This Privacy & Data Protection Policy explains how The Elevation Church (“TEC”, “we”, “us”, “our”) processes personal information on elevationng.church and related church apps and APIs. It is written for people we serve in Nigeria and internationally (including UK and EU campuses), with dual coverage under UK/EU GDPR and the Nigeria Data Protection Act 2023 (NDPA), as implemented by the Nigeria Data Protection Commission's General Application and Implementation Directive (GAID) 2025.
TEC may update this policy as our platform or the law changes. Material updates will be signalled on elevationng.church (for example via a notice or version date). Please check this page periodically.
1. Who we are
The Elevation Church is the data controller for personal information processed through the elevationng.church platform and related church systems used to serve our campuses and online community.
Privacy requests — please use:
- In-app support / help channels on elevationng.church (support tickets), and/or
- Email: admin@elevationng.org
We will respond to privacy and data-subject requests within the statutory timeline that applies to you:
- UK / EU (GDPR): generally one month from receipt of a valid request (subject to lawful extensions).
- Nigeria (NDPA / GAID): without constraint or unreasonable delay, and generally within 30 days (one month) of receipt, as required under the NDPA and NDPC / GAID rules (subject to any lawful extension).
- United States, Canada, and other jurisdictions: without undue delay and as required by applicable law.
Our Data Protection Officer
TEC has designated a Data Protection Officer (DPO) responsible for overseeing our compliance with the NDPA and, where applicable, UK/EU GDPR.
- Name/Role: TEC Data Protection Officer
- Email: dpo@elevationng.org
- Postal address: Pistis Heights, No 1 Resurrection Drive, Jakande, Lekki, Lagos
You may contact our DPO directly on any matter relating to how your personal data is processed, or to exercise any of the rights described in this policy.
TEC may designate additional regional DPO contacts as campuses require.
2. Scope — what this covers
This policy covers personal data processed in connection with membership, Greatness Track (GT / TECi), Greatness Community (GC), ushering & Sunday attendance, baptism, celebrations, support tickets, guest care / engagements, and staff / volunteer tools.
| Area | Examples of data use |
|---|---|
| Membership | Accounts, profiles, campus affiliation, membership class progress, certificates |
| Greatness Track (GT / TECi) | Enrolment, live class & recording attendance, quizzes, checklists, progress, certificates |
| Greatness Community (GC) | Centre / zone placement, leader roles, community attendance, pastoral coordination |
| Ushering & Sunday attendance | Service check-in / attendance records for care and operations |
| Baptism | Baptism interest, queues, scheduling, pastoral handoffs |
| Celebrations | Birthday (and similar) reminders for pastoral care — where enabled |
| Support tickets | Messages you send for help, technical issues, or privacy requests |
| Guest care / engagements | First-time guest registration and follow-up (forms, QR, bots where used) |
| Staff / volunteer tools | Role-based access for pastors, HODs, ushers, GC leaders, and admins |
Public marketing pages on third-party sites (e.g. social media) may have their own policies; this document focuses on TEC’s platform and ministry systems.
3. What personal data we collect
Depending on how you engage with us, we may process:
- Identity & contact — name, email, phone number, campus / expression, preferred language or communication channel.
- Account & security — login credentials (stored securely), one-time codes (OTP), session / device information needed to keep accounts safe.
- Ministry & discipleship — membership and Greatness Track progress, class attendance, quiz results, GC assignment, baptism status, ushering / service attendance, celebration dates you share.
- Communications — emails, SMS/WhatsApp messages we send or receive for service notices, class reminders, pastoral follow-up, and support ticket content.
- Technical — IP address, browser/app type, approximate location signals used for service features, and logs needed for security and reliability.
Sensitive personal data
Under the NDPA, information about your religious beliefs and practice is classified as sensitive personal data, and this includes data connected to baptism status, baptism scheduling, and similar faith-practice records. We process this category of data on the basis of our status as a registered religious organisation processing the data of our own members and regular attendees (NDPA s.30(1)(d)), and, in addition, as a safeguard, we will seek your specific affirmative consent at the point such information is first collected (for example, when you register interest in baptism or join a discipleship pathway). We do not seek health data, ethnic origin data, or other special-category information through the platform, and any sensitive personal data we do hold is not shared outside TEC without your explicit consent, except where required by law.
We collect data when you register, update your profile, join a programme, check in at church, message support, or when leaders record attendance / pastoral workflow information as part of serving you.
4. Why we use your data
- Provide membership, Greatness Track, and Greatness Community services you take part in
- Record attendance (classes, GC, Sunday / ushering) so we can care for people and run church operations
- Support baptism journeys and pastoral handoffs
- Send service-related messages (class reminders, account security, schedule changes)
- Run birthday / celebration pastoral touches where that feature is enabled
- Respond to support tickets and improve the platform
- Protect the security and integrity of our systems
- Meet legal, safeguarding, and accountability obligations of the church
Marketing vs service communications — service messages necessary for programmes you joined, security, or support are part of running the church platform. Optional marketing / promotional messages rely on consent where required, and you can opt out.
5. Legal bases
| Basis | Typical use |
|---|---|
| Contract / performance of a service | Creating your account; delivering Membership, Greatness Track, GC tools, tickets you open |
| Legitimate interests | Church operations, pastoral care coordination, attendance analytics for ministry health, platform security — balanced against your rights |
| Consent | Optional marketing; non-essential cookies/analytics (when enabled); certain communications where consent is required |
| Consent (sensitive personal data) + religious-organisation exemption | Baptism interest and status, faith-practice records, and other data closely tied to religious belief or practice processed under NDPA s.30(1)(d) as data relating to our own members/regular attendees, reinforced by your specific consent at collection. |
| Legal obligation | Where law requires retention or disclosure (e.g. lawful authority requests) |
| Vital interests / safeguarding | Rare cases involving serious risk to someone’s safety |
Under the Nigeria Data Protection Act 2023 (NDPA), we likewise process data lawfully, fairly, and for specified purposes, with appropriate security and respect for data subject rights. Where GDPR applies to people in the UK/EU, we honour GDPR rights and principles for those individuals even when systems are operated across borders.
7. International transfers
Because TEC serves Nigeria, the UK, the United States, Canada, the EU, and other campuses, your data may be stored or accessed in countries other than where you live including through service providers such as our hosting, cloud storage, video-conferencing, and messaging providers (see Section 6). Where UK/EU GDPR applies, we rely on Standard Contractual Clauses or appropriate safeguard for each such transfer. Where the NDPA applies, and in the absence of an adequacy decision by the Nigeria Data Protection Commission (NDPC) for the destination country, we rely on one of the following, as appropriate to each transfer: a Commission-recognised Cross-Border Data Transfer Instrument (such as standard contractual clauses, certifications, or binding corporate rules), or another lawful basis recognised under Part VIII of the NDPA (including contractual necessity, vital interest, public interest, or your informed consent). We maintain a written Data Processing Agreement with each processor that receives your personal data, recording the purpose, location, and legal basis of processing, in line with NDPC guidance.
8. How long we keep data
We keep personal data only as long as needed for the purposes above (and any legal retention requirements). Typical approaches include keeping active accounts while you remain engaged plus a wind-down period; programme progress and certificates for the life of the relationship and a reasonable pastoral archive; attendance for operational care and reporting; support tickets until resolved plus a limited quality period; and security logs for a short period unless investigating an incident.
9. Your rights
Subject to applicable law (GDPR and/or the NDPA), you may have the right to access, correction, deletion, restriction, objection, portability (where GDPR portability applies), and to withdraw consent where we rely on consent.
You also have the right not to be subject to a decision based solely on automated processing (including profiling) that produces legal or similarly significant effects concerning you. You may object to such a decision and request human review by contacting us using the details in Section 1.
We do not currently make solely automated decisions that produce legal or similarly significant effects. If that changes, we will update this notice and honour this right.
How to request — use the in-app / portal Delete account flow (member Profile → Security on web, or Profile → Delete account in the TEC LMS app), in-app support tickets, and/or email admin@elevationng.org. Deletion requests are queued for controlled erasure review and are not completed instantly. Please tell us which right you wish to exercise and enough detail to verify your identity. You may also lodge a complaint with a supervisory authority (e.g. the UK ICO, an EU DPA, or Nigeria’s Data Protection Commission) if you believe your rights have not been respected.
10. Children & young people
Our platform is primarily designed for adults and church members engaging in membership and discipleship pathways. Where a data subject is a child (under 18) or another person lacking legal capacity to consent, we will only process their personal data with the consent of a parent or legal guardian, obtained before that data is collected. Where we offer online services to children, we apply the age of consent set by law and ask a parent or guardian where needed. Where practicable, we verify this consent using an appropriate method. For example, requesting a government-issued form of identification from the consenting parent or guardian, consistent with NDPC guidance. Leaders and staff must collect only the minimum data needed for the relevant programme, and extra care applies before enabling celebrations, messaging, or any public display of a minor's data. Because children are treated as a higher-vulnerability category under data protection law, programmes involving minors' data are subject to additional internal review before launch. If you believe we hold a child's data inappropriately, or without proper consent, contact us using the details in Section 1 and we will review promptly.
12. Security
We use organisational and technical measures appropriate to a church platform — including access controls, encrypted transport (HTTPS), hardened hosting practices, and least-privilege roles for staff tools. No online system is perfect; please use a strong password and protect your OTP codes.
In the event of a data breach
If a data breach happens that could seriously affect you, we will tell you and the authorities as the law requires.
If a personal data breach occurs that is likely to affect your rights or freedoms, we will notify the Nigeria Data Protection Commission within 72 hours of becoming aware of it, and we will notify you directly, as soon as reasonably practicable, where the breach affects your personal data. Where direct notification isn't feasible, we will make a public communication through a widely accessible channel instead. Any notification we send will explain what happened, what data was involved, what we're doing about it, and how you can protect yourself.
13. Changes to this policy
We may update this policy as our platform or the law changes. Material updates will be signalled on elevationng.church (for example via a notice or version date). Continued use after an update means you should read the revised text.