Privacy Policy
Contents
1. Introduction & Responsible Entity
- Website operator
- Responsible for content & data processing
- Data Protection Officer (DPO)
- What is the ICF Movement?
- Legal basis
2. Principles of Data Processing
- β Transparency
- π― Purpose Limitation
- β Data Minimization
- π Security
- π Storage Limitation
- π Lawfulness
3. Collection & Use of Personal Data
- π¬ Contact & forms
- π Newsletter & communication
- π³ Donations
- π Website use & tracking
- π» Server logs & IT security
4. Use of Cookies & Tracking Technologies
- πͺ What are cookies?
- πͺ Consent Management (CookieHub)
- βοΈ Consent-based cookies
- π Management via Google Tag Manager
- π Analytics and performance tools
- π Forms, newsletter & communication
- π₯ Media embeds
- βοΈ Other tools
6. Your Rights
- π Right of confirmation and access
- βοΈ Right to rectification
- β Right to erasure
- π§― Right to anonymization, blocking or erasure
- π« Right to object
- π€ Right to portability
- π Right to withdraw consent
- π§ββοΈ Right to lodge a complaint with the supervisory authority
7. Data Sharing & Processing by Third Parties
- π€ Working with service providers (data processors)
- π Transfer to other countries
- π General principles
- π What this means for you
9. International Data Transfer
- π What does this mean in practice?
- πΊπΈ Example: USA
10. Security
- π Technical & organizational measures
- π‘οΈ What you should know
11. Legal Basis for Processing & Scope of Application
- Brazil (LGPD)
- Other jurisdictions
12. Contact for Data Protection Matters
13. Changes
Introduction & Responsible Entity
For us, data protection isn’t a legal formality β it’s an expression of responsibility. As ICF Rio de Janeiro, we are committed to treating your data with care and respect.
This Privacy Policy informs you which personal data we process on our website, for what purpose, and what rights you have in relation to it.
It applies to the subdomain https://icf.church/rio in all its language versions, as well as to the following legal entities operating under the ICF (International Christian Fellowship) brand:
- ICF Movement (association, Switzerland) β the international organization that founded ICF Rio de Janeiro as one of its churches
- ICF RIO – INTERNATIONAL CHRISTIAN FELLOWSHIP
CNPJ 32.418.141/0001-15 (ICF Rio de Janeiro)
Whenever this Privacy Policy refers to Β«ICFΒ» or Β«WeΒ», it means β depending on context β one or more of these organizations.
Website Operator
ICF Rio de Janeiro
Rua Lopes TrovΓ£o, 233
IcaraΓ β NiterΓ³i – RJ
CEP 24.220-070, Brazil
[email protected]
For the entity’s full identification details (legal name, CNPJ, legal representative), please see our Imprint.
Responsible for Content & Data Processing
ICF Rio de Janeiro
Rua Lopes TrovΓ£o, 233
IcaraΓ β NiterΓ³i – RJ
CEP 24.220-070, Brazil
[email protected]
Data Protection Officer (DPO)
Paulo AndrΓ© Carneiro Campos Cordeiro ICF Rio de Janeiro, [email protected]]
Appointing a Data Protection Officer with a publicly disclosed contact is a requirement under art. 41 of Brazil’s LGPD (Law No. 13,709/2018).
What is the ICF Movement?
ICF is a Christian church on a biblical foundation. We grew out of the dream of shaping church to be dynamic, close to real life, and in tune with the times.
The ICF Movement is an organization that supports the founding of churches, primarily in Europe and selectively elsewhere in the world, with the goal that people become more like Jesus Christ, live fearlessly, and positively change their surroundings. ICF Rio de Janeiro is one of these churches.
Beyond founding new ICF churches, the ICF Movement works to renew and strengthen the existing church landscape, offering resources, conferences, courses (ICF College), leadership, and coaching.
We believe healthy, socially relevant local churches can spark transformation around the world. It’s our deepest conviction that the local church is the hope of the world!
Learn more at https://icf.church/movement
Legal Basis
The information about each tool used in this Privacy Policy is processed exclusively to handle your respective request. More information is available in the chapter Β«Legal Basis for Data ProcessingΒ».
Principles of Data Processing
We process personal data with a clear purpose and only to the extent necessary for it. We follow the principles set out in art. 6 of the LGPD:
β Transparency
We want you to be able to understand at any time what happens to your data. That’s why we openly describe in this policy which tools we use and why (art. 6, VI, LGPD).
π― Purpose Limitation
We collect and use personal data only for the purpose intended β for example, for contact requests, newsletter sign-up, analysis of website use, or processing donations (art. 6, I, LGPD).
β Data Minimization
We collect and process only as much data as necessary. Where anonymous or pseudonymous use is possible, we use it (art. 6, III, LGPD).
π Security
Your data is protected with us. We use technical and organizational measures to protect it against loss, misuse, or unauthorized access (art. 6, VII, and art. 46, LGPD).
π Storage Limitation
We store personal data only for as long as it’s needed for the respective purpose, or as long as legal retention obligations exist (art. 15 and 16, LGPD).
π Lawfulness
Our data processing is always based on one of the legal grounds set out in art. 7 of the LGPD: be it your consent, compliance with a legal obligation, or legitimate interest. We do not make decisions based solely on automated processing that produce legal effects without the possibility of review (art. 20, LGPD).
Note: for certain data processing operations with elevated risk (e.g. processing of sensitive data), we prepare, when necessary, a Data Protection Impact Report (RIPD), in accordance with art. 5, XVII, and art. 38 of the LGPD.
Collection & Use of Personal Data
We collect personal data when you actively provide it to us (e.g. via a form) or when it’s technically necessary β for example, through a form, your IP address when viewing a page, when donating, or when using our website.
Here’s when that happens and how we use that data:
π¬ Contact & Forms
When you contact us through a contact form or register for an event, we process the data you entered (e.g. name, e-mail, request) to answer your inquiry or provide the requested service.
π Newsletter & Communication
If you sign up for our newsletter or stay in touch with us (e.g. through interest in resources or events), we store and use your contact details to send regular e-mails, inspiration, and updates.
You can unsubscribe from the newsletter at any time via the unsubscribe link in every e-mail.
π³ Donations
Donations to ICF Rio de Janeiro can be made by bank transfer/deposit, PIX, credit card, or recurring-giving platforms (see Generosity).
Payment processing may be handled by external providers (e.g. PicPay, PayPal, or contribution-management platforms such as Eklesia Online). Once you choose one of these payment services, you’ll be redirected to their platform. Their own privacy policies apply to any further processing of your data.
The data you provide (e.g. name, e-mail, amount, payment method) is processed to handle your donation and for documentation purposes (e.g. issuing receipts). Donations to religious organizations may, in some cases, allow inferences about your religious belief (a sensitive personal data category under art. 5, II, and art. 11 of the LGPD). This processing only takes place with specific, distinguished consent or where permitted by law (art. 11, I and II, LGPD).
π Website Use & Tracking
When you visit our website, certain technical information is automatically processed, such as:
- IP address (shortened/pseudonymized)
- Browser type and version
- Operating system
- Date and time of access
- pages visited / time spent
This data helps us run our website in a technically stable way and continuously improve it (see the section Β«Cookies & TrackingΒ»).
π» Server Logs & IT Security
When you access our pages, our hosting automatically processes server logs (e.g. IP address, date/time, requested URL, referrer, user agent). This serves the technical delivery of the site and IT security.
Tools & Third Parties Used
We use selected third-party providers to make our website user-friendly, secure, and modern. Below, we explain which tools we use, what data is processed, and why.
[TODO: this list reflects the global ICF platform’s (new.icf.church) tool stack. Confirm before publishing which of these are actually active on the /rio subsite.]
π Analytics and Performance Tools
Google Analytics
We use this to understand how visitors use our website. The collected data (e.g. page views, time spent, device used) is analyzed in anonymized form.
Google Tag Manager
Used to manage tracking tags and cookies. Tag Manager itself does not store personal data.
Meta Pixel
Used to measure marketing campaigns and display relevant content.
Google Ads
Used for campaign tracking and conversion measurement, to assess the effectiveness of our advertising.
Microsoft Clarity
Used to analyze user behavior (e.g. click paths, heatmaps). The data is analyzed in anonymized form.
Gleap
We use Gleap as a support and communication platform. It handles support requests, displays help articles, evaluates user feedback, and shows targeted chat messages, notifications, or banners.
Pulsetic
Monitors the availability and performance of the website. No personal data is stored.
Sentry
Captures error reports (bugs) and technical data to improve stability.
π Forms, Newsletter & Communication
MailGun
We use MailGun as an SMTP service to reliably deliver e-mails technically (e.g. confirmations, newsletters).
Google reCAPTCHA
To protect our forms against abuse and spam, we use Google reCAPTCHA (versions 2 & 3). This service checks whether input comes from a human or a bot. It analyzes and transmits to Google, among other things, IP address, time spent on the page, and mouse movements.
Salesforce Account Engagement (Pardot)
Our marketing automation platform, through which we manage newsletters and campaigns. Pardot tracks which content is relevant to you, to send you appropriate information.
π₯ Media Embeds
YouTube & Vimeo
YouTube and Vimeo videos are embedded on our website (e.g. our celebrations streamed at youtube.com/c/ICFRIO). These providers may set cookies and collect usage data (e.g. which videos are watched).
Spotify
Audio files and videos from Spotify are embedded on our website. Spotify may set cookies and collect usage data (e.g. which podcasts are listened to).
ICF Hub
Sermons, offerings, service times, and certain organizational data, such as social media links, address, or contact details, are transmitted to the website from our own internal ICF platform via an API, and are technically necessary for core functionality to work.
βοΈ Other Tools
- Google Maps: for interactive maps on the website (e.g. the church’s location in IcaraΓ, NiterΓ³i)
- Algolia: for the internal search function for events, sermons & locations
- Shortpixel: image optimization
- Zapier: automation (e.g. data transfer between tools)
- WPML (translation): manages multilingual display of content
Your Rights
Protecting your personal data matters to us. You have the right to know what happens to your data, and we transparently show you the options available to you. Here are your rights, under art. 18 of the LGPD:
π Right of Confirmation and Access
You can ask at any time whether and which personal data we have stored about you (art. 18, I and II, LGPD).
βοΈ Right to Rectification
If something is no longer correct, you can request the correction of your data (art. 18, III, LGPD).
β Right to Erasure
You have the right to request that your data be deleted β for example, when it’s no longer needed for its original purpose or you have withdrawn your consent (art. 18, VI, LGPD).
π§― Right to Anonymization, Blocking or Erasure
You can request the anonymization, blocking, or erasure of unnecessary, excessive, or unlawfully processed data (art. 18, IV, LGPD).
π« Right to Object
You can object to data processing carried out on a legal basis that dispenses with your consent, whenever non-compliance with the LGPD is found (art. 18, Β§ 2, LGPD).
π€ Right to Portability
You can request that your data be ported to another service or product provider, upon an express request (art. 18, V, LGPD).
π Right to Withdraw Consent
You can withdraw your consent at any time, free of charge and in a simplified manner (art. 8, Β§ 5, and art. 18, IX, LGPD).
π§ββοΈ Right to Lodge a Complaint with the Supervisory Authority
If you believe your data protection concerns haven’t been adequately addressed, you have the right to file a complaint with the competent authority (art. 18, VII, LGPD).
In Brazil, the competent authority is:
- ANPD β Autoridade Nacional de ProteΓ§Γ£o de Dados (gov.br/anpd)
Retention Period
We keep personal data only for as long as it’s necessary for the respective purpose β or as long as required by law.
π General Principles
- Contact requests are stored for a maximum of 2 years (for follow-up and internal analysis purposes), unless a deletion request is received, a legitimate interest in retention exists, or a legal retention obligation applies.
- Newsletter data is stored until you unsubscribe or withdraw your consent.
- Donor data is subject to bookkeeping retention obligations under Brazilian law (typically between 5 and 10 years, depending on the type of accounting/tax record β [TODO: confirm the exact period with an accountant/lawyer]).
- Tracking data (e.g. via Google Analytics) is stored in anonymized form, to track long-term trends and improve the ICF website.
π What This Means for You
We comply with legal deadlines and regularly review which data can be deleted or anonymized.
International Data Transfer
Some of the services we use (e.g. hosting, newsletter, analytics) are based, or process data, in countries outside Brazil β particularly in the United States.
π What Does This Mean in Practice?
When personal data is transferred to countries that don’t have a level of data protection equivalent to that required by the LGPD, we make sure your data remains properly protected (art. 33, LGPD).
We ensure this, for example, through:
- standard contractual clauses approved by the ANPD
- ANPD adequacy decisions, where they exist
Additional technical/organizational measures, such as encryption or strict access restrictions.
πΊπΈ Example: USA
Some of our service providers (e.g. Google, Meta, MailGun, Vimeo) are headquartered in the United States. The LGPD is still in the process of regulating international transfer mechanisms equivalent to the EU/US Data Privacy Framework.
In the meantime, we seek to contractually ensure, wherever possible, a level of protection equivalent to that required by the LGPD with these providers.
Security
Protecting your data matters to us. That’s why we implement comprehensive security measures to reliably protect it against loss, misuse, or unauthorized access.
π Technical & Organizational Measures
We employ technical and organizational security measures (art. 46, LGPD) to protect your data against loss, misuse, unauthorized access, or disclosure. This includes, among others:
- careful selection and oversight of service providers
- encryption of connections (SSL/TLS), recognizable by”https://” in the browser’s address bar
- access restrictions to our systems
- regular security and software updates
- secure password policies & two-factor authentication (internal)
π‘οΈ What You Should Know
No digital system is 100% secure. But we do our best to ensure a high level of protection β and react immediately whenever there is cause for concern. If you notice anything, please reach out to us. We take your reports seriously. Despite careful technical and organizational measures, a residual risk in transmitting data over the internet (e.g. when using third-party services) can never be fully excluded. In the event of a relevant security incident, we will notify the ANPD and affected data subjects, in accordance with art. 48 of the LGPD.
Legal Basis for Processing & Scope of Application
This Privacy Policy is guided by the provisions of Brazil’s General Data Protection Law (LGPD, Law No. 13,709/2018).
Our data processing relies on the legal bases set out in art. 7 of the LGPD, according to the context and specific purpose of each processing activity.
π§π· Brazil
Data processing at ICF Rio de Janeiro is based on the legal grounds set out in the LGPD, in particular:
- Art. 7, I, LGPD β consent of the data subject
- Art. 7, II, LGPD β compliance with a legal or regulatory obligation
- Art. 7, V, LGPD β performance of a contract or preliminary procedures
- Art. 7, IX, LGPD β legitimate interest (e.g. our interest in analyzing usage behavior to improve the website or ensure IT security)
- Art. 11, LGPD β processing of sensitive personal data (e.g. in the context of donations, which may reveal religious belief), only with specific, distinguished consent or another applicable legal basis
The applicable legal basis is indicated, where necessary, in the relevant section of this policy, according to the specific purpose of processing.
Other Jurisdictions
For users accessing our services from other countries β e.g. the European Union (GDPR), Switzerland (FADP), or the United States (CCPA) β additional rights under those laws may apply. If you access our services from another country, we recommend also familiarizing yourself with the local data protection rules that apply.
Contact for Data Protection Matters
If you have questions about data protection or want to exercise your rights (e.g. access, erasure, withdrawal of consent), please reach out to us.
Contact
ICF Rio de Janeiro
Rua Lopes TrovΓ£o, 233
IcaraΓ β NiterΓ³i – RJ
CEP 24.220-070, Brazil
[email protected]
We’ll answer your request as quickly as possible β and in any case within the legally required timeframe (art. 19, Β§ 1, LGPD).
Changes
We regularly review our Privacy Policy and adapt it, where necessary, to new legal requirements (e.g. ANPD regulations or changes to the LGPD) or technical changes. The current version is always available on our website.
Last updated: Version 1.0 β July 2026