Skip to content

Data Processing Addendum

Last updated: May 2026

This Data Processing Addendum ("DPA") supplements the GovSynth Terms of Service and Privacy Policy, and governs the processing of Customer Data by GovSynth in connection with the Service.

1. Roles

  • Customer is the Data Controller for Customer Data
  • GovSynth acts as Data Processor for Customer Data
  • GovSynth acts as Controller for account, billing, and telemetry data

2. Data Processing Scope

  • Processing limited to providing and improving the Service
  • No use of Customer Data for advertising
  • No use of Customer Data for AI model training

3. Data Location

  • Data stored and processed exclusively in Microsoft Azure Commercial US regions
  • No transfer outside the United States

4. Subprocessors

  • Microsoft Azure — infrastructure
  • Microsoft Entra ID — identity
  • Azure OpenAI — inference only, no training

5. Security Measures

  • Encryption in transit (TLS 1.2+)
  • Encryption at rest (Azure-managed TDE / storage encryption)
  • RBAC-based access control with tenant isolation
  • Logging and monitoring via centralized telemetry

6. Breach Notification

GovSynth will notify Customer without undue delay after confirming unauthorized access to Customer Data.

7. Data Retention and Deletion

  • Data retained only as necessary to provide the Service
  • Upon termination, Customer Data is deleted following export opportunity

8. Audit Rights

  • Customer may request security documentation
  • No direct system audit without mutual agreement

9. Compliance Position

  • Platform supports customer compliance
  • No certification guaranteed