POPIA Compliance

Speiro CMS — Church Management Platform

Last updated: September 2026

Speiro is built for South African churches, and compliance with the Protection of Personal Information Act 4 of 2013 (POPIA) is designed into the platform from the ground up. This page summarises how Speiro supports POPIA compliance. For full detail on how personal information is handled, see our Privacy Policy.

Who is responsible for your data

Under POPIA, your church is the Responsible Party — it decides what personal information to collect, why, and how it is used. Speiro is the Operator, processing personal information on the church's behalf and only on its instruction, under our service agreement. Questions about how your church uses your data should go to your church administrator; questions about how Speiro handles data as the platform provider can come to us.

The eight POPIA conditions

Speiro is designed to help churches meet the eight conditions for lawful processing:

  • Accountability — clear Responsible Party (church) and Operator (Speiro) roles, governed by a service agreement.
  • Processing limitation — data is collected for legitimate church-management purposes, and members give consent at registration.
  • Purpose specification — information is collected for defined church purposes (membership, pastoral care, communication, giving).
  • Further processing limitation — data is not reused for unrelated purposes; Speiro never sells or shares church data.
  • Information quality — members can view and request correction of their own details in the app.
  • Openness — this page and the Privacy Policy explain what is collected and why.
  • Security safeguards — encryption in transit and at rest, per-church data isolation, role-based access, and audit logging (see below).
  • Data subject participation — members can access, correct, and request deletion of their information.

Consent at registration

When a member registers on the Speiro mobile app, they must affirmatively accept the Privacy Policy before an account is created. This consent is recorded with a timestamp, giving both the member and the church an auditable record in line with POPIA's consent requirements.

Where your data lives

All personal information is hosted on Amazon Web Services in the Africa (Cape Town) region (af-south-1) — your data stays in South Africa. No personal data is transferred outside South Africa unless a church explicitly activates a third-party integration (for example, Google or Outlook calendar sync). Each church's data is fully isolated from every other church using row-level security.

Special categories of information

Church membership is inherently religious information. Under POPIA Section 27(d), processing of religious information is permitted where it is carried out by a religious institution in the course of its legitimate activities, provided the information is not disclosed to third parties without consent. Where a church records children's information (for example, children's check-in), the church is responsible for obtaining parental or guardian consent as required by POPIA Section 34.

Your rights under POPIA

  • Right of access — view your personal data via the app's "My Details" screen.
  • Right to correction — update your details, or request corrections via your church administrator.
  • Right to deletion — request account deletion; your data is anonymised or removed within 30 days.
  • Right to object — opt out of communications via notification preferences.
  • Right to data portability — request an export of your data from your church administrator.

Security measures

  • Encryption of data in transit (TLS) and at rest.
  • Per-church data isolation enforced at the database level (row-level security).
  • Role-based access control so members only see what they are permitted to.
  • Audit logging of sensitive administrative actions.
  • Hosting within South Africa on AWS Cape Town.

Reporting a concern

To exercise a right or raise a data-protection concern, contact your church administrator in the first instance, or email Speiro at support@speiro.africa. You also have the right to lodge a complaint with the Information Regulator (South Africa).

This page is provided for information and does not constitute legal advice. Each church remains responsible, as the Responsible Party, for its own POPIA compliance.