Data Processing Agreement

1. Introduction

This DPA reflects the parties' agreement on the processing of personal data in connection with the Services provided under the Services Agreement between [Legal Entity Name] ("Syncendio," "Processor") and the customer identified in the applicable Services Agreement ("Customer," "Controller"). It applies to the extent Syncendio processes personal data that is subject to the EU/UK GDPR, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act, Canada's Personal Information Protection and Electronic Documents Act ("PIPEDA") and substantially similar provincial law, or substantially similar data protection law ("Data Protection Laws") on Customer's behalf. PIPEDA is called out specifically because Syncendio is a Canadian business handling personal information in the course of commercial activity; it applies by virtue of that activity, not by virtue of where the data is stored. Syncendio's infrastructure is currently hosted in the United States — see Annex 1 and Section 7.

2. Definitions

Terms such as "personal data," "processing," "controller," "processor," "data subject," and "supervisory authority" have the meanings given in the GDPR, applied correspondingly under other Data Protection Laws. Additional terms:

3. Roles of the parties

As between the parties, Customer is the Controller (or processor acting on behalf of a further controller) of Customer Personal Data, and Syncendio is the Processor. Syncendio processes Customer Personal Data only to provide the Services and only on Customer's documented instructions, as set out in the Services Agreement, this DPA, and Customer's ordinary use of the Services — unless otherwise required by law, in which case Syncendio will inform Customer of that legal requirement before processing, unless the law prohibits such notice.

4. Scope, nature & purpose of processing

The subject matter, duration, nature and purpose of processing, types of personal data, and categories of data subjects are described in Annex 1.

5. Processor obligations

Syncendio will:

6. Sub-processors

Customer provides general authorization for Syncendio to engage the Sub-processors listed in Annex 3. Syncendio will:

7. International data transfers

Syncendio's databases are hosted in the United States (Neon, AWS us-east-2, Ohio) — see Annex 1. Customer Personal Data is therefore processed outside Canada and outside the EEA, and Customers should assume it may be subject to lawful access requests by United States authorities.

Where Syncendio transfers Customer Personal Data originating in the EEA, UK, or Switzerland to the United States or to any other country not deemed to provide an adequate level of protection, the transfer is governed by the Standard Contractual Clauses (Module 2: Controller-to-Processor, or Module 3: Processor-to-Processor, as applicable), incorporated by reference into this DPA, together with the UK International Data Transfer Addendum where the transfer originates in the UK.

PIPEDA does not require that personal information be stored in Canada. It does require that an organisation transferring personal information for processing outside Canada use contractual or other means to provide a comparable level of protection, and be transparent about the practice — which is the purpose of this Section and of Annex 3.

8. Data subject rights assistance

Where a data subject submits a request to Syncendio to exercise their rights under Data Protection Laws in respect of Customer Personal Data, Syncendio will forward the request to Customer without undue delay, and will not respond directly except to confirm receipt or as legally required. Syncendio will provide reasonable assistance to help Customer fulfill its obligation to respond.

9. Personal data breach notification

Syncendio will notify Customer without undue delay, and in any event within [48 hours — confirm this commitment with counsel; it needs to leave Customer enough time to meet its own 72-hour GDPR regulator notification deadline] of becoming aware of a Security Incident affecting Customer Personal Data. The notification will describe, to the extent known: the nature of the incident, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed to address it. This process follows Syncendio's internal Data Security & Breach Notification Policy.

10. Audits

On reasonable request, no more than once per 12-month period (except following a confirmed Security Incident, or where required by a supervisory authority), Syncendio will make available information reasonably necessary to demonstrate compliance with this DPA, including relevant third-party audit reports or certifications where available, and will allow for and contribute to audits conducted by Customer or an independent auditor Customer appoints, subject to reasonable confidentiality and scheduling terms.

11. Deletion or return of data

Upon termination or expiration of the Services Agreement, Syncendio will, at Customer's choice, delete or return all Customer Personal Data, except to the extent applicable law requires retention — consistent with the retention terms described in the Privacy Policy.

12. Liability

Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Services Agreement.

13. Term & termination

This DPA remains in effect for as long as Syncendio processes Customer Personal Data under the Services Agreement, and terminates automatically upon termination or expiration of the Services Agreement.

14. Governing law

This DPA is governed by the same governing law as the Services Agreement, as set out in the Terms of Service, except that the Standard Contractual Clauses (where they apply under Section 7) are governed by the law of the EU member state in which the data exporter is established, or otherwise as specified in the Clauses themselves.

Annex 1 — Details of processing

Annex 2 — Technical & organizational security measures

Summarized below; see Syncendio's Security page and internal Data Security & Breach Notification Policy for full detail.

Annex 3 — Approved sub-processors

Syncendio will update this Annex when Sub-processors are added or replaced, consistent with Section 6.