Draft for counsel review — not yet in force. This page publishes the working draft of our DPA so your privacy office can evaluate it. The executed DPA accompanies your ordering document; request it at [email protected] or via the contact page.
The agency (or contractor entity) that subscribes to the service is the controller and owner of the data it submits. [LEGAL ENTITY] ("GovSecure AI") acts as a processor / service provider, processing that data only to provide the service described in the Terms of Service and per the agency's documented instructions, including the configuration choices the agency makes in the platform.
Processing consists of: storing and organizing systems, control implementations, evidence, and POA&M data; hashing, versioning, and malware-scanning uploaded evidence and recording it in an append-only ledger; generating OSCAL documents; running scheduled monitoring jobs; AI-assisted drafting via the sub-processor listed below; billing and entitlement enforcement; and audit logging. Processing continues for the subscription term plus the retention period in Section 8.
Data subjects are the agency's users and personnel referenced in compliance content. Data categories: account data (name, email, role, sign-in and MFA status), compliance content the agency submits, audit records (actor, IP address, user agent, action), and billing records. The platform is not approved for classified information, and the agency agrees not to submit it.
GovSecure AI limits access to agency data to personnel who need it to operate and support the service, bound by confidentiality obligations. Administrative access is logged in the same append-only audit log as tenant activity.
Current sub-processors: InsForge (managed Postgres hosting, object storage for evidence files, payments integration), Stripe (payment processing), Anthropic (AI model provider, engaged only when the agency uses AI features), and Inngest (background job orchestration). Consent-gated website analytics (Google) applies to the marketing site, not to agency compliance content. GovSecure AI gives advance notice of material sub-processor changes and imposes data-protection obligations on sub-processors consistent with this Addendum.
Production data is hosted in [DATA HOSTING REGION(S) — counsel to confirm with infrastructure provider]. GovSecure AI does not transfer agency data outside those regions except through the sub-processors listed above as needed to provide the service.
GovSecure AI notifies the agency of a confirmed security incident affecting its data without undue delay, and in any event within [BREACH NOTIFICATION WINDOW], including the nature of the incident, the data affected, and remediation steps, with updates as the investigation proceeds — sufficient to support the agency's own incident-response and reporting obligations.
GovSecure AI assists the agency in responding to data-subject and oversight requests to the extent the platform holds the relevant data. The append-only audit log and evidence ledger provide the processing records for the agency's tenancy; extracts are available on request.
On termination, the agency may export its data, including generated OSCAL documents and uploaded evidence, for [DATA EXPORT WINDOW]. Thereafter GovSecure AI deletes agency data per the retention terms of the ordering document. Deletion in the platform is soft deletion (records marked deleted and excluded from use); the audit log and evidence ledger are append-only by design, and their disposition at termination is addressed in the ordering document.
The executed DPA and ordering document control over this published draft. Contact: [LEGAL ENTITY], [ADDRESS], [email protected].