This Data Processing Addendum ("DPA") supplements the GovSynth Terms of Service and Privacy Policy, and governs the processing of Customer Data by GovSynth in connection with the Service.
1. Roles
- Customer is the Data Controller for Customer Data
- GovSynth acts as Data Processor for Customer Data
- GovSynth acts as Controller for account, billing, and telemetry data
2. Data Processing Scope
- Processing limited to providing and improving the Service
- No use of Customer Data for advertising
- No use of Customer Data for AI model training
3. Data Location
- Data stored and processed exclusively in Microsoft Azure Commercial US regions
- No transfer outside the United States
4. Subprocessors
- Microsoft Azure — infrastructure
- Microsoft Entra ID — identity
- Azure OpenAI — inference only, no training
5. Security Measures
- Encryption in transit (TLS 1.2+)
- Encryption at rest (Azure-managed TDE / storage encryption)
- RBAC-based access control with tenant isolation
- Logging and monitoring via centralized telemetry
6. Breach Notification
GovSynth will notify Customer without undue delay after confirming unauthorized access to Customer Data.
7. Data Retention and Deletion
- Data retained only as necessary to provide the Service
- Upon termination, Customer Data is deleted following export opportunity
8. Audit Rights
- Customer may request security documentation
- No direct system audit without mutual agreement
9. Compliance Position
- Platform supports customer compliance
- No certification guaranteed