Data Processing Addendum
Last updated: September 10, 2026
This Data Processing Addendum (the “DPA”) describes how MortonApps, LLC processes personal data on your behalf when you engage Morton Growth, the done-for-you website and managed SEO / AI-search optimization service described in our Terms of Service. It supplements and forms part of your signed Services Agreement, and should be read alongside our Privacy Policy. It is written to be read, plainly, and without surprises.
If anything in this DPA conflicts with your signed Services Agreement, the Services Agreement controls. This page is a plain-English addendum, not a substitute for it.
1. Roles of the Parties
For the personal data collected and processed through the website we build and operate for you, your business is the data controller (the “business” under the CCPA/CPRA) and MortonApps LLC is the data processor (the “service provider” under the CCPA/CPRA). Your business decides what your website offers, what it asks visitors for, and how leads should be handled. We process personal data only on your documented instructions, which are the instructions set out in your signed Services Agreement, this DPA, our Terms of Service, and the configuration choices you make for your site. If we believe an instruction would violate applicable law, we will tell you.
2. Categories of Personal Data and Data Subjects
The personal data we process on your behalf depends on how your website is set up, but generally includes:
- Lead and inquiry data: the name, email address, phone number, and message content someone submits through your website’s contact form, booking widget, or click-to-call links, along with the service or page they were interested in.
- Technical data collected with an inquiry: IP address, timestamp, and the page that referred the visitor to your site.
- Published contact details: any name, phone number, email address, or other contact information your business chooses to publish on the site itself.
- Your staff account details: the name, email address, and login credentials of the people at your business we set up with access to reporting or admin tools.
- Website analytics: aggregate visit data such as pages viewed, device and browser type, approximate location, and referring source, collected through standard analytics tools.
The data subjects are the members of the public who visit your website and the prospective customers who contact your business through it, along with your own staff who use any admin or reporting tools we provide.
3. Purpose and Duration of Processing
We process this personal data to build and operate your website, capture inquiries and forward them to you as they arrive, provide reporting on how the site is performing, and carry out the managed SEO and AI-search optimization work described in your Services Agreement. We do not use it for any other purpose. Processing continues for as long as your engagement runs, and for the wind-down period described in Section 11.
4. CCPA and CPRA Service Provider Terms
Where the personal data we process for you relates to California residents, MortonApps LLC acts as a service provider to your business under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA). As a service provider, we commit that we:
- Do not sell or share personal data.
- Do not retain, use, or disclose personal data for any purpose other than performing the services set out in your Services Agreement and this DPA, except as the CCPA/CPRA otherwise permits.
- Do not use personal data outside the direct business relationship between us and you.
- Do not combine personal data we process on your behalf with personal data we receive from or on behalf of another source, except where the CCPA/CPRA permits it, such as to detect security incidents or to operate shared infrastructure that other clients also rely on.
- Will notify you if we determine we can no longer meet these obligations.
You may take reasonable steps to stop and remediate any unauthorized use of personal data by us under this section.
5. Confidentiality of Personnel
Anyone we allow to access personal data under this DPA is bound by a duty of confidentiality, whether through an employment agreement, a contractor agreement, or a professional obligation, and understands that lead and website data is to be used only to do the work described in your Services Agreement.
6. Security Measures
Our security practices are described in full on our Security page, and we point to it here rather than repeat it. In short: all traffic to and from your website is encrypted in transit over HTTPS, access to your website’s admin tools, lead data, and hosting configuration is limited to the people who need it to build, operate, or support your site, and your site runs on Cloudflare’s network rather than on a server we manage ourselves.
7. Sub-processors
We rely on a small number of infrastructure providers to deliver the service:
- Cloudflare: hosts your website and provides content delivery, DNS, and edge security through Cloudflare Pages.
- Google: where you ask us to connect Google Search Console or Google Analytics to your site, Google processes the resulting data at your direction.
- Amazon Web Services (Amazon SES): delivers email so we can forward lead notifications from your website’s forms to you as they arrive.
If we add or replace a sub-processor that will process your personal data, we will tell you before it begins processing, and you may object on reasonable grounds.
8. International Transfers
Morton Growth is operated from the United States, and our sub-processors are US-based. If your website collects personal data from people in the European Union or United Kingdom, standard contractual clauses will apply to that transfer. Tell us if this applies to your business so we can put the right paperwork in place.
9. Assistance with Data Subject Requests
If someone asks you to access, correct, or delete their personal data, we will help you locate and act on it within your website’s lead data, contact forms, and analytics. If someone contacts us directly about data collected through your website, we will forward the request to you and let them know we have done so.
10. Personal Data Breach Notification
If we become aware of a personal data breach affecting data we process on your behalf, we will notify you without undue delay after becoming aware of it, describing what we know at the time: the nature of the incident, the data involved, and what we are doing about it.
11. Deletion and Return of Data at the End of the Engagement
You keep your domain throughout the engagement and after it ends. If your engagement includes a lead guarantee, your website stays live for 90 days after you exit under that guarantee. Lead data collected during that period, and everything collected before it, belongs to you, and we will provide it to you. Once the engagement fully ends, we will delete the personal data we hold on your behalf within a reasonable period, except where we need to retain something to comply with the law.
12. Audits
On reasonable request, we will provide you with information reasonably necessary to confirm we are meeting our obligations under this DPA, in a way that does not disrupt the service we provide to you or to our other clients.
13. Order of Precedence
If there is a conflict between these documents regarding the processing of personal data, your signed Services Agreement controls, then this DPA, then our Terms of Service.
14. Contact
Questions about this DPA: [email protected].
See also our Privacy Policy, Terms of Service, and Security page.