GoldenIris ← Back
On This Page
Scope Nature of Processing Data Types Security Measures Sub-Processors Data Subject Rights Deletion Audit Rights International Transfers
All Legal Docs
Privacy Policy Terms of Service EULA Data Processing Agreement Sub-Processors Acceptable Use Policy Cookie Policy

Data Processing Agreement (DPA)

Last updated: March 22, 2026 • Golden Tech Solutions LLC • GoldenIris

This Data Processing Agreement (“DPA”) forms part of the agreement between you (“Controller”) and Golden Tech Solutions LLC (“Processor”) for use of the GoldenIris Service. This DPA applies where and to the extent that Golden Tech Solutions processes personal data on your behalf in providing the Service.

1. Scope and Relationship

Golden Tech Solutions LLC acts as a data processor with respect to personal data you submit to GoldenIris. You act as the data controller, determining the purposes and means of processing. This DPA governs that relationship.

Golden Tech Solutions processes personal data only on your documented instructions, as set out in these Terms and this DPA, unless required to do so by applicable law.

2. Nature and Purpose of Processing

Golden Tech Solutions processes personal data to:

  • Operate and maintain the GoldenIris Service on your behalf
  • Store, encrypt, and retrieve the content and data you submit
  • Facilitate AI-assisted content generation using your prompts and context
  • Deliver notifications and transactional communications
  • Process payments via Stripe
  • Provide customer support

3. Types of Personal Data Processed

  • Account data: Name, email address, hashed password
  • Content data: Captures, drafts, voice profiles, ICP definitions, knowledge base items (all encrypted at rest)
  • Usage data: IP addresses, session logs, feature usage
  • Payment data: Billing information (handled by Stripe; we receive only subscription status tokens)
  • AI API keys: If provided by you (encrypted at rest with per-user envelope encryption)

4. Security Measures

Golden Tech Solutions implements and maintains the following technical and organizational security measures:

  • AES-256-GCM encryption of all content data at rest
  • Per-user Data Encryption Keys (DEKs) with envelope encryption
  • Crypto shredding on account deletion (DEK destruction renders data permanently unrecoverable)
  • TLS 1.2+ on all connections
  • Access controls restricting database access to the application layer only
  • Regular dependency audits
  • Incident response procedures

5. Sub-Processors

A current list of sub-processors is maintained at goldeniris.ai/sub-processors. Golden Tech Solutions will provide 30 days’ notice of material sub-processor additions where required by applicable law.

6. Data Subject Rights Assistance

Golden Tech Solutions will assist you in fulfilling data subject requests (access, correction, deletion, portability) to the extent technically feasible. Users may exercise their rights directly through the Service (Settings → Data) or by contacting [email protected].

7. Deletion and Return of Data

Upon account termination, your Data Encryption Key is destroyed (crypto shredding). This renders all encrypted content permanently unrecoverable. You may export your data in JSON or CSV format before account deletion via Settings → Data → Export.

8. Audit Rights

Upon reasonable written request, Golden Tech Solutions will provide information reasonably necessary to demonstrate compliance with this DPA. Audit requests should be submitted to [email protected].

9. International Data Transfers

GoldenIris is hosted and operated in the United States. Data transferred to the United States is subject to United States law. If you are accessing the Service from outside the United States, you acknowledge and consent to this transfer.

For questions about this DPA: [email protected]

© 2026 Golden Tech Solutions LLC • GoldenIris is a product of Golden Tech Solutions LLC

Privacy Terms EULA DPA Sub-Processors Acceptable Use Cookies Contact