Skip to content

We use cookies

We use cookies and similar technologies to keep this site working, measure how it performs, and (with your permission) personalise ads. Choose your preferences below.

Goosy BearJoin the waitlist

Legal · Last updated August 25, 2026

Data Processing Addendum

The standard terms under which Goosy Bear processes personal data on behalf of business customers — roles, instructions, security, sub-processors, transfers, and deletion.

1. Introduction and applicability

This Data Processing Addendum ("DPA") forms part of the Terms of Service at https://goosybear.ai/terms (the "Agreement") between AI Code That Works LLC, a Texas limited liability company doing business as Goosy Bear ("Goosy Bear," "we," "us," or "our") and the customer that accepts the Agreement (the "Customer"). It applies wherever Goosy Bear processes personal data on the Customer's behalf in the course of providing the Goosy Bear application — the Customer's contacts, leads, audience members, and the individuals whose data enters the Customer's workspace through connected accounts ("Customer Personal Data"). No signature is required: the DPA applies automatically to every business customer, incorporated into the Agreement by reference.

"Data protection law" means the laws that apply to the processing of Customer Personal Data, including the GDPR, the UK GDPR, and the CCPA/CPRA and comparable US state laws; "processing," "controller," "processor," "business," and "service provider" have the meanings those laws give them.

2. Roles

For Customer Personal Data, the Customer is the controller (or a processor acting for another controller, in which case the Customer warrants its instructions to us are authorized) and Goosy Bear is the processor. Under the CCPA, Goosy Bear acts as the Customer's service provider: we process Customer Personal Data only to provide the services in the Agreement, and we do not sell it, share it for cross-context behavioral advertising, retain it beyond the Agreement's purposes, or combine it with data from other sources except as the CCPA permits a service provider to do.

For the data described in the Privacy Policy at https://goosybear.ai/privacy where Goosy Bear decides the purposes and means — website visitors, account holders' own registration and billing data, product analytics — Goosy Bear is the controller, and this DPA does not apply to that data.

3. Processing on documented instructions

We process Customer Personal Data only on the Customer's documented instructions — the Agreement, this DPA, the configuration and actions the Customer takes in the application (including the budgets, approval gates, and automation settings they set), and any further written instructions we agree to — unless the law we are subject to requires otherwise, in which case we tell the Customer before processing unless that law forbids it. We will inform the Customer if, in our opinion, an instruction infringes data protection law.

4. Details of processing

  • Subject matter and nature — hosting, storing, organizing, analyzing, and acting on marketing and CRM data as the application's features provide: content creation and publishing, CRM and messaging, advertising management on customer-owned accounts, analytics, and reporting.
  • Purpose — providing the Goosy Bear application to the Customer under the Agreement.
  • Duration — the term of the Agreement, plus the deletion window in section 12.
  • Categories of data subjects — the Customer's contacts, leads, subscribers, and audience members; the individuals who interact with the Customer's pages, forms, messages, and campaigns; the Customer's own team members using the application.
  • Categories of personal data — the categories described in the Privacy Policy's data-collection and connected-accounts sections: contact details, communication content, engagement and campaign data, CRM records, and analytics identifiers. The application is not designed for, and the Customer agrees not to submit, special categories of data or data about children.

5. Confidentiality and personnel

Access to Customer Personal Data is limited to the people who need it to provide or support the services, each bound by confidentiality obligations. Operator access to live customer data is limited and logged.

6. Security measures

We implement and maintain appropriate technical and organizational measures for the risk of the processing, as described in the Privacy Policy's security section: encryption in transit and at rest, database-enforced row-level isolation between customers, encrypted vault storage for connected-account tokens with logged access, least-privilege credentials, approval gates and budgets on consequential actions, audit trails, and automated error and anomaly monitoring. We may improve these measures over time; we will not materially reduce the overall protection during a subscription term.

7. Sub-processors

The Customer gives general authorization for the sub-processors listed at https://goosybear.ai/subprocessors, and we impose data-protection obligations on each that are no less protective than this DPA. We remain responsible to the Customer for each sub-processor's performance. We give notice of a material addition or replacement before it takes effect — the sub-processor page and the Privacy Policy's change-notice terms are the mechanism — and the Customer may object on reasonable data-protection grounds within 30 days of the notice; if we cannot address the objection, the Customer may terminate the affected services and receive a pro-rata refund of prepaid fees for the unused remainder.

8. Assistance with data subject requests

Taking into account the nature of the processing, we assist the Customer with appropriate technical and organizational measures to fulfil the Customer's obligation to respond to data subject requests — access, correction, deletion, restriction, portability, and objection. If a data subject contacts us directly about Customer Personal Data, we pass the request to the Customer and do not respond on the merits except on the Customer's instruction or where the law requires.

9. Personal data breach

We notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, with the information reasonably available to us — the nature of the breach, the categories and approximate numbers affected, the likely consequences, and the measures taken or proposed — supplementing the notice as more becomes known. We reasonably assist the Customer with its own notification obligations. Notification is not an admission of fault.

10. International transfers

Customer Personal Data is processed primarily in the United States. Where a transfer from the EEA, the UK, or Switzerland requires a safeguard, the parties incorporate the European Commission's Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (controller to processor), into this DPA by reference — with the Customer as data exporter, Goosy Bear as data importer, the details of processing in section 4 serving as Annex I, the security measures in section 6 serving as Annex II, and the optional docking clause included. For UK transfers the UK International Data Transfer Addendum applies to those clauses; for Swiss transfers the clauses apply with the adaptations Swiss law requires. Where a sub-processor's transfer needs a safeguard, we put an equivalent one in place.

11. Audits and information

On written request, no more than once in any 12-month period unless a supervisory authority requires more or a breach has occurred, we make available the information reasonably necessary to demonstrate compliance with this DPA — security documentation, third-party audit reports and certifications where held, and written answers to a reasonable security questionnaire. Where data protection law gives the Customer a right to an audit that these materials do not satisfy, the audit is conducted on reasonable notice, during business hours, no more than annually, under confidentiality, at the Customer's cost, and without access to other customers' data or to systems in a way that would compromise them.

12. Deletion and return on termination

During the term, the Customer can export Customer Personal Data through the application's export features. On termination or expiry of the Agreement — after the 30-day account-recovery grace period — we delete Customer Personal Data within 30 days, and connected-account data within 30 days of each disconnection, except where the law requires us to keep something, in which case we keep only what it requires, protected under this DPA, for only as long as it requires. Backup snapshots containing deleted records expire on the schedule in the Privacy Policy.

13. Liability, precedence, and changes

  • Liability under this DPA is subject to the limitations and exclusions of liability in the Agreement.
  • If this DPA conflicts with the Agreement on the processing of Customer Personal Data, this DPA controls; if the Standard Contractual Clauses conflict with either, the Clauses control for the transfers they govern.
  • We may update this DPA to reflect changes in law or in the services; material changes are notified under the Agreement's change-notice terms, and no change reduces the protection of Customer Personal Data during a paid term.
  • This DPA terminates automatically with the Agreement, surviving only as long as we hold Customer Personal Data.

14. Contact

Questions about this DPA, or a request to exercise its terms:

Talk to Goosygoosy@goosybear.ai

AI Code That Works LLC, 2303 Ranch Road 620 S., Suite 160-240, Lakeway, TX 78734, United States. Effective 2026-08-25.