Data Processing Agreement
Last updated: August 8, 2026
This Data Processing Agreement ("DPA") is incorporated into and forms part of the Syncendio Terms of Service between Syncendio and any customer with an active account (the "Services Agreement"). It applies automatically wherever Syncendio processes personal data on a customer's behalf. If your organization requires a separately executed or countersigned copy for its own records, contact legal@syncendio.com.
1. Introduction
This DPA reflects the parties' agreement on the processing of personal data in connection with the Services provided under the Services Agreement between [Legal Entity Name] ("Syncendio," "Processor") and the customer identified in the applicable Services Agreement ("Customer," "Controller"). It applies to the extent Syncendio processes personal data that is subject to the EU/UK GDPR, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act, Canada's Personal Information Protection and Electronic Documents Act ("PIPEDA") and substantially similar provincial law, or substantially similar data protection law ("Data Protection Laws") on Customer's behalf. PIPEDA is called out specifically because Syncendio is a Canadian business handling personal information in the course of commercial activity; it applies by virtue of that activity, not by virtue of where the data is stored. Syncendio's infrastructure is currently hosted in the United States — see Annex 1 and Section 7.
2. Definitions
Terms such as "personal data," "processing," "controller," "processor," "data subject," and "supervisory authority" have the meanings given in the GDPR, applied correspondingly under other Data Protection Laws. Additional terms:
- "Customer Personal Data" — personal data that Syncendio processes on Customer's behalf in providing the Services, including data entered into the Syncendio platform and data submitted through Syncendio's website forms on Customer's behalf.
- "Sub-processor" — a third party engaged by Syncendio to process Customer Personal Data (see Section 6 and Annex 3).
- "Standard Contractual Clauses" or "SCCs" — the European Commission's standard contractual clauses for international transfers of personal data (Commission Implementing Decision (EU) 2021/914), as updated or replaced.
- "Security Incident" — has the meaning given in Syncendio's Data Security & Breach Notification Policy: a confirmed or suspected event that could compromise the confidentiality, integrity, or availability of Customer Personal Data.
3. Roles of the parties
As between the parties, Customer is the Controller (or processor acting on behalf of a further controller) of Customer Personal Data, and Syncendio is the Processor. Syncendio processes Customer Personal Data only to provide the Services and only on Customer's documented instructions, as set out in the Services Agreement, this DPA, and Customer's ordinary use of the Services — unless otherwise required by law, in which case Syncendio will inform Customer of that legal requirement before processing, unless the law prohibits such notice.
4. Scope, nature & purpose of processing
The subject matter, duration, nature and purpose of processing, types of personal data, and categories of data subjects are described in Annex 1.
5. Processor obligations
Syncendio will:
- Process Customer Personal Data only on Customer's documented instructions, including regarding international transfers, unless required otherwise by law.
- Ensure personnel authorized to process Customer Personal Data are bound by confidentiality obligations.
- Implement appropriate technical and organizational measures to protect Customer Personal Data, as described in Annex 2 and Syncendio's Security page.
- Engage Sub-processors only as permitted under Section 6.
- Assist Customer, taking into account the nature of processing, in responding to data subject rights requests (Section 8).
- Assist Customer with data protection impact assessments and prior consultations with supervisory authorities, to the extent required by Data Protection Laws and reasonably related to Syncendio's processing.
- Notify Customer of Security Incidents affecting Customer Personal Data as described in Section 9.
- At Customer's choice, delete or return Customer Personal Data at the end of the Services Agreement, as described in Section 11.
- Make available information reasonably necessary to demonstrate compliance with this DPA, and allow for audits as described in Section 10.
6. Sub-processors
Customer provides general authorization for Syncendio to engage the Sub-processors listed in Annex 3. Syncendio will:
- Impose data protection terms on each Sub-processor that are no less protective than this DPA.
- Remain liable to Customer for a Sub-processor's performance of its data protection obligations.
- Notify Customer before adding or replacing a Sub-processor, via an update to Annex 3 on this page or by direct notice, giving Customer the opportunity to object on reasonable data-protection grounds. If the parties cannot resolve the objection, Customer may terminate the affected Service as its sole remedy.
7. International data transfers
Syncendio's databases are hosted in the United States (Neon, AWS us-east-2, Ohio) — see Annex 1. Customer Personal Data is therefore processed outside Canada and outside the EEA, and Customers should assume it may be subject to lawful access requests by United States authorities.
Where Syncendio transfers Customer Personal Data originating in the EEA, UK, or Switzerland to the United States or to any other country not deemed to provide an adequate level of protection, the transfer is governed by the Standard Contractual Clauses (Module 2: Controller-to-Processor, or Module 3: Processor-to-Processor, as applicable), incorporated by reference into this DPA, together with the UK International Data Transfer Addendum where the transfer originates in the UK.
PIPEDA does not require that personal information be stored in Canada. It does require that an organisation transferring personal information for processing outside Canada use contractual or other means to provide a comparable level of protection, and be transparent about the practice — which is the purpose of this Section and of Annex 3.
8. Data subject rights assistance
Where a data subject submits a request to Syncendio to exercise their rights under Data Protection Laws in respect of Customer Personal Data, Syncendio will forward the request to Customer without undue delay, and will not respond directly except to confirm receipt or as legally required. Syncendio will provide reasonable assistance to help Customer fulfill its obligation to respond.
9. Personal data breach notification
Syncendio will notify Customer without undue delay, and in any event within [48 hours — confirm this commitment with counsel; it needs to leave Customer enough time to meet its own 72-hour GDPR regulator notification deadline] of becoming aware of a Security Incident affecting Customer Personal Data. The notification will describe, to the extent known: the nature of the incident, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed to address it. This process follows Syncendio's internal Data Security & Breach Notification Policy.
10. Audits
On reasonable request, no more than once per 12-month period (except following a confirmed Security Incident, or where required by a supervisory authority), Syncendio will make available information reasonably necessary to demonstrate compliance with this DPA, including relevant third-party audit reports or certifications where available, and will allow for and contribute to audits conducted by Customer or an independent auditor Customer appoints, subject to reasonable confidentiality and scheduling terms.
11. Deletion or return of data
Upon termination or expiration of the Services Agreement, Syncendio will, at Customer's choice, delete or return all Customer Personal Data, except to the extent applicable law requires retention — consistent with the retention terms described in the Privacy Policy.
12. Liability
Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Services Agreement.
13. Term & termination
This DPA remains in effect for as long as Syncendio processes Customer Personal Data under the Services Agreement, and terminates automatically upon termination or expiration of the Services Agreement.
14. Governing law
This DPA is governed by the same governing law as the Services Agreement, as set out in the Terms of Service, except that the Standard Contractual Clauses (where they apply under Section 7) are governed by the law of the EU member state in which the data exporter is established, or otherwise as specified in the Clauses themselves.
Annex 1 — Details of processing
| Subject matter | Syncendio's provision of its inventory, purchasing, sales, and assembly platform, and its marketing/lead-capture website, to Customer. |
|---|---|
| Duration | For the term of the Services Agreement, plus any post-termination retention period described in the Privacy Policy. |
| Nature & purpose | Hosting, storage, and processing of Customer Personal Data as needed to operate the Services: account management, platform functionality (inventory/purchasing/sales records), billing via Stripe, and related support and communications. |
| Categories of data subjects | Customer's personnel and authorized users; Customer's own customers or suppliers to the extent their data is entered into the platform (e.g., order or contact records); website leads and partner applicants. |
| Types of personal data | Name, business email, business name/role, billing and subscription metadata (via Stripe), and any personal data Customer chooses to enter into records such as orders, contacts, or supplier details. No special categories of data (e.g., health, biometric data) are intentionally processed. |
| Location of processing | United States — Neon Platform Database and per-tenant databases in AWS us-east-2 (Ohio). Application hosting region: [to be confirmed before execution — not yet deployed]. See Section 7 on transfers, and Annex 3 for Sub-processor locations. |
Annex 2 — Technical & organizational security measures
Summarized below; see Syncendio's Security page and internal Data Security & Breach Notification Policy for full detail.
- Encryption of data in transit (HTTPS/TLS) and at rest — Azure and Neon both encrypt stored data by default.
- Least-privilege access controls; unique credentials per team member; multi-factor authentication for administrative access.
- Secrets management for API keys and credentials; no secrets committed to source control.
- Logging and monitoring of access to production systems.
- Payment data handled entirely by Stripe (PCI DSS Level 1 certified); card data never touches Syncendio's servers.
- Documented incident response plan covering detection, containment, eradication, recovery, and notification.
- Periodic access reviews and vendor/sub-processor risk assessment before onboarding.
Annex 3 — Approved sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Stripe, Inc. | Payment processing | United States (and Stripe's own sub-processors — see Stripe's published subprocessor list) |
| Microsoft Azure | Application hosting, CDN/WAF (Front Door), Static Web Apps | [to be confirmed before execution — not yet deployed] |
| Neon, Inc. | Platform & tenant database hosting | United States (AWS us-east-2, Ohio) |
| [Email delivery provider] | Transactional email | TBD |
Syncendio will update this Annex when Sub-processors are added or replaced, consistent with Section 6.