Data Management

Understand how your data is stored, retained, exported, and deleted in Ecclesly. Learn about our data retention policies and the secure purge process.

Your Data, Your Control

Ecclesly is committed to data transparency and security. You maintain ownership of your organization's data at all times. Our data management features help you:

  • Export your data in standard formats for backup or migration
  • Understand our data retention policies during subscription lifecycle
  • Request permanent deletion when you no longer need the service
  • Maintain compliance with data protection requirements

Data Retention Policy

Your data is retained based on your subscription status. Understanding these policies helps you plan for account changes and ensure continuity.

Subscription Lifecycle

StatusData AccessDuration
ActiveFull read/write accessWhile subscription is active
TrialingFull read/write accessTrial period (typically 14 days)
Past DueFull access while payment resolvesUntil payment succeeds or fails
Grace PeriodRead-only access30 days after cancellation
CancelledData retained, access suspendedUntil purge requested
ExpiredData retained, access suspendedUntil purge requested

Reactivation

You can reactivate your subscription at any time before data purge. All your data will be immediately accessible again with full read/write permissions.

Data Retention by Category

When an organization's subscription ends and data purge is initiated, different data categories are handled according to their legal retention requirements. Some data must be retained for compliance purposes even after account closure.

DataPurgeable?RetentionWhat Happens on Purge
Member profiles (no donations)Yes90 days post-cancelPermanently deleted
Member profiles (with donations)Partial7 yearsNames/contact pseudonymized; donation amounts preserved
Donation recordsNo7 yearsAnonymized but retained
Journal entries & expensesNo7 yearsRetained with anonymized user references
Bank reconciliationsNo7 yearsRetained
Audit logsNo3–7 years (by category)Archived, then deleted
Care notes & medical infoYesImmediatePermanently deleted
Emergency contactsYesImmediatePermanently deleted
Attendance recordsYes3 yearsPermanently deleted
AI chat conversationsYesImmediatePermanently deleted
Ministry/volunteer dataYes2 yearsPermanently deleted

IRS Compliance

Financial records are retained for 7 years per IRS IRC §6001 and §6501. This includes donation records, journal entries, expenses, and bank reconciliations. Personal identifiers on these records are pseudonymized to protect privacy while maintaining the financial audit trail.

Data Export

Export your data at any time for backup, reporting, or migration purposes. Exports are available in standard formats compatible with other systems.

Available Exports

Data TypeFormatsLocation
MembersCSV, ExcelMembers → Export
DonationsCSV, Excel, PDFDonations → Export
Financial ReportsPDF, ExcelReports → Download
Journal EntriesCSV, ExcelAccounting → Journal → Export
Contribution StatementsPDFReports → Statements

Tip: Regularly export and backup your financial reports and contribution statements. These serve as important records even after your subscription ends.

Data Purge

When your organization cancels its Ecclesly subscription, your data remains available during a grace period. After this period, you may request permanent deletion of all your organization's data through a secure two-step verification process.

Permanent Deletion Warning

Data purge is irreversible. Once completed, all your organization's data will be permanently deleted, including members, donations, financial records, accounting data, bank connections, and audit logs. This action cannot be undone.

When Data Purge is Available

Data purge can only be requested when your subscription is in one of the following states:

  • Grace Period: Subscription cancelled but still within the 30-day grace period
  • Cancelled: Subscription has been cancelled and grace period has ended
  • Expired: Subscription has fully expired

Data Retention During Grace Period

Your data remains intact and accessible (in read-only mode) during the grace period. You can reactivate your subscription at any time during this period without losing any data.

Two-Step Verification Process

Data purge requires verification from both the Kaleo Systems administrator and your organization to prevent accidental or unauthorized deletion:

1Initiate Purge Request

  1. Kaleo Systems administrator initiates a purge request
  2. Administrator provides a reason for the purge (for audit trail)
  3. Administrator confirms the organization name by typing it exactly
  4. A 6-digit verification PIN is generated and emailed to your organization's registered email address
  5. The PIN expires after 30 minutes

2Confirm Deletion

  1. You (the customer) receive the verification PIN via email
  2. Review the email carefully to confirm this is a legitimate request
  3. If you authorize the deletion, provide the PIN to the administrator
  4. The administrator enters both the PIN and their admin password to complete the purge
  5. All data is permanently deleted from Ecclesly systems

Protect Your PIN

Only share the verification PIN if you have personally authorized the data deletion. If you receive a purge verification email unexpectedly, contactsupport@kaleosystems.com immediately.

Security Measures

Security FeatureDescription
PIN ExpirationVerification PINs expire after 30 minutes
Attempt LimitsMaximum of 5 PIN entry attempts before request is invalidated
Dual AuthorizationRequires both customer PIN and admin password
Complete Audit TrailAll purge requests and actions are logged, including failed attempts
Email VerificationPIN is sent only to your organization's registered email

What Gets Deleted

A complete data purge removes all of your organization's data from Ecclesly, including:

  • All members, families, and contact information
  • All donations, pledges, and giving history
  • All funds and fund allocations
  • All journal entries and expenses
  • Chart of accounts and balances
  • Bank connections and transaction history
  • All reports and statements
  • Staff accounts and permissions
  • Audit logs and system data
  • All uploaded documents and files

Before Requesting Purge: We recommend exporting all reports and downloading any data you may need for record-keeping purposes. Once deleted, data cannot be recovered. See the Data Export section above.

Data Security

Ecclesly employs industry-standard security measures to protect your data throughout its lifecycle.

Encryption at Rest

All data is encrypted using AES-256 encryption while stored in our databases.

Encryption in Transit

All connections use TLS 1.3 encryption for secure data transmission.

Access Controls

Role-based permissions ensure users only access data they're authorized to see.

Audit Logging

Complete audit trail of all data access and modifications for accountability.