Privacy Policy

Assemblios, operated by Resiliatech. Last updated 3 August 2026.

Assemblios is a church management system used by churches in Zimbabwe and Southern Africa to run membership, giving, communication, events and volunteer rosters. Churches trust us with the personal information of their congregations, including children. This policy explains what is collected, why, who can see it, and what we never do.

Who we are

Resiliatech, Harare, Zimbabwe. Contact: hello@assemblios.com.

The church is the data controller

Each church (or denomination) using Assemblios decides what member information to record and who in the church may see it. Assemblios processes that information on the church's behalf. If you are a church member with questions about what your church has recorded about you, your first point of contact is your church's administrator; we will also help directly where we can.

Information we process

Children and minors

What we never do

Per-church data isolation

Every church's data is strictly isolated from every other church's, and within a denomination, access is scoped by branch and role. A branch administrator sees only their branch; denomination HQ roles see only their own denomination's branches. Access controls are enforced on the server on every request, and administrator, finance and leader accounts require two-factor authentication.

Who we share it with

Export and deletion

Your data is yours. A church can export its member directory, giving records and reports at any time from its portal, in standard formats. If a church closes its account, we delete its data within 30 days of a confirmed request, except records we must retain for accounting or legal purposes. Individual members may ask their church, or us, to correct or delete their personal information; we action verified requests within 30 days.

How long we keep it

We keep a church's records while its account is active so its history stays available. Backups are retained for up to 30 days, with encrypted archives kept for disaster recovery.

Security

Traffic is encrypted with HTTPS. Administrative access is restricted and logged, staff and church admin accounts use two-factor authentication, and databases are backed up nightly to encrypted storage. Payment processing is idempotent and auditable.

Your rights

You may ask to see, correct or delete the personal information held about you, and you can ask your church to stop contacting you by SMS at any time. Email hello@assemblios.com and we will respond within 30 days.

Changes

If this policy changes materially we will update this page and the date above, and notify church administrators.