Privacy Policy
Last updated: 2026-08-21. This is a v0 operational policy for early access—not formal legal advice.
Who we are
Laterus (laterus.org) provides construction, facility, and IT operations software for Catholic institutions and related contractors.
Data we collect
- Account: email address, optional display name
- Organization data: org name/type, sites, projects, assets, work items, memberships
- Quote / demo requests: name, work email, organization, optional phone, interest area, and message submitted from the public marketing form
- Occupant work requests: name, email, chosen site, and request text submitted from
/request— stored as a facility work item so stewards can respond - Workspace Drive copies (when an organization connects Google): a copy of a quote request or occupant work request may be written to that organization's Google Workspace Drive as a Google Doc and shared with addresses the organization's admins name (Durward's Glen default:
paul.quist@durwardsglen.org). Google then emails those addresses. Refresh tokens and, when set by an org admin, the Google OAuth client id and secret are stored in Laterus D1 as versioned secrets for that organization (onboard / rotate / retire; the previous secret is kept only during rotation) — not in a browser profile. Connecting requires a@durwardsglen.orgWorkspace account. - Work attachments: images and PDFs (8MB cap) attached to work items, stored on Cloudflare (R2 when bound, otherwise D1) for the organization only
- Learning (when an organization enables the LMS): course enrolments (user id, course, student/teacher role, source), assignment/quiz submissions and scores, and gradebook entries. Completions record the fact and date of completion. We do not collect date of birth, gender, race, religion, or other protected-class attributes on enrolment. Library (template) courses never appear in a public catalog.
- Job descriptions: role text an organization publishes for a seat. Not an application file — we do not collect resumes or candidate applications through Laterus.
- Safe-environment checks: when an organization records a background, Virtus, or similar clearance we store the subject (a Laterus user, vendor, or RACI seat id), check type, issued and expiry dates, status, and optional notes. We do not store criminal-record findings, protected-class attributes, or parishioner pastoral data.
- Operator and vendor contacts: name, role, organisation, work email and phone for facilities and governance. Laterus does not store parishioner or sacramental records.
- Form submissions: the fields an organization defined on a published form. We do not store IP address or user agent on submissions.
- Public site / CMS: page copy, flyers, and testimonials the organization publishes.
- Click-through donations: the fact that someone clicked an off-site giving link (time and fundraiser id). No card data, no IP.
- Operational telemetry (IoT / HVAC): metric name, numeric value, unit, and time from devices an organization registers, plus HVAC equipment names, points, and alarm messages. Ingest uses a device token and the organization id. We do not store a network address or user agent on readings. This is building telemetry, not occupant identity.
- Technical: session cookies, basic security logs (e.g. rate limits, hashed IP for abuse control)
We do not intentionally collect sacramental records, donor data, or parishioner pastoral profiles in v0. LMS grades are operational training records, not HR files.
How we use data
To authenticate you, operate the multi-tenant application, respond to quote and demo requests, prevent abuse, and improve reliability. Marketing form submissions are used only to follow up on your request—not sold or used for third-party advertising.
Cookies
We use a single strictly necessary session cookie (laterus_session) after sign-in. No advertising or third-party analytics cookies in v0.
Processors
Infrastructure is hosted on Cloudflare. If email delivery is enabled, a transactional email provider (e.g. Resend) processes your email address to send magic links. When a tenant connects Workspace Drive, Google is a processor of the submission copy and of the OAuth tokens used to write it. The OAuth client id and secret are stored in Laterus D1 as versioned secrets for that organization (or as Pages secrets if an operator set them there). They are not stored in a browser profile and are never returned over HTTP after save.
Retention
Account and organization data is retained while the organization is active. Magic-link tokens expire within minutes. Sessions expire after inactivity/TTL.
Contact
Privacy questions: use the operator email on your account domain or contact the Laterus operator who invited you.