Church data stays separate
Each church’s data is kept separate. This separation is enforced in the database.
SECURITY & PRIVACY
For pastors, finance teams and IT reviewers. Here is how Apprenta protects sensitive giving and contact data — from bank access to data processing.
Explore your questions ↓FOR EVERYDAY CHURCH LIFE
Each church’s data is kept separate. This separation is enforced in the database.
Apprenta imports transactions. The bank connection cannot initiate transfers or direct debits.
Admin, editor and viewer roles separate management, finance work and read-only access. Sensitive actions are checked on the server.
AI functions receive the data needed for the task. Donor names are hidden for general finance questions.
ARCHITECTURE
Access checks take place on the server and in the database. Technical credentials for banking, AI and email services stay on the server; bank credentials are additionally encrypted at rest.
HTTPS between your device and the server
Email confirmation and optional two-factor authentication
Sensitive actions and valid sessions are checked
Data separated by church
Bank and donor data encrypted with AES-256
FOR EVERYDAY CHURCH LIFE
New accounts confirm their email address. A second factor is optional; sensitive actions require a valid session.
Technical credentials for the bank connection are stored encrypted. The payment provider handles card numbers and security codes directly.
Contact information has its own access rules. Bounces, complaints and unsubscribes are considered in communications.
Credentials for AI services stay on the server. Suggested texts and emails are checked for harmful content.
Access, export and deletion are established processes. Roles limit visibility according to team responsibilities.
Apprenta provides documents covering safeguards, data flows and responsibilities for privacy and security questionnaires.
FOR YOUR DUE DILIGENCE
How we handle your bank connection – in concrete terms, not acronyms.
Read transactions only. Apprenta cannot send transfers, set up direct debits, add payees, or change any account settings. That separation is enforced by your bank itself, not by us.
Through your bank’s official open-banking interface, brokered by a payment service that is licensed and supervised by the German federal financial regulator. There is no screen scraping and no storage of your bank login credentials at Apprenta. You authorize the connection directly with your bank.
You – any time, both inside Apprenta and directly in your bank’s online portal. The authorization also expires on a regular schedule by law and must be renewed.
No, not in normal operations. Staff do not have routine access to your data. Support cases follow a documented two-person rule and require your consent.
Who owns the data, what happens if you leave, and how you get it back.
Your church. Apprenta only processes the data on your behalf. We do not claim ownership, do not sell it, and do not pass it on to third parties for our own purposes.
Yes. You can download donors, gifts, lists, transactions, and settings as a structured export (CSV or JSON) at any time – with no waiting and no extra cost.
We delete your active data within 30 days after you cancel, and your data falls out of our rotating backups after another 60 days. You can request written confirmation of deletion. You can pull a full copy of your data any time beforehand.
Yes. Backups are encrypted and stored in the same region as the main database (Frankfurt, Germany). They do not leave that region.
What we use AI for – and what we deliberately do not.
For pastoral suggestions, summaries, categorization, and drafting messages – tasks where a human always decides at the end. AI is **not** allowed to initiate payments, **not** allowed to send messages without approval, and **never** writes to your bank.
No. Customer data is not used to train public AI models. We only use AI business and API setups whose terms do not allow training on customer API requests. Inputs are at most kept briefly for abuse prevention and then deleted.
Only what is actually needed for the specific task. For general finance questions, donor names are stripped before the AI ever sees them. Specific personal references are included only when the task genuinely requires them – for example drafting a message to one specific person.
No. Every AI suggestion is a draft and must be actively approved before it becomes visible or is sent.
Where your data physically lives and which services are involved.
In a data centre in Frankfurt, Germany. Database, file storage, and backups all live in the same region. Your donor and giving data does not leave Germany.
To run the service we work with a few carefully selected providers – for example for database and storage (in Frankfurt), card payments, read-only bank access, email delivery, and AI features. A full list including provider, location, and role is part of our contract.
Your central data – donors, gifts, the database, and backups – stays in Germany. For a few supporting features, providers outside the EU may be involved; only what is needed for that reaches them, and always under the appropriate data-protection agreements.
What we formally have, what we don’t, and what we rely on.
We build on infrastructure whose providers are certified to recognised standards (e.g. ISO 27001), and on top of that we show in plain terms what we do ourselves. A written overview of our controls, data flows, and responsibilities is available as part of a vendor review.
Our database and sign-in layer is audited against the standard security frameworks used for cloud providers. Card payments run through a payment provider that operates under one of the strictest standards for card data. Read-only bank access runs through a payment service that is licensed and supervised by the German federal financial regulator. We can share or link to these external audit reports on request.
We are working towards structured, recurring tests by independent security professionals. We share the current state transparently in a vendor review and do not represent it as more than it is.
What we commit to in writing, and how we handle risk.
For each customer we sign a service contract and a data-processing agreement that lays out our responsibilities. On request we add appendices for your own review – for example sub-processor list, technical and organisational measures, and our incident-handling procedure.
For customers outside the German privacy regime we adapt the agreements to your local legal context and provide clear documentation that lets your lawyers and IT reviewers make a confident assessment.
Liability and how tasks are split if something goes wrong – notification, follow-up, and donor communication – are clearly set out in writing. We also discuss the topic of insurance coverage with you as part of a vendor review.
A guided setup and personal support to get you started. Additional documentation for your board or a review is available on request.
How we respond when something happens.
No known security incidents so far. If one were to happen, we would inform affected customers without delay and keep them updated as we work through it.
Detect → immediate action (close access, rotate anything compromised) → analyse → inform customers → follow-up with concrete measures. We share this procedure as a short, readable document.
At security@apprenta.de. Reports from researchers or customers are handled promptly and without blame.
Another question? security@apprenta.de ↗︎
LET’S TAKE A CLOSER LOOK.
In 30 minutes, we’ll explore your questions
and show you Apprenta in person.