legal
Privacy Notice
This Privacy Notice explains how personal data is collected, used, stored, shared and protected within the D.O.M. Christian multi-confessional digital ecosystem.
About this Privacy Notice
This Privacy Notice explains how Deus Optimus Maximus Corporation collects, uses, stores, discloses and protects personal data when people access or use the D.O.M. Christian multi-confessional digital ecosystem.
It applies to D.O.M. websites, applications, accounts, profiles, community functions, publications, messaging, audio and video communication, events, pastoral-service requests, verification processes, support, files and other related services.
Data controller
- Controller:
- Deus Optimus Maximus Corporation
- Organization type:
- Church and religious nonprofit corporation
- Jurisdiction:
- State of Wyoming, United States
- Official organization and contact details:
- https://dom.gd/doc/legal-notice
Deus Optimus Maximus Corporation determines the purposes and means of processing personal data within D.O.M. and is the data controller unless a different role is expressly identified for a specific service.
Chakloon Pass and account access
Chakloon Pass is the unified authentication and account-access system used across the D.O.M. ecosystem.
Chakloon Pass uses widely adopted industry-standard identity and authorization protocols, including OAuth 2.0 and OpenID Connect. D.O.M. receives only the account information required to recognize the user, establish a session and provide the requested functions, such as a unique account identifier, username, display name, email address and selected profile information.
D.O.M. does not store or validate the user’s Chakloon Pass password. Authentication credentials and other security-sensitive account information are managed by the unified authentication system and protected using safeguards appropriate to their nature and risk.
D.O.M. uses secure session cookies to maintain signed-in access. These cookies are configured with protections including Secure, HttpOnly and SameSite attributes where supported.
Personal data we collect
Depending on how D.O.M. is used, we may collect and process:
- account identifiers, username, display name, email address and account status
- profile information, biography, avatar, location text and localized public names
- language, country, city, timezone, UTC offset and interface preferences
- publications, comments, reactions, subscriptions, follows, hashtags and other community activity
- messages, message attachments, message metadata, conversation participants, read status and activity previews
- audio and video communication metadata, including participants, call status, start time, end time and technical connection information
- event information, subscriptions, attendance status and participation records
- pastoral-service or religious-service requests, selected clergy, booking time, timezone, status and notes voluntarily provided by the user
- clergy or organization profile information, availability, verification submissions, supporting files, review status and administrative notes
- files, images, audio, video and other media uploaded by users, together with file names, types, sizes and technical metadata
- notifications, support requests, reports, appeals and correspondence
- security and audit information, including account actions, timestamps, IP address, browser or device information, request information and system logs
- browser language, approximate location derived from network information where enabled, and precise device location only when the user actively grants browser permission
- cookies, local storage and session storage necessary for authentication, settings, communication state, navigation continuity and security
- other information a user voluntarily submits through D.O.M
Information from other sources
We may receive personal data from:
- Chakloon Pass when a user authenticates or updates account information
- other users who mention, contact, report or interact with a person
- clergy, churches or organizations involved in verification, events, pastoral communication or service requests
- the user’s browser, device and network
- security, hosting, storage, communication and infrastructure systems used to operate D.O.M
- publicly available sources where reasonably necessary to verify an organization, public role or submitted claim
- lawful requests and communications from authorities or other parties
How we use personal data
We process personal data to:
- create, recognize, secure and maintain accounts
- provide D.O.M. functions requested by users
- show profile and content information according to user-selected visibility and audience settings
- enable communication between users, clergy, churches, communities and organizations
- provide events, subscriptions, pastoral-service requests, bookings and related reminders
- process clergy or organization verification
- store, deliver, resize, format and display user files and media
- personalize language, timezone, interface and notification settings
- provide support and respond to requests, reports and appeals
- moderate content and enforce the Terms of Use and Community Rules
- protect accounts, users, D.O.M. and third parties against fraud, abuse, security threats and unlawful conduct
- maintain logs, backups, service continuity and technical integrity
- understand service performance, diagnose errors and improve usability
- create a safe, respectful, comfortable and useful environment for participation in the D.O.M. ecosystem
- comply with legal obligations, lawful requests and the establishment, exercise or defense of legal claims
Legal bases for processing
Where applicable data-protection law requires a legal basis, D.O.M. relies on one or more of the following:
- performance of a contract, including providing the services requested under the Terms of Use
- consent, where the user makes a choice or where consent is required by law
- legitimate interests in operating, securing, improving and protecting D.O.M., provided those interests are not overridden by the user’s rights and freedoms
- compliance with a legal obligation
- protection of vital interests in urgent safety situations
- establishment, exercise or defense of legal claims
- other lawful bases available under applicable law
Where processing is based on consent, the user may withdraw consent at any time. Withdrawal does not affect processing already carried out lawfully before withdrawal.
Religious information and other sensitive data
Because D.O.M. is a Christian multi-confessional ecosystem, information voluntarily provided or generated through certain functions may reveal or strongly suggest a person’s religious beliefs, affiliation, practices or participation.
This may include church affiliation, clergy status, religious publications, event participation, selected pastor, requests for religious services, pastoral communication and related profile information.
Where such information is treated as sensitive or special-category data under applicable law, D.O.M. processes it only where a lawful condition is available. Depending on the circumstances, this may include explicit consent, information manifestly made public by the user, processing connected with legitimate activities of a religious nonprofit organization with appropriate safeguards, protection of vital interests, legal claims or another condition permitted by law.
Users should not disclose sensitive information unless they understand the visibility setting and are comfortable with the intended audience.
Public information and audience settings
D.O.M. processes, stores and displays information according to the functions used by the user, the visibility and audience settings selected by the user, and the permissions necessary to provide the requested service.
Information marked public may be visible to registered users, visitors and search engines. Public content may be copied, quoted or shared by other people outside D.O.M., and D.O.M. cannot fully control information after it has been lawfully accessed by others.
Information restricted by user settings is made available only to the selected audience, subject to technical operation, safety, moderation, legal compliance and authorized administrative access.
Users are responsible for reviewing visibility settings before publishing information.
Messaging and communications
D.O.M. provides internal messaging and audio and video communication functions as part of the D.O.M. product.
Messages and related metadata may be stored and processed to deliver conversations, synchronize devices, show message history, maintain read status, support attachments, prevent abuse and investigate reports.
Audio and video communication may process live media streams and technical connection data needed to establish and maintain a call. D.O.M. does not state that every communication is end-to-end encrypted. Users should not assume that communications have the same confidentiality as a legally privileged professional relationship.
D.O.M. does not record audio or video calls as a standard product function unless a separate recording feature is clearly presented and lawful notice or consent is obtained where required.
Pastoral and religious-service information
Requests to contact clergy, select a pastor, book a religious service or participate in a religious event may reveal sensitive religious information and may also include personal notes voluntarily supplied by the user.
This information is made available to the relevant user, clergy member, authorized organization personnel and authorized D.O.M. personnel only as necessary to provide, administer, secure or review the requested function.
D.O.M. is a technical environment and does not guarantee confidentiality equivalent to sacramental, professional, medical, psychological or legal privilege.
Cookies and local device storage
D.O.M. uses cookies and browser storage that are necessary or useful for:
- maintaining secure authenticated sessions
- completing authorization and registration flows
- remembering temporary navigation and return paths
- maintaining communication state and device continuity
- remembering language or interface preferences
- protecting against fraud, replay and unauthorized access
- improving performance and reliability
Some local or session storage may contain technical identifiers, synchronization tokens, recent communication state or cached interface data. Users can clear browser storage through browser settings, but doing so may sign them out or interrupt certain functions.
Any non-essential analytics, advertising or similar tracking technology will be addressed separately and, where required, activated only after an appropriate notice or consent choice.
Sharing and recipients
Personal data may be disclosed only where reasonably necessary to:
- other users, visitors or search engines according to the user’s actions and visibility settings
- clergy, churches, communities or organizations involved in a user-requested interaction, event, verification or service
- authorized employees, volunteers and contractors who require access for defined operational, support, security, moderation or legal purposes
- hosting, storage, authentication, communication, translation, security, backup and other infrastructure providers acting for or supporting D.O.M
- professional advisers, auditors or insurers where reasonably necessary
- public authorities, courts or other parties where disclosure is legally required or necessary to protect rights, safety and security
- a successor organization in connection with a lawful restructuring, transfer or reorganization, subject to appropriate protections
D.O.M. does not sell personal data as an independent commercial product. D.O.M. does not disclose personal data to advertisers for cross-context behavioral advertising unless a separate notice and any legally required choice are provided.
Internal access and confidentiality
Access to personal data within Deus Optimus Maximus Corporation is restricted to authorized persons who require access for defined operational, security, support, moderation or legal purposes.
The Corporation applies access controls, role-based permissions, confidentiality expectations, audit records and internal procedures intended to prevent unauthorized disclosure, copying or transfer of personal data by employees, volunteers and contractors.
Personal data may not be accessed or disclosed for personal purposes. Suspected misuse may result in removal of access, disciplinary measures, termination of a relationship and legal action where appropriate.
Security
D.O.M. uses technical and organizational measures designed to protect personal data against unauthorized access, alteration, disclosure, loss and destruction.
Depending on the system and risk, these measures may include:
- encrypted network connections using current transport-security protocols
- protected credential handling through Chakloon Pass
- signed and protected session cookies
- role-based access restrictions
- network and service isolation
- firewalls, rate limiting and request validation
- file-type and file-size controls
- logging, monitoring and audit records
- backups and recovery procedures
- security updates and review of operational systems
Not every item of personal data is encrypted at the individual database-field level. Some information must remain available to authorized systems in order to provide the service. No online system can guarantee absolute security.
International data processing
Deus Optimus Maximus Corporation is organized in the United States, while D.O.M. infrastructure, users and service providers may be located in the United States, the European Economic Area and other countries.
Personal data may therefore be processed in a country different from the user’s country of residence. Where applicable law requires safeguards for an international transfer, D.O.M. will use an available lawful mechanism or another legally permitted basis for the transfer.
Storage and retention
D.O.M. retains personal data only for as long as reasonably necessary for the purposes described in this Notice, including service operation, security, dispute resolution, legal compliance and protection of rights.
Retention depends on the type of data and the context. In general: active account and profile information is retained while the account remains active;
publications, comments, messages, files, event records and service requests are retained until deleted, removed, expired or no longer needed, subject to technical and legal exceptions;
security, audit and moderation records may be retained after content or account deletion where reasonably necessary to prevent abuse, document decisions or address legal claims;
server and request logs are retained for a limited operational period and may be retained longer when needed to investigate security incidents;
production backups are created for continuity and recovery and may temporarily retain data after deletion from active systems;
local production backups are generally retained for up to 14 days unless a backup is preserved for incident response, migration, legal compliance or another documented reason;
legal, tax, transaction and dispute records may be retained for the period required or permitted by law.
When data is no longer required, D.O.M. will delete it, anonymize it or place it beyond ordinary use, subject to technical feasibility and legal requirements.
Account deletion
Users may request account deletion through available account tools or by contacting the contact form linked from the Legal Notice.
Deletion may not immediately remove:
- information retained in another user’s lawful conversation or activity history
- public content copied or shared by others before deletion
- security, moderation, fraud-prevention or audit records
- records required to comply with law or resolve disputes
- data temporarily remaining in backups
- information that has been aggregated or anonymized
D.O.M. may need to verify identity before acting on a deletion or access request.
User rights
Depending on applicable law and the user’s location, users may have rights to:
- receive information about processing
- access personal data
- correct inaccurate or incomplete data
- delete personal data
- restrict processing
- object to certain processing based on legitimate interests
- withdraw consent
- receive portable data in an available structured format
- complain to a competent data-protection authority
- appeal or request review of certain decisions
- receive information about applicable international-transfer safeguards
- exercise other rights provided by law
Requests may be sent to the contact form linked from the Legal Notice. D.O.M. may request information reasonably necessary to verify identity, locate data and prevent unauthorized disclosure.
Rights are not absolute. A request may be limited or refused where permitted by law, including where necessary to protect another person’s rights, maintain security, comply with legal obligations or preserve legal claims.
Automated processing
D.O.M. may use automated tools to detect language, translate content, identify abuse patterns, apply rate limits, organize content or support moderation and security.
D.O.M. does not currently rely solely on automated processing to make a decision that produces legal effects or similarly significant effects concerning a user, unless a specific function clearly explains otherwise and applicable safeguards are provided.
Children
D.O.M. is not directed to children under 13, and persons under 13 may not create or independently use a D.O.M. account.
A person must generally be at least 16 years old to create or independently operate an account. Where applicable law requires parental or guardian authorization for a user of that age or older, the user may use D.O.M. only with valid authorization to the extent required by law.
If D.O.M. learns that personal data from a child has been collected contrary to these requirements, reasonable steps will be taken to restrict or delete the account and data, subject to legal and safety obligations.
Legal requests and safety
D.O.M. may preserve, use or disclose information where reasonably believed necessary to:
- comply with law, legal process or a lawful governmental request
- protect the rights, property or safety of a user, D.O.M. or another person
- investigate fraud, exploitation, security incidents or serious Terms violations
- protect children or vulnerable persons
- establish, exercise or defend legal claims
D.O.M. will seek to limit disclosures to information reasonably necessary for the relevant purpose.
Changes to this Privacy Notice
D.O.M. may update this Privacy Notice to reflect changes in law, services, technology, organizational structure or processing practices.
Where required by law, users will receive appropriate notice of material changes. The current effective date and last-updated date are displayed automatically as document properties.
Contact
Privacy questions and requests may be sent to the contact form linked from the Legal Notice.
Written correspondence may be addressed to: the organization identified in the Legal Notice.