Privacy Policy
Assemblios, operated by Resiliatech. Last updated 3 August 2026.
Assemblios is a church management system used by churches in Zimbabwe and Southern Africa to
run membership, giving, communication, events and volunteer rosters. Churches trust us with the
personal information of their congregations, including children. This policy explains what is
collected, why, who can see it, and what we never do.
Who we are
Resiliatech, Harare, Zimbabwe. Contact:
hello@assemblios.com.
The church is the data controller
Each church (or denomination) using Assemblios decides what member information to record and
who in the church may see it. Assemblios processes that information on the church's behalf. If you
are a church member with questions about what your church has recorded about you, your first
point of contact is your church's administrator; we will also help directly where we can.
Information we process
- Member records your church enters or imports: name, phone number, household
and family links, branch, departments, cells/groups, membership status and transfer history.
- Phone numbers, used to identify members, deliver one-time login codes (SMS
OTP), giving receipts, event reminders and church broadcasts.
- Giving records: amounts, giving categories (tithes, offerings, campaigns,
pledges), dates, and the payment references returned by Paynow. We never see or store
mobile-money PINs, bank details or card numbers.
- Attendance and check-in records for services and events, including child
check-in and guardian codes where the church has enabled children's ministry.
- Volunteer and roster information: serving roles, availability and swaps.
- Prayer requests and messages members submit through the member web surface.
- Basic technical logs (timestamps, delivery status, error records) needed to
operate and secure the service.
Children and minors
- Records about children are created by the church with the consent of a parent or
guardian, and child check-in is opt-in per church.
- We apply data minimisation to minors: only what is needed for safe check-in and children's
ministry is stored.
- Child check-in uses guardian codes so a child is only released to an
authorised guardian, and check-in/out events are logged.
- Children are never contacted directly by Assemblios; communication goes to the guardian.
What we never do
- We never hold or move church funds. Giving goes directly to the church's
own Paynow merchant account. Assemblios only records, reconciles, receipts and reports.
- We do not sell, rent or share personal information with advertisers or
data brokers - not members' data, not giving data, not anyone's.
- We do not use one church's data for any other church, or for our own marketing.
- We do not send unsolicited marketing SMS to members. SMS messages members receive are sent
on behalf of their own church, or are service messages such as login codes and receipts.
Per-church data isolation
Every church's data is strictly isolated from every other church's, and within a denomination,
access is scoped by branch and role. A branch administrator sees only their branch; denomination
HQ roles see only their own denomination's branches. Access controls are enforced on the server on
every request, and administrator, finance and leader accounts require two-factor authentication.
Who we share it with
- Your church's authorised administrators and leaders, scoped by their role
(for example, only treasurers see detailed giving records).
- Paynow (Webdev Pvt Ltd, Zimbabwe) processes member giving through the
church's own merchant account.
- PayPal processes the church's own platform subscription and messaging
credit payments.
- Mugonat Systems (Zimbabwe), our SMS gateway, delivers login codes,
receipts, reminders and church broadcasts to members' phones.
- Our hosting provider stores data on secured servers.
- We may disclose information if required by law.
Export and deletion
Your data is yours. A church can export its member directory, giving records and reports at
any time from its portal, in standard formats. If a church closes its account, we delete its data
within 30 days of a confirmed request, except records we must retain for accounting or legal
purposes. Individual members may ask their church, or us, to correct or delete their personal
information; we action verified requests within 30 days.
How long we keep it
We keep a church's records while its account is active so its history stays available. Backups
are retained for up to 30 days, with encrypted archives kept for disaster recovery.
Security
Traffic is encrypted with HTTPS. Administrative access is restricted and logged, staff and
church admin accounts use two-factor authentication, and databases are backed up nightly to
encrypted storage. Payment processing is idempotent and auditable.
Your rights
You may ask to see, correct or delete the personal information held about you, and you can ask
your church to stop contacting you by SMS at any time. Email
hello@assemblios.com and we will respond within 30 days.
Changes
If this policy changes materially we will update this page and the date above, and notify
church administrators.