GoshenConsulting LLCLegal Center ↗
Addendum / Data Processing

Data Processing Addendum

When this addendum applies

This Data Processing Addendum (“DPA”) applies only when an order form or written customer agreement expressly incorporates it and Goshen Consulting LLC processes personal data on the customer’s behalf in providing goOS or related services. The customer is the controller or business and Goshen is the processor or service provider, unless applicable law assigns different roles. The customer agreement and this DPA are together the “Agreement.”

Document review required

This public version describes Goshen’s standard processing terms but is not a substitute for customer-specific legal review. Regulated, international, sensitive, healthcare, financial, employment, children’s, biometric, or large-scale processing requires written review before use. Contact privacy@goshenconsultingllc.com to request an executed customer-specific copy or required transfer terms.

Processing instructions

Goshen will process customer personal data only to provide, secure, support, and improve the contracted Services; follow documented customer instructions; comply with law; and prevent fraud or abuse. The Agreement, enabled features, approved integrations, support requests, and authorized user actions constitute documented instructions. Goshen will notify the customer if an instruction appears unlawful where legally permitted.

Processing details

Processing may include collection, organization, storage, retrieval, analysis, transmission, generation of requested outputs, access control, logging, deletion, and return. Data subjects may include customer users, employees, prospects, customers, vendors, and other business contacts submitted by the customer. Data may include contact, professional, communication, account, workflow, integration, usage, and business-record information. Highly sensitive categories are excluded unless expressly approved in writing.

Customer obligations

The customer will provide lawful instructions; maintain required notices, consents, and legal bases; limit data to what is necessary; configure access and retention appropriately; respond to data-subject requests as controller; and ensure users and integrations comply with law. The customer will not instruct Goshen to process prohibited data or conduct unlawful outreach, monitoring, profiling, or automated decision-making.

Confidentiality and security

Goshen will require personnel with access to customer personal data to be bound by confidentiality duties and will maintain reasonable administrative, technical, and organizational safeguards appropriate to the service and risk. Measures may include access controls, encrypted transmission, credential protection, tenant isolation, multifactor authentication, logging, rate and spend controls, private storage, backups, secure development, incident procedures, and human approval boundaries. No system can guarantee absolute security.

Subprocessors

The customer authorizes Goshen to use the providers on the Subprocessor List for contracted Services. Goshen will require subprocessors to protect customer personal data through appropriate contractual obligations. Goshen remains responsible for its subprocessor obligations to the extent required by the Agreement. A customer with a legally required objection may contact privacy@goshenconsultingllc.com with reasonable details.

Security incidents

After becoming aware of a confirmed personal-data breach affecting customer personal data, Goshen will notify the customer without undue delay as required by applicable law and provide reasonably available information needed for the customer’s response. Notification is not an admission of fault. Customers must promptly provide requested cooperation and maintain current security contacts.

Data-subject and regulatory assistance

Taking into account the nature of processing and information available, Goshen will provide reasonable assistance for verified data-subject requests, security assessments, legally required impact assessments, and regulator inquiries. The customer remains responsible for determining whether a request is valid and communicating with the requester or regulator. Additional or unusual assistance may require a separate scope and reasonable fees where legally permitted.

Return, deletion, and retention

Upon termination or verified written instruction, Goshen will delete or return customer personal data within a commercially reasonable period, subject to product functionality, backups, legal holds, fraud prevention, security records, billing and tax obligations, and other lawful retention. Data retained under an exception remains protected and is not used for unrelated purposes.

International transfers

Data may be processed in the United States and countries where authorized subprocessors operate. If applicable law requires Standard Contractual Clauses or another transfer mechanism, the parties will execute or incorporate the appropriate current module and required annexes before the relevant restricted transfer.

Audit information

Upon reasonable written request and subject to confidentiality, Goshen may provide available policies, security summaries, or independent assessment information relevant to contracted processing. On-site audits are limited to circumstances required by law or where available evidence does not reasonably address a substantiated concern, and must avoid disruption and exposure of other customers’ information.

Order of precedence and liability

This DPA controls only for a direct conflict concerning processing of customer personal data. All liability under this DPA is subject to the exclusions and limitations in the customer agreement unless applicable law prohibits that limitation. Changes to processing scope, regulated data, or jurisdiction-specific requirements must be documented in writing.