Privacy — the app

Privacy notice for people who use the Masjid Amanah app

For members, families, staff and volunteers of a masjid that uses the app. Plain English, following the ICO's privacy-notice checklist. Version 1.0 — 6 September 2026.

Who is responsible for your data

Your masjid is the data controller. It decides what information is collected about its community and why; its trustees are accountable for it under charity law and UK data protection law.

Masjid Amanah is the data processor. The platform is operated by Ghulam Hussain trading as Masjid Amanah — a not-for-profit service funded by charitable donations. We hold and process your information only on your masjid's instructions, under a written Data Processing Agreement. We never use it for our own purposes, never sell it and never use it for advertising.

Questions about your data go to your masjid first (its trustees, or the data-rights contact it names). Questions about the platform itself: [email protected].

What the app collects

Only what the service you use needs:

  • Your account — name, email, phone, the masjid you belong to, your login (password, optional two-factor / Face ID — biometric checks happen on your device; we never receive biometric data).
  • Membership — status and dates, contributions, votes cast (the record proves that you voted, never what you chose).
  • Family and education — children enrolled in the madrasa, guardians, attendance, progress and reports, fees; medical, dietary or additional-needs notes only where you or the masjid record them for a pupil's care.
  • Giving — donations, Gift Aid declarations, Direct Debit mandates (collected by GoCardless on the masjid's behalf), Funeral Assurance Cover contributions.
  • Roles — if you serve the masjid: role, workforce records, DBS check outcomes, training, right-to-work evidence (staff and volunteers only).
  • Safeguarding — concerns raised and how they were handled (restricted to the safeguarding lead).
  • Meetings — attendance and votes at governance meetings; for consented governance meetings, a recording and an AI-drafted set of minutes (see below).
  • Requests and messages — service-desk tickets, announcements, notifications.
  • Technical — the device push token (if you allow notifications) and standard logs needed to run and secure the service. No advertising or tracking cookies.

Why, and on what legal basis

Running the masjid's membership, meetings, elections and records — the masjid's legitimate interests in governing itself and its legal obligations as a charity (religion: Article 9(2)(d), a not-for-profit religious body). Madrasa administration and pupil welfare — contract / legitimate interests, vital interests in an emergency; health notes by explicit consent when you record them. Donations, Gift Aid, Direct Debits, Funeral Assurance Cover — your contract with the masjid and the masjid's legal obligations (HMRC, charity accounting). Safeguarding and DBS checks — legal obligation / substantial public interest (Data Protection Act 2018, Schedule 1). Notifications and the service desk — legitimate interests in running the service you asked for. Security and audit — legitimate interests and legal obligation.

Elections — the secret ballot

Your vote is secret from everyone, including the platform. The record proves that you voted; what you chose is stored with no link to you. If you vote online you are shown a private receipt once — kept only on your device, never on the platform — and only that receipt can reveal your choices. Votes cast at a kiosk have no receipt.

AI minutes (governance meetings only)

When a governance meeting is recorded with the meeting's consent, the recording is transcribed and a draft of the minutes is produced by third-party AI services (Deepgram and Anthropic, both in the United States) under contracts that forbid them using the content to train their models. The draft is reviewed and adopted by the trustees — the AI is never the record. Education meetings are never recorded. Members' meetings (AGM/SGM) are listen-only broadcasts.

Who sees your data

Your masjid's authorised people, each limited to their role (a teacher sees their class; the safeguarding lead sees concerns; trustees see the register). Access is enforced by the platform, not by policy alone, and every access to restricted records is logged.

Sub-processors that run the service — listed below with their regions and safeguards. Nobody else. We do not share, sell or trade your data; we disclose it only if the law requires.

Where it is held

Your masjid's records are held in London (UK). The named services below process specific data elsewhere. Transfers outside the UK are covered by the UK International Data Transfer Addendum or standard contractual clauses in those providers' agreements.

Sub-processors

ServiceWhat it doesRegion
Supabasedatabase, logins, storage, functionsLondon (UK)
Amazon Web Services (S3, CloudFront, IVS, SES)files, recordings, live broadcast, emailLondon (UK)
GoCardless · TrueLayerDirect Debits · bank reconciliation (each masjid's own accounts)UK
8x8 (JaaS)video meetings and their recordings (each masjid's own account)EU (recordings via Oracle object storage)
Deepgram · Anthropicspeech-to-text and drafting of consented governance minutes; the governance assistantUnited States (no-training terms)
Expopush notifications and app updatesUnited States
Homedatapostcode → address lookup (operator screens)UK
freetsa.orgtime-stamps a weekly hash of the governance record (a hash only — no personal data)Germany
Appleapp distributionglobal

How long

Your masjid keeps your data only as long as its purpose or a legal obligation requires — for example the register of members (10 years after you leave, by law), Gift Aid declarations and accounting records (6 years), employment records (6 years after leaving), accident records (3 years). Safeguarding records are kept under the safeguarding lead's control. When you ask to be forgotten, everything the law allows is erased at once; anything the law requires the masjid to keep is held and erased automatically when that period ends — and you are told exactly which records and why.

Your rights

You can ask your masjid to see the data it holds about you (a readable export within one month), to correct it, to erase it (subject to the legal retentions above), to restrict or object to processing, and to withdraw consent where consent is the basis. Ask the trustees, or use My account → Data rights in the app; the platform gives the masjid the tools to respond and records that it did. You also have the right to complain to the Information Commissioner's Office (ico.org.uk, 0303 123 1113).

Changes

We will tell your masjid — and the app will tell you — when this notice changes. Previous versions are kept. This notice covers the app; the website has its own privacy policy.