Member information

Privacy Notice

Version 1.0 · Effective 12 August 2026

CCI Joy Family Church, Juja respects the privacy and dignity of every member, child, visitor, volunteer, employee, ministry participant and other person whose personal data we handle. This notice explains what we collect, why we use it, how long we keep it, who may receive it, and the choices and rights available to you.

1. Who is responsible for your data

CCI Joy Family Church, Juja is the data controller for the personal data described in this notice. This means the church decides why and how that information is used and is responsible for handling it in accordance with the Data Protection Act, 2019 and applicable regulations in Kenya.

The church has designated a contact point for privacy questions and data-subject requests. The name and contact details of that officer are published in section 12 of this notice.

2. Personal data we collect

We collect only the information needed to maintain member records, communicate with members, organise ministry service and place children in the appropriate Sunday school classes.

  • For members, we collect names, contact details, marital status, spouse details and the ministries in which they serve.
  • For children, we collect their names, their parents’ or guardians’ names and their ages so that they can be placed in the appropriate Sunday school class.

3. How we collect personal data

  • Directly from you when you join, register, volunteer, attend, request support, communicate with us or use the member portal.
  • From a parent or legal guardian where information concerns a child.
  • From authorised church leaders, ministry administrators or existing records when updating membership, attendance, leadership or safeguarding information.

4. Why we use personal data

  • To maintain accurate membership and ministry records and provide appropriate access to the church portal.
  • To organise worship services, ministries, home churches, classes, meetings, attendance, volunteering and church programmes.
  • To communicate service information, ministry updates, pastoral messages, invitations and urgent notices.
  • To provide pastoral care, prayer, welfare support and safeguarding, including responding to emergencies or concerns about a child or vulnerable person.
  • To administer staff, volunteers, church finances, reimbursements, budgets, strategic-plan reporting and other governance responsibilities.

5. Our lawful basis for using data

Depending on the activity, we rely on consent, performance of an agreement or requested service, compliance with a legal obligation, protection of vital interests, and the church’s legitimate interests in administering its membership, ministries, governance, security and pastoral mission. Where consent is the basis, you may withdraw it at any time without affecting processing that was lawful before withdrawal.

Religious belief, health information and other sensitive personal data are used only where the law permits, including with explicit consent, for legitimate activities of a not-for-profit religious body concerning its members and regular contacts with appropriate safeguards, for vital interests, or where another legal condition applies. Sensitive information is not disclosed outside the church without consent unless the law allows or requires it.

6. Who we share data with

We do not sell personal data. Access inside the church is limited according to a person’s role and ministry responsibilities. We may share the minimum necessary information with:

  • Authorised pastors, elders, administrators, ministry leaders, teachers, safeguarding personnel, finance personnel and volunteers who need it for an approved church duty.

7. Where is data hosted?

The church’s data is hosted in a secure cloud environment provided by a reputable web-hosting provider. Access is restricted to authorised church members and administrators according to their assigned roles and responsibilities. The system uses individual password-protected accounts, secure connections, role-based permissions, controlled sessions, backups and regular security maintenance to help prevent unauthorised access, loss, misuse or alteration of personal data.

8. How long we keep data

We keep personal data only for as long as it is needed for the purpose for which it was collected. Records are reviewed and corrected where necessary, and access may be deactivated when it is no longer required.

9. How we protect personal data

We use proportionate administrative, physical and technical safeguards, including role-based access, individual accounts, password protection, secure sessions, restricted access to sensitive records, staff or volunteer confidentiality expectations, backups and appropriate deletion procedures. No system is completely risk-free, but suspected loss, misuse or unauthorised access is investigated and reported where the law requires.

10. Children’s personal data

Children’s information is used only for appropriate church, education, attendance, safety, safeguarding and pastoral purposes. We seek consent from a parent or legal guardian where required, explain the use of information in clear language, limit access to authorised adults and place the child’s best interests first. A parent or guardian may exercise applicable privacy rights on the child’s behalf.

11. Your data-protection rights

Subject to the Data Protection Act and any lawful limitations, you may:

  • Be informed about how your personal data is used.
  • Ask whether we hold your data and request access to it.
  • Ask us to correct personal data that is inaccurate, incomplete, outdated or misleading.
  • Object to processing, or ask us to restrict it, where the law gives you that right.
  • Ask for personal data to be erased where there is no lawful reason to keep it.
  • Receive data you provided in a structured, commonly used and machine-readable format where data portability applies.
  • Withdraw consent at any time where we rely on consent.
  • Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects. The church does not currently make such decisions through this portal.
  • Make a complaint to the Office of the Data Protection Commissioner if you believe your data has been handled unlawfully. We encourage you to contact the church first so that we can try to resolve the concern promptly.

12. Contact us or make a request

To ask a privacy question, exercise a right or raise a complaint, contact the church’s Data Protection Officer or designated privacy contact using the details below. We may ask for reasonable proof of identity before acting on a request so that personal data is not disclosed to the wrong person.

Data Protection Officer / designated privacy contact

Name
Gladys Maina
Telephone
0734255743
Postal or physical address
CCI Joy Family Church, Opposite JKUAT Gate B

13. Changes to this notice

We may update this notice when our activities, systems or legal duties change. The current version and effective date are shown at the top of the notice. A significant change will be communicated through an appropriate church channel and the updated notice will be published in the member portal.

CCI Joy Family Church, Juja · Version 1.0 · Effective 12 August 2026