Home / Privacy policy
Last updated March 2, 2026Privacy policy
What we collect when you write to us, why we are allowed to keep it, how long it stays, and how you make us delete it.
This policy covers the public website at pewroster.com. Congregation data held inside the PewRoster scheduling application is governed by the data processing terms in the customer agreement, and a church remains the controller of its own volunteer records.
Who is responsible for your data
The controller for this website is MLJ, SASU, a French simplified joint stock company registered under SIREN 934 769 837, publisher of the PewRoster service. The publication director is Jimenez Julien. For any privacy question, any request to exercise your rights, or any complaint about how your information has been handled, write to jimenezjulien42@gmail.com. Postal and registration details are listed in the legal notice.
What the contact form collects
The only place this website asks for personal information is the request form on the home page. When you submit it, the following named fields are transmitted and stored:
- name: the full name you enter, so a reply can be addressed to a person.
- email: the work email address we reply to.
- company: your church or parish name.
- role: your role at the congregation, chosen from a list.
- request: what you are asking for, chosen from a list.
- size: your average weekly attendance band, chosen from a list.
- message: the free text you write about your serving teams.
- consent: the record that you ticked the agreement box before sending.
Three hidden fields travel with the submission and contain no information about you: form-name, which routes the message, subject, which labels it, and recipient, which addresses it to the publisher. A honeypot field named bot-field is present and must stay empty; it exists only to catch automated spam. Netlify additionally records the submission time and the IP address the request came from, as part of its spam filtering.
Please do not send personal details about your volunteers or members through this form. If you want to discuss an import file, we will arrange a secure transfer rather than accepting member records by email.
Why we are allowed to process it
For visitors in the European Union and the United Kingdom, the legal basis under the General Data Protection Regulation is Article 6(1)(b), steps taken at your request before entering into a contract, together with Article 6(1)(f), our legitimate interest in answering enquiries about our own product. The consent checkbox records your agreement to be contacted about your enquiry, and you can withdraw it at any moment. For visitors in the United States, we process the information to respond to a request you initiated, which is a compatible and disclosed purpose under state privacy law.
Who processes the data with us
This site is hosted by Netlify, Inc., 512 2nd Street, Suite 200, San Francisco, CA 94107, United States. Form submissions are received, filtered for spam and stored by Netlify Forms, then forwarded by email to the publisher. Netlify acts as our processor for that storage and delivery, and its own data protection terms apply to the infrastructure. Our reply reaches you through an email provider, so the content of the exchange also sits in ordinary mailboxes on both sides. We use no other processor for this website, and we do not send enquiry data to any advertising network, data broker or lead marketplace.
How long we keep it
Enquiries that do not turn into a customer relationship are deleted from the Netlify Forms store and from our mailbox within 24 months of the last message in the thread. If your congregation becomes a customer, the enquiry is retained for the life of the account and then for the period set out in the customer agreement, because it forms part of the commercial record. Accounting documents that we are legally required to hold are kept for ten years under French commercial law. You can ask for an earlier deletion at any time, and we will act on it unless a legal retention duty applies.
Cookies and measurement
This website sets no advertising cookies, runs no third party analytics scripts, and loads no social media tracking pixels. There is no visitor profiling, no cross site tracking and no consent banner, because nothing here requires one. Two web fonts are requested from Google Fonts so that the pages render in EB Garamond and Assistant; that request necessarily reveals your IP address to Google as the font host. Netlify keeps standard server logs, including IP address and user agent, for security and abuse prevention, and rotates them on a short cycle.
International transfers
MLJ, SASU is established in France, while our host is established in the United States, so data submitted through this form is transferred outside the European Economic Area. That transfer relies on the European Commission standard contractual clauses incorporated into the Netlify data processing agreement, supported by encryption in transit and at rest. Within the PewRoster application itself, congregation and volunteer records for US churches are stored on servers located in the United States.
Your rights in the United States
If you live in California, Colorado, Connecticut, Utah or Virginia, state privacy law gives you the right to know what personal information we hold about you, to obtain a copy of it, to have it corrected, and to have it deleted. California residents also have the right not to be discriminated against for exercising those rights, and the right to know the categories of information disclosed. We do not sell personal information, we do not share it for cross context behavioral advertising, and we use no automated profiling to make decisions about you, so there is nothing to opt out of on those grounds. To exercise any of these rights, write to jimenezjulien42@gmail.com with the email address you used, and we will verify the request and respond within 45 days.
Your rights under the GDPR
If you are in the European Union or the United Kingdom, you hold the rights of access, rectification, erasure, restriction of processing, portability and objection, and the right to withdraw consent at any moment without affecting processing already carried out. Requests go to the same address, jimenezjulien42@gmail.com, and are answered within one month. If you are not satisfied with our answer, you may complain to your national supervisory authority; in France that authority is the CNIL.
Children's privacy
This website is aimed at church staff and volunteer coordinators, and is not directed at children. We do not knowingly collect information from anyone under 16 through this site. Congregations that schedule minors as volunteers inside the application are responsible for holding the appropriate parental consent, and the application restricts what a minor's record can display. If you believe a child has sent us information through this form, write to us and we will delete it promptly.
Security
Traffic to this site is served over HTTPS. Form submissions are encrypted in transit and at rest, access to the submission store is limited to the publication director, and administrative access uses two factor authentication. No transmission over the internet can be guaranteed to be perfectly secure, but we will tell affected people and the relevant authority without undue delay if a breach ever puts personal data at risk.
Changes to this policy
If this policy changes in a way that affects how enquiry data is handled, we update this page and change the date at the top. Material changes are also mentioned in the reply to any open enquiry thread. This version was published on March 2, 2026 and replaces every earlier version.