Home / Privacy
Privacy Policy
Last updated: 1 July 2026
This policy explains how Kehilla collects and uses personal data when you use kehilla.io and our services. It applies alongside UK GDPR, the Data Protection Act 2018, and (where applicable) EU GDPR.
Who holds your data
Kehilla operates the platform. Each synagogue or community using Kehilla is the controllerof its members' and visitors' data — they decide what is collected and why. Kehilla acts as a processor, providing software and hosting on their instructions.
For questions about how your own community uses your data, contact them directly. For anything about Kehilla itself, email info@kehilla.io.
What we process
- Contact and account: name, title, email, phone, address; sign-in details (including Google where used); date of birth.
- Family and dependent details: names, relationships, and dates of birth of household members you add.
- Memorial (yahrzeit) information: names, relationships, and dates of deceased relatives you or your community add.
- Payments: invoices, subscriptions, payment status, and identifiers held by payment providers (e.g. Stripe, Achisomoch). Gift Aid declarations including name, house name or number, and postcode where provided.
- Events and messaging: registrations, answers to event questions (which may include dietary or access requirements), notification preferences, and a record of emails sent.
- Rotas and sign-ups: which dates you have volunteered for or sponsored, any note you add (for example what meal you are bringing), and a dedication where you have given one. Where a rota is shared by link, anyone with that link can sign up by giving a name and email address, without a community account.
- Consent records: timestamps recording when you agreed to this policy and, separately, any consent to marketing emails.
- Technical: we do not keep our own log of IP addresses or browsing activity. Our infrastructure providers process technical data such as IP addresses transiently in their operational logs to run and secure the service, under their own short retention periods. To count how many times a class recording has been played we use an anonymous, random identifier that is not linked to your identity; where an IP address is used for this, it is stored only in a hashed form.
Sensitive (special category) data
Synagogue membership reveals religious belief, which is special category data under UK GDPR Article 9. Family details, memorial dates, and health or dietary information collected via event forms are also treated as sensitive. A rota arranged to support a family — meals during bereavement or illness — can reveal health or bereavement information about that family, so those rotas are private by default, reachable only by a link the family or the community chooses to share, and their free-text details are deleted automatically once the rota has finished. Our primary basis for processing this data is your explicit consent, given at sign-up (Article 9(2)(a)). It is also supported, for membership and community records, by the condition that allows a not-for-profit religious body to process its members' data for legitimate organisational purposes (Article 9(2)(d)). This processing is carried out by your community, and by Kehilla on its behalf as its processor — it is not disclosed outside the community except to the service providers needed to run the platform.
Why we process it
We process data to deliver the service: hosting, accounts, payments, communications, and support. The lawful bases we rely on are:
- Contract — for account creation, billing, and service delivery.
- Legal obligation — to meet HMRC requirements for Gift Aid records (retained for 6 years).
- Legitimate interests — for security, fraud prevention, operational reliability, and to keep members informed with community and fundraising communications from their own community (which you can opt out of at any time).
- Consent — for processing sensitive personal data at sign-up. You can withdraw consent at any time.
Who we share data with
We share data with the following categories of processor or independent controller as necessary to operate the service:
- Database hosting: Neon (PostgreSQL)
- File storage: Cloudflare R2
- Email delivery: Resend
- Payments: Stripe, Achisomoch
- Sign-in: Google (OAuth only — email, name, and Google ID)
- Accounting (optional): Xero
- Prayer times (optional): third-party zmanim API (date/location only, no personal data)
Some of these providers, including our database host, process data in the United States. Where personal data is transferred outside the UK, we rely on appropriate safeguards — UK International Data Transfer Agreements (IDTAs) or the UK Addendum to the EU Standard Contractual Clauses — as required by UK GDPR Chapter 5.
How long we keep it
We keep data only as long as necessary for the purposes above. The periods below are the defaults we apply on behalf of communities; a community, as the controller of its members' data, may set different periods, in which case its own decisions govern. Records required by law (such as Gift Aid and accounting records) are kept for at least the legal minimum even if you ask us to delete them.
| Data type | Retention period | Reason |
|---|---|---|
| Member and contact records | Kept while your community needs them; deleted by an admin or on your request. Cancelling a membership does not delete the record. | Contract / legitimate interests |
| Yahrzeit / memorial records | Kept while the member maintains them; deleted if that account is deleted | Legitimate interests |
| Invoices and Gift Aid records | At least 6 years (Gift Aid: from the end of the accounting period of the last donation under the declaration), then reviewed and deleted or anonymised | Legal obligation (HMRC / Companies Act) |
| Consent records | Duration of membership and a period afterwards, as proof consent was given | Legal obligation / legitimate interests |
| Event attendance records | Kept for as long as useful to the community; erasure on request | Legitimate interests |
| Sensitive event-form answers (e.g. dietary, access, health) | Deleted around 30 days after the event | Data minimisation |
| Rota sign-ups (who covered which date) | Kept for as long as useful to the community; erasure on request | Legitimate interests |
| Rota free text on support rotas (dietary needs, delivery notes) | Deleted automatically once the rota closes (60 days by default) | Data minimisation |
| Email and SMS logs | 1 year | Legitimate interests / dispute resolution |
| Audio/video recordings (shiurim) | Kept as part of the community's learning archive while useful; removed at the community's discretion or a speaker's request | Legitimate interests |
| Unsubscribe records | A minimal record (e.g. email address) kept indefinitely to honour your choice not to be contacted | Legal obligation (PECR) |
| Backups | Personal data may persist in encrypted backups for a short period (no more than a few days) after deletion, then is overwritten | Security / integrity |
Data Kehilla holds as its own controller
For most member data, your community is the controller and Kehilla is its processor. Separately, Kehilla is the controller of a small amount of data about its own relationships: the accounts and contact details of community administrators, billing records for communities that subscribe to Kehilla, support correspondence, and visitors to kehilla.io. We keep this for as long as the relationship lasts and a reasonable period afterwards, and security and operational logs for up to 12 months. For these, you can contact us directly at info@kehilla.io.
Your rights
UK GDPR gives you the following rights over your personal data:
- Access — request a copy of all data held about you (Subject Access Request).
- Rectification — ask us to correct inaccurate data.
- Erasure — request deletion of your data where there is no overriding legal reason to keep it. Note: Gift Aid records must be retained for 6 years under HMRC rules even after a deletion request.
- Restriction — ask us to pause processing while accuracy is disputed.
- Portability — receive your data in a machine-readable format (JSON).
- Object — object to processing based on legitimate interests, or to direct marketing (which we must stop immediately).
- Withdraw consent — where we rely on consent, you can withdraw it at any time. This does not affect the lawfulness of processing before withdrawal.
How to exercise your rights
For rights relating to how your community uses your data, sign in to your member portal and open Your data & privacy, where you can contact your community's administrators directly, or email them.
On the same Your data & privacy page you can download a copy of your data, or delete your account. Deleting your account removes your profile and personal details; invoices and Gift Aid records are kept where HMRC and accounting law require, retaining only the name and address those records need and no longer linked to a profile.
For anything about Kehilla itself, email info@kehilla.io. We will respond within one calendar month.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at any time, without first contacting us.
Community and fundraising emails
We send a few kinds of email. Community and service messages — shul news, events, and billing information — are sent to members as part of their membership. Fundraising appeals are sent to members on the basis of their relationship with the community. You can opt out of community updates and/or fundraising emails at any time using the unsubscribe link in any email, the email preferences page it links to, or your member portal. Essential service messages (such as billing and confirmations for things you have registered for) are always sent. We do not sell your data or send you third-party marketing.
Security
We use HTTPS for all data in transit, AES-256 encryption at rest (via Neon and Cloudflare), bcrypt password hashing, and strict separation between communities. Access is limited to what the service requires. We have procedures to detect, report, and investigate personal data breaches, and will notify the ICO within 72 hours of becoming aware of a notifiable breach.
Children
Family members including children may be recorded by account holders (parents or guardians). We do not knowingly send marketing communications to anyone under 18. If you believe a child's data has been processed without appropriate consent, contact us at info@kehilla.io.
Changes
We will update this page when the policy changes and adjust the date at the top.