logo

Lorica Security, Inc.

Privacy Policy

Effective Date: March 3, 2026

This Privacy Policy (“Policy”) describes how Lorica Security, Inc., a Delaware corporation (“Lorica,” “we,” or “us”), collects, uses, discloses, and protects information in connection with the Lorica platform and related services (collectively, the “Services”).

This Policy applies globally to all users of the Services, including company representatives, professionals, and visitors.

1. Relationship to Contractual Terms

This Policy should be read together with Lorica’s Terms of Service and, where applicable, the Master Services Agreement (“MSA”) entered into between Lorica and a customer entity.

For paid or managed Services, the MSA governs data rights, processing, and controls.

In the event of any conflict between this Policy and the MSA, the MSA controls.

This Policy does not create contractual obligations beyond those set forth in the MSA.

2. Information We Collect

2.1 Information Provided by Customers and Users

We collect information submitted by or on behalf of users in connection with the Services, including: account, contact, and authentication information; company profile and administrative information; professional profile data (such as licenses, certifications, training records, and related metadata); documents uploaded to the Services; and communications or support requests.

Lorica processes this information solely as directed by customers or users and in accordance with applicable agreements.

2.2 Automatically Collected Information

We may automatically collect certain technical and usage information, including: IP addresses and approximate location data; device, browser, and operating system information; access logs, timestamps, and error reports; and usage metrics and diagnostic data.

This information is used to operate, secure, and improve the Services and to generate Usage Data, as described below.

2.3 No Intentional Collection of Sensitive Data

The Services are not intended for processing sensitive personal data such as biometric identifiers, health information, or financial account numbers. Users should not submit such information unless expressly agreed in writing.

2.4 Website Visitors and Marketing Analytics

When you visit Lorica’s public-facing website (including www.loricaplatform.com) without logging into the platform, we may collect limited information for marketing, analytics, and site optimization purposes.

Such collected information may include, but is not limited to: IP address and approximate geographic region; browser and device information; page views, referral sources, and session duration; interactions with website forms or marketing materials; and cookie and tracking data as described below.

We may use third-party analytics and marketing tools to understand website performance, measure campaign effectiveness, and improve user experience. These tools may collect information through cookies, pixels, or similar technologies.

Website analytics data is used for aggregate measurement and marketing insights and is not used to alter or determine compliance, credential, or employment-related outcomes within the platform.

Users may manage cookie preferences through their browser settings. Disabling cookies may limit certain website functionality.

3. How We Use Information

Lorica uses information collected through the Services to: provide, operate, maintain, and support the Services; secure the Services and prevent fraud, abuse, or misuse; enable compliance, personnel management, vendor management, and analytics workflows; respond to inquiries and provide customer support; comply with applicable legal obligations; and generate aggregated, anonymized, or de-identified analytics.

Lorica does not use Customer Data or professional profile information for consumer advertising or to provide targeted advertising based on platform activity.

When users voluntarily provide contact information for newsletters, updates, or marketing communications, we may use that information to send informational or promotional content. Users may opt out at any time using the unsubscribe link in such communications.

4. Data Ownership and Control

4.1 Customer Data

As between Lorica and its customers, customers retain ownership and control of Customer Data, as defined in the MSA.

Lorica processes Customer Data only as necessary to provide and secure the Services and in accordance with customer instructions and applicable agreements.

4.2 Professional Profiles

Professional profile information may be visible to companies with whom the professional has a direct relationship or has authorized access, subject to platform settings and contractual permissions.

Lorica does not independently verify, certify, or guarantee the accuracy or legal sufficiency of professional information.

5. Artificial Intelligence and Machine Learning

Lorica uses automated systems, including machine learning and artificial intelligence techniques, to support and enhance platform functionality.

These systems may use Customer Data and usage information to: extract, classify, or organize credential and compliance data; improve search, analytics, risk indicators, and workflow prioritization; enhance security, anomaly detection, and platform performance; and train and refine internal models used solely to operate and improve the Services.

Lorica does not use Customer Data to train general-purpose models offered to third parties, and does not design models to recreate, infer, or disclose identifiable individual records.

Use of Customer Data for model training is limited to improving and operating the Services and is subject to the contractual controls set forth in the MSA.

Automated tools support administrative and informational workflows and do not replace customer judgment or make final legal, employment, licensing, or regulatory determinations.

6. Aggregated and Anonymized Data

Lorica may create and use aggregated, anonymized, or de-identified data derived from the Services (“Aggregated Data,” which constitutes Usage Data as defined in the MSA where applicable).

Aggregated Data: does not identify, and cannot reasonably be used to identify, any individual or customer; is combined across users, companies, or datasets; and is subject to reasonable technical and organizational safeguards to prevent re-identification.

Lorica may use Aggregated Data for internal purposes such as analytics, benchmarking, research, security, and product development, and may license or share Aggregated Data with third parties, including insurers, underwriters, researchers, or analytics partners, for independent analytical or commercial purposes. Aggregated Data does not include identifiable Customer Data or Professional Data.

Lorica does not attempt to re-identify Aggregated Data and contractually restricts recipients from doing so.

7. Data Sharing and Disclosure

Lorica may disclose information: to service providers and subprocessors who support the operation of the Services under confidentiality and data-protection obligations; as directed or authorized by customers or users; to comply with law, regulation, or legal process; or to protect the rights, security, or integrity of Lorica, users, or the Services.

Lorica does not sell personal information as that term is commonly defined under applicable privacy laws.

For clarity, Aggregated Data is not personal information and may be shared or sold as described above.

8. Data Security

Lorica maintains administrative, technical, and physical safeguards designed to protect information against unauthorized access, disclosure, or misuse.

These safeguards are aligned with industry-standard practices for software-as-a-service (SaaS) providers and the Trust Services Criteria applicable to SOC 2 (Security, Availability, and Confidentiality).

Data security is subject to a shared responsibility model. Lorica is responsible for securing the infrastructure, application environment, and systems under its control. Customers and users are responsible for managing user access, protecting credentials, configuring permissions appropriately, and ensuring that data submitted to the Services complies with applicable laws and internal policies.

9. Data Retention and Deletion

Lorica retains information only for as long as necessary to provide the Services, comply with legal obligations, and support legitimate business purposes.

Upon termination or expiration of applicable services: Customer Data is deleted or anonymized in accordance with the MSA and Lorica’s standard retention practices, subject to legal or archival requirements. Inactive or dormant accounts may be deactivated or removed.

10. International Use

The Services are operated from the United States. Information collected through the Services may be processed and stored in the United States or other jurisdictions where Lorica or its service providers operate.

By using the Services, you acknowledge that information may be transferred and processed outside your country of residence, subject to applicable legal safeguards.

11. Individual Rights

Lorica responds to privacy requests in accordance with applicable law and contractual obligations.

For Customer Data processed on behalf of a customer, requests to access, correct, or delete information should be directed to the relevant customer, as Lorica acts as a service provider with respect to such data.

12. No Children’s Use

The Services are intended for professional and commercial use only and are not directed to children. Lorica does not knowingly collect personal information from individuals under the age of 18.

13. Changes to This Policy

Lorica may update this Policy from time to time. Changes will be effective upon posting. Continued use of the Services constitutes acknowledgment of the updated Policy.

14. Contact

Questions or requests regarding this Privacy Policy may be directed to: info@loricaplatform.com