Data Processing Agreement · English

Data Processing Agreement for Overseas Churches

English translation of the agreement between overseas churches and the Company.
The Korean original prevails.

Translation — effective 12 October 2026

This is an English translation provided for your understanding. The Korean original is the authoritative version (Article 17). Korean original: 개인정보 처리위탁 약정. This Agreement applies between the Company and churches that use the service outside the Republic of Korea; nothing changes for churches in Korea. An overseas church accepts this Agreement on the service screen after the Company's approval.

The church that uses the service outside the Republic of Korea (the "Church") and Wesleysoft (the "Company") agree as follows on the processing by the Company, on behalf of the Church, of the personal data that the Church enters into Wesley Gyojeok (웨슬리 교적), Wesley Jaejeong (웨슬리 재정) and Wesley Simbang Plus (웨슬리 심방플러스) (the "Service"). This Agreement applies together with the Company's Terms of Use, its Privacy Policy and the "Privacy Policy Annex for Overseas Churches" (the "Annex"). Where they differ on the processing of personal data, this Agreement prevails.

Article 1 (Roles)

  1. With respect to the personal data that the Church enters into the Service, the Church determines the purposes and means of processing (controller), and the Company processes the data on behalf of the Church (processor).
  2. The Church is responsible for ensuring that the collection of personal data and its entry into the Service comply with the laws of the Church's country, and informs members of the processing and obtains their consent where required.

Article 2 (Details of Processing)

The subject matter and duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Schedule 1.

Article 3 (Processing on the Church's Instructions)

  1. The Company processes personal data only on the documented instructions of the Church. The Church's use of functions and choice of settings on the screens of the Service are regarded as the Church's instructions.
  2. The Company does not process personal data for any purpose other than providing the Service, unless required to do so by law. Where the law requires processing, the Company informs the Church before processing unless the law prohibits this.
  3. If the Company considers that an instruction of the Church infringes data protection law, it informs the Church without delay.

Article 4 (Confidentiality)

The Company limits the persons who may process personal data to the minimum necessary and ensures that they are bound by a duty of confidentiality. This duty continues after their work has ended.

Article 5 (Security Measures)

The Company takes technical and organisational measures appropriate to the risks to personal data, as set out in Schedule 2. The Company may change these measures as technology develops, but will not lower the level of protection.

Article 6 (Separation by Church)

The Company keeps the Church's data separate from the data of other churches and ensures that users of other churches cannot see the Church's data.

Article 7 (Sub-processing)

  1. The Church authorises the Company to engage the sub-processors listed in Schedule 3.
  2. If the Company intends to add or replace a sub-processor, it informs the Church at least 30 days in advance, and the Church may object on reasonable grounds within that period. If the Company does not accept the objection, the Church may terminate the service contract without penalty.
  3. The Company imposes on each sub-processor, by contract, data protection obligations of the same level as in this Agreement, and remains liable to the Church if a sub-processor fails to fulfil those obligations.

Article 8 (Assistance with Data Subjects' Rights)

  1. When members or other data subjects exercise rights such as access, rectification, erasure, restriction of processing or data portability, the Company provides the functions of the Service and the cooperation needed for the Church to respond.
  2. If a data subject makes a request directly to the Company, the Company forwards it to the Church without delay and does not respond directly without the Church's instructions.

Article 9 (Personal Data Breaches)

  1. If the Company becomes aware of an incident in which the Church's personal data has been or may have been leaked, it notifies the Church without delay and in any event within 48 hours of becoming aware of it.
  2. The notification describes the nature and circumstances of the incident, the categories and approximate number of data subjects and personal data records concerned, the likely consequences, the measures the Company has taken or will take, and a contact person. Information that cannot be provided at once is provided in stages as it becomes known.
  3. The Company provides the information and cooperation needed for the Church to notify the supervisory authority and data subjects under the laws of its country.

Article 10 (Other Assistance)

Taking into account the nature of processing and the information available to the Company, the Company provides the information the Church needs to fulfil its obligations under the laws of its country, such as ensuring security, carrying out data protection impact assessments and prior consultation with the supervisory authority.

Article 11 (Storage Location and International Transfers)

  1. The Company stores the Church's data on servers located in the Republic of Korea and does not transfer it outside the Republic of Korea, except as described in Article 6 of the Annex (route guidance).
  2. Transfers from the Church's country to the Republic of Korea follow Article 4 of the Annex. Where the laws of that country require a separate mechanism, such as standard contractual clauses, the Church and the Company put it in place together with this Agreement.

Article 12 (Return and Destruction after the End of the Service Contract)

  1. The Church may download its data using the export function of the Service before the service contract ends and for 90 days after it ends.
  2. After that period, the Company destroys the Church's data so that it cannot be recovered. If the Church requests immediate destruction, the Company destroys the data without delay. Data that the law requires to be retained is kept for the period required.
  3. Data remaining in backup copies is destroyed after 90 days for backups on the Company's servers and after 1 year for backups on a separate storage device managed by the Company. Until then, it is not used for any purpose other than restoration.
  4. At the Church's request, the Company confirms the destruction in writing.

Article 13 (Information and Audits)

  1. The Company provides the Church with the information needed to demonstrate compliance with the obligations of this Agreement.
  2. The Church may submit written questions once a year, which the Company answers free of charge. If the Church or an auditor appointed by the Church wishes to carry out an on-site audit, the request must be made 30 days in advance and the cost is borne by the Church. The auditor is bound by a duty of confidentiality.

Article 14 (Liability)

Each of the Church and the Company is liable for damage caused to the other by its breach of this Agreement or of the law. The Company's liability is limited to the total fees paid by the Church in the 12 months before the date on which the damage occurred. This limit does not apply to damage caused by the Company's intent or gross negligence, or where the law does not permit liability to be limited.

Article 15 (Term)

This Agreement is effective from the date on which the Church, having been approved by the Company, concludes the service contract, until the obligations under Article 12 have been fulfilled after the service contract ends.

Article 16 (Governing Law and Jurisdiction)

This Agreement is governed by the laws of the Republic of Korea. However, provisions of the data protection laws of the Church's country that cannot be varied by agreement, and the powers of the supervisory authority of that country, continue to apply. Disputes relating to this Agreement are subject to the court having jurisdiction over the Company's address.

Article 17 (Language and Conclusion)

  1. The Korean version of this Agreement is the authoritative original. If a translation differs from it, the Korean original prevails, unless the laws of the Church's country provide otherwise.
  2. This Agreement is concluded when the Church selects "Agree" (동의) for this Agreement on the screen. The Company keeps a record of this and provides a signed copy at the Church's request.

Schedule 1 — Details of Processing

Subject matterMember data and financial records that the Church enters into the Service
Categories of data subjectsMembers and their families, newcomers and visitors, donors, church staff and users of the Service
Types of personal dataThe items in Article 2 of the Privacy Policy and Article 3 of the Annex — name (family and given name in Latin letters), sex, date of birth (optional), contact details, address, photograph, church office, district (subdivision of the congregation) and class meeting, member category, baptism and confirmation records, service roles and occupation, family relationships, attendance, visit records and prayer requests, care notes, offering records, records of personal data consent, and donor information for donation receipts of that country
Special categories of dataThe fact of church membership and records of religious life (data revealing religious beliefs); health information that the Church enters in care notes
Nature and purposeProviding the Service — storage, viewing, editing, printing, export, backup, sending e-mails, and drafting visit texts (no information that identifies a member is sent)
DurationThe term of the service contract and 90 days after it ends (backup copies: Article 12(3) — 90 days on servers, 1 year on the separate storage device)

Schedule 2 — Security Measures

Schedule 3 — Sub-processors (all established and processing in the Republic of Korea)

Sub-processorActivity
YourIT Co., Ltd.Provision of servers and storage; data storage
NHN Cloud Corp.Sending e-mails (no text messages are sent to mobile numbers outside Korea)
Upstage Co., Ltd.Drafting sermon texts in Wesley Simbang Plus (no information that identifies a member is sent)
Toss Payments Co., Ltd.Processing of fee payments (Overseas Churches currently pay by bank transfer)

Wesleysoft · Representative: Choi Sangbong · Business Registration No. 237-31-01809
Address: 101-105, 74 Bonghwa-ro, Wonju-si, Gangwon State, Republic of Korea (Dangye-dong, Dangye Samik Apartment)
Telephone +82 10-2586-5119 · E-mail wesleysoft@wesleysoft.com

문의하기

교회 상황을 알려주시면 알맞은 요금제를 안내해 드리겠습니다. 처음 설정도 도와드립니다.

보내주신 정보는 도입 상담 목적으로만 사용하며, 상담이 끝나면 파기합니다. 자세한 내용은 개인정보처리방침을 참고하십시오.
폼이 어려우시면 wesleysoft@wesleysoft.com으로 보내주셔도 됩니다.