Data Processing Addendum

This Data Processing Addendum (“DPA”) is an addendum to the Professional Services Agreement (“Agreement”) entered into between Company and Institution, as those terms are defined in the Agreement. Any capitalized terms used but not defined in this DPA shall have the meaning given them in the Agreement.

Whereas, Company (i) provides Services to Institution pursuant to the Agreement; and (ii) may be required to Process, on behalf of Institution, Personal Information in connection with the Services;

Now therefore, in consideration of the mutual covenants and agreements in this DPA and the Agreement, and for other good and valuable consideration, the sufficiency of which is hereby acknowledged, Institution and Company agree as follows:

I. Definitions

  • “Account Data” means information provided to Company to establish, administer, or maintain an account for accessing the Services, including administrator contact information, billing details, and authentication credentials.
  • “Aggregate” means, unless defined under applicable Privacy Laws, to gather and express raw data in a summary form for statistical analysis.
  • “De-identify” means, unless defined under applicable Privacy Laws, to remove any personally identifiable information and other similar attributes from the data so that no individual identification can reasonably be made.
  • “Feedback” means any suggestions, comments, feature requests, enhancement ideas, or other feedback provided by Institution regarding the Services.
  • “Personal Information” means information that identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular individual or household, that may be Processed by Company in connection with the performance of the Agreement. For the avoidance of doubt, Personal Information does not include De-identified data, Aggregated data, Usage Data, Account Data, or Feedback.
  • “Privacy Laws” means laws that regulate the processing, privacy, or security of Personal Information and that are directly applicable to each Party to this DPA in the context of Company Processing Personal Information.
  • “Process” (and its derivatives) means any operation or set of operations performed, whether or not by automated means, on Personal Information, such as the collection, use, storage, disclosure, analysis, deletion, or modification of Personal Information.
  • “Usage Data” means technical and operational data generated through the use of the Services, including system logs, performance metrics, feature usage statistics, session data, error reports, and similar telemetry data that relates to the operation, support, or improvement of the Services.
  • The terms “Business,” “Business Purpose,” “Controller,” “Processor,” “Sell”, “Share” and “Service Provider” shall have the meanings ascribed to them in applicable Privacy Laws.

II. Roles and Responsibilities of the Parties

  • Company’s Obligations and Authority when acting as a Service Provider or Processor to Process Personal Information:
    1. Except as provided in Section II(A)(8) below, Company acts as a Service Provider or Processor with respect to Personal Information Processed in connection with the Services. The Institution shall be the Controller of such Personal Information. Notwithstanding the foregoing, if Company enters into a separate agreement with a diocese, district, group, or other oversight entity associated with Institution covering the same Services (such entity, the “Supervising Controller”), the data processing terms of that separate agreement shall govern with respect to Personal Information associated with those Services, and the corresponding provisions of this DPA shall be deemed superseded to the extent of any conflict. Upon such supersession, Company will Process Personal Information in accordance with the instructions of the Supervising Controller, and Company shall have no obligation to act upon or reconcile any conflicting instructions from Institution unless directed to do so by the Supervising Controller. Institution acknowledges that Company may enter into such an agreement with a Supervising Controller at any time. Institution agrees that Company shall have no liability to Institution arising from its good faith compliance with the instructions of a Supervising Controller. Any notice required or permitted under this DPA with respect to Services subject to a Supervising Controller’s agreement may be delivered to the Supervising Controller, and such delivery shall constitute valid notice to Institution.
    2. Company, with respect to Personal Information and, subject to applicable Privacy Laws, will Process Personal Information in accordance with Institution’s instructions and Annex 1 of this DPA.
    3. Except as described in Section II(A)(6)-(7) below, Company will not (i) Sell or Share Personal Information; (ii) retain, use or disclose Personal Information (a) for any purpose other than for the limited Business Purposes specified in the Agreement and Annex 1 of this DPA, or (b) outside of the direct business relationship between Institution and Company; or (iii) combine Personal Information received pursuant to the Agreement with Personal Information received from or on behalf of another person(s), or collected from Company’s own interaction with individuals, unless permitted by applicable Privacy Laws. Company certifies that it understands and will comply with the requirements and restrictions set forth in this Section II(A)(2). For purposes of clarity, this Section II(A)(2) shall not apply to De-identified or Aggregated data created in accordance with applicable Privacy Laws.
    4. Company shall comply with relevant obligations as a Service Provider and Processor under applicable Privacy Laws and provide the level of privacy protection for Personal Information as is required by applicable Privacy Laws.
    5. To the extent required by applicable Privacy Laws, Company will:
      • notify Institution if Company makes a determination that it can no longer meet its obligations under this DPA or applicable Privacy Laws;
      • taking into account the nature of the Processing of Personal Information, reasonably assist Institution in fulfilling Institution’s obligations to respond to rights requests received from individuals pursuant to Privacy Laws;
      • maintain reasonable and appropriate safeguards and other security measures appropriate to the risk of Processing designed to protect the security, integrity, and confidentiality of Personal Information from unauthorized access, destruction, acquisition, use, modification, or disclosure;
      • notify Institution without undue delay upon becoming aware of unauthorized access to, or acquisition, use, modification or disclosure of, Personal Information in Company’s possession that compromises the security, confidentiality or integrity of such Personal Information. Company shall provide such information as is required to enable Institution to satisfy Institution’s obligations under applicable law;
      • upon Institution’s reasonable request, make available information in its possession necessary to demonstrate Company’s compliance with its obligations under this DPA, provided Company shall have no obligation to provide commercially confidential information;
      • at no cost to Company, allow for and cooperate with reasonable assessments by Institution (or Institution’s designee), or alternatively arrange for such assessment by a qualified independent assessor of Company’s choosing, of Company’s policies and technical and organizational measures in support of relevant obligations under applicable Privacy Laws. Company shall provide a report of such assessment to Institution upon request;
      • ensure that any Company personnel who Process Personal Information in the context of the Services are subject to a duty of confidentiality with respect to the Personal Information.
      • where Company provides a third party with access to Personal Information or contracts any of its rights or obligations concerning Personal Information to any other person (“Sub-Processor”), Company will (i) to the extent required by applicable Privacy Law, notify Institution of such engagement and, give Institution an opportunity to object before Personal Information is provided to the Sub-Processor; and (ii) enter into a written agreement with each such Sub-Processor that imposes obligations on the Sub-Processor that are similar in all material respects to those imposed on Company under Section II(A) of this DPA; and
      • at Institution’s direction, delete or return Personal Information at the end of the provision of the Services, unless retention of the Personal Information is required by applicable law or Institution affirmatively requests a different time period.
    6. To the extent permitted by applicable Privacy Laws, Company may retain, use, or disclose Personal Information obtained in the course of providing the Services: (i) to retain and employ another Service Provider as a Sub-Processor, where the Sub-Processor meets the requirements for a Service Provider under applicable Privacy Laws; (ii) for internal use by Company to build or improve the quality and functionality of its services, provided that the use does not include building or modifying household or consumer profiles to use in providing services to another business, or correcting or augmenting data acquired from another source; (iii) to detect data security incidents, or protect against fraudulent or illegal activity; (iv) to comply with federal, state, or local laws; (v) to comply with a civil, criminal, or regulatory inquiry, investigation, subpoena, or summons by federal, state, or local authorities; (vi) to cooperate with law enforcement agencies concerning conduct or activity that Company reasonably and in good faith believes may violate federal, state, or local law; or (vii) to exercise or defend legal claims.
    7. Notwithstanding any provision to the contrary, Institution agrees that Company may create, use, and disclose De-identified or Aggregated data derived from Personal Information Processed in connection with the Services for its own business purposes, including research, analytics, and improvement of its services, provided such data cannot reasonably be used to identify any individual. Company shall own all rights in such De-identified or Aggregated data and shall maintain it in a manner consistent with applicable Privacy Laws. Company agrees not to attempt to re-identify such data unless permitted or required by applicable law.
    8. Notwithstanding Section II(A)(1) above, Company acts as Controller with respect to Usage Data, Account Data, and Feedback. Company may collect, use, and disclose Usage Data, Account Data, and Feedback for its legitimate business purposes, including: (a) operating, maintaining, and improving the Services; (b) developing new products, features, and services; (c) generating benchmarking, analytics, and industry insights (provided such outputs do not identify Institution or any individual); (d) providing technical support and communicating with Institution; and (e) ensuring security and preventing fraud.
  • Institution represents and warrants that Institution has complied in all material respects with applicable Privacy Laws in relation to all Personal Information disclosed or otherwise made available to Company, including without limitation (i) ensuring the accuracy, quality and legality of the Personal Information; and (ii) providing any notices and obtaining any consents necessary to enable Company to Process Personal Information in accordance with the Agreement and this DPA.
  • Institution acknowledges and agrees that, unless otherwise expressly agreed to in writing by the Parties, the Services are not directed to children below the applicable age threshold for valid consent under Privacy Laws and are not designed to collect or solicit Personal Information directly from such children. While the Services may receive or Process Personal Information about such children, Institution acknowledges that such information is intended to be provided by adults acting on behalf of the child, such as parents, guardians, or authorized Institution personnel. Accordingly, Institution agrees that it shall be solely responsible for complying with its obligations under applicable Privacy Laws relating to children’s data (such as the federal Children’s Online Privacy Protection Act of 1998, 15 U.S.C. §§ 6501-6506, and its implementing regulations, 16 C.F.R. Part 312 (“COPPA”)), including but not limited to providing required notices and obtaining any required parental consent in Institution’s capacity as agent for parents. Company shall not be responsible for obtaining such consent unless the Parties have expressly agreed in writing that the Services are intended for direct use by children subject to those laws.
  • If COPPA applies to Personal Information Processed by Company as part of its provision of the Services to Institution:
    1. Company will process Personal Information only for educational purposes;
    2. Institution represents and warrants that it has reviewed (i) Company’s direct notice of its collection, use and disclosure practices with respect to Personal Information collected online from children under age 13 (“COPPA Direct Notice”), available at https://factsmgt.com/childrens-online-privacy-protection/; and (ii) Company’s Privacy Policy, available at https://factsmgt.com/privacy-policy/. Institution covenants that it will make available Company’s COPPA Direct Notice and Company’s Privacy Policy to parents of children under 13 from whom Company collects Personal Information pursuant to the Services (hereinafter, “Participating Parents”).
    3. Institution acts as an agent on behalf of all Participating Parents to authorize the collection, use and disclosure of Personal Information collected online from children under age 13.
    4. Any Personal Information collected by Company pursuant to the Services is under the direct control of Institution with regard to Company’s use and maintenance of the Personal Information.
  • Institution further acknowledges and agrees that, by and through its designated representative signing this DPA, that it has authority to authorize the collection of Personal Information. Institution shall ensure that the instructions Institution provides to Company in relation to the Processing of Personal Information do not (i) violate Privacy Laws or any other applicable laws; or (ii) put Company in breach of its obligations under applicable law.
  • If applicable, pursuant to the Family Educational Rights and Privacy Act of 1974, 20 U.S.C. § 1232g, and its implementing regulations, 34 C.F.R. Part 99 (“FERPA”), if Company will have access to education records, as such term is used under FERPA, Institution hereby designates Company as a “school official” with a “legitimate educational interest” that performs an institutional service or function for which Institution would otherwise use employees. Institution further warrants that it owns the Personal Information within the education records that is subject to FERPA and Company will use and disclose such information only in accordance with the terms of the Agreement and this DPA for the purpose and benefit of the Institution.
  • To the extent permitted by applicable Privacy Laws, Institution may (i) take reasonable and appropriate steps to ensure that Company uses Personal Information in a manner consistent with Institution’s obligations under applicable Privacy Laws; and (ii) upon notice, take reasonable and appropriate steps to stop and remediate unauthorized use of Personal Information.

III. DATA INSIGHTS PRODUCT TERMS

  • Data Insights Overview. Company may make available to Institution a data analytics product (“Data Insights”) that Aggregates and De-identifies data from educational institutions within Institution’s administrative purview. Data Insights outputs consist solely of Aggregated, De-identified information derived from such source data and do not contain Personal Information.
  • Permitted Uses. Institution may use Data Insights outputs solely for: (a) internal school trend analysis and operational benchmarking; and (b) reporting to the National Catholic Educational Association or successor accreditation bodies (collectively, “Permitted Purposes”). Any use beyond the Permitted Purposes requires Company’s prior written consent.
  • Prohibition on Reidentification. Institution shall not, and shall not permit any third party to: (a) attempt to reidentify, directly or indirectly, any individual from Data Insights outputs; (b) link, combine, or correlate Data Insights outputs with any other dataset, information source, or publicly available information for the purpose of identifying any individual; or (c) use Data Insights outputs as a basis for any decision affecting an identifiable individual.
  • Disclosure Restrictions. Institution shall not disclose Data Insights outputs to any third party except to authorized personnel, contractors, or regulatory bodies who (a) have a legitimate need to access such outputs for the Permitted Purposes, and (b) are bound by written obligations at least as protective as those set forth herein, including the prohibitions on reidentification and use limitations. Institution remains responsible for any breach by its authorized recipients and shall ensure equivalent flow-down restrictions apply to any further downstream disclosure.
  • Security Controls. Notwithstanding the deidentified nature of Data Insights outputs, Institution shall implement and maintain administrative, technical, and physical safeguards appropriate for high-sensitivity analytics data, including access controls, encryption in transit and at rest, audit logging, and periodic access reviews. Institution shall treat Data Insights outputs with the same degree of care as Confidential Information under this Agreement.

ANNEX 1: SCOPE OF THE PERSONAL INFORMATION PROCESSING

This Annex 1 forms part of the DPA between Institution and Company.

Nature and duration of the Processing of Personal Information

Company Processes Personal Information on behalf of Institution for the purpose of providing the Services.

The duration of the Processing will not exceed a commercially reasonable time period following Institution’s instruction to delete or return the Personal Information upon termination of the Agreement, unless continued retention or other Processing is required by applicable law.

The Processing concerns the following categories of Personal Information:

The categories of Personal Information that may be Processed in connection with the Services include, depending on the applicable Service and the Personal Information made available by Institution, parents/guardians or students in connection with the Services:

  • Personal Identifiers, such as: name, mailing address, telephone number, email address, and government-issued identifiers (if applicable).
  • Internet or Other Electronic Network Activity Information, such as information collected via cookies, web beacons, and similar automated technologies, including: IP address, device identifiers, browser and device characteristics, geolocation data (to the extent derived from device settings or usage), referring URLs and clickstream data, dates and times of website visits.
  • User-Provided Information: Any other information inputted into the Services or otherwise made available to the Company by the Institution or parents/guardians in connection with the Services, which may include user-generated content, account preferences, personal characteristics, or educational records (as applicable).

The Processing concerns the following categories of Sensitive Data:

Sensitive Data means Personal Information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic data, biometric data, government-issued identifiers, financial account information, precise geolocation data, data concerning health, sex life or sexual orientation.

The categories of Sensitive Data that may be Processed in connection with the Services include, depending on the applicable Service and the Sensitive Data made available by Institution, parents/guardians or students in connection with the Services:

  • Personal characteristics such as: birthdate, age, gender, and religious affiliation.
  • Photographic Information: Including photos and any other visual imagery submitted by or on behalf of users.
  • Health-Related Information: Including any medical or health-related details provided in connection with use of the Services.

Company Processes Personal Information for the following Business Purposes, in accordance with the Agreement:

  1. Helping to ensure security and integrity, to the extent the use of Personal Information is reasonably necessary and proportionate for these purposes.
  2. Debugging to identify and repair errors that impair existing intended functionality.
  3. Performing Services on behalf of Institution, including maintaining or servicing accounts, providing customer service, processing or fulfilling orders and transactions, verifying customer information, processing payments, providing financing, providing analytic services, providing storage, or providing similar services on behalf of Institution.
  4. Undertaking internal research for technological development and demonstration.
  5. Undertaking activities to verify or maintain the quality or safety of a service or device that is owned, manufactured, manufactured for, or controlled by Institution, and to improve, upgrade, or enhance the service or device that is owned, manufactured, manufactured for, or controlled by Institution.

© 2026 FACTS, All rights reserved.