Legal

Data Processing Addendum

This Data Processing Addendum governs Loreto Media LLC’s processing of Customer Data in Loreto Sites. It forms part of the Terms of Service when Loreto processes personal information for a Customer.

Last updated: August 12, 2026

1. Scope and roles

This Addendum applies when Loreto Media LLC (“Loreto”) processes personal information for a Customer in connection with Loreto Sites. The Customer is the business, nonprofit, school, parish, ministry, or other organization that decides why and how that information is processed. Loreto is the Customer’s processor or service provider.

Loreto is a separate business or controller for its own account, billing, security, fraud prevention, support, and legal records. The Privacy Policy governs those activities.

“Customer Data” means personal information that Customer or a visitor submits to the Services, or that Customer asks Loreto to store, import, publish, analyze, or process for Customer. “Applicable Privacy Law” means a privacy or data-protection law that applies to Customer Data or the parties’ processing.

2. Instructions and service purpose

Loreto will process Customer Data only to provide, secure, support, maintain, and improve the Services that Customer requests, as described in the Terms, this Addendum, Customer’s account settings, written instructions, or a written order.

The Services may include hosting Customer Sites; storing pages, assets, documents, schedules, and forms; routing form submissions; sending requested email; scanning public sources; preparing drafts; answering support requests; providing analytics; managing access; preventing abuse; and meeting legal duties.

Loreto will tell Customer if it reasonably believes an instruction violates Applicable Privacy Law. Customer is responsible for the lawfulness of the instruction, the notice given to people, the permissions obtained, and the accuracy of Customer Data.

3. Data and people

Customer Data may include names, contact details, account details, public staff or school details, form responses, free-text messages, schedules, images, documents, source website material, device and request data, and other fields that Customer chooses to send.

The people may include Customer users, employees, volunteers, parishioners, donors, families, visitors, students, parents, event attendees, and people who contact a Customer through a Customer Site.

Customer must not send passwords, full payment-card numbers, health records, student records, government identification numbers, confession records, or other sensitive information unless Customer has a lawful purpose, the required authority and notices, suitable safeguards, and a written Loreto agreement that permits it.

4. Loreto duties

Loreto will keep Customer Data confidential, use it only for the permitted purposes, and ensure that people who may access it are bound to confidentiality. Loreto will use reasonable administrative, technical, and organizational safeguards designed to protect Customer Data from unauthorized access, loss, alteration, or disclosure.

Loreto will not sell Customer Data, use it for cross-context behavioral advertising, or use it to train a general-purpose model. Loreto may create aggregate statistics that do not identify Customer or a person.

Loreto will notify Customer at support@loretosites.com without undue delay after confirming a security incident that materially affects Customer Data, to the extent law allows. Loreto will give information reasonably available to help Customer meet a legal notice duty.

5. Customer duties

Customer must give a clear privacy notice at or before collection, identify Customer as the party receiving Customer Site form data, link to Customer’s privacy policy, collect only needed information, maintain lawful instructions, and answer requests from the people whose information it controls.

Customer must limit user access, choose appropriate recipients, review imported and automated content, keep its account secure, and promptly tell Loreto about a request, complaint, correction, deletion, or security concern that requires Loreto’s help.

School Customers must maintain the direct control, use limits, parent and student notices, access rules, and redisclosure limits required for their school data. Customer remains responsible for FERPA, COPPA, state student privacy laws, and any education or child-safety rule that applies to its activities.

6. Rights requests and assistance

Loreto will provide reasonable help, taking into account the Services, for Customer to respond to a verified request to access, correct, delete, export, restrict, or otherwise exercise a right under Applicable Privacy Law. Customer must send the request to support@loretosites.com with the account, site, and data needed to find it.

Loreto may direct a person to the Customer when Customer controls the purpose of the processing. Loreto will not answer a Customer’s rights request based only on an unverified instruction from a person who lacks authority.

7. Subprocessors

Customer gives Loreto general authorization to use the named providers on the Subprocessors page. Loreto remains responsible for its subprocessors’ processing under this Addendum. Loreto will require each subprocessor to protect Customer Data under written terms appropriate to its service.

Loreto will update the Subprocessors page when it adds or replaces a material provider. A Customer may object in writing on reasonable data-protection grounds within fifteen days after notice. Loreto may offer a suitable alternative, stop the affected feature, or end the affected Services if the parties cannot resolve the objection.

8. Automated features

When Customer requests scanning, extraction, drafting, classification, review, support, or another automated feature, Loreto may send the minimum needed Customer Data to the provider named on the Subprocessors page. Loreto will not use that Customer Data to train a general-purpose model.

Customer must decide whether an automated feature is suitable for its data and must review the result. Loreto does not make an automated result a record of fact, a legal decision, a school decision, or a pastoral decision.

9. Return, deletion, and retention

During the relationship, Customer may export available site data through the Services or request help from support. When the Services end, Loreto will delete or return Customer Data according to Customer’s written instruction, the Terms, the plan, and the normal deletion cycles of backups and systems.

Loreto may keep Customer Data when needed for security, fraud prevention, legal obligations, billing, audit, dispute resolution, or a legal hold. The retained information remains protected and will be deleted when the reason for retention ends.

10. Audit information

On reasonable written request, Loreto will provide information about its security and processing practices that is reasonably needed to show compliance with this Addendum. Customer may not use an audit to access another Customer’s data, source code, credentials, or confidential information, or to disrupt the Services. The parties will agree on scope, timing, cost, and confidentiality before an on-site audit.

11. International processing

Loreto and its providers may process Customer Data in the United States and other locations where they operate. Customer is responsible for giving transfer notices and obtaining permissions required for its use of the Services. If Applicable Privacy Law requires a separate transfer or regional addendum, the parties will use the applicable written terms for that processing.

12. Term, precedence, and contact

This Addendum starts when Customer accepts the Terms and uses a feature covered by this Addendum. It ends when Loreto stops processing Customer Data for Customer, subject to the retention section. If this Addendum conflicts with the Terms about Customer Data, this Addendum controls.

Effective date: August 12, 2026. DPA version: 2026-08-12.

Send data-protection notices to support@loretosites.com or Loreto Media LLC, 501 S Midvale Blvd, Madison, WI 53711.

Related policies