Lyteworkgo · Legal
Data Processing Addendum
How Gonzware LLC processes personal information on behalf of a Lyteworkgo Customer, and the terms U.S. state privacy laws require between a business and its service provider.
Effective September 24, 2026
1. What this document is and when it applies
This Data Processing Addendum ("DPA") is part of the Terms of Service between the business that creates or purchases a Lyteworkgo workspace ("Customer") and Gonzware LLC ("we", "us", "our"). It is incorporated into the Terms by this reference. No separate signature is required — accepting the Terms accepts this DPA in the version then in effect.
It applies whenever we process personal information contained in Customer Data on Customer's behalf. Capitalized terms not defined here carry the meaning given in the Terms.
"Personal information" means information in Customer Data that identifies or is reasonably capable of being associated with a particular individual or household, as those concepts are defined by the applicable U.S. state privacy law. "Applicable privacy law" means the U.S. state privacy and data-protection laws that apply to Customer's use of the Service.
Where this DPA and the Terms conflict on the processing of personal information, this DPA controls. The Terms govern everything else, including the limitations of liability, which apply to this DPA as though set out in it.
2. Roles, and the two kinds of data
Two distinct relationships run through the Service, and they are governed differently. Confusing them is the most common mistake in reading a document like this one, so we state them separately.
Customer Data — Customer is the business, we are the service provider. The records in a workspace about Customer's own clients, their requests, quotes, jobs, invoices, payments, messages, photos and signatures belong to Customer's relationship with those people. Customer determines why and how that information is processed. We process it on Customer's behalf, on Customer's instructions, and this DPA governs it.
Our own account and marketing information — we are the business. Information about the people who create and administer a workspace, what they send us, and the leads who fill in a form on our website is ours to determine. Our Privacy Policy governs that, not this DPA, and nothing here makes Customer responsible for it.
The practical consequence, and the reason we spell it out: an individual who wants to exercise a privacy right over information in a Customer's workspace deals with that Customer, not with us. If they reach us instead, we will not decide on Customer's behalf what should happen — see Section 5.
3. Our instructions, and the purposes we may process for
Customer's instructions to us are the Terms, this DPA, the configuration Customer chooses in the Service, and any further written instruction Customer gives that we accept. We will process personal information in Customer Data only on those instructions, and only for these purposes:
- Providing, maintaining, securing and supporting the Service for Customer
- Carrying out the communications, documents and automations Customer configures — sending a quote, an invoice, a reminder, a review request
- Detecting, preventing and investigating fraud, abuse, and security incidents
- Complying with law, and responding to lawful demands, subject to Section 9
- Internal use reasonably necessary to build, test and improve the Service, in the manner and only in the manner Section 7 permits
4. Service-provider commitments
These are the commitments applicable privacy law requires a service provider or processor to make, and they are the reason this document exists. With respect to personal information in Customer Data, we:
- Will not sell it, and will not share it for cross-context behavioral advertising. We do not do this with any data, on any plan
- Will not retain, use, or disclose it for any purpose other than the business purposes set out in Section 3, including any commercial purpose of our own, except as applicable privacy law expressly permits a service provider or processor
- Will not retain, use, or disclose it outside the direct business relationship between Customer and us
- Will not combine it with personal information we receive from or on behalf of anyone else, or collect ourselves, except where applicable privacy law permits a service provider to do so — for example to detect security incidents or protect against fraud
- Will provide the same level of privacy protection that applicable privacy law requires of Customer as the business
- Will notify Customer if we determine that we can no longer meet our obligations under applicable privacy law with respect to that information
- Will require personnel who handle it to be bound by confidentiality obligations, and will limit access to those who need it for their work
5. Helping Customer answer its clients' requests
Customer is responsible for responding to privacy-rights requests from its own clients and personnel, and for giving them whatever privacy notice the law requires. We are responsible for making that possible.
We will give Customer reasonable assistance in identifying, exporting, correcting or deleting personal information in its workspace in response to such a request, using the Service's own features where they are sufficient. Where a request requires effort disproportionate to the Service's ordinary use, we may charge for the work, and will say so before starting it.
If we receive a privacy-rights request that clearly concerns personal information in a Customer's workspace, we will not act on it ourselves. We will direct the individual to the relevant business where we can do so without disclosing more than necessary, and we will inform Customer. Whether and how to honor it is Customer's decision.
We will also provide Customer, on reasonable request, the information it needs to complete an assessment or record of processing that applicable privacy law requires of it, so far as that information concerns our processing.
6. Subprocessors
We use other providers to deliver the Service — hosting, database and authentication, email and text delivery, payments, mapping, website and network protection, product analytics, and error monitoring. Customer authorizes us to engage them as subprocessors for the processing this DPA describes.
Our subprocessors, and what each does, are named in our Subprocessor List. The list is kept in one place rather than repeated here so there is only ever one version of it to update.
Before a subprocessor processes personal information in Customer Data, we will bind it in writing to obligations substantially as protective as those in this DPA for the processing it performs. We remain responsible to Customer for a subprocessor's performance as if we had performed it ourselves.
If Customer has a reasonable, documented objection to a new subprocessor on data-protection grounds, Customer should tell us. We will work in good faith to find an alternative. If none is available and the objection stands, Customer may stop using the affected feature, or terminate as the Terms allow — we will not treat a genuine data-protection objection as a breach by Customer.
7. Aggregated and de-identified information
We may create and use aggregated or de-identified information derived from Customer Data to operate, secure, analyze and improve the Service. Information counts as aggregated or de-identified for this purpose only when it cannot reasonably be used to infer anything about, or be linked to, a particular individual, household, or Customer.
We will maintain and use that information in de-identified form, will not attempt to re-identify it except to test whether our de-identification actually works, and will contractually prohibit anyone we give it to from re-identifying it.
We do not use one Customer's workspace content to build features for, or to train models used on behalf of, another Customer except through information that meets the standard in this Section.
8. Security, and security incidents
We maintain administrative, technical and physical safeguards designed to protect personal information in Customer Data against unauthorized access, use, disclosure, alteration and destruction, appropriate to the nature of the information and to the size and complexity of our business. The Terms describe those safeguards; this DPA does not promise a different set.
If we confirm a breach of security affecting personal information in Customer Data, we will notify Customer without undue delay, and in any event within the time applicable law requires. Our notice will describe, so far as we then know: what happened and when, the categories of personal information and the approximate number of individuals or records involved, what we have done to contain and remediate it, and what we recommend Customer consider.
We will notify Customer — not Customer's clients. Customer is the business those individuals dealt with, and any notice to them is Customer's to give and to word. We will cooperate reasonably with Customer in preparing it.
Notifying Customer is not an admission of fault by either party.
9. Government and legal demands
If we receive a subpoena, warrant, court order or other legal demand for personal information in Customer Data, we will, unless legally prohibited, notify Customer promptly and give Customer a reasonable opportunity to respond or object before we produce anything.
Where we are prohibited from notifying Customer, we will take the steps reasonably available to us to challenge or narrow the prohibition, and will notify Customer as soon as we lawfully may.
We will produce only what the demand actually requires.
10. Verification
Customer may take reasonable and appropriate steps to satisfy itself that we process personal information in Customer Data consistently with Customer's own obligations under applicable privacy law — the right applicable law requires Customer to have.
In practice that means: on reasonable written request, and no more than once in any twelve-month period unless applicable privacy law or a security incident requires otherwise, we will respond to a reasonable written security and privacy questionnaire and provide the summaries or third-party assessment reports we then hold. Where we hold a relevant third-party report, providing it satisfies this Section.
If Customer has notified us of unauthorized processing, Customer may take reasonable and appropriate steps to stop and remediate it, and we will cooperate with those steps.
An on-site audit is available where applicable privacy law entitles Customer to one and the measures above genuinely do not satisfy it. It is at Customer's expense, on at least thirty days' written notice, during business hours, subject to confidentiality, and conducted so as not to disrupt the Service or other Customers. No audit will be given access to another Customer's data.
11. Deletion after termination
After the Terms end, Customer Data is deleted or de-identified in the ordinary course, as Section 16 of the Terms and the Privacy Policy describe. Customer should export what it needs while its subscription is active, using the export and download features in the Service. After termination we have no obligation to retain, assemble, or deliver Customer Data; we may still help with a copy on request, at our discretion.
We may retain personal information where applicable law requires us to, and for as long as it requires — for example transaction and tax records, and the records evidencing consent to receive text messages, which exist to prove that a recipient agreed and would be worth less than nothing if deleted on request. While retained for that reason it stays subject to this DPA and is not used for anything else.
12. Scope: United States only
The Service is offered to businesses located in the United States (Terms Section 1), and this DPA is written for U.S. state privacy law. It is not a GDPR Article 28 data-processing agreement. It does not incorporate Standard Contractual Clauses or any other cross-border transfer mechanism, and it does not make us a processor for personal data subject to the GDPR or the UK GDPR.
We say so plainly rather than staying quiet about it. A Customer whose processing is subject to those regimes should not rely on this document, and should speak to us before using the Service for that processing.
Where a U.S. state privacy law other than California's applies to Customer and requires a term this DPA does not contain, that term is incorporated here to the extent applicable law requires it of us as Customer's processor or service provider, and we will comply with it.
13. Changes to this DPA
We may update this DPA as the Service or applicable privacy law changes. We will not make a change that materially reduces the protections in Sections 4, 5, 6 or 8 without giving notice in the way the Terms require for a material change to them, and Customer keeps whatever rights the Terms give on such a change.
Each version carries the effective date shown at the top of this page.
14. Contact
Requests under this DPA — assistance with a privacy-rights request, a subprocessor objection, a security questionnaire, or notice of unauthorized processing — should be sent to the address below.
Questions, requests, and legal notices: Gonzware LLC · support@gonzware.com · 1041 Main Ave #588, De Pere, WI 54115 · https://qa-get.lyteworkgo.com
Legal notices to us may be sent by email to the address above, effective on receipt, or by mail to the postal address above — effective three business days after being sent by a nationally recognized overnight courier or by certified mail with return receipt requested, and otherwise on actual receipt.
