Legal
Data Processing Addendum
Last updated: September 8, 2026
Controller and processor terms for customer personal data handled through Cemstree.
Status: Founder-approved draft — not attorney reviewed.
Roles and instructions
Customer organizations ordinarily control ministry records submitted to Cemstree. Mad Tech Solutions LLC, a Michigan limited liability company operating Cemstree, ordinarily processes that data to provide, secure, maintain, support, and improve the contracted service; follow documented customer instructions; prevent abuse; comply with law; and exercise or defend legal rights.
Each party may independently control account, billing, security, legal-compliance, and business-administration information it determines to process.
Customer responsibilities
Customers are responsible for lawful collection, accuracy, minimization, required notices and consent, user permissions, safeguarding, communications consent, donor and payment obligations, and lawful processing instructions. Cemstree must not be used for protected health information subject to HIPAA unless a separate signed agreement expressly authorizes it.
Confidentiality and security
Cemstree restricts access to authorized service, support, security, legal, and operational purposes and uses the safeguards described in the Security Addendum. No control description guarantees that an incident cannot occur.
Security incidents
Cemstree will notify the customer without undue delay after confirming a breach of Customer Personal Data for which notice is legally or contractually required. The operating target is no later than 72 hours after confirmation, subject to law-enforcement restrictions and the time needed to validate scope and avoid materially inaccurate notice.
Subprocessors
Customers generally authorize the providers on the current Subprocessor List. When practical, Cemstree targets 14 calendar days of notice before a new material subprocessor begins processing Customer Personal Data.
Rights requests and deletion
Cemstree will reasonably assist with verified access, correction, deletion, restriction, and export requests when the customer cannot fulfill them through product tools. No customer data is automatically destroyed merely because an account becomes deletion-eligible; a separately authorized, audited confirmation and verified export opportunity are required.
Processing details
The service processes church, ministry, nonprofit, and organizational records during the subscription term and approved retention periods. People may include personnel, members, visitors, volunteers, minors, guardians, donors, attendees, communication recipients, and public-page users. Cemstree is offered to United States customers at launch unless a signed agreement states otherwise.
Contact
Privacy, legal, accessibility, billing, and support requests may be sent to support@cemstree.com. Security vulnerabilities, suspected unauthorized access, and abuse reports should be sent to security@cemstree.com.
