Legal
Data Processing Addendum
Last updated August 27, 2026
This Data Processing Addendum (the “DPA”) forms part of the Terms of Servicebetween Scout Intelligence LLC, a California limited liability company with its principal place of business at 3380 Mono Drive, Riverside, CA 92506 (“Scout,” “we,” “us,” or “our”), and the church, ministry, or other organization that uses the Scout church management platform (the “Customer,” “you,” or “your”).
This DPA applies automatically and requires no separate signature. It is incorporated into the Terms of Service by reference and takes effect for every Customer that acts as a controller (or “business”) with respect to Customer Personal Data under the GDPR, the UK GDPR, the CCPA, or another applicable Data Protection Law. If your board, insurer, or legal counsel requires a countersigned copy, email hello@scout.church and we will execute one without changing these terms.
Capitalized terms not defined here have the meanings given in the Terms of Service. Where this DPA conflicts with the Terms of Service or the Privacy Policyon the subject of Scout’s processing of Customer Personal Data, this DPA controls.
1. Definitions
- “Customer Personal Data”means personal data contained in Customer Data that Scout processes on the Customer’s behalf in providing the Service. It does not include personal data about the Customer’s account holders and billing contacts that Scout processes as a controller in its own right, which is governed by the Privacy Policy.
- “Data Protection Law” means any law applicable to the processing of Customer Personal Data under this DPA, including the GDPR, the UK GDPR, the Swiss Federal Act on Data Protection, the CCPA, and other United States state privacy laws.
- “GDPR” means Regulation (EU) 2016/679. “UK GDPR” means the GDPR as incorporated into the law of the United Kingdom by the European Union (Withdrawal) Act 2018, read with the UK Data Protection Act 2018.
- “CCPA” means the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act, Cal. Civ. Code § 1798.100 et seq., and its implementing regulations.
- “Subprocessor” means a third party engaged by Scout to process Customer Personal Data in connection with the Service.
- “SCCs” means the Standard Contractual Clauses annexed to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
- “UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018.
- “controller,” “processor,” “data subject,” “personal data,” “personal data breach,” “processing,” and “special categories of personal data” have the meanings given in the GDPR. “business,” “service provider,” “sell,” “share,” and “business purpose” have the meanings given in the CCPA.
2. Roles of the parties
With respect to Customer Personal Data, the Customer is the controller and the business, and Scout is the processor and the service provider. The Customer determines what personal data to collect about its congregants, why, and who may access it. Scout processes that data only to provide the Service.
Where the Customer is itself acting as a processor on behalf of a third party controller, the Customer warrants that it has the third party’s authority to enter into this DPA on the controller’s behalf, and references to the Customer as controller are construed accordingly.
Scout is an independent controller of the account, billing, and product usage data described in Section 3.1 of the Privacy Policy. Nothing in this DPA makes the parties joint controllers.
3. Scope and duration of processing
Scout will process Customer Personal Data only for the duration of the Customer’s Account and for the retention periods described in Section 10 of this DPA. The subject matter, nature, purpose, duration, categories of data subjects, and types of personal data processed are described in Annex I.
4. Scout’s processing obligations
4.1 Documented instructions
Scout will process Customer Personal Data only on the Customer’s documented instructions, including with regard to transfers to a third country, unless required to do otherwise by law to which Scout is subject. Where such a legal requirement applies, Scout will inform the Customer of that requirement before processing, unless the law prohibits that notice on important grounds of public interest.
The Terms of Service, this DPA, the Privacy Policy, and the Customer’s configuration and use of the Service through its Account together constitute the Customer’s complete and final documented instructions. Additional instructions outside their scope require a written agreement between the parties. Scout will inform the Customer if, in its opinion, an instruction infringes Data Protection Law.
4.2 Purpose limitation
Scout will not retain, use, or disclose Customer Personal Data for any purpose other than performing the Service for the Customer and the other business purposes specified in this DPA, including for any commercial purpose of its own. Specifically, Scout will not:
- sell or share Customer Personal Data, as those terms are defined in the CCPA;
- use Customer Personal Data for cross-context behavioral advertising, targeted advertising, or profiling for advertising purposes;
- use Customer Personal Data to train, fine-tune, or improve any artificial intelligence or machine learning model, whether Scout’s own or a third party’s;
- combine Customer Personal Data with personal data received from or on behalf of another person, or collected from Scout’s own interactions with a data subject, except as permitted by Data Protection Law for a service provider; or
- disclose Customer Personal Data to a data broker, marketing network, or advertising exchange.
Scout may create aggregate, de-identified statistical data derived from Customer Personal Data and use it to operate, secure, and improve the Service, provided that the data cannot reasonably be used to identify the Customer or any individual and Scout does not attempt to re-identify it.
Scout certifies that it understands the restrictions in this Section 4.2 and will comply with them, and will notify the Customer if it determines that it can no longer meet its obligations under Data Protection Law.
4.3 Artificial intelligence
Section 6 of the Privacy Policylists each AI feature in the Service and states what Customer Personal Data that feature sends to Scout’s AI Subprocessor. Scout’s AI Subprocessor is contractually prohibited from training its models on data submitted through its commercial API, and Scout has not enrolled in any program that would change that default. A Customer may direct Scout to disable AI features for its Account at any time by writing to hello@scout.church. This is not a self-serve setting; Scout carries out the request by hand and confirms once it is in effect.
4.4 Confidentiality of personnel
Scout will ensure that any person authorized to process Customer Personal Data is subject to an appropriate obligation of confidentiality, whether contractual or statutory, and is granted access only to the extent necessary to perform their role. Scout limits personnel access to Customer Personal Data on a least-privilege basis.
4.5 Security
Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk to data subjects, Scout will implement and maintain appropriate technical and organizational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, and unauthorized disclosure or access. Those measures are described in Annex II. Scout may update them over time provided it does not materially reduce the overall level of protection.
4.6 Assistance with data subject rights
The Service gives the Customer the ability to access and correct Customer Personal Data directly through its Account, and to export giving records, audit records, lists, and event rosters. Where a request cannot be satisfied that way, including deletion of a person’s record and export of any other category, Scout will provide reasonable assistance, taking into account the nature of the processing, to help the Customer respond within the time limits set by Data Protection Law.
If Scout receives a request directly from a data subject relating to Customer Personal Data, Scout will not respond to it substantively except to acknowledge receipt and direct the data subject to the Customer, and will inform the Customer of the request without undue delay.
4.7 Assistance with the Customer’s wider obligations
Scout will provide reasonable assistance to the Customer in relation to the Customer’s obligations under Articles 32 to 36 of the GDPR (security, breach notification, data protection impact assessments, and prior consultation), taking into account the nature of the processing and the information available to Scout.
5. Subprocessors
5.1 General authorization
The Customer grants Scout general authorization to engage Subprocessors, subject to this Section 5. The Subprocessors engaged as at the date of this DPA are listed in Annex III.
5.2 Notice of changes and right to object
Scout will give the Customer at least thirty (30) days’ notice before a new Subprocessor begins processing Customer Personal Data, by email to the Customer’s account contact and by updating Annex III on this page. The Customer may object on reasonable data protection grounds within thirty (30) days of the notice by writing to hello@scout.church. The parties will work together in good faith to resolve the objection. If it cannot be resolved, the Customer may terminate the affected part of the Service, or the Terms of Service in full, on written notice, and Scout will refund fees prepaid for the terminated portion covering the period after termination.
5.3 Subprocessor obligations
Scout will impose on each Subprocessor, by written contract, data protection obligations that are materially no less protective than those in this DPA, to the extent applicable to the nature of the Subprocessor’s service. Scout remains fully liable to the Customer for the performance of each Subprocessor’s obligations.
6. Personal data breach
Scout will notify the Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notification will describe, to the extent known at the time and supplemented as more information becomes available: the nature of the breach and the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed to address it and mitigate its effects; and a contact point for further information.
Scout will take reasonable steps to contain and investigate the breach and will cooperate with the Customer’s own investigation. Notification of a breach is not an acknowledgement of fault or liability. As processor, Scout does not notify supervisory authorities or data subjects on the Customer’s behalf; those notifications remain the Customer’s responsibility as controller.
7. Audits and information rights
Scout will make available to the Customer the information reasonably necessary to demonstrate compliance with this DPA. On written request, and no more than once in any twelve (12) month period unless required more often by a supervisory authority or following a personal data breach affecting the Customer, Scout will respond to a reasonable security and privacy questionnaire covering the measures in Annex II.
Where Data Protection Law entitles the Customer to conduct an audit or inspection that the information above does not satisfy, the parties will agree the scope, timing, and duration in advance. Any such audit will be conducted during normal business hours, on at least thirty (30) days’ notice, subject to confidentiality obligations, in a manner that does not disrupt the Service or compromise the data of other customers, and at the Customer’s expense.
8. International transfers
Scout is established in the United States and stores and processes Customer Personal Data there. The Customer instructs Scout to transfer Customer Personal Data to the United States and to the Subprocessor locations listed in Annex III.
Where the Customer transfers Customer Personal Data protected by the GDPR from the European Economic Area to Scout, the SCCs apply and are incorporated into this DPA by reference, as follows:
- Module Two (controller to processor) applies where the Customer is a controller. Module Three (processor to processor) applies where the Customer is itself a processor.
- Clause 7 (the docking clause) applies.
- In Clause 9, Option 2 (general written authorization) applies, with the notice period set out in Section 5.2 of this DPA.
- In Clause 11, the optional independent dispute resolution language does not apply.
- In Clause 17, Option 1 applies and the SCCs are governed by the law of Ireland. In Clause 18(b), the courts of Ireland resolve disputes arising from the SCCs.
- Annexes I, II, and III to the SCCs are populated by Annex I, Annex II, and Annex III to this DPA respectively.
Where the Customer transfers Customer Personal Data protected by the UK GDPR, the SCCs apply as amended by the UK Addendum, which is incorporated by reference. Table 1 of the UK Addendum is populated by Annex I.A; Tables 2 and 3 by the selections above and Annexes I to III; and in Table 4, neither party may end the UK Addendum as set out in section 19.
Where the Customer transfers Customer Personal Data protected by Swiss law, the SCCs apply with references to the GDPR read as references to the Swiss Federal Act on Data Protection, the competent authority read as the Swiss Federal Data Protection and Information Commissioner, and the term “member state” read so as not to deprive data subjects in Switzerland of their right to sue in their place of habitual residence.
If a transfer mechanism is invalidated or superseded, the parties will work in good faith to adopt a replacement. If no lawful mechanism is available, either party may suspend the affected transfers or terminate the affected part of the Service.
9. Government and law enforcement requests
If Scout receives a legally binding request from a public authority for Customer Personal Data, Scout will notify the Customer before responding unless legally prohibited from doing so. Where prohibited, Scout will use reasonable efforts to obtain a waiver of the prohibition and to communicate as much information as it lawfully can, as soon as it lawfully can. Scout will review the legality of each request, challenge it where there are reasonable grounds to consider it unlawful, and disclose only the minimum amount of data the request requires on a reasonable interpretation.
10. Deletion and return
The Customer may export Customer Personal Data from its Account at any time during the term, and may request an export within thirty (30) days after termination as set out in Section 17 of the Terms of Service.
Scout will delete Customer Personal Data within ninety (90) days after termination of the Account, including donation and giving records, so the Customer should export any giving history it needs for tax or accounting purposes before that window closes; payment transaction records remain with the payment processor under its own terms. The remaining exceptions are: our database provider’s backup and history window operates on a cycle measured in hours, not days, so deleted data does not persist there beyond that short window; and server logs and security telemetry are retained by our hosting provider for a limited period and are not separately archived by Scout. Data retained under these exceptions remains subject to this DPA for as long as it is held.
11. Liability
Each party’s liability arising out of or related to this DPA is subject to the limitations and exclusions in Section 16 of the Terms of Service. Nothing in this DPA limits a data subject’s rights under Data Protection Law or under the SCCs, and nothing in this Section limits either party’s liability to a data subject under the third-party beneficiary provisions of the SCCs.
12. Changes to this DPA
Scout may update this DPA where the change is required by Data Protection Law, reflects a change to the Service or its Subprocessors, or does not materially reduce the protections it provides. Material changes take effect thirty (30) days after we post the revised version and notify the Customer’s account contact by email. Changes to Annex III follow the notice and objection process in Section 5.2.
13. Notices and contact
Privacy and data protection notices under this DPA should be sent to hello@scout.church, or by post to Scout Intelligence LLC, Attn: Privacy, 3380 Mono Drive, Riverside, CA 92506, USA. Scout has not appointed an Article 27 representative in the European Union or the United Kingdom, because it does not offer the Service to data subjects in those territories independently of a Customer relationship.
Annex I — Description of the processing
I.A. List of parties
Data exporter. The Customer: the church, ministry, or other organization identified in the Account, acting as controller (or, where applicable, as processor) of Customer Personal Data. Contact details are those held in the Account. Activities relevant to the transfer: use of the Scout church management platform to manage the people the organization serves.
Data importer. Scout Intelligence LLC, 3380 Mono Drive, Riverside, CA 92506, USA. Contact: hello@scout.church. Role: processor. Activities relevant to the transfer: provision of the Scout church management platform as described in the Terms of Service.
I.B. Description of the transfer
- Categories of data subjects.The Customer’s Authorized Users (staff, pastors, administrators, volunteers, and group and team leaders); congregants, including members, attendees, and visitors; donors; group and team participants; children whose records the Customer maintains for check-in; and the parents, guardians, and authorized pickup adults associated with those children.
- Categories of personal data. Name, email address, telephone number, postal address, date of birth, gender, photograph, household and family relationships, marital status, and a Scout-issued person identifier; participation records, including check-in records, group and team membership, volunteer schedules and history, background-check clearance date and who recorded it, event registrations, and form submissions; giving records, including donation amounts, dates, designated funds, recurring gift schedules, whether a gift is marked anonymous, and any donor or staff memo on a gift; pastoral records, including notes, prayer requests, care needs, and follow-up history; engagement scores and AI-generated narratives derived from the above; authentication data, including hashed passwords and session tokens; and device records for the mobile apps, including push notification tokens, platform, app version, and locale.
- Special categories of personal data.Religious or philosophical beliefs, which are inherent to the use of a church platform and may be inferred from the fact of membership or participation. Where the Customer chooses to record them: data concerning health, including allergies recorded for children’s check-in and pastoral notes that may reference health, mental health, or family circumstances. The Customer decides whether to collect any of these. Scout applies the restrictions in Section 4.2 and the measures in Annex II to them, and additionally excludes prayer requests from AI note classification.
- Children’s data.Where the Customer uses check-in, personal data about children, typically name, birthdate, household, allergies, and authorized pickup adults. The Customer is responsible for obtaining any parental consent required by COPPA, GDPR Article 8, or state children’s privacy law.
- Frequency of the transfer. Continuous, for the duration of the Account.
- Nature and purpose of the processing. Hosting, storage, retrieval, organization, structuring, analysis, and deletion of Customer Personal Data for the purpose of providing the Scout church management platform, including people records, participation and scheduling, giving, check-in, forms, pastoral notes, engagement intelligence, the member app and its notifications, and support.
- Retention. As set out in Section 10 of this DPA.
- Subprocessor processing.Each Subprocessor in Annex III processes Customer Personal Data for the purpose stated against its name, for as long as Scout’s engagement of it continues and subject to the retention periods in Section 10.
I.C. Competent supervisory authority
Where the SCCs apply under Clause 13, the competent supervisory authority is the supervisory authority of the EEA member state in which the Customer is established, or, where the Customer is not established in the EEA but falls within the territorial scope of the GDPR under Article 3(2), the supervisory authority of the member state in which the Customer’s Article 27 representative is established. For transfers subject to the UK GDPR, the competent authority is the UK Information Commissioner’s Office. For transfers subject to Swiss law, it is the Swiss Federal Data Protection and Information Commissioner.
Annex II — Technical and organizational measures
Scout implements and maintains the measures below. They apply to all Customer Personal Data and, where relevant, to the Subprocessors listed in Annex III through the contractual obligations described in Section 5.3.
- Encryption in transit. All connections to the Service, and all connections between Scout and its Subprocessors, use TLS.
- Encryption at rest. The primary database and file storage are encrypted at rest by the infrastructure providers named in Annex III. Application secrets are encrypted at rest.
- Tenant isolation. Scout is a multi-tenant platform. The set of tenant-scoped models is maintained in code and verified against the database schema by an automated check that runs on every change, so that a newly added model cannot silently bypass scoping. Tenant-scoped queries carry a single church identifier, and a scoping client is available that injects it automatically.
- Access control.Access to the Service is role-based. The Customer assigns each Authorized User a role that determines which records and which categories of data, including giving and pastoral notes, that user can see. Sensitive categories are gated behind discrete permissions rather than inferred from a user’s general access, except that a Customer’s own administrators hold every permission by design.
- Authentication.Passwords are stored using bcrypt, a one-way salted hash; Scout never stores a password in a recoverable form. Sign-in additionally supports one-time email codes and federated sign-in. Sessions are carried in signed tokens, and sign-in tokens are bound to the church that issued them and rejected on another church’s host.
- Abuse and rate limiting. Authentication and other sensitive endpoints are rate limited to resist credential stuffing and enumeration.
- Minimization in AI processing.For the engagement narrative feature, a person’s name is replaced with a placeholder before the request is sent to the AI Subprocessor and restored only after the response is received. Scout does not send email addresses, telephone numbers, postal addresses, dates of birth, or payment instrument details to the AI Subprocessor. Giving data is sent only as part of report narratives, as a percentage, never a name or a dollar amount, and only for a staff member permitted to view giving. Section 6 of the Privacy Policy states, for each feature, what is sent.
- Payment data. Card and bank account numbers are captured directly by the payment Subprocessor through tokenized elements and are never received, logged, or stored by Scout.
- Logging and monitoring. Application errors and exceptions are captured through the monitoring Subprocessor named in Annex III. Session replay is disabled.
- Least privilege for personnel. Access to production systems and Customer Personal Data is limited to personnel who require it to operate and support the Service, and is subject to the confidentiality obligations in Section 4.4.
- Backups. The primary database is backed up by the database Subprocessor named in Annex III. Backups are encrypted and expire on the cycle stated in Section 10.
- Change management. Changes to the Service are version-controlled, reviewed, and subject to automated type checking and tests before release.
- Deletion.The Customer can archive a person’s record and delete individual tags and group or team memberships from its Account directly; a pastoral note cannot be deleted from the Account today. Deletion of a person’s record, deletion of a pastoral note, and deletion or export of the whole Account, are performed by Scout on the Customer’s written request, on the timetable in Section 10.
Annex III — Subprocessors
Each Subprocessor below is engaged under a written agreement containing data protection terms as described in Section 5.3, and processes Customer Personal Data only to deliver the function stated against its name. All process data in the United States.
- Vercel Inc. Application hosting, content delivery, serverless compute, and file storage for uploaded images and documents. United States.
- Neon, Inc.Managed PostgreSQL hosting for Scout’s primary data store. United States.
- Stripe, Inc. Subscription billing, donation processing, and Stripe Connect for church giving. United States.
- Resend, Inc. Transactional email delivery, including sign-in codes, invitations, receipts, billing notices, event registration confirmations, recurring-gift failure notices, and follow-up notifications. United States.
- Anthropic, PBC. Large language model API used for the AI features described in Section 6 of the Privacy Policy. United States.
- Google LLC. Firebase Cloud Messaging, which delivers push notifications to the Android member app. United States.
- Apple Inc. Apple Push Notification service, which delivers push notifications to the iOS member app. United States.
- Upstash, Inc. Redis-backed rate limiting and abuse protection for sensitive endpoints. United States.
- Functional Software, Inc. d/b/a Sentry. Application error and exception monitoring. United States.
Push notification Subprocessors receive the device token and the contents of the notification itself, which Scout keeps to a short prompt without sensitive detail. They do not receive the underlying person record.
Where the Customer connects an outside system to Scout, that system is not a Scout Subprocessor. The principal example is Planning Center Online: where the Customer chooses to import its records, it supplies its own credentials, Scout reads from Planning Center and does not write to it, and the Customer’s relationship with that provider is governed by the Customer’s own agreement with it. Scout acts on the Customer’s instruction in performing the import and processes the imported data under this DPA once it is in the Service.