Privacy

Privacy policy

This page explains which personal data is processed on the ImaMissio websites and in the ImaConnect app, by whom, why, for how long, and how to exercise your rights.

Last updated: 15 September 2026

Who is responsible for your data

Synergie Innovation is the controller for processing related to your ImaConnect account, the national imamissio.fr website and demo requests. Its details are given in the legal notice.

When you entrust information to a parish or a diocese — a prayer intention, a donation, a sacrament request or a registration — that organisation is the controller. Synergie Innovation hosts and processes the data on its behalf, as a processor.

Data we process

  • Your ImaConnect account: name, email address, password (stored in a form that cannot be read back), followed parishes and preferences, and the date, IP address and version of the terms of use accepted at sign-up.
  • Your requests: name, email address and message content (prayer intention, sacrament or information request). For a demo request, also your phone number and organisation name.
  • Your donations, when online giving is offered: name, email address, amount, optional message and tax receipt. Payment is handled by a specialised provider; no card number is stored by the platform.
  • Login and security: IP address and browser linked to your session; log of actions performed in the management areas.
  • Notifications, if you enable them: the technical subscription address provided by your browser.

Belonging to a parish, a prayer intention or a sacrament request may reveal your religious beliefs. This information is only used to handle your request. No data is sold or used for advertising.

Purposes and legal bases

  • Providing the service (account, followed parishes, requests, notifications): performance of the terms of use you accepted.
  • Data revealing religious beliefs: your explicit consent, given when you send the request, or, for parishes and dioceses, the exemption for not-for-profit bodies with a religious aim regarding their members and people in regular contact with them (Article 9(2)(d) GDPR).
  • Donations and tax receipts: legal accounting and tax obligations.
  • Parish registers (baptisms, marriages, funerals): record-keeping required by canon law, under Article 9(2)(d) GDPR.
  • Service security (logs, abuse prevention): legitimate interest in protecting the platform and its users.
  • Demo requests: pre-contractual steps taken at your request.

Recipients

Your data is only accessible to those who need it: the parish or diocese concerned by your request, and the Synergie Innovation team for operations and support.

It is processed by the following providers:

  • Scaleway (France): hosting, database, file storage and email delivery.
  • OVHcloud (France): mailbox of the contact address.
  • The payment provider handling online donations, when they are offered. It may be located outside the European Union; any such transfer is covered by the safeguards required by the GDPR.

Some content is loaded by your browser directly from third-party services, which then receive your IP address:

  • IGN – Géoplateforme: the access map shown on parish websites.
  • OpenFreeMap: the ImaConnect parish map, which also receives the area of the map you view.
  • Your browser's push service (Google, Mozilla or Apple), if you enable notifications. This service may be located outside the European Union.

How long we keep data

  • ImaConnect account: kept until you ask for it to be deleted, with no time limit until you do — no automatic deletion for inactivity is applied at present. A deletion request takes effect 30 days after it is made, during which time you can cancel it.
  • Login sessions: 7 days without activity, then deleted.
  • Donations: kept to meet accounting and tax obligations, which require 10 years. If your account is deleted, they are detached from your identity.
  • Parish registers: kept by the parish in accordance with canon law; deleting an account does not erase them.
  • Requests sent to a parish: as long as needed to handle and follow up on them.
  • Security logs: as long as needed to secure the service and to evidence actions performed in the management areas.

Cookies

The ImaMissio websites and ImaConnect only use cookies that are strictly necessary: keeping you logged in and remembering the parish you are viewing, your language and your display preferences. No advertising cookies or audience-measurement tools are used, so no consent is requested.

Security

Data is hosted in France. Connections are encrypted (HTTPS), the database is encrypted at rest and passwords are never stored in plain text. Access to the management areas is restricted by role and logged.

Your rights

  • Access and portability: obtain a copy of your data in a reusable format.
  • Rectification: correct inaccurate or incomplete data.
  • Erasure: request the deletion of your data, subject to retention required by law.
  • Restriction and objection: ask for processing to be suspended, or object to it on grounds relating to your situation.
  • Withdrawal of consent at any time, for processing based on it.
  • Instructions on what happens to your data after your death.

With an ImaConnect account, you can export your data and request the deletion of your account from your personal area. You may also lodge a complaint with the CNIL, the French data protection authority (cnil.fr).

Exercising your rights

Write to dpo@imamissio.fr. For data entrusted to a parish, you can also contact the parish directly. You will receive a reply within one month.