E.A.M.S

Privacy Policy

How Systema Administrationis Rerum Ecclesiasticarum protects Church data, pastoral records, and the people they serve.

Effective date: 10 September 2026. This policy explains how Systema Administrationis Rerum Ecclesiasticarum (“we”, “our”, or “the Platform”) collects, uses, stores, and protects information when dioceses, deaneries, parishes, clergy, staff, and members use our Ecclesiastical administration services.

Stewardship Church records are treated as a sacred trust.
Security Access is role-based and activity is accountable.
Transparency We explain what we collect and why.
Control Dioceses remain stewards of their own data.

1. Our commitment to the Church

Systema Administrationis Rerum Ecclesiasticarum is built to support Catholic dioceses and related Ecclesiastical units. We recognise that baptismal, marriage, funeral, clergy, membership, and pastoral information is sensitive and must be handled with reverence, confidentiality, and care consistent with Church teaching and applicable data-protection law.

We design the Platform so that diocesan and parish leaders can administer their communities digitally without surrendering pastoral responsibility or exposing the faithful to unnecessary risk.

2. Who this policy covers

This policy applies to visitors of our public website and to authorised users of the Platform, including:

  • System / platform administrators
  • National / episcopal conference administrators
  • Diocese, deanery, and parish staff
  • Clergy and authorised ministry leaders
  • Members or applicants who use public registration or support forms

3. Information we process

Depending on how the Platform is used, we may process:

  • Account & identity data — names, emails, roles, unit assignments, and login credentials (stored as secure password hashes).
  • Ecclesiastical & pastoral records — membership, sacrament, clergy, society, calendar, and related parish/diocese records entered by authorised users.
  • Operational content — documents, messages, support tickets, attendance, finance references, and administrative notes created in the Platform.
  • Technical data — IP address, browser type, device signals, session timing, and security logs needed to protect accounts and diagnose issues.
  • Public contact submissions — name, email, subject, and message content sent through Contact / Support forms.

We do not sell personal data. We do not use pastoral or sacrament records for advertising.

4. Why we process data (lawful purposes)

We process information to:

  • Provide secure Ecclesiastical administration tools requested by Church organisations
  • Authenticate users and enforce role-based access
  • Maintain pastoral, sacramental, and organisational records under diocesan stewardship
  • Respond to support requests and protect Platform integrity
  • Meet legal, regulatory, and audit obligations where applicable
  • Improve reliability, security, and service quality

Where national or regional data-protection laws apply (for example GDPR-style frameworks or local privacy statutes), processing is based on legitimate organisational interest, contract/service provision to the diocese, consent where required, or legal obligation.

5. Global data-protection principles we follow

Across jurisdictions, Systema Administrationis Rerum Ecclesiasticarum is guided by widely recognised principles:

  • Lawfulness & fairness — process data for clear pastoral and administrative purposes.
  • Purpose limitation — do not reuse Church data for unrelated commercial aims.
  • Data minimisation — collect what is needed for ministry and administration.
  • Accuracy — support authorised correction of records by responsible Church officers.
  • Storage limitation — retain data while needed for pastoral, canonical, legal, or archival purposes defined by the diocese/platform administrators.
  • Integrity & confidentiality — protect data with technical and organisational safeguards.
  • Accountability — document access roles, support actions, and security controls.

6. How we protect Church data

Safeguards include, as implemented in the Platform and hosting environment:

  • Encrypted transport (HTTPS) on production hosts
  • Password hashing and session controls, including idle timeout
  • Role-based permissions aligned to Church structure (parish, deanery, diocese, national, platform)
  • Tenant isolation by diocese / organisational scope
  • Access restrictions for sensitive modules and administrative functions
  • Operational logging and support workflows for accountable handling of requests
  • Hardening practices such as CSRF protection on forms and restricted direct access to sensitive directories

No online system can guarantee absolute security. We continuously improve controls and expect dioceses to appoint trustworthy administrators, use strong credentials, and grant access only to those with a genuine pastoral or administrative need.

7. Who can access information

Access is limited to:

  • Authorised users within the relevant Church unit, according to assigned roles
  • Platform administrators, only as needed to operate, secure, or support the service
  • Service providers strictly required to host or operate the Platform (for example infrastructure providers), under confidentiality and security expectations
  • Authorities where disclosure is legally required

Dioceses remain the primary stewards of records created for their territory. Platform staff do not use pastoral data for marketing.

8. Cross-border & multi-diocese hosting

Where the Platform is hosted centrally for multiple dioceses or countries, data may be stored or processed in the hosting region selected for the service. We apply tenant separation so one diocese’s operational data is not exposed to another diocese’s users. If a diocese uses a dedicated domain, access remains scoped to that diocese’s configuration.

9. Retention

Retention follows pastoral, canonical, administrative, and legal needs. Sacramental and membership archives may be kept for long periods because of their enduring Church significance. Account, support, and technical logs are retained as needed for security and service continuity. Diocesan administrators may request correction, export assistance, or deletion where compatible with Church record-keeping duties and applicable law.

10. Your rights & Church responsibilities

Depending on your location and role, you may have rights to access, correct, restrict, or object to certain processing, or to lodge a complaint with a supervisory authority. For records held by a parish or diocese inside the Platform, please contact that Church unit first—they are ordinarily the steward of the pastoral file. For Platform-level privacy questions, contact us using the details below.

11. Children & pastoral sensitivity

The Platform may contain information relating to minors in membership, sacrament, or family contexts. Such data must be entered and accessed only by authorised Church personnel for legitimate pastoral purposes. Extra care is expected when sharing screens, exporting reports, or granting staff permissions.

12. Cookies & similar technologies

We use essential cookies/session storage to keep users signed in securely and to operate the website. We do not use advertising trackers on pastoral records. Where optional analytics or security widgets are enabled by administrators, they are used to protect or improve the service.

13. Changes to this policy

We may update this Privacy Policy to reflect legal, pastoral, or Platform changes. The effective date above will be revised when material updates are published. Continued use of the Platform after an update constitutes notice of the revised policy for organisational users bound by their diocese’s service arrangement.

14. Contact

For privacy questions about Systema Administrationis Rerum Ecclesiasticarum:

If your request concerns a specific parish or diocese record, please include the diocese name and enough detail for us to route your request to the correct steward.