ChERP
Back to home

Privacy and Content Policy

Last updated 12 August 2026

Welcome to ChERP. We are committed to protecting your personal information and ensuring transparency in how we collect, use, and share your data. This Privacy and Content Policy (Policy) is a binding legal document and forms part of our contractual relationship with you. It outlines our practices concerning the collection, use, and disclosure of your information in compliance with the Protection of Personal Information Act (POPIA), the General Data Protection Regulation (GDPR), and other applicable laws.

Definitions

Personal Information: Information relating to an identifiable, living natural person or existing juristic person, as defined by POPIA and GDPR. Data Subject: The individual or entity to whom the personal information relates. Processing: Any operation or activity concerning personal information, including collection, storage, use, dissemination, or destruction. Child: For the purposes of this policy, a person under the age of 18 years. Platform: The website, applications, and digital services operated by Appetite Technology (Pty) Ltd (registration number 2023/849612/07), trading as "Cherp Connect", "ChERP" and "Cherp".

Application of the Protection of Personal Information Act (POPIA)

To the extent relevant and applicable, all references to the Protection of Personal Information Act, 4 of 2013 (POPIA) and the General Data Protection Regulation (EU) 2016/679 (GDPR) shall be construed as functionally equivalent and shall be interpreted interchangeably for the purposes of this Policy. The provisions of this document shall therefore be read and applied in a manner that gives effect to the core principles, rights, and obligations prescribed by either or both regimes. Where a conflict arises between POPIA and GDPR, or where jurisdiction-specific requirements differ, the more stringent, expansive, or protective standard affording greater rights to the Data Subject shall prevail. Nothing in this Policy shall be construed as limiting any rights afforded to a Data Subject under either legal regime, and cherp.co.za undertakes to implement reasonable and appropriate safeguards to uphold those rights consistently across all regions in which it operates.

Processing

cherp.co.za acknowledges its legal and ethical obligation to protect the personal information of users and complies with POPIA. We undertake to process all personal information in accordance with the conditions for lawful processing set out in Chapter 3 of POPIA, including accountability, processing limitation, purpose specification, further processing limitation, information quality, openness, security safeguards, and data subject participation. Personal information will only be collected and processed where: (a) the data subject consents thereto; (b) processing is necessary to carry out actions for the conclusion or performance of a contract; (c) processing complies with an obligation imposed by law; (d) it protects a legitimate interest of the data subject or a third party; or (e) it is necessary for the proper performance of a public law duty or to pursue our legitimate interests. Data subjects have the right to access their personal information; request correction, deletion or destruction of personal information; object to processing or to direct marketing; and lodge a complaint with the Information Regulator.

Who controls your data

Each church is the controller of the records it captures in ChERP. Appetite Technology (Pty) Ltd operates the platform as a processor and only handles church data to run the service, provide support, and meet legal obligations.

Information we collect

  • Contact information — name, email address, phone number, physical address.
  • Account and role details for staff users, including sign-in activity.
  • Member records your church captures: contact details, family links, group membership, attendance and check-in history.
  • Pastoral notes, counselling requests and background-check outcomes, restricted to pastoral roles.
  • Financial records: giving, pledges, expenses, payouts and supporting documents.
  • Digital identifiers — IP address, browser type, device information.
  • Usage data — interactions with the platform, preferences, and settings.
  • Payment and transaction data — information required to process donations, ticket sales and subscriptions, including billing addresses and transaction history.
  • Device and technical data — operating system, device type, technical identifiers, and, where you enable notifications, a device push-notification token.

How we collect information

We collect personal information through direct interactions (when you register, capture records, or contact us); automated technologies such as cookies and similar tracking technologies; third-party integrations you link to the platform, such as calendar or messaging providers; and, where legally permissible, public sources.

Purpose of collection

We process your personal information for service delivery (to operate your church's workspace and provide our services); communication (updates, enquiries and support); improvement (analysing usage patterns to improve the platform); legal compliance; fraud detection and risk management; and marketing, where you have opted in.

Marketing communications

We may use your information to send promotional emails or marketing materials where you have opted in, or where we rely on legitimate interest. You may withdraw consent or opt out at any time by clicking unsubscribe or contacting us directly.

Legal basis for processing

Consent: where you have given voluntary, specific and informed consent, which you may withdraw at any time without affecting processing carried out before withdrawal. Contractual necessity: where processing is necessary to enter into or perform a contract with you. Legal obligation: where we must process information to comply with applicable laws, regulations or enforceable governmental requests. Legitimate interests: where processing is necessary for our legitimate business interests, such as improving and securing the platform, preventing fraud, or enforcing legal claims, except where overridden by your fundamental rights and freedoms. Where more than one basis applies, we rely on the one offering the highest level of protection to the data subject.

Privacy firewall between ministry and finance

Pastoral notes, counselling records and background-check outcomes are never visible to finance-only roles. Access rules are enforced in the database itself, not just in the interface, and sensitive views are recorded in the audit log.

Sharing of information

We may share your personal information with service providers who assist us in operating the platform, subject to confidentiality agreements. These currently include Supabase (database, authentication and file storage), Resend (transactional email), Paddle and Paystack (payment processing), and Twilio (WhatsApp and SMS messaging, where your church enables it). We may also share information with legal authorities where required by law or to protect our legal rights, in the event of a merger, acquisition or sale of assets, and with affiliates for internal business, compliance and administrative purposes. We do not sell your personal information to third parties.

AI processing

ChERP's AI assistant, Naya, and related assistant features send the relevant text to third-party AI providers — currently Google Gemini, Groq, DeepSeek or OpenRouter, depending on availability — solely to generate a reply or complete the requested task. These providers process the request under our commercial terms with them and do not use it to train their own models.

Data security

We implement appropriate technical and organisational measures to protect your personal information, including encryption of data in transit and at rest, access controls limiting access to authorised personnel and roles, regular audits and monitoring of our security systems, and breach notification to you and the appropriate regulators in accordance with legal requirements.

Data retention periods

We retain your personal information only as long as necessary to fulfil the purposes outlined in this policy, unless a longer retention period is required by law. Account information is retained for the duration of your active use and up to 12 months after closure. Billing and financial records are kept for 5 years in accordance with tax laws. Churches set their own audit-log retention window in Settings. When a church closes its account we delete or return its records within 30 days, except where South African law requires longer retention. Data no longer required is securely destroyed or anonymised.

Your rights

Under POPIA and GDPR you have the right to access your personal information; request correction of inaccurate or incomplete information; request deletion; request a copy of your data in a structured, commonly used, machine-readable format; object to processing; and lodge a complaint with the Information Regulator or relevant supervisory authority. Members may ask their church directly, and church administrators can action most requests inside ChERP. To exercise these rights with us, contact admin@cherp.co.za. We will respond within the statutory time frame and may request identity verification first.

Cookies and tracking technologies

We use cookies and similar technologies to keep you signed in, remember your theme preference and enhance your experience. You can manage your cookie preferences through your browser settings and may opt out of non-essential cookies at any time.

Third-party links

Our platform may contain links to third-party websites. We are not responsible for the privacy practices of these websites and encourage you to read their privacy policies. Use of such links is at your own risk.

Children's privacy

Churches may capture records of minors, such as children's ministry check-ins, on the lawful basis of parental consent obtained by the church. Our own services are not directed to individuals under 18 and we do not knowingly collect personal information from children directly without parental consent. Users must be at least 16 years old to provide consent, unless applicable law allows a lower age (not below 13 years). For users under the age of consent, verifiable parental consent is required. We apply data minimisation, plain language notices and the highest privacy settings by default for child records, and we may restrict or terminate accounts where parental consent cannot be verified.

International data transfers

We may transfer your personal information to countries other than the one in which you reside. These countries may have data protection laws that differ from your own. We ensure appropriate safeguards are in place to protect your personal information.

Changes to this policy

We may update this policy from time to time. Any changes will be posted on this page with an updated revision date. Substantive changes will be communicated to you where required by law.

Reporting a security concern

Email support@cherp.co.za with the details. Please do not include member personal information in your first message.

Contact us

If you have any questions or concerns about this policy or our data practices, please contact us at: Appetite Technology (Pty) Ltd, trading as cherp.co.za, company registration number 2023/849612/07, registered office: 350 Parkstation Road, Greenwood Park, Durban, KwaZulu-Natal, 4051, South Africa. General and privacy queries: admin@cherp.co.za. Support: support@cherp.co.za.

This page is maintained by the ChERP team at Appetite Technology. It describes our current practices and is not an independent certification or legal advice. Questions? admin@cherp.co.za