KingdomFlow legal
Data protection commitments
A plain-language summary of the controls that support a church's data-protection responsibilities.
Effective 25 September 2026
Processing instructions
KingdomFlow processes church-controlled personal information to provide the subscribed service and documented support. The church is responsible for lawful instructions, notices, consent where required, and the access it grants to its users.
Access and confidentiality
Access is limited by tenant, role, and workspace. Personnel and service providers with access are expected to follow confidentiality and security obligations appropriate to their duties.
Security incidents
Suspected incidents are investigated, contained, documented, and communicated to affected customers where required by law or contract. Churches should report concerns promptly to security@kingdomflow.co.ke.
Return, export, and deletion
Authorised administrators can request an export or deletion when a subscription ends, subject to identity checks, backups, active legal holds, and statutory retention duties. Backup copies expire through controlled retention cycles.
Formal agreement
This page is a product summary, not a signed data-processing agreement. Enterprise and regulated customers should execute a formal agreement describing scope, sub-processors, retention, assistance, audits, and cross-border safeguards before production use.