Last updated: 2026-06-01
1. About this policy and who we are
KH Planner is a tool for planning duties and assignments at a congregation's
meetings. This policy explains what personal data the service processes, why,
and what rights you have.
The data controller is the congregation that uses KH Planner
and records information about its members. The congregation decides what data
is recorded and how it is used in planning.
The data processor is KH Planner by Mats Cedergren, which operates and provides
the technical platform on the congregation's behalf and processes the data only
according to the congregation's instructions and this policy.
If you have questions about your data, contact your congregation's planner or
administrator first. Technical questions about the platform can be sent to
[email protected].
2. What data is processed
Depending on your role, the following data may be processed.
For people assigned to duties:
- Name
- Email address (if provided)
- Phone number (if provided)
- Internal notes added by the planner
- Language preference
- Which duties you can perform (capabilities)
- Availability and reported absences
- Your assignment history (date, meeting and duty)
- A personal share link (a random code) if one is created for you
For users who sign in (administrators and planners):
- Name and display name
- Email address (used to sign in)
- Phone number (if provided)
- Password – stored only as a secure hash, never in plain text
- Notification preferences
When using the mobile app:
- A sign-in token that identifies your device
- A push token used to send notifications (if you allow notifications)
- Device type (e.g. iOS)
Technical logs: the service writes operational logs that may
temporarily contain, for example, email addresses or names for troubleshooting.
These logs are deleted automatically (see section 5).
3. Purpose and legal basis
The data is used to:
- plan and show who is assigned to which duty at each meeting,
- send reminders and notifications about upcoming meetings and reported absences,
- share schedules through read-only share links, and
- handle sign-in and account security.
The legal basis is the congregation's legitimate interest in organising its
activities and in providing the service. Push notifications additionally rely on
you granting your device permission to receive them.
4. What data is shared and with whom
Data is never sold. It is shared only to the extent needed for the service to function:
- Within the congregation: planners and administrators see the
data needed for planning. Anyone holding a share link can see the schedule that
link refers to (one month, or one person's own assignments) – read-only, without signing in.
- Email: email (e.g. password resets and absence notifications) is
sent via the service SMTP2GO, which processes the recipient's
email address and the message content to deliver it.
- Push notifications: notifications to the mobile app are sent via
Expo and onward to Apple's push service (APNs)
for iOS. This processes a push token tied to your device.
- Operation and storage: data is stored in a database with the
provider that operates the platform on the congregation's behalf.
5. How long data is kept
- Active people and assignments are kept as long as the person is
active in the congregation's planning.
- History (date, meeting and duty) is kept as part of the
congregation's planning record even after a person is removed, then in anonymised
form (see section 6).
- Outcome and absence statistics are kept for a configurable period,
by default 3 months, and purged automatically afterwards.
- Operational logs are deleted automatically after a short period,
by default 7 days.
- Sign-in and push tokens are removed when you sign out, when a
person is removed, or after a period of inactivity.
6. Your rights
Under the General Data Protection Regulation (GDPR) you have the right to:
- be told what data is processed about you (access),
- have inaccurate data corrected,
- have your data erased (“the right to be forgotten”),
- object to or request restriction of processing, and
- lodge a complaint with your data protection authority.
How erasure works in KH Planner. When an erasure request is carried out:
- Direct personal data is deleted or cleared – the name is replaced with
“Removed person”, and email, phone, notes, language preference and personal
share link are removed.
- Future, not-yet-held assignments are removed so the duty can be given to someone else.
- App sign-in and push subscriptions are removed.
- Past schedule history (date and duty) is kept but linked to the anonymised label
“Removed person”, so the congregation's historical planning stays accurate.
Contact your congregation's administrator to exercise your rights.
7. Security
Passwords are stored as secure hashes. Share links use random, hard-to-guess codes
and grant only read-only access to the intended schedule. Administrative functions
require signing in.
8. Children's data
The service may contain data about minors who are assigned to duties at meetings.
Such data is entered and managed by the congregation as the data controller.
9. Changes to this policy
This policy may be updated. For significant changes the date at the top of the page
is updated. The latest version is always available on this page.
10. Contact
Questions about your data: your congregation's planner or administrator.
Technical questions about the platform: [email protected].