This Data Processing Agreement is incorporated into the Terms of Service whenever Loracta processes personal data on behalf of a customer organization. It is intended to satisfy Art. 28 GDPR for platform processing.
Subject matter and duration
Loracta processes personal data to provide, secure, support, improve, and administer the platform service selected by the customer. Processing begins when the customer creates or configures a workspace and continues for the subscription term plus any export, deletion, backup, audit, or legal-retention period.
Processing details (Annex II)
| Nature and purpose | Hosting, indexing, searching, publishing, transcription, translation, AI assistance, donation workflows, support, security, backups, and audit logging. |
|---|---|
| Data categories | Workspace user data, member/admin account data, donor records where enabled, uploaded media and documents, transcripts, translations, contributor metadata, audit logs, and support communications. |
| Data subjects | Customer staff, contributors, publication subjects, donors, event participants, public-site visitors, and other individuals represented in customer content. |
| Processing operations | Collection, storage, retrieval, indexing, access control, transformation, transmission, publication at the customer’s instruction, deletion, and export. |
Instructions
Loracta processes customer personal data only on documented instructions from the customer, including these terms, workspace configuration, support requests, and written instructions. If an instruction appears unlawful, Loracta will inform the customer unless prohibited by law.
Technical and organisational security measures (Art. 32)
- TLS 1.2+ for all data in transit between user agents, internal services, subprocessors, and the database.
- Encryption at rest for object storage (media, transcripts, derived artifacts) and database backups where the deployment supports it.
- Role-based access control with tenant isolation, least-privilege admin roles, and per-route permission checks.
- Append-only audit logging of administrative actions, with HMAC-hashed IP and user-agent fields and a configurable retention window.
- CSRF protection, hardened session cookies, brute-force throttling on authentication, and cookie-consent controls.
- Backup procedures with periodic restore rehearsal, operational monitoring, and structured request logging with truncated IPs.
- Personnel and subprocessor access limited to those who require it to operate, secure, or support the service, under written confidentiality.
Subprocessors
The current subprocessor schedule is reproduced below and kept at /subprocessors. Loracta may add or replace subprocessors where needed to provide the service, subject to appropriate data-processing terms and transfer safeguards.
Material additions or replacements are announced through the workspace inbox or another durable channel at least 14 days in advance where feasible. Customers may object on reasonable data-protection grounds.
AI — large language models (chat / assistant)
| Subprocessor | Purpose | Region | Transfer mechanism |
|---|---|---|---|
|
OpenAI, L.L.C.
Conditional: Engaged only when the platform/tenant configures OpenAI as the chat provider. |
Hosted large-language-model inference for chat/assistant flows when the operator selects OpenAI as the chat provider. | United States | EU SCCs (2021/914) + supplementary measures; data-processing addendum. |
|
Anthropic, PBC
Conditional: Engaged only when the platform/tenant configures Anthropic as the chat provider. |
Hosted large-language-model inference for chat/assistant flows when the operator selects Anthropic as the chat provider. | United States | EU SCCs (2021/914) + supplementary measures; data-processing addendum. |
AI — speech-to-text transcription
| Subprocessor | Purpose | Region | Transfer mechanism |
|---|---|---|---|
|
AssemblyAI, Inc.
Conditional: Engaged only when the tenant's `asr_data_residency` setting is `cloud_us` or `cloud_any` AND diarization is required. |
Speech-to-text transcription with speaker diarization for uploaded audio/video, when the tenant's ASR data-residency policy permits cloud processing. | United States | EU SCCs + DPA. |
|
Groq, Inc.
Conditional: Engaged only when the tenant's `asr_data_residency` setting is `cloud_us` or `cloud_any` AND diarization is not required. |
Hosted Whisper-compatible speech-to-text inference for non-diarized transcription when the tenant's ASR residency policy permits cloud processing. | United States | EU SCCs + DPA. |
Payments and donations
| Subprocessor | Purpose | Region | Transfer mechanism |
|---|---|---|---|
| Stripe Payments Europe, Ltd. | Payment processing for subscriptions, donations, and Connect-based tenant payouts. | European Union (Ireland) with US-based group entities | Intra-group SCCs; Stripe DPA. |
Transactional email delivery
| Subprocessor | Purpose | Region | Transfer mechanism |
|---|---|---|---|
| SMTP delivery provider (configured per environment) | Transactional email delivery (verification codes, password resets, magic-link rights requests, system notifications). | European Union (preferred); falls back per operator configuration | Operator selects a provider with SCCs/DPA in place. |
Object storage (media, transcripts, derived artifacts)
| Subprocessor | Purpose | Region | Transfer mechanism |
|---|---|---|---|
| S3-compatible object storage (MinIO or hosted equivalent) | Persistent storage for uploaded media (audio, video, images, PDFs), transcripts, generated TTS audio, and thumbnails. | European Union (preferred); per operator configuration | Operator selects a storage provider with SCCs/DPA in place. |
User-initiated content import
| Subprocessor | Purpose | Region | Transfer mechanism |
|---|---|---|---|
|
Google Ireland Limited (Google Drive)
Conditional: Engaged only when a user explicitly connects their Google Drive account to assist with imports. |
Assisted document import from a user-connected Google Drive account via OAuth. | European Union (Ireland) | Google Workspace DPA; SCCs for any onward US transfer. |
Error reporting and logging
| Subprocessor | Purpose | Region | Transfer mechanism |
|---|---|---|---|
| Functional Software, Inc. (Sentry) | Application error reporting, performance monitoring, and profiling. | United States | EU SCCs + DPA; Loracta configures Sentry with `send_default_pii=False` and redacts cookies, POST bodies, and sensitive headers before send. |
| Grafana Labs / self-hosted Loki | Structured application log aggregation. | European Union (preferred); per operator configuration | Self-hosted or operator-selected hosted Loki with DPA. |
Controller assistance and data-subject rights
Taking into account the nature of processing, Loracta assists customers with data-subject requests, security incidents, DPIAs, prior consultations, and regulator inquiries using platform controls, exports, logs, and written support.
Customers may use the platform export, deletion, and rectification features — and the magic-link rights flow at /account/data-request — to honour Art. 15 (access), Art. 16 (rectification), Art. 17 (erasure), Art. 18 (restriction), Art. 20 (portability), and Art. 21 (objection) requests within the statutory deadlines.
Personal data breach notification
Loracta notifies the customer without undue delay, and in any event within 72 hours after becoming aware of a personal data breach affecting customer personal data. The notification describes the nature of the breach, the categories and approximate number of data subjects and records concerned, likely consequences, and the measures taken or proposed to address it and mitigate its possible adverse effects.
Return and deletion on termination
On termination, customer data is made available for export through the workspace where technically feasible and then deleted or anonymized within the applicable deletion period, unless retention is required by law, security, dispute, accounting, or backup obligations.
Audits
Loracta provides reasonable audit information, security summaries, subprocessor records, and responses to written audit questions. On-site or third-party audits require advance notice, confidentiality, scope controls, and must not compromise other tenants or platform security.
Governing law and venue
This Data Processing Agreement is governed by the laws of the Federal Republic of Germany, excluding its conflict-of-laws rules and the UN Convention on Contracts for the International Sale of Goods. Exclusive venue for any disputes is the seat of the Loracta legal entity identified in the imprint, to the extent legally permissible.
Version history
We update this page when the underlying processing, service terms, or legal references change materially.