Data Processing Addendum
Effective . Version 2026-09-08. This Addendum forms part of the online Terms of Service.
1. Parties, roles, and instructions
The Customer identified through its account and acceptance of the Terms of Service is the controller of personal data it submits to its workspace, or a processor acting with its controller's authority. GovSecure AI is its processor or subprocessor. We process that customer personal data only on documented instructions to provide the service, including this agreement, account settings, and authorized support requests, unless applicable law requires otherwise. We will inform Customer of such a legal requirement unless prohibited by law, and notify Customer if an instruction appears to violate applicable data protection law.
Customer is responsible for lawful collection, required notices and permissions, its users' instructions, and the suitability of the service for the data submitted. Our independent processing of business contact, billing, and website data is described in the Privacy Policy.
2. Processing details
The subject matter is Customer's use of compliance workspaces. Processing includes collection, storage, organization, retrieval, authorized sharing, document generation, evidence integrity checks, monitoring workflows, audit logging, requested AI assistance, and return or deletion. Processing lasts for the service term and the return or deletion process below. Data subjects are Customer's authorized users, personnel, contractors, assessors, and people referenced in its content. Data includes names, professional contact information, roles, user identifiers, activity records, and personal information that Customer includes in system records, evidence, or documents.
The online service does not accept classified information, CUI requiring an authorized environment, protected health information, or other information requiring safeguards not expressly agreed in writing. Customer should minimize personal information in uploads and AI requests. This Addendum is not a FedRAMP authorization, a business associate agreement, or a representation that every regulated use is supported.
3. Confidentiality and security
We will restrict personnel access to those who need it to provide and support the service and require confidentiality obligations. We will maintain technical and organizational measures appropriate to the processing risks and applicable law. Service controls include encrypted transport, hashed passwords, tenant-scoped access, role permissions, available multifactor authentication, audit records, and evidence hashes and scan-status controls. Customer is responsible for account access, its endpoints, and reviewing invited users. No certification, exclusive hosting region, or dedicated infrastructure is implied.
4. Service providers
Customer authorizes use of InsForge for database, storage, and managed email through Amazon SES; Railway for application hosting, Cloudflare for network delivery and protection, Anthropic for requested AI processing, Inngest for enabled background workflows, and Resend when configured for transactional email. Stripe processes payment information; optional Google website analytics is consent-gated. The Privacy Policy describes their functions and the information disclosed.
We will impose data protection obligations appropriate to the processing on subprocessors and remain responsible for their performance of those obligations. We will notify the account administrator before adding or replacing a subprocessor that processes customer personal data and allow a reasonable opportunity to object on data protection grounds. Contact us promptly with an objection. If we cannot resolve it, Customer may stop using the affected feature or terminate the affected service and receive a refund for its unused prepaid portion. We do not sell customer personal data or use it for unrelated advertising.
5. Locations and international transfers
The service uses United States infrastructure and providers that may process data in other countries. This online Addendum does not itself incorporate Standard Contractual Clauses, a UK transfer addendum, or a data-localization commitment. Where a transfer requires a particular legal mechanism or location restriction, Customer must arrange the applicable safeguards with us before submitting that data. We will not treat acceptance of these terms as permission to bypass applicable transfer restrictions.
6. Personal data incidents
We will notify Customer without undue delay after becoming aware of a personal data breach affecting its data. We will provide information available about the nature of the breach, affected data and people, likely consequences, mitigation, and a contact for follow-up. Information may be supplied in stages as the investigation develops. We will take reasonable steps to contain and remediate the incident and assist Customer with its applicable reporting obligations. Notice is not an admission of liability.
7. Requests, assistance, and review
Taking account of the nature of processing and information available, we will assist Customer with individual rights requests, security obligations, breach reporting, data protection impact assessments, and required regulator consultations. We will direct requests about customer-controlled data to Customer unless law requires us to act. We will make relevant information available to demonstrate our obligations and permit reasonable audits or inspections by Customer or its independent auditor, subject to confidentiality, security, and protection of other customers' data. These arrangements do not limit a regulator's powers or mandatory audit rights.
8. Return and deletion
Export available records before service access ends. Customer may request a support-assisted return of remaining data within 30 days after your subscription ends. At the end of processing, we will, at Customer's choice, return or delete customer personal data and arrange deletion of remaining copies unless retention is required by applicable law. Send instructions to our contact below; we verify authority before disclosing or deleting data.
Cancellation does not automatically run a purge. In-app soft deletion and append-only audit records require a separate support-managed deletion process, as explained in the Privacy Policy. We will explain the scope and timing of that process and any legally required retention. Retained data remains protected under this Addendum and is used only for the retention purpose. Where immediate removal from backups is not feasible, we will restrict further use pending deletion and explain the applicable retention cycle. These operational steps do not override applicable individual rights or legal deadlines.
9. Precedence and contact
This Addendum controls over the online Terms for customer personal data processing. A separately signed data processing agreement controls where it conflicts with this Addendum. Applicable law and mandatory data protection rights remain unaffected. Contact GovSecure AI at [email protected] for instructions, incidents, objections, data requests, or transfer arrangements.