Data Processing Addendum
Version: August 8, 2026
When this addendum applies
This Data Processing Addendum (“DPA”) applies only when an order form or written customer agreement expressly incorporates it and Goshen Consulting LLC processes personal data on the customer’s behalf in providing goOS or related services. The customer is the controller or business and Goshen is the processor or service provider, unless applicable law assigns different roles. The customer agreement and this DPA are together the “Agreement.”
Document review required
This public version describes Goshen’s standard processing terms but is not a substitute for customer-specific legal review. Regulated, international, sensitive, healthcare, financial, employment, children’s, biometric, or large-scale processing requires written review before use. Contact privacy@goshenconsultingllc.com to request an executed customer-specific copy or required transfer terms.
Processing instructions
Goshen will process customer personal data only to provide, secure, support, and improve the contracted Services; follow documented customer instructions; comply with law; and prevent fraud or abuse. The Agreement, enabled features, approved integrations, support requests, and authorized user actions constitute documented instructions. Goshen will notify the customer if an instruction appears unlawful where legally permitted.
Processing details
Processing may include collection, organization, storage, retrieval, analysis, transmission, generation of requested outputs, access control, logging, deletion, and return. Data subjects may include customer users, employees, prospects, customers, vendors, and other business contacts submitted by the customer. Data may include contact, professional, communication, account, workflow, integration, usage, and business-record information. Highly sensitive categories are excluded unless expressly approved in writing.
Customer obligations
The customer will provide lawful instructions; maintain required notices, consents, and legal bases; limit data to what is necessary; configure access and retention appropriately; respond to data-subject requests as controller; and ensure users and integrations comply with law. The customer will not instruct Goshen to process prohibited data or conduct unlawful outreach, monitoring, profiling, or automated decision-making.
Confidentiality and security
Goshen will require personnel with access to customer personal data to be bound by confidentiality duties and will maintain reasonable administrative, technical, and organizational safeguards appropriate to the service and risk. Measures may include access controls, encrypted transmission, credential protection, tenant isolation, multifactor authentication, logging, rate and spend controls, private storage, backups, secure development, incident procedures, and human approval boundaries. No system can guarantee absolute security.
Subprocessors
The customer authorizes Goshen to use the providers on the Subprocessor List for contracted Services. Goshen will require subprocessors to protect customer personal data through appropriate contractual obligations. Goshen remains responsible for its subprocessor obligations to the extent required by the Agreement. A customer with a legally required objection may contact privacy@goshenconsultingllc.com with reasonable details.
Security incidents
After becoming aware of a confirmed personal-data breach affecting customer personal data, Goshen will notify the customer without undue delay as required by applicable law and provide reasonably available information needed for the customer’s response. Notification is not an admission of fault. Customers must promptly provide requested cooperation and maintain current security contacts.
Data-subject and regulatory assistance
Taking into account the nature of processing and information available, Goshen will provide reasonable assistance for verified data-subject requests, security assessments, legally required impact assessments, and regulator inquiries. The customer remains responsible for determining whether a request is valid and communicating with the requester or regulator. Additional or unusual assistance may require a separate scope and reasonable fees where legally permitted.
Return, deletion, and retention
Upon termination or verified written instruction, Goshen will delete or return customer personal data within a commercially reasonable period, subject to product functionality, backups, legal holds, fraud prevention, security records, billing and tax obligations, and other lawful retention. Data retained under an exception remains protected and is not used for unrelated purposes.
International transfers
Data may be processed in the United States and countries where authorized subprocessors operate. If applicable law requires Standard Contractual Clauses or another transfer mechanism, the parties will execute or incorporate the appropriate current module and required annexes before the relevant restricted transfer.
Audit information
Upon reasonable written request and subject to confidentiality, Goshen may provide available policies, security summaries, or independent assessment information relevant to contracted processing. On-site audits are limited to circumstances required by law or where available evidence does not reasonably address a substantiated concern, and must avoid disruption and exposure of other customers’ information.
Order of precedence and liability
This DPA controls only for a direct conflict concerning processing of customer personal data. All liability under this DPA is subject to the exclusions and limitations in the customer agreement unless applicable law prohibits that limitation. Changes to processing scope, regulated data, or jurisdiction-specific requirements must be documented in writing.