CLOUD SERVICE AGREEMENT AND DATA PROTECTION POLICY PARISH RECORD KEEPER WORKSPACE Alpha Version PLEASE READ THIS CLOUD SERVICE AGREEMENT AND DATA PROTECTION POLICY ("AGREEMENT" or the "Cloud Service Agreement") CAREFULLY BEFORE USING THE PARISH RECORD KEEPER WORKSPACE FACILITY ("WORKSPACE"). BY USING THE WORKSPACE, YOU AGREE TO BE BOUND BY THE TERMS AND CONDITIONS OF THIS AGREEMENT. IF YOU DO NOT AGREE TO THESE TERMS AND CONDITIONS, DO NOT USE THE WORKSPACE. 1. Relationship to the Software Licence Agreement The Parish Record Keeper desktop software ("Software") is governed by a separate End User Licence Agreement ("Software EULA"), available on parishrecordkeeper.com and in the Documentation folder of the installation directory. This Agreement governs only the optional online Workspace facility described below; it does not replace or amend the Software EULA. The Software functions in full without the Workspace, and using the Workspace is entirely voluntary. 2. What the Workspace Is The Workspace is the optional online facility, hosted or arranged by the Developer, Bernhard Udelhoven (referred to in this Agreement as the "Developer"), that a parish, or a group of parishes agreeing to share data, takes as a whole for one data file and for a term of its own choosing. The word "Workspace" in this Agreement means that facility in its entirety, and not any single part of it. It comprises, as the Developer makes them available from time to time: the shared master data file that several Users may upload, download and merge in turn; the online search facility, through which those records may be read in a browser; the accounts of the Workspace Members and the shared credentials described in Section 6; the Offline App described in Section 8; the parish transport booking register described in Section 4; and any further function the Developer provides through the same Workspace. All of these are covered by the single contribution described in Section 12 and are governed by this Agreement alike. The Workspace is not a professional commercial cloud-storage, backup, archive, disaster-recovery, legal-compliance, or records-management service. It is an Alpha-stage facility connected with an Alpha-stage parish software project, offered only on the terms set out in this Agreement, and used at the User's own risk. 3. Definitions In this Agreement: "User" means any person, parish, institution, or other body using or accessing a Workspace. "Workspace Administrator" means the User or person who requests, manages, or coordinates access to a Workspace on behalf of a parish or group of Users, including through the administrator role available on the Workspace's web page. "Workspace Members" means Users given access to a Workspace by or through the Workspace Administrator or by agreement with the Developer. "Workspace Data" means data uploaded, downloaded, stored, searched, merged, synchronised, or otherwise processed through a Workspace. 4. Data Uploaded to the Workspace Workspace Data may include parishioner names, sacramental records such as baptism, marriage, and related records, financial and contribution records, and other information a User chooses to enter into the Software and upload. This data belongs to the User and the parish or parishes concerned; the Developer does not claim ownership of it. Workspace Data also includes data entered directly into the Workspace's own web facilities rather than uploaded from the Software. In particular, the transport booking register records the journeys a parish organises and, for each booking, the name and any telephone number given, the number of seats, the amounts due and paid, every individual payment, and the name typed by the person who took the booking. Such passengers are frequently NOT parishioners and have no record in the parish data file. This data is entered by the User, is held on the Developer's server for as long as the User keeps the journey, is not part of the parish data file and is not contained in its backups, and is removed when the User deletes the journey or clears the Workspace. The responsibilities set out in the following paragraph apply to it in full. The User, the Workspace Administrator, and the parish or parishes concerned are solely responsible for deciding what data is entered, uploaded, shared, accessed, retained, exported, corrected, or deleted, and for ensuring a lawful basis and any necessary permissions to do so, including compliance with applicable Zambian data protection law, other applicable civil or canonical law, diocesan policy, and safeguarding obligations. Where a Workspace is shared by several Users or parishes, each User remains responsible for the data they themselves upload, change, or disclose, and for the access they give to others. 5. Data Protection Roles The Developer provides or arranges the technical Workspace facility. The Developer does not decide what parish records should be collected, what they should contain, who should be included, or how long records should be kept. For this reason, the User, Workspace Administrator, or parish concerned normally remains responsible for the substantive data-protection decisions concerning Workspace Data; to the extent that data-protection law distinguishes between a controller and a processor, the User or parish normally acts as controller, while the Developer acts only as a limited technical service provider for the purpose of operating the Workspace, unless a different written arrangement is expressly agreed. The Developer does not provide legal, data-protection, canonical, or safeguarding advice. The User and the parish concerned must obtain their own advice where needed. 6. User Accounts, Access, and Passwords The User and the Workspace Administrator are responsible for controlling who is allowed to access a Workspace, for keeping login details secure, and for ensuring that only authorised persons use it. Users must take reasonable precautions to prevent unauthorised access, including careful handling of shared computers, email accounts, exported files, and passwords. The Developer is not responsible for unauthorised access, disclosure, alteration, deletion, or misuse of Workspace Data caused by weak or shared passwords, compromised email accounts, infected devices, careless handling of files, internal parish disputes, or any other act or omission of Users or third parties. The Workspace additionally offers SHARED CREDENTIALS, which a Workspace Administrator may create for people who have no account of their own: a transport booking login, used to take bookings on a phone, and a reports login, used to read the parish figures a Workspace Administrator has chosen to make visible and, where the Administrator allows it, to send proposed corrections for review. A shared credential is by its nature used by more than one person and cannot identify who is using it; the Workspace records the name each person types and logs what is done, and that log is the only accountability such a credential permits. Creating, distributing, restricting, switching off, and deleting shared credentials, and deciding what each may see, is entirely the act and the responsibility of the Workspace Administrator, and the preceding paragraph applies to them with particular force. Nothing sent through a reports login alters any parish record by itself: proposed corrections are reviewed and applied within the Software by the User, in the same way as change notes under Section 8. 7. Encryption and Security The master data file, any versions uploaded for sharing among Workspace Members, and any change notes sent to the Workspace from the Offline App (Section 8) are stored on the Developer's server in the same form in which they were sent. The Developer does not independently encrypt these files at rest. Change notes are plain text and contain the parish data of the records they concern. Any protection of their contents, such as a database password the User has applied within the Software before uploading, results entirely from the User's own action, and remains the User's own responsibility to manage, including deciding whether and how to share such a password securely among Workspace Members. A Workspace Member who cannot open a downloaded master file should first check with the Workspace Administrator or other Members whether the file has been protected with such a password. Where a User separately uploads data to make parish records searchable through the Workspace's online search facility, that data is, by contrast, encrypted at rest on the Developer's server (AES-256-CBC or a comparable standard then in use), field by field, using a key held by the Developer. In both cases, the Developer takes reasonable, industry-standard measures to protect Workspace Data more generally, such as restricting server access and using secure connections for transmission, but encryption and security measures reduce risk without eliminating it; the Developer does not warrant that the Workspace, server, transmission, or any related infrastructure will be secure, uninterrupted, or immune from unauthorised access, data loss, or other incidents. The Developer is a single individual and cannot guarantee continuous monitoring or immediate response. The User accepts that the Developer may at times be unavailable, without server access, or otherwise unable to respond for extended periods. 8. Offline Copies on Phones and Personal Devices The Workspace includes an optional offline facility ("Offline App", provided as the installable applications PRK Admin for Workspace Members and PRK Finance for holders of a shared reports login) that allows a logged-in Workspace Member, or the holder of a shared reports login within the scope granted to it, to download a copy of the Workspace's searchable data onto a phone or other personal device, to search that copy without an internet connection, and to record proposed changes ("change notes") for later review and import into the Software. Downloading such an offline copy is a deliberate act of the User. A Workspace Member may either transfer change notes to the computer by their own means, such as a messaging application, email, or a cable, or send them to the Workspace, where they are stored on the Developer's server as described in Section 7 until the Software reports that they have been imported or a Workspace Member removes them. Sending change notes to the Workspace is likewise a deliberate act of the User, and the resulting change notes are Workspace Data for the purposes of this Agreement. A change note is not consumed by being sent: it remains on the device, and is sent again with each subsequent send, until the User deletes it there. The offline copy is stored on the device itself in unencrypted form. It is protected only by the device's own security measures (such as its screen lock) and, where the User sets one, by the optional PIN of the Offline App, which is an access convenience and not encryption. A copy downloaded by a holder of a shared reports login contains the financial records within that login's scope and the person details needed to read them, and no sacramental register. The User, the Workspace Administrator, and the parish concerned are solely responsible for deciding who may hold offline copies, for the physical and technical security of the devices used, for removing offline copies from devices that are no longer used for this purpose or that change hands, for deciding whether change notes are sent to the Workspace or transferred by other means, and for the secure handling and deletion of exported change files and of change notes held on devices, in the Workspace, or on the computer after import. Change notes have no effect on any database until they are reviewed and applied within the Software by the User. The Developer has no access to, control over, or responsibility for data stored on Users' devices. Sections 6 (User Accounts, Access, and Passwords), 15 (No Warranty and Limitation of Liability) and 16 (Alpha Stage Disclaimer) of this Agreement apply to the Offline App in the same way as to the rest of the Workspace. 9. Backups and Independent Copies The Workspace is not a guaranteed backup service. The User and the Workspace Administrator are solely responsible for maintaining independent, current, restorable backups of all important data, as also stated in Section 5 of the Software EULA. Users who need to preserve Workspace Data must download and export it themselves; they should not rely on the Workspace, the Developer, the hosting provider, or parishrecordkeeper.com as their only copy or means of access to the data. 10. Deletion, Export, and Correction A Workspace Administrator may delete their Workspace's own data, including the shared data files held in the Workspace, any change notes sent to the Workspace and not yet imported, and the corresponding records held in the Workspace's search database, immediately and at will, using the delete function provided on the Workspace's own web page. This is the primary, self-service way to remove Workspace Data, and it takes effect at once; the Workspace Administrator does not need to write to the Developer to use it. Beyond that self-service function, a User, or the Workspace Administrator on behalf of the Workspace Members, may also request deletion, export, or correction of data by writing to the contact details in Section 20. Because the Developer is a single individual who may be unavailable or without server access for extended periods, the Developer does not undertake to act on any such written request within any fixed or guaranteed timeframe, and will make reasonable efforts to do so when able. Routine server backups that are provided by the hosting server may retain deleted data for a further period before being overwritten in the ordinary course of the backup cycle; the Developer is not obliged to search, alter, or delete historical backup copies manually unless required by applicable law and technically feasible. 11. No Disclosure to Third Parties The Developer will not sell or rent Workspace Data to third parties. The Developer may disclose or process Workspace Data where reasonably necessary to: (a) operate, maintain, secure, or back up the hosting infrastructure, including through the Developer's web hosting provider, currently Hostinger (Hostinger.com), which stores the encrypted data but is not knowingly given the means to decrypt it, and which maintains its own separate terms of service and privacy policy governing the underlying infrastructure independently of this Agreement; (b) comply with applicable law, legal process, or a lawful order of a competent authority; (c) protect the rights, property, or safety of the Developer, Users, or others, or investigate suspected abuse; or (d) carry out the User's own instructions, including upload, download, merge, export, or deletion. Server access logs (such as IP addresses) are handled on the same basis as described for the Software in Section 11 of the Software EULA. 12. Workspace Contribution, Term of Access, and Non-Renewal Access to a Workspace is offered against a contribution, as described in Section 12 of the Software EULA. The Software itself remains free of charge; the contribution applies only to the optional Workspace. Because the Developer incurs real, ongoing costs in securing and maintaining a Workspace, the amounts needed to cover those costs are published on parishrecordkeeper.com. The User chooses the TERM for which the contribution is made: at the time of writing, one year, three years or five years, the longer terms being offered at a lower amount for each year covered. These amounts are referred to elsewhere in the Software, on parishrecordkeeper.com, and in the Documentation as the "contribution" or the "yearly contribution"; where a term of more than one year has been chosen, the yearly figure means the amount divided by the number of years it covers. The terms on offer and their amounts are also shown in the Software itself, on the window used to request a new Workspace, read from the server at the time so that what is displayed is what is currently in force. Each term is quoted in two currencies, and the two amounts are set independently of one another rather than converted at any exchange rate: one is the amount asked of a parish contributing in Zambian Kwacha, the other the amount asked of a User contributing from outside Zambia. Neither amount is a conversion of the other, and no exchange rate forms part of this Agreement. The User may contribute in either currency. Requesting a Workspace costs nothing and commits the User to nothing. No Workspace is created, and no amount becomes due, until the User has decided to proceed and the contribution for the chosen term has been received; the Developer then creates the Workspace by hand. The term may still be changed when the request is confirmed, at the point where the User declares that payment has been made. The contribution is a service fee, retained to cover the Workspace's hosting, security, and maintenance costs and to support the continued development and maintenance of the Software. It is not a donation to Lumimba Parish Outreach ministries and is not represented as tax-deductible or charitable. Any amount given significantly beyond the published amount for the chosen term is treated as a voluntary donation to Lumimba Parish Outreach ministries, as described in Section 12 of the Software EULA. Where a term of more than one year is chosen, it is the Developer's intention that the amounts received for the later years of that term be applied to the server and hosting costs of those years. This paragraph states an intention and a practice; it does not create a trust, an escrow, a separate fund, or any obligation enforceable by the User. Access to a Workspace granted on this basis is provided for the chosen term and does not renew automatically without a further arrangement between the User, or the Workspace's members, and the Developer. The date to which the current term runs is recorded by the Developer and is shown to the Workspace's members in the Software, on its start screen, which also gives warning during the final month. Where a renewal is made, it is normally counted from the date the current term runs out rather than from the date the contribution is received, so that a late renewal does not shorten the period paid for, and an early one loses nothing. A renewal may be made on any term then on offer, and need not be the same term as before. In the Developer's ordinary practice, a Workspace is not closed on the day its term runs out: it continues to work for a further period of about a month, during which the Developer will normally send a reminder to the Workspace Administrator or Administrators. If the contribution has still not been received after that period, the Developer may close the Workspace, so that its members can no longer sign in either through parishrecordkeeper.com or through the Software. Closing a Workspace in this way removes no data: the master data file, previously published versions, and any search data remain on the server, and the Workspace is reopened when the contribution is received. Closing is carried out deliberately by the Developer and does not happen automatically. The preceding paragraph describes the Developer's ordinary practice and is not a guarantee, a fixed procedure, or an entitlement to notice, to a reminder, to any particular period of grace, or to reopening. Whether it is followed in a given case remains at the Developer's discretion. Separately from it, and notwithstanding it, the Developer reserves the right, but is not obliged, to take an unrenewed Workspace's data off the servers and reclaim the server space, at a time of the Developer's own choosing, without being bound to give advance notice or to wait any particular period beforehand. Users who wish to keep their data should download or export it, or use the delete function described in Section 10 themselves, before the period ends; the User should not rely on continued access, on a reminder, on a period of grace, or on data remaining available for any particular time after non-renewal. All contributions and donations paid in connection with Workspace access are non-refundable, including where access is not renewed, is suspended or ends for any other reason, or is not used for the full period, except where a refund is required by applicable law and except as provided in the following paragraph. Where a User has contributed for a term longer than one year and the Workspace is discontinued before that term ends, the Developer, or any successor under Section 19, will on request refund the portion of the contribution attributable to the unexpired part of the term, so far as funds and circumstances permit. This is the sole remedy for such discontinuation. It is an undertaking given in good faith and is not intended to create, and does not create, an obligation enforceable against the Developer's estate. 13. Suspension, Restriction, or Discontinuation The Developer may suspend, restrict, modify, migrate, disable, or discontinue any Workspace, account, function, server, or related service at any time, with or without advance notice, where he considers this necessary or appropriate, including in cases involving non-payment, non-renewal, suspected abuse, excessive server use, security concerns, legal concerns, hosting-provider restrictions, technical failure, or discontinuation of the project. The Developer is not obliged to provide replacement hosting, migration, technical support, data recovery, continued access, notice, compensation, or refunds because of such action, except where required by applicable law and except for the refund of an unexpired multi-year term described in the last paragraph of Section 12. Section 19 describes what may happen to a Workspace, and to a term already paid for, if the Developer is no longer able to carry the project on. 14. Security Incidents If the Developer becomes aware of a security incident affecting Workspace Data, he may, when reasonably able and where he considers it appropriate, take steps such as investigating the issue, restricting access, or informing affected Users. The Developer does not undertake to monitor the Workspace continuously, to detect every security incident, or to notify Users within any fixed timeframe. Users and parishes remain responsible for their own legal, diocesan, and data-protection duties. 15. No Warranty and Limitation of Liability To the fullest extent permitted by law, the Workspace is provided "as is" and "as available," without warranties of any kind, including as to availability, uninterrupted operation, security, data integrity, or fitness for a particular purpose. The Developer does not warrant that the Workspace will be free of downtime, data loss, corruption, unauthorised access, or security incidents. To the fullest extent permitted by law, the Developer shall not be liable for any direct, indirect, incidental, special, consequential, exemplary, or punitive damages arising from the use of, inability to use, unavailability of, suspension of, or discontinuation of the Workspace, including but not limited to loss of data, loss of access, business or ministry interruption, financial loss, unauthorised access, or regulatory consequences, even if the Developer has been advised of the possibility of such damages. This limitation is in addition to, and does not replace, the limitation of liability set out in the Software EULA. Nothing in this Agreement limits liability where such limitation is not permitted by applicable law. 16. Alpha Stage Disclaimer As with the Software itself, the Workspace is in an early developmental Alpha stage and may contain errors, incomplete functions, design limitations, or other issues. It is used at the User's own risk, in addition to the risks described in the Software EULA. 17. Changes to This Agreement The Developer may update this Agreement from time to time, including to reflect changes in the Workspace's features, hosting arrangements, or applicable law. Updated versions will be made available on parishrecordkeeper.com and in the Documentation folder of the installation directory. Continued use of a Workspace after an updated Agreement has been made available constitutes acceptance of it; if the User does not agree, the User must stop using the Workspace and should export or delete any data as described in Section 10 while access remains available. 18. Governing Law This Agreement shall be governed by and construed in accordance with the laws of Zambia, without regard to its conflict of laws principles. 19. Succession, Assignment, and the Life of the Project Parish Record Keeper and its Workspace are written and maintained by one person, with help from friends of the project. They are not the product of a company, and neither the Software nor the Workspace carries any assurance that the project will still be operating in five or ten years. The User should not assume otherwise, and should read this Section together with Sections 13 and 15. What does not depend on the project continuing is the User's own records. The parish's data file resides on the parish's own computer; the Software is free, requires no server, requires no licence check, and requires no permission from the Developer in order to open it. It continues to function whether or not the Workspace, the servers, parishrecordkeeper.com, or the project itself continue. The Workspace is the online part only, and it is that part which may one day cease. Section 9 and Section 10 describe the User's own responsibility to keep independent copies and the self-service means of exporting and deleting Workspace Data at any time; a User contributing for a longer term is encouraged to make use of them as a matter of course. The Developer may transfer, assign, or novate this Agreement, the Workspace, and the rights and obligations arising under it to another person, group, association, or legal body, including any body that may later be formed to carry the project on, without the further consent of the User, provided that the successor accepts those obligations. In the event of the Developer's death or incapacity, this Agreement and any unexpired term already contributed for may be continued by such a successor, or may be terminated in accordance with Section 13, in which case the refund described in the last paragraph of Section 12 applies so far as funds and circumstances permit. The Developer is at present working towards placing the project on a more permanent footing, so that responsibility for the Software and the Workspace would in due course be carried by an established and enduring institution rather than by one individual. As at August 2026 that process is under way, and the Developer expects it to be concluded in the course of the following year. This paragraph records an intention and work in progress. It is not a representation that any such arrangement exists or has been agreed, nor an undertaking that it will be concluded, whether within that period or at all, and it creates no obligation and confers no right. Nothing in this Agreement obliges the Developer to arrange for a successor, to establish any body to carry the project on, or to secure the continuation of the Workspace beyond the Developer's own ability to provide it, and no User should assume that any such arrangement exists or is in place. The preceding paragraph is subject to this one in full. This Agreement is entered into in good faith on both sides: the User contributes towards the real running costs of the Workspace, and the Developer maintains it for as long as he is able. Neither party acquires a claim upon the other beyond that, save as expressly set out in this Agreement or as required by applicable law. 20. Contact Information For questions regarding this Agreement, including requests concerning Workspace Data, please contact: Bernhard Udelhoven Lumimba Catholic Church P.O. Box 530081 Lundazi Zambia Email: developer@parishrecordkeeper.com bernhard@fenza.org The contact details above may change, and the Developer does not guarantee continuous availability by post, email, website, telephone, server, or any other means. Sending a request does not guarantee that it will be received, read, or acted upon within any particular time. By using the Workspace, the User acknowledges that they have read and understood this Agreement and agree to be bound by its terms and conditions.