Privacy policy
Chrestos is a trading name of ThenMedia Limited. References in this policy to “Chrestos”, “we”, “us” or “our” refer to ThenMedia Limited, the legal entity responsible for providing our services and for the handling and protection of personal data in accordance with this policy.
ThenMedia Limited (“ThenMedia”, “we”, “us” or “our”) respects the privacy of its customers, staff, suppliers, website visitors and other contacts. We process personal data in accordance with applicable UK data protection legislation, including the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Data (Use and Access) Act 2025.
ThenMedia Limited is registered in England and Wales under company number 07990449. For enquiries relating to privacy or data protection, please email data@thenmedia.co.uk or telephone 01244 478727.
Personal data
ThenMedia may store and process personal data relating to staff, customers, prospective customers, suppliers, contractors and other business contacts. Personal data we process may include a person’s title, name, postal address, telephone number, email address, job title, organisation and other information provided to us in connection with our services.
- We only collect and process personal data where we have a lawful basis for doing so.
- Depending on the circumstances, our lawful basis may include processing necessary for the performance of a contract, compliance with a legal obligation, our legitimate interests or your consent.
- Where we rely on legitimate interests, these may include operating and improving our business, providing and supporting our services, maintaining customer and supplier relationships, administering our systems and protecting the security of our services. We consider whether those interests are proportionate and whether they are overridden by the rights and interests of the individuals concerned.
- We may process personal data in order to provide our services, administer customer accounts, provide technical support, respond to enquiries, maintain our systems, fulfil contractual and legal obligations and communicate with our customers and business contacts.
- We take reasonable steps to ensure that the personal data we hold is accurate and kept up to date.
- Access to personal data held within our own systems is restricted to authorised personnel who require access for legitimate business purposes.
- We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, including satisfying contractual, legal, accounting and regulatory requirements. Different categories of information may therefore be retained for different periods.
Where we process personal data on behalf of one of our customers through a website, cloud system or bespoke application, our customer will normally be the data controller and ThenMedia will act as a data processor. In those circumstances, requests relating to the personal data should normally be directed to the relevant customer in the first instance.
Sharing personal data
ThenMedia does not sell personal data.
We may disclose or make personal data available to trusted service providers where this is necessary to operate our business or provide our services. Depending on the service being used, these may include hosting and infrastructure providers, analytics providers and payment service providers.
Where a third party processes personal data on our behalf, we take appropriate steps to ensure that suitable contractual and data protection arrangements are in place.
We may also disclose personal data where required by law, regulation, court order or another lawful authority, or where reasonably necessary to establish, exercise or defend legal rights.
Some third-party services may process information outside the UK. Where this involves a restricted transfer of personal data, we take appropriate steps to ensure that a lawful transfer mechanism and appropriate safeguards are in place.
Your data protection rights
Depending on the circumstances and the lawful basis on which your personal data is processed, you may have rights including:
- The right to be informed about how your personal data is used.
- The right to request access to personal data we hold about you.
- The right to request correction of inaccurate or incomplete personal data.
- The right to request erasure of your personal data in certain circumstances.
- The right to request restriction of processing in certain circumstances.
- The right to object to certain processing, including processing based on legitimate interests.
- The right to data portability where applicable.
- The right to withdraw consent at any time where processing is based on consent.
These rights are subject to certain legal limitations and exemptions.
To exercise your rights, or to ask what personal data ThenMedia holds about you, please email data@thenmedia.co.uk.
We may need to request information to confirm your identity before responding to a request.
You also have the right to raise a concern with the Information Commissioner’s Office (ICO), the UK’s independent data protection regulator. Further information is available at https://ico.org.uk/.
Data storage
- ThenMedia stores and manages data using its own web-based software and associated hosting infrastructure.
- Our software and cloud services use technologies including Linux, MariaDB, NGINX, PHP and Javascript for the storage, management and retrieval of data.
- ThenMedia’s infrastructure is protected by technical and organisational security measures including firewalls, access controls and restrictions on administrative access.
- Our primary UK hosting infrastructure is located in data centres in London.
- Data is backed up to separate locations for resilience and disaster-recovery purposes.
- Access to systems containing customer data is restricted to authorised users and administrators.
Cookies and similar technologies
ThenMedia hosts websites for itself and its customers. These websites may use cookies and similar technologies.
Cookies are small pieces of information stored on a user’s device. Some cookies are required for a website or online service to operate correctly, while others may be used for purposes such as analytics or remembering user preferences.
Interactive websites, including websites where a user can sign in, may use session cookies or similar technologies that are strictly necessary to authenticate users, maintain sessions, provide security and deliver requested functionality. Where these technologies are strictly necessary to provide a service requested by the user, consent is not normally required.
ThenMedia websites may also use analytics technologies, including Google Analytics, to understand how websites are used and to help us improve their content, performance and usability.
Where analytics technologies meet the applicable statutory exemption for statistical purposes, they may be used without prior consent provided that the legal requirements for that exemption are satisfied, including providing users with clear information and a simple means of objecting.
Where an analytics, advertising, tracking or other technology does not qualify for an exemption, it will only be activated after any consent required by the Privacy and Electronic Communications Regulations (PECR) has been obtained.
Where Google Analytics is used, further information about Google’s terms and privacy practices is available at https://marketingplatform.google.com/about/analytics/terms/gb/ and https://policies.google.com/privacy.
Individual websites hosted or developed by ThenMedia may have their own cookie notices or consent controls providing more specific information about the cookies and technologies used on that website.
Data Security
This section explains how and where data is stored when you use ThenMedia Cloud, a ThenMedia product such as Loudhailer or Chrestos, or a bespoke project created by ThenMedia which uses our cloud infrastructure.
We use appropriate technical and organisational measures designed to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction, damage or disclosure.
No method of electronic storage or transmission can be guaranteed to be completely secure. Customers are therefore also responsible for maintaining appropriate copies and backups of data they upload where required by their own business continuity arrangements.
Hardware & software
ThenMedia Limited operates and manages virtual and physical server infrastructure located within UK data-centre facilities.
Our infrastructure incorporates resilience measures including redundant systems and backup arrangements. Physical access to data-centre facilities is monitored and controlled by the relevant data-centre operator.
The servers and software systems operated by ThenMedia are managed by authorised ThenMedia personnel. Data-centre engineers or other authorised service personnel may occasionally require controlled access to infrastructure for essential maintenance, repair or upgrades. Such access is limited to what is reasonably necessary.
Our infrastructure is protected by firewalls and access controls. Administrative access to sensitive services is restricted and monitored.
ThenMedia’s cloud systems use MariaDB for data storage and a content management system developed by ThenMedia using an NGINX/PHP architecture. The infrastructure runs on a customised Linux-based environment selected for its security, reliability and performance.
Capture & storage
Data transmitted between users and ThenMedia websites and cloud services is protected using HTTPS and current Transport Layer Security (TLS) protocols where appropriate.
Customer data is protected using access controls designed to prevent unauthorised access.
By default, access to uploaded customer data is restricted according to the permissions configured for the relevant cloud system. A cloud administrator is normally allocated as part of the customer’s account setup. The administrator may create additional users and grant appropriate permissions.
Passwords are stored using security measures designed to prevent ThenMedia staff from retrieving a user’s original password. Where necessary, authorised personnel may initiate a password reset.
Customer data is backed up for resilience and disaster-recovery purposes. Backup copies are protected by access controls and are retained in accordance with our applicable backup and retention procedures.
Access to customer systems may be logged for security and auditing purposes. Suspicious or repeated unsuccessful sign-in attempts may result in access being temporarily or permanently blocked in order to protect the relevant account and system.
For more information about how we manage and protect data, please email data@thenmedia.co.uk or telephone 01244 478727.
Payment Card Security and PCI DSS
Any organisation that stores, processes or transmits payment card data has responsibilities under the Payment Card Industry Data Security Standard (PCI DSS).
Where ThenMedia websites offer card payments, we use Stripe payment services to reduce the amount of cardholder data handled by ThenMedia systems.
When an appropriate Stripe-hosted or embedded payment integration is used, payment card details are transmitted directly to Stripe rather than being stored on ThenMedia servers.
Stripe is a PCI Level 1 Service Provider and undergoes independent assessment against the applicable PCI DSS requirements. Using Stripe significantly reduces the scope of cardholder data handled by ThenMedia, but the use of Stripe does not in itself remove all PCI DSS responsibilities from ThenMedia or its customers.
Further information about Stripe’s security and PCI compliance is available at https://stripe.com/docs/security and https://stripe.com/guides/pci-compliance.
Encryption of sensitive data and communication
Payment card information handled by Stripe is protected using Stripe’s own security infrastructure and controls. ThenMedia does not store full payment card numbers, card security codes or equivalent sensitive authentication data on its own servers when payments are processed using the intended Stripe integration.
Information exchanged between a user’s browser and ThenMedia websites is protected using HTTPS and Transport Layer Security (TLS).
TLS is the modern protocol used to protect information while it is transmitted across a network. The older Secure Sockets Layer (SSL) protocols have been superseded by TLS, although the term “SSL certificate” is still commonly used when referring to website security certificates.
TLS is designed to:
- Encrypt data transmitted between a user’s device and the relevant server.
- Protect the integrity of information while it is being transmitted.
- Help verify that a user’s browser is communicating with the intended website.
All ThenMedia websites are configured to use HTTPS/TLS, including websites which do not provide online payment facilities.
Third Party Payment Methods
Stripe may provide integrations with third-party payment methods and digital wallets, such as Apple Pay and other supported payment services.
Where ThenMedia enables these payment methods through Stripe, payment information is handled through the relevant payment provider and Stripe integration. ThenMedia does not intentionally retrieve or store full payment card details on its own servers.
The privacy and security practices of Stripe and any third-party payment provider will also apply to information processed by those organisations. Users should refer to the privacy information provided by the relevant payment provider for further details.
Changes to this policy
We may update this Privacy Policy from time to time to reflect changes to our services, technology, business practices or legal and regulatory requirements.
The latest version will be published on the ThenMedia website.
Contact us
If you have any questions about this Privacy Policy, the personal data we hold or the way in which we process personal data, please contact:
ThenMedia Limited
Charter Court
2 Well House Barns
Chester Road
Bretton
Chester
CH4 0DH
Email: data@thenmedia.co.uk
Telephone: 01244 478727
Website: www.thenmedia.co.uk
Discover more
Explore the tools, compare our packages or talk to the team.
Chrestos Cloud
Web-design, Planmaker, Loudhailer, Database and Signage, all managed from one place.
Packages & pricing
No build fee and no long contract. Pick the package that suits your church and grow from there.
Talk to us
Questions, a demo or a chat about what your circuit needs. We are happy to help.
Ready to get started?
Let’s explore how Chrestos can support your church, circuit or district.

Technology for a brighter church
