Data Processing Addendum
When your team uses GovernKit, we process a small, well-defined set of personal data on your behalf. This addendum describes that processing for teams subject to GDPR, UK GDPR, CCPA, and similar laws.
Last updated: July 7, 2026
1. Scope and roles
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between Zyref, LLC (“Zyref”, the provider of GovernKit) and the customer team (“Customer”). It applies whenever we process personal data on the Customer's behalf.
For governance records, including requests, decisions, policies, acknowledgements, and the audit log, the Customer is the controller (or a processor acting for its own controller) and Zyref is the processor. For account credentials, billing, and our own service operations, Zyref acts as an independent controller as described in the Privacy Policy.
2. What we process, and about whom
| Category | Details |
|---|---|
| Data subjects | The Customer's employees and contractors who are members of the Customer's GovernKit team. |
| Personal data | Names, work email addresses, team roles and department, tool requests and use-case descriptions, review decisions and notes, policy acknowledgements, and audit-log entries attributing governance actions to individuals. |
| Special categories | None by design. The request form asks for a description of intended use and the categories of data involved. It does not ask employees to submit the underlying content, and Customers should instruct their users accordingly. |
| Purpose | Providing the GovernKit service: request and approval workflows, the tool directory, policy management, vendor vetting, and the audit trail. |
| Duration | The term of the Customer's subscription, plus the deletion window in section 8. |
GovernKit deliberately does not process employee prompts, AI conversation content, files, browsing activity, or screen data. It has no mechanism to collect them.
3. Our obligations as processor
- Process personal data only on the Customer's documented instructions, including the Terms, this DPA, and the Customer's configuration and use of the service, unless the law requires otherwise. If that happens, we'll inform the Customer unless prohibited.
- Ensure everyone we authorize to process personal data is bound by confidentiality.
- Implement the technical and organizational measures in section 6.
- Assist the Customer, as reasonably needed, with data subject requests, security, breach notification, and data protection impact assessments.
- Delete or return personal data at the end of the engagement (section 8).
- Make available the information reasonably necessary to demonstrate compliance, including responding to written security questionnaires and, where legally required, allowing audits with reasonable notice.
4. Subprocessors
The Customer authorizes the following subprocessors, each engaged under terms no less protective than this DPA:
| Subprocessor | Purpose | Data involved |
|---|---|---|
| Stripe, Inc. | Payment processing and invoicing | Billing contact email; card details go directly to Stripe and never touch our servers. |
| Brevo (Sendinblue SAS) | Transactional email delivery | Recipient name, email address, and notification content (e.g. decision emails, invitations). |
| OpenAI, L.L.C. | AI features: policy drafting, tool documentation drafting, vendor document analysis | Text needed for the task, including team name, questionnaire answers, tool names and descriptions, and vendors' public documents. Never member names or email addresses. Not used to train OpenAI's models under their API terms. |
| Amazon Web Services, Inc. | Hosting the application and its database | All service data, encrypted in transit and at rest. |
| Cloudflare, Inc. | Serving the marketing website and front-end performance and security (CDN, DDoS protection) | Standard connection metadata (IP address, requested URLs). Cloudflare has no access to application or database data. |
| Functional Software, Inc. (Sentry) | Crash and error reporting | Technical error context (stack traces, request metadata). |
We will notify Customers before adding or replacing a subprocessor; if the Customer reasonably objects on data protection grounds and we cannot accommodate, the Customer may cancel with a refund of any unused prepaid period.
5. International transfers
Zyref, LLC is a United States company and processing occurs primarily in the United States. Where personal data of EU, UK, or Swiss data subjects is transferred, the parties rely on the European Commission's Standard Contractual Clauses (module two, controller to processor), which are incorporated into this DPA by reference, together with the UK Addendum where applicable. Subprocessor transfers are covered by equivalent safeguards in our agreements with them.
6. Security measures
- Encryption in transit (TLS) for all connections to the service; the production database and its backups are encrypted at rest.
- Passwords stored as salted hashes; two-factor authentication (TOTP with hashed backup codes) available to every user.
- Strict team isolation: each team's members, tools, policies, and billing are separate, with no cross-team access.
- Role-based access control (owner, admin, manager, member) with permission checks on sensitive actions.
- An append-only audit log of governance actions.
- Least-privilege operational access for Zyref personnel, used only to operate and support the service.
Our security overview describes these measures in more detail.
7. Personal data breaches
If we become aware of a personal data breach affecting Customer personal data, we will notify the Customer without undue delay, describe the nature and likely consequences of the breach, and the measures taken or proposed to address it. The notice will include enough detail for the Customer to meet its own notification obligations.
8. Deletion and return
Both return and deletion are self-serve. Team owners and admins can, at any time, download a complete workspace export from team settings. This is a ZIP of JSON files (team profile, members, departments, invitations, tools, requests with their discussion threads, decommission requests, policies, acknowledgements, and the full audit log) plus each policy as Markdown. Every export is itself recorded in the audit log. Team deletion is equally available in-product; on deletion, personal data is removed from the live database immediately, and residual copies in encrypted backups expire within 30 days, except where retention is required by law. Vendor document snapshots contain public vendor documents, not Customer personal data, and are pruned automatically after 180 days.
9. Data subject requests
Members can already self-serve the two most common requests: access and portability via the personal JSON export in account settings, and erasurevia self-serve account deletion, which removes personal data immediately and anonymizes the member's entries in the team's audit records. If a data subject contacts us directly about data we process on the Customer's behalf, we will redirect them to the Customer and inform the Customer of the request, and we will assist the Customer in fulfilling access, correction, deletion, and restriction requests.
10. Precedence and signing
If this DPA conflicts with the Terms of Service, this DPA prevails for data protection matters. This DPA applies automatically to Customers whose use of GovernKit is subject to the laws above. If your compliance process requires a countersigned copy, email hello@governkit.ai and we'll arrange one.
11. Contact
Zyref, LLC · hello@governkit.ai