licerçar

Data Processing Agreement (DPA)

Last updated on August 19, 2026

This document is a draft, still under legal review. We publish it marked as such rather than presenting it as final — the date above shows the last revision.

This is a translation. The Portuguese version is the one that governs, since the platform and its data-protection obligations are Brazilian.

This DPA forms part of the Alicerçar Terms of Use and governs RAVI Tecnologia, CNPJ 39.867.820/0001-10, processing a church's congregational personal data.

It is published as a draft pending legal review. A church should obtain its own advice before signing or adopting it as a contractual instrument.

Roles of the parties

The church is the controller of congregational data. RAVI Tecnologia is the operator and processes that data only on the church's documented instructions and to provide the Alicerçar platform.

RAVI Tecnologia remains an independent controller of sign-in-account data: name, e-mail, password credential, sessions, devices, locale, theme, and related account preferences.

Subject, duration, and categories

Processing lasts while the church keeps its account and covers storage, organisation, consultation, authorised transmission, export, and deletion needed for the contracted features.

Data subjects may include members, non-member contacts, visitors, volunteers, leaders, staff, children recorded by the church, and users with sign-in accounts.

  • name, date of birth, and gender;
  • e-mail, telephone number, and residential address;
  • home building and family relationships;
  • group and ministry membership and positions;
  • event attendance, named or as a headcount;
  • deliberately thin records for non-members;
  • giving records only when that deferred module exists and under its confidentiality rule.

Instructions and confidentiality

The operator follows the church's documented instructions and restricts access to authorised people bound by confidentiality duties. Processing is limited to maintaining church records, authentication and roles, system messages, address suggestions, payments when enabled, and protecting, supporting, backing up, and restoring the service.

Alicerçar does not sell congregational data, use it for advertising or its own profiling, or train artificial-intelligence models on congregational records. Non-identifying aggregate product metrics belong to Alicerçar; active-member count may be derived only for billing when billing exists.

Security

We use technical and organisational controls proportionate to risk, including encrypted traffic, hashed passwords, revocable sessions, church-level isolation, role-based access, and operational records.

Sub-processors

The church authorises these sub-processors for the stated purposes:

  • Hostinger — production and development compute, primary database storage, and network hosting;
  • Microsoft Azure — encrypted production database-backup storage in Brazil South, with storage and restoration verified;
  • Brevo — transactional e-mail;
  • Google Places — address suggestions when autocomplete is used;
  • Stripe — paid-plan payment processing only when billing is enabled.

RAVI Tecnologia gives the controller church advance notice before adding or replacing a sub-processor.

Data location

Primary application processing and database storage are in São Paulo, Brazil. Production backups are stored in Microsoft Azure Brazil South, and restoration from that storage was operationally verified on August 19, 2026. Primary database storage and production-backup storage therefore remain in Brazil.

Security incidents

RAVI Tecnologia is accountable for response through the Privacy Incident Owner at privacidade@alicercar.com.br. After confirming an incident affecting personal data, this role notifies the controller church within 2 business days with what is known, affected data and people when known, measures taken and planned, uncertainty, update cadence, and decisions required from the church.

Data-subject and authority requests

The church answers requests about congregational records. Alicerçar provides means to search, correct, export, and delete on the church's instruction and gives reasonable assistance with impact assessments and authority requests. Alicerçar answers requests about sign-in-account data for which it is controller.

Return and deletion

The church can export its data at any time. Only an explicit deletion request starts the 90-day grace period. Non-payment, cancellation, downgrade, or plan limits never delete, hide, lock, start, or shorten deletion of existing records.

Evidence and audit

On reasonable written request, Alicerçar provides evidence it actually maintains and that is relevant to this relationship: current security measures, the sub-processor list, data-location records, and incident records concerning that church. This is not a promise of certification, independent audit, penetration testing, or unrestricted system access.