Christian Fellowship Church (CFC), Charity No. 101476
Data Controller: Christian Fellowship Church (Charity No. 101476), known as CFC.
Registered address: 10 Belmont Road, Belfast BT4 2AN
Data Protection Lead: Ashleigh Beattie
Contact: moc.cfcsisiht@rpdg | 028 9067 1838
ICO Registration Number: Z9467502
Date of Policy: 21st May 2018
Last Updated: 23rd July 2026
This is the privacy notice and data protection policy for CFC. It covers how we process (use and store) your data, what data we hold, your individual rights, and how you can contact us about your data. This policy covers our use of personal data, meaning any information about a living individual which allows them to be identified, either from that information alone or together with other information (for example a name, photograph, video, email address, or postal address).
Our processing of personal data is governed by the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and other relevant legislation including the Human Rights Act 1998.
This privacy notice is provided by Christian Fellowship Church, Charity No. 101476, which is the Data Controller for your data. CFC operates as a single charity across multiple locations in Northern Ireland. All staff and relevant volunteers at every location who process your information do so on behalf of, and under the responsibility of, CFC as the single Data Controller — this notice applies equally wherever you engage with us.
Our current locations are:
CFC processes: names, titles and aliases, and photographs; contact information including telephone numbers, postal/residential addresses, and email addresses.
Where there is a legitimate interest in facilitating our charitable aims and activities, or where you have provided it to us, we may process demographic information such as gender, age, date of birth, marital status, nationality, education and work history, academic or professional qualifications, hobbies, family composition, and dependants.
Where you give financially to CFC or pay for church activities (such as event bookings), we process financial identifiers such as bank account numbers, payment card numbers, and payment or transaction identifiers.
As a church, the fact that we hold data about you at all may itself indicate something about your religious beliefs, so this data is likely to constitute special category data. Where you provide it, we may also process other special category data: racial or ethnic origin, health data (including details of injuries, medication, or treatment), sexual orientation, and, separately, criminal offence data (such as details of criminal records, cautions, or fines relevant to safeguarding).
As Data Controller, CFC and all appointed persons will comply with their legal obligations to keep personal data accurate and up to date; to store and destroy it securely; to avoid collecting or retaining excessive data; and to protect it from loss, misuse, and unauthorised access or disclosure through appropriate technical and organisational measures. If you have any concerns about how your data is used, please contact our Data Protection Lead.
We only hold data that we are legally obliged to hold, or that helps us fulfil our missional and charitable aims as a church. We are a membership organisation, and good communication with our membership is an essential part of being a church. We hold and process data to:
Our processing also includes the use of CCTV for the prevention and prosecution of crime. See the CCTV section below for details.
As all locations form part of the same charity and Data Controller, your data (for example membership records, safeguarding records, or children’s check-in information) may be shared between CFC locations where necessary — for example if you attend one location but a family member is checked in to a children’s or youth group at another, or where centrally held systems such as ChurchSuite are used across all sites. This is not a transfer to a third party, as all locations operate under the same Data Controller and the same policy applies wherever your data is held.
Safeguarding concerns, including how to raise a concern and who to contact, are covered in full in our separate safeguarding policy, published at thisiscfc.com/safeguarding. That page sets out our central Safeguarding Lead and a named Site Safeguarding Deputy for each location, and should be read alongside this privacy notice for anything relating to a safeguarding disclosure or concern. Safeguarding records are processed under Article 10 UK GDPR and Schedule 1, Part 2 of the Data Protection Act 2018, and are retained in line with statutory safeguarding retention requirements regardless of which location holds them.
CFC operates CCTV at all locations for the purposes of crime prevention, detection, and the safety of staff, volunteers, and visitors. Signage is displayed at all monitored entrances. Footage is retained for 30 days unless required for longer as part of an investigation, and access is restricted to [named roles] at each site. Requests for footage, including subject access requests, should be directed to the Data Protection Lead.
For ordinary personal data, most of our processing relies on legitimate interests: for example, maintaining membership records, recording financial donations, and operating rotas for the effective running of services. Some processing is necessary to comply with a legal obligation, such as retaining safeguarding records and Gift Aid declarations. Some processing is necessary for the performance of a contract with you or to provide a service you have requested, such as buying tickets or registering for an event. Where none of these apply, we will ask for your consent before processing your data.
Special category data (such as data revealing religious belief, health data, or data concerning sexual orientation) requires a further legal basis under Article 9 UK GDPR, in addition to the bases above. Where CFC processes this data, it relies on Article 9(2)(d) UK GDPR and the condition at Schedule 1, Part 2, paragraph 17 of the Data Protection Act 2018, which permits not-for-profit bodies with a religious or philosophical aim to process the personal data of members, former members, or persons with regular contact with the body in connection with its purposes, subject to appropriate safeguards and provided the data is not disclosed outside the organisation without consent.
Criminal offence data, including safeguarding-related records, is processed under Article 10 UK GDPR and Schedule 1, Part 2 of the Data Protection Act 2018, in connection with our safeguarding responsibilities as a charity working with children and adults at risk.
We treat your personal data as strictly confidential. It is only shared with third parties where necessary for the performance of our tasks, or where you have given prior consent. We may share data with:
Where any of these providers process data outside the UK, see Transfer of Data Abroad below.
Our general rule is to keep data no longer than necessary. Where you continue to actively engage with our church services, activities, and events, we retain appropriate membership data to support your involvement. We carry out an annual review to assess who is actively engaging in church membership; where this is not the case, we remove your data.
We keep some records permanently where we are legally required to, for example service, wedding, and baptism registers, and some safeguarding records. We keep some other records for a defined extended period: current best practice is to retain financial records for a minimum of seven years to support HMRC audits.
Website comments and their metadata are retained indefinitely, unless otherwise specified.
When exercising any of the rights below, we may need to verify your identity before processing your request, so we may ask you for proof of identity.
Where any of our data processors or systems store or process personal data outside the UK, we will only permit this where the destination is covered by UK adequacy regulations, or where appropriate safeguards are in place, such as the ICO’s International Data Transfer Agreement or an approved UK Addendum to the EU Standard Contractual Clauses. It is our general practice not to publish personal data on our website.
If we wish to use your personal data for a new purpose not covered by this notice, we will provide you with an updated notice explaining the new use before processing begins, setting out the relevant purposes and legal basis. Where necessary, we will seek your prior consent.
This website is thisiscfc.com, managed by Christian Fellowship Church, Belfast.
When visitors leave comments on our website, we collect the data shown in the comment form, together with the visitor’s IP address and browser user agent string, to help with spam detection. An anonymised string created from your email address (a hash) may be sent to the Gravatar service to check whether you use it; the Gravatar privacy policy is available at automattic.com/privacy. Once your comment is approved, your profile picture is visible publicly alongside it.
We may collect and retain information submitted through forms on this website and ChurchSuite for administrative purposes.
If you leave a comment, you may opt in to saving your name, email address, and website in a cookie for one year, for your convenience on future visits. If you have an account and log in, we set a temporary cookie to check whether your browser accepts cookies; this contains no personal data and is discarded when you close your browser.
On login we also set cookies to save your login information and screen display choices. Login cookies last two days, or two weeks if you select “Remember Me”; screen option cookies last a year. Logging out removes your login cookies. Editing or publishing an article sets an additional cookie containing only the post ID, which expires after one day.
We use Google Analytics to understand how people find and use our website and what sources generate interest. Google Analytics sets cookies on your device to distinguish you from other visitors. These cookies are not essential to the site functioning and are only set with your consent, given via the cookie banner when you first visit the site. You can withdraw or change your consent at any time via [link/mechanism]. Information collected includes pages visited, time on site, and general location and device information; it does not, on its own, identify you by name. Data is processed by Google in accordance with Google’s privacy policy, and some data may be transferred outside the UK as part of that processing (see Transfer of Data Abroad).
Pages on this site may include embedded content, such as videos, images, or articles. Embedded content behaves as if the visitor had visited the other website directly. These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that content, including tracking your interaction if you are logged in to that website.
We use Google Analytics to understand how people find and use our website and what sources generate interest. This is aggregated information and does not identify individual users.
We use your data for our own purposes only and do not share it with third parties except where specified in this notice. Data is held on ChurchSuite (our church database system).
If you leave a comment, the comment and its metadata are retained indefinitely. They are regularly reviewed and may be deleted unless we need to keep them for a legal reason.
Visitor comments may be checked through an automated spam-detection service.
Data transmitted from your browser to this website is encrypted using SSL/TLS, so that it cannot be read if intercepted. Data held on our servers is protected by firewalls and appropriate security measures.
Should we become aware of a security breach, we will act as quickly as possible to resolve it. We will notify affected users of the extent of the breach and advise on any actions they should take. Where required, we will also notify the ICO within 72 hours of becoming aware of a breach, in line with our legal obligations.
We use database tools from ChurchSuite. This website and other CFC websites integrate with those systems to keep your information up to date and respect your communication preferences. If you wish to be removed from any system, please contact us.
We do not currently profile users’ data or present different content based on prior user behaviour.
If you have any queries or concerns about how we use your data, or wish to exercise any of your rights, please contact:
The Data Protection Lead, CFC, 10 Belmont Road, Belfast BT4 2AN, or by email at moc.cfcsisiht@rpdg, or by phone on 028 9067 1838.
You can opt out of receiving communications from the church at any time using the same contact details.
For safeguarding concerns specifically, do not use the data protection contact above — contact our Safeguarding Lead directly, or your local Site Safeguarding Deputy, as listed at thisiscfc.com/safeguarding. If there is a serious risk of harm to anyone, call 999 immediately.
Christian Fellowship Church is a registered charity:
NI Charity no. 101476