Deleting your account

You can permanently delete your account at any time from Settings → Delete account in the mobile app, or by visiting ekklesiaevents.com/delete-account if you no longer have the app installed. We complete deletion within 30 days.

Deletion removes your profile, credentials, sessions, saved events, RSVPs and organisation memberships.

If you are the only owner of an organisation, we will ask you to transfer ownership first. If you would rather not, you can choose to have the organisation’s upcoming events unpublished and the organisation archived as part of the deletion, so your account deletion is never blocked.

Two categories of record survive deletion in de-identified form:

  • Trust and safety records, because removing moderation history would let banned users return and would undermine platform safety.
  • Financial records, where these exist, because we are required to retain transaction records for tax and accounting purposes.

To be precise about what “de-identified” means here: we sever the link between the record and your identity by removing your name, email and account identifier and replacing them with a non-reversible reference. We do not retain a key that would let us re-link these records to you.

10. Security

We protect your data using encryption in transit (TLS) and at rest, salted password hashing, access controls limiting staff access to what is necessary, and logging of security-relevant actions. No system is perfectly secure, but if a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours and notify you without undue delay where the risk is high.

11. Your rights

Depending on where you live, including under the UK GDPR and EU GDPR, you have the right to:

  • access the personal data we hold about you;
  • correct data that is inaccurate or incomplete;
  • erase your data (see section 9);
  • restrict or object to processing based on our legitimate interests;
  • portability — receive your data in a structured, machine-readable format;
  • withdraw consent at any time, where we rely on consent; and
  • complain to a data protection authority.

Contact david@ekklesiaevents.com to exercise any of these. We respond within one month, and will tell you if we need longer for a complex request.

If you are in the UK you can complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113. If you are in the EEA you can complain to your national supervisory authority.

12. Cookies and similar technologies

Our website uses a small number of strictly necessary cookies to keep you signed in and to protect against cross-site request forgery. These are exempt from consent requirements because the service cannot work without them. We do not use advertising, tracking or third-party analytics cookies. The mobile apps do not use cookies; they store an authentication token in your device’s secure storage.

13. Children

You must be at least 13 years old to create an Ekklesia account. In the EEA, where your country sets a higher age for consenting to online services, that higher age applies (16 in some member states).

Ekklesia is not directed at children, and we do not knowingly collect personal data from anyone below these ages. Family-oriented events may be listed on the platform, but accounts are intended for adults and for older children with their parent’s involvement. If you believe a child has created an account, contact david@ekklesiaevents.com and we will remove it promptly.

14. Changes to this policy

If we make material changes we will update the date at the top and notify you in the app or by email before the changes take effect. Previous versions are available on request.

15. Contact

  • Privacy, data protection and general support: david@ekklesiaevents.com
  • Post: David Taribo, trading as Ekklesia Events, 76 Millard Road, Deptford, London SE8 3GB, United Kingdom