Parish Bell

Privacy Notice

Last updated: 5 October 2026

Parish Bell is a bulletin platform for Catholic parishes, operated from Penang, Malaysia. It runs the editor parish offices use and the public pages readers open. This notice explains, in plain language, what we do with personal information — for parish offices and for readers. Questions are welcome at [email protected] or WhatsApp.

Two kinds of people use the service

Parish offices and their volunteers sign in to prepare and publish bulletins. Readers open a parish's bulletin link — usually from WhatsApp. What we hold about each is very different, and deliberately so.

Parish office accounts

  • What we hold: the name and email address of each person a parish office invites; how they sign in (an email sign-in link, or Google/Facebook where a parish has enabled those); and the bulletin content they enter.
  • Why: to operate the service — signing people in, keeping a parish's work available to the right people, publishing the bulletin, and answering support questions. Under the GDPR, the legal bases are performing our agreement with the parish and our legitimate interest in running the service securely.

Notices sent in by parish ministries

A parish can give its ministries a private link for sending notices to the office. The form asks for the sender's name and phone number so the office can follow up; these go only to that parish's office and are never published. They are kept with the parish's records and removed on the same terms as the rest of its content. Any contact details the sender adds for parishioners are printed in the bulletin if the office approves the notice.

People reading a bulletin (and reactions)

  • What we record when a bulletin page opens: which week, which language edition, the kind of device (phone, tablet or desktop) and when. We do not store IP addresses, and there are no visitor profiles — this is by design.
  • Reactions (the thumbs-up hearts on notices): a random identifier created by the reader's own browser and kept only in it, so one device counts once per notice. It is never connected to a person. Clearing the browser's site data removes it.
  • Cookies: the only cookie is the parish editor's sign-in session (when a parish worker is signed in). There are no tracking cookies, no advertising and no third-party analytics.

Personal information inside bulletins

Bulletins may mention people by name — mass intentions, wedding banns, collections. That information is entered and published by the parish office, and the parish decides what appears. Requests about that content are best made to the parish office, who have the full picture; we assist them when asked.

Who processes data for us

  • Hosting — the service runs in a professional data centre in Singapore, with the host's own physical safeguards behind it.
  • Network delivery and backup storage — the websites are delivered through a global content network, and the encrypted off-site backups are kept with a storage provider.
  • Email delivery — a transactional email provider sends service emails (sign-in links, operational alerts).
  • AI transcription — used only to transcribe the diocese's weekly reflection documents. These are the diocese's own documents; no reader or parishioner information is sent.

We share personal information with such providers only so they can perform their part of the service. Some processing happens outside Malaysia (Singapore and the providers' own infrastructure); where the law requires it, our agreements with providers include standard contractual clauses and similar safeguards.

How long we keep things

  • Parish content (bulletins, uploads, accounts) is kept while the parish uses the service, and removed when the parish asks us to remove it or stops using the service.
  • Print/share copies are deleted automatically after 90 days. Backups rotate: 30 days of daily copies on the server, and encrypted off-site copies as 14 daily + 6 monthly snapshots.
  • Reader statistics are counts without personal identifiers, kept so parishes can see how their bulletin is doing.

Security, and what happens if something goes wrong

The service uses HTTPS throughout, invitation-only accounts, hashed sign-in tokens, encryption for off-site backups, restricted server access, and monitoring that emails us when something fails. If a security incident affects personal information, we notify Malaysia's Personal Data Protection Commissioner — and the people affected, where required. For EU/UK data, we notify the competent supervisory authority within 72 hours where the law requires it.

Your rights

In Malaysia (Personal Data Protection Act): you may access and correct your personal information, withdraw consent where consent is the basis, and lodge a complaint with the Jabatan Perlindungan Data Peribadi (JPDP).

In the EU/UK (GDPR): you may access, correct, delete, restrict or object to processing, receive your information in a portable form, withdraw consent, and complain to your local supervisory authority.

To exercise any of these, contact us at [email protected] or WhatsApp — we answer requests under the PDPA within 21 days, and under the GDPR within one month. One honest note for readers: because bulletin analytics carry no identifiers, there is usually nothing about a reader personally for us to find or delete; content inside a bulletin is handled by the parish office.

Data protection contact

Our data protection contact — the person who handles PDPA and GDPR matters for Parish Bell — can be reached at [email protected]. The same address handles data protection questions, access and correction requests, and complaints.

Children

Parish Bell serves parish offices; it is not directed at children. Information about a young person appears only if a parish chooses to publish it.

Changes

When the service changes, this notice changes with it. The date at the top shows the latest revision, and anything significant will be raised with parish offices directly.