1. Purpose
This Data Breach Response Policy explains how MinistryCount handles suspected or confirmed security incidents that may affect church data, user accounts, member records, visitor records, communication logs or platform systems.
2. What may count as an incident
A security incident may include unauthorised account access, accidental disclosure, malware, exposed credentials, database compromise, misdirected exports, lost admin access, suspicious activity, unusual SMS sending or other events that may affect confidentiality, integrity or availability of data.
3. Reporting an incident
Churches and users should report suspected security issues as soon as possible. Reports should include the church name, affected user, page or feature involved, approximate time, screenshots where safe, and any suspicious messages or activity observed.
Do not post sensitive incident details publicly or in large groups. Use official support channels.
4. Initial review and containment
When MinistryCount receives or detects a possible incident, we may take steps to investigate and contain it.
- Review affected accounts, logs, pages or services.
- Temporarily suspend suspicious access where needed.
- Reset or advise password/PIN changes where appropriate.
- Limit affected functionality if it creates ongoing risk.
- Work with hosting, SMS, email or other providers where needed.
5. Assessment
MinistryCount will assess the nature of the incident, the type of data involved, affected churches or users, likely cause, possible harm and actions needed to reduce risk.
Not every technical issue is a data breach. Some issues may be bugs, failed requests, incorrect permissions, user error or provider failures without unauthorised data access.
6. Communication
Where an incident is likely to affect a church’s data or users, MinistryCount will communicate with the affected church through appropriate channels. Communication may include known facts, affected areas, recommended actions and ongoing updates where necessary.
Churches may also have their own responsibility to notify members, visitors, leaders or regulators depending on the situation and applicable law.
7. Remediation
After containment, MinistryCount may fix code, update access controls, patch systems, rotate credentials, review logs, improve monitoring, update policies, guide affected churches and take other corrective actions.
8. User and church responsibilities
Churches should keep admin access limited, remove old users, use strong passwords, report suspicious activity, protect exported files and avoid sharing login credentials.
Users should promptly report lost devices, exposed passwords, suspicious SMS activity or any unusual access to church data.
9. Contact
To report a suspected data breach or security concern, contact support@ministrycount.com.