Data Processing Addendum
Last updated August 18, 2026 (version 1.1)
Exhibit A to the wtxLabs Sync Terms and Conditions. WTXLABS, LLC — sync.wtxlabs.com. Version 1.1 · Effective August 18, 2026 · Published at https://sync.wtxlabs.com/dpa
This Data Processing Addendum (the “DPA”) forms part of, and is incorporated by reference into, the wtxLabs Sync Terms and Conditions between WTXLABS, LLC, a Georgia limited liability company at 279 W. Crogan Street - TRS, Lawrenceville, Georgia 30046 (the “Company”), and the customer that has accepted those Terms and Conditions (the “Customer”) (together, the “Agreement”). This DPA governs the Company’s Processing of Personal Data on the Customer’s behalf in connection with the wtxLabs Sync service (the “Service”).
1. Definitions
Capitalized terms not defined here have the meaning given in the Agreement.
“Public Record Data” means the Customer’s Planning Center records that the Customer has designated as public and that the Service retrieves — calendar events, group listings, registration and signup listings, sermon and media listings, form listings, fund names, announcements, and setlists. The Service does not retrieve the Customer’s people or member roster, group membership lists, individual check-in records, donation or donor records, form submission content, or private staff notes.
“Customer Personal Data” means Personal Data that the Company Processes on the Customer’s behalf under the Agreement, comprising Administrator Data and any Personal Data incidentally contained within Public Record Data.
“Administrator Data” means Personal Data relating to the individuals the Customer authorizes to administer its Sync account.
“Data Protection Laws” means all privacy and data protection laws applicable to a party’s Processing of Customer Personal Data under the Agreement.
“Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data Processed by the Company or a Subprocessor.
“Planning Center” means the Planning Center Online service operated by Ministry Centered Technologies, Inc., with which the Customer maintains its own separate agreement.
“Processing” means any operation performed on Personal Data, whether or not by automated means, including collection, storage, caching, retrieval, use, disclosure, and deletion. “Process” and “Processed” are construed accordingly.
“Subprocessor” means any third party engaged by the Company to Process Customer Personal Data in connection with the Service.
“Sync Embed” means the JavaScript snippet and associated assets provided by the Company for installation on the Customer’s website.
2. Roles of the Parties
2.1 As between the parties, the Customer is the controller of Customer Personal Data and the Company is a processor acting on the Customer’s behalf. The Customer determines the purposes and means of Processing, including which Planning Center records are designated for public display.
2.2 The Customer is responsible for the accuracy, quality, and legality of Customer Personal Data, for the means by which it acquired that data, and for having a lawful basis to instruct the Company to Process it.
2.3 Planning Center is not a Subprocessor of the Company. The Customer maintains its own direct relationship and agreement with Ministry Centered Technologies, Inc., and the Company retrieves data from Planning Center only under authorization the Customer grants through OAuth.
2.4 The Service retrieves only those Planning Center records that the Customer has designated as public within Planning Center. The Company does not retrieve records the Customer has not so designated, and does not retrieve the Customer’s people or member roster, group membership lists, individual check-in records, donation or donor records, form submission content, or private staff notes on service plans. These exclusions are enforced in the application, not by policy alone.
3. Processing Instructions
3.1 The Company shall Process Customer Personal Data only on the Customer’s documented instructions, except where required by applicable law, in which case the Company shall inform the Customer of that requirement before Processing unless the law prohibits it.
3.2 The Agreement, this DPA, and the Customer’s configuration choices within the Service constitute the Customer’s complete documented instructions.
3.3 The Company shall promptly inform the Customer if, in its opinion, an instruction infringes Data Protection Laws.
3.4 The Company shall not: (a) sell or share Customer Personal Data as those terms are defined under applicable Data Protection Laws; (b) Process Customer Personal Data for its own commercial purposes or for advertising; (c) retain, use, or disclose Customer Personal Data outside the direct business relationship with the Customer; or (d) combine Customer Personal Data with data from other sources except as necessary to provide the Service.
3.5 Artificial Intelligence Providers. When the Service submits content to a third-party artificial-intelligence provider, the Company will process that content only for the purposes described in the Agreement and will use the privacy and data-use controls available under the Company’s agreement with that provider. The Company will not independently use Customer Personal Data or AI-generated output to train a general-purpose artificial-intelligence model.
4. Confidentiality
4.1 The Company shall treat Customer Personal Data as confidential and shall ensure that any person authorized to Process it is bound by an appropriate obligation of confidentiality.
4.2 The Company shall limit access to Customer Personal Data to those personnel who require access to provide, maintain, or support the Service.
5. Security
5.1 The Company shall implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against a Personal Data Breach, taking into account the state of the art, the costs of implementation, and the nature, scope, and purposes of Processing. The measures in place as of the effective date are described in Schedule 2.
5.2 The Company may update the measures in Schedule 2 from time to time provided the updates do not materially reduce the overall level of security.
5.3 Security Measures. The Company will maintain reasonable technical and organizational safeguards appropriate to the nature of the Customer Personal Data processed through the Service. Schedule 2 describes the material safeguards implemented as of the DPA’s effective date. The Company may replace a safeguard with a substantially equivalent or more protective safeguard, provided that the change does not materially reduce the Service’s overall security.
6. Subprocessors
6.1 The Customer grants the Company general authorization to engage the Subprocessors listed in Schedule 3.
6.2 The Company shall notify the Customer at least 30 days before engaging a new Subprocessor or replacing an existing one. Notice may be given by email to the Customer’s account administrator or by updating a subprocessor page and notifying the Customer of the update.
6.3 The Customer may object to a new Subprocessor on reasonable data protection grounds within 15 days of notice. If the parties cannot resolve the objection, the Customer may terminate the Agreement for the affected portion of the Service without penalty and receive a pro-rata refund of prepaid fees.
6.4 The Company shall impose data protection obligations on each Subprocessor that are no less protective than those in this DPA, and remains liable to the Customer for each Subprocessor’s performance.
7. Data Subject Rights
7.1 Taking into account the nature of the Processing, the Company shall provide reasonable assistance to the Customer, through appropriate technical and organizational measures and insofar as possible, in fulfilling the Customer’s obligation to respond to requests from individuals exercising rights under Data Protection Laws.
7.2 If the Company receives such a request directly from an individual, it shall not respond substantively other than to direct the individual to the Customer, and shall notify the Customer without undue delay.
7.3 The Customer acknowledges that Customer Personal Data originates in the Customer’s Planning Center account, and that correction or deletion at source in Planning Center is the primary mechanism for fulfilling many such requests. Cached copies held by the Service are refreshed from Planning Center approximately every fifteen minutes.
8. Personal Data Breach Notification
8.1 The Company shall notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data.
8.2 The notification shall describe, to the extent known: the nature of the breach; the categories and approximate number of individuals and records affected; the likely consequences; and the measures taken or proposed. Information may be provided in phases as it becomes available.
8.3 The Company shall take reasonable steps to contain and remediate the breach and shall reasonably cooperate with the Customer’s own notification obligations. Notification under this section is not an acknowledgment of fault or liability.
9. Assistance and Assessments
9.1 Taking into account the nature of Processing and the information available to it, the Company shall provide reasonable assistance to the Customer with data protection impact assessments and prior consultations with supervisory authorities, where required by Data Protection Laws.
9.2 Assistance under Sections 7 and 9 that exceeds reasonable support may be subject to a reasonable fee, notified in advance.
10. Return and Deletion of Customer Personal Data
10.1 Planning Center records retrieved by the Service are held only as a cache to render the Sync Embed, are refreshed automatically approximately every fifteen minutes, and are deleted when the Customer disconnects Planning Center through the Customer dashboard.
10.2 Where the Customer connects but does not subscribe, cached data is purged automatically after thirty days of inactivity.
10.3 Support correspondence is retained in the Company’s email systems for 12 months and is not covered by the automated purge in clause 10.2.
10.4 Internal sync logs are retained for fourteen days.
10.5 On disconnection, the Customer’s own design settings (colours, fonts, layouts) are retained so that the Customer is not required to reconfigure the Service on return. These are deleted on request.
10.6 On expiry or termination of the Agreement, the Company shall delete Customer Personal Data within 30 days, except to the extent it is required to retain a copy by applicable law, in which case it shall continue to protect that copy under this DPA.
10.7 Removal Requests. Upon Customer’s written request, the Company will use commercially reasonable efforts to delete specified Personal Data from the Company-controlled cache and public display. Customer is responsible for correcting, removing, or changing the source record in Planning Center when necessary to prevent the information from being retrieved again.
11. Audits and Information Rights
11.1 The Company shall make available to the Customer information reasonably necessary to demonstrate compliance with this DPA, including the descriptions in Schedules 2 and 3 and any third-party certifications held by its Subprocessors.
11.2 Where the information made available under clause 11.1 is not sufficient, the Customer may request an audit no more than once in any twelve-month period, on at least 30 days’ written notice, during normal business hours, subject to confidentiality obligations and at the Customer’s expense.
12. Minors
12.1 The Service does not retrieve the Customer’s people or member roster, group membership lists, individual check-in records, or form submission content. This constraint is enforced in the application rather than by policy. Accordingly, the Service does not receive individual-level records of the Customer’s members, attendees, or group participants, whether adults or minors.
12.2 The Customer acknowledges that Personal Data may nonetheless appear incidentally within Public Record Data — for example, a contact email address published on a public group listing, or the name of a speaker published on a public sermon listing — and that such an individual could in principle be a minor.
12.3 The Customer is responsible for determining what it designates as public within Planning Center, for whether any such designation may lawfully be published, and for obtaining any parental or guardian consent required by applicable law.
12.4 The Company does not knowingly solicit or collect Personal Data directly from children. All Public Record Data reaches the Service from the Customer’s Planning Center account at the Customer’s direction, and never from the individual.
12.5 On the Customer’s written request, or on request of a parent or guardian forwarded by the Customer, the Company will use commercially reasonable efforts to delete the specified individual’s Personal Data from the Company-controlled cache and public display. The Customer is responsible for correcting, removing, or changing the source record in Planning Center when necessary to prevent the information from being retrieved again.
13. Sensitive and Special Category Data
13.1 The parties acknowledge that Personal Data indicating an individual’s association with a religious organization may constitute sensitive or special category Personal Data under certain Data Protection Laws.
13.2 The Customer shall not instruct the Company to Process any category of sensitive Personal Data beyond that inherent in the Service’s described purpose without the Company’s prior written agreement.
14. Liability, Term, and General
14.1 This DPA takes effect on the date the Customer accepts the Agreement and continues for as long as the Company Processes Customer Personal Data.
14.2 Liability. Each party’s liability arising out of or relating to this DPA is subject to the limitations, exclusions, and procedures stated in the “Limitation of Liability” section of the Terms and Conditions, which caps the Company’s total aggregate liability at the total fees paid by the Customer in the twelve (12) months immediately preceding the event giving rise to the claim. Nothing in this DPA expands either party’s liability beyond the liability established under the Agreement, except to the extent a limitation or exclusion is prohibited by applicable law.
14.3 In the event of a conflict between this DPA and the Agreement in respect of the Processing of Customer Personal Data, this DPA prevails.
14.4 Dispute Resolution. This DPA is governed by the laws of the State of Georgia, without regard to its conflict of laws principles. The dispute-resolution and binding-arbitration provisions contained in the wtxLabs Sync Terms and Conditions apply to disputes arising out of or relating to this document.
14.5 If any provision of this DPA is held invalid or unenforceable, the remainder continues in full force.
15. Acceptance and Updates
15.1 This DPA is accepted by the Customer at the time the Customer accepts the Agreement. No separate signature is required, and the absence of a handwritten or electronic signature does not affect the binding effect of this DPA.
15.2 The current version of this DPA is published at https://sync.wtxlabs.com/dpa. Each version is identified by a version number and effective date shown at the head of the document. The version in force between the parties is the version in effect on the date the Customer accepted the Agreement, until superseded in accordance with clause 15.3.
15.3 The Company may update this DPA from time to time. For any update that materially reduces the Customer’s rights or materially increases the Customer’s obligations, the Company shall give at least 30 days’ notice by email to the Customer’s account administrator before the update takes effect. Continued use of the Service after the effective date of the update constitutes acceptance of the updated version. Changes to Subprocessors are governed by Section 6 rather than by this clause.
15.4 The Company maintains a record of each Customer’s acceptance, including the version accepted and the date and time of acceptance, and shall make that record available to the Customer on request.
Schedule 1 — Details of Processing
Subject matter. Provision of the wtxLabs Sync service, which retrieves records the Customer has designated as public in Planning Center and renders them on the Customer’s website through an embedded JavaScript snippet.
Duration. The term of the Agreement, plus the deletion periods described in Section 10.
Nature and purpose of Processing. Retrieval of Customer-designated public records from Planning Center via authorized API access; temporary caching, formatting, and display of those records through the Sync Embed; account administration and authentication via OAuth; subscription billing and payment processing; and optional AI-assisted analysis of the Customer’s website for theme and styling extraction.
Categories of data subjects. The Customer’s authorized account administrators. Individuals whose Personal Data appears incidentally within Customer-designated public Planning Center records — principally the contact person named on a public group listing and speakers named on public sermon listings; the Service does not retrieve member rosters or group membership lists, so members, attendees, and group participants are not themselves data subjects of the Service. Visitors to the Customer’s website on which the Sync Embed is installed, in respect of technical data only: because the Embed is served from sync.wtxlabs.com, the visitor’s browser necessarily makes a request to the Company and the Company therefore receives the visitor’s IP address and user agent, as any web server does. The Company does not use this to identify or profile visitors, sets no cookies, and runs no analytics.
Categories of Personal Data. Administrator identity: first and last name, email address, Planning Center person identifier. Incidental data within public records: a contact email address published on a public group listing; speaker names published on public sermon listings. Location: group location, honouring the Customer’s Planning Center display preference — a precise location is stored only where the Customer set the preference to “exact”; where the preference is “approximate” the street address is discarded before storage and only “City, ST” is retained; where “hidden,” nothing is stored. Technical data (sync.wtxlabs.com only): IP address, browser type, domain names, access times, referring website addresses. Placement: the page URL on the Customer’s own site where an embed runs, with the query string stripped. Billing: billing contact details held by the payment processor; cardholder data is submitted directly to the payment processor and is never received or stored by the Company. Support correspondence: the administrator’s email address and the free-text content of any support message, whose content is determined by the Customer and may contain Personal Data relating to third parties. Authentication: Planning Center OAuth access and refresh tokens, encrypted at rest.
Schedule 2 — Technical and Organizational Measures
The following measures are in place as of the effective date of this DPA.
Encryption. Data in transit is protected using TLS/SSL. Planning Center OAuth access and refresh tokens are encrypted at rest using AES-256-GCM. Token encryption is enforced through a single controlled code path, so that no other component can read or write those credentials in plaintext. The system fails closed on a missing, malformed, or tampered encryption key rather than falling back to plaintext.
Access control. Administrative functions are access-restricted. Authentication to the Service is performed through Planning Center OAuth; the Company does not store Customer passwords.
Data minimization. The Service retrieves only records the Customer has designated as public within Planning Center, enforced in the application’s module registry rather than left to configuration. The Service does not request the Customer’s people or member roster, group membership lists, individual check-in records, donation or donor records, form submission content, or private staff notes; where a related endpoint is used at all, only non-personal metadata is read — for example, the list of giving fund names, never donations or donors. Group locations honour the Customer’s Planning Center display preference, enforced on the way in rather than by hiding data after storage. Public group tags are narrowed on ingestion to only those tags Planning Center itself publishes on the church’s public group finder. Only the page URL on which an embed runs is recorded, with the query string stripped. Planning Center records are held only as a refresh cache, not as a durable store of record.
Visitor privacy. The Embed sets no cookies and runs no analytics, and transmits no behavioural or identifying data about visitors back to the Company. It writes one item of local state to the visitor’s browser — local storage recording which announcements that visitor has dismissed, so that dismissing one notice does not suppress the next. This is strictly necessary to a function the visitor has requested and is not used for tracking. When an embed fails to render, a diagnostic report is sent to the Company describing what failed and the page path with the query string stripped, never who was viewing. Where a visitor submits a form or makes a payment, Planning Center’s own interface opens over the Customer’s page and the submission passes directly to Planning Center without traversing the Company’s systems.
Payment data. Cardholder data is submitted directly from the Customer’s browser to the payment processor. The Company does not receive, transmit, or store cardholder data.
Infrastructure and change management. Application hosting and database infrastructure are provided by the vendors identified in Schedule 3. Database changes are applied through version-controlled migrations as part of the deployment process. An automated test suite is maintained and run against the application.
Schedule 3 — Approved Subprocessors
The Customer authorizes the following Subprocessors as of the effective date of this DPA.
Amazon Web Services, Inc. (Amplify Hosting; Simple Email Service; CloudWatch Logs) — application hosting and compute, transactional and support email delivery, and application logging. Processes all Customer Personal Data transiently in the course of serving requests; via email, the administrator’s email address and the free-text content of support messages; via logging, Customer organization names and error detail. Processing location: United States (AWS US East 1, Northern Virginia).
Neon, LLC, a subsidiary of Databricks, Inc. (serverless Postgres) — primary database and storage. Processes Administrator Data, cached Planning Center public records, and encrypted OAuth tokens. Processing location: United States (AWS US East 1, Northern Virginia).
Stripe, Inc. — subscription billing and payment processing. Processes billing contact data. Cardholder data is collected directly by Stripe and is never received by the Company. Processing location: United States, with transfers to Stripe affiliates and sub-processors in other jurisdictions as provided in Stripe’s own data processing agreement.
Anthropic PBC — AI-assisted website analysis and theme extraction. Processes publicly accessible content from the Customer’s website submitted for analysis. No Planning Center data is submitted to this Subprocessor. Processing location: United States.
The Company uses no analytics providers, advertising networks, or third-party error-monitoring services.
Contact
WTXLABS, LLC
Email Address: sync@wtxlabs.com
Mailing address: 279 W. Crogan Street - TRS, Lawrenceville, Georgia 30046
Phone number: (470) 223-8233