Data Processing Agreement
Version 1. Effective 2026-09-08.
Version: 1, in effect from 2026-09-08. Contact: legal@syncropic.com.
This Data Processing Agreement ("DPA") forms part of the Terms of Service (the "Terms") between Syncropic Inc., a Delaware Public Benefit Corporation ("Syncropic"), and the customer that accepts the Terms (the "Controller"). It applies automatically, without signature, whenever the Controller's use of the hosted Service involves personal data protected by Data Protection Law. Either party may request a countersigned copy by email to legal@syncropic.com. Where the Controller is itself a processor for its own customers, this DPA applies to it in that capacity and Syncropic acts as its subprocessor.
Definitions. "Data Protection Law" means the EU General Data Protection Regulation (EU) 2016/679 (the "GDPR"), the UK GDPR and the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection, and any other law that applies to the processing of personal data under this DPA. "Personal data", "processing", "controller", "processor", "data subject", "personal data breach" and "supervisory authority" have the meanings given in the GDPR. "Customer Data" means personal data that the Controller or its members put into the Controller's workspace, including in records, threads, runs, files and prompts to the assistant. "Subprocessor" means a third party engaged by Syncropic to process Customer Data. "SCCs" means the standard contractual clauses in Commission Implementing Decision (EU) 2021/914. "UK Addendum" means the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner, version B1.0, in force 21 March 2022. "Subprocessor List" means the list published at https://syncropic.com/legal/subprocessors, which is incorporated into this DPA by reference.
1. Roles and scope
1.1 For Customer Data, the Controller is the controller (or, where the Controller acts for its own customers, the processor) and Syncropic is the processor (or subprocessor). Syncropic processes Customer Data only as described in this DPA.
1.2 For account, authentication, billing, support and operational telemetry data about the Controller and its members, Syncropic is an independent controller and processes that data as described in its Privacy Policy. This DPA does not apply to that data.
1.3 Where this DPA and the Terms conflict, this DPA prevails for the processing of Customer Data. Where this DPA and the SCCs conflict, the SCCs prevail.
2. Description of processing
The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are described in Annex I. The Controller decides what personal data it and its members put into the workspace, and confirms that it has a lawful basis to do so and to instruct Syncropic to process it.
3. Instructions
3.1 Syncropic processes Customer Data only on the Controller's documented instructions, including with regard to transfers to a third country, unless required to do otherwise by law that applies to Syncropic, in which case Syncropic will inform the Controller of that requirement before processing unless the law prohibits it on important grounds of public interest.
3.2 The Controller's documented instructions are: this DPA, the Terms, and the Controller's and its members' use of the Service's features (including creating, sharing and exporting content, erasing content where the erasure feature is available and the Controller's erasure settings cover it, closing the workspace, granting permissions, publishing links, and invoking the assistant). Further instructions may be given by email to legal@syncropic.com; Syncropic will tell the Controller promptly if it cannot follow an instruction, and may charge reasonable costs for instructions that go beyond the Service's ordinary features.
3.3 Syncropic will immediately inform the Controller if, in its opinion, an instruction infringes Data Protection Law.
4. Confidentiality
Syncropic ensures that every person it authorises to process Customer Data is bound by a contractual or statutory duty of confidentiality, and that access is limited to those who need it to provide the Service.
5. Subprocessors
5.1 The Controller gives Syncropic general written authorisation to engage the Subprocessors named on the Subprocessor List, which states for each the service it provides, the category of data it processes and the location in which it processes it. A change to the Subprocessor List never requires this DPA to be re-executed.
5.2 Syncropic will give the Controller at least 30 days' notice before adding or replacing a Subprocessor, by updating the Subprocessor List and by email to the workspace owner, except where a replacement is needed urgently to keep the Service running, in which case Syncropic will notify the Controller as soon as practicable and the Controller keeps the same objection right.
5.3 The Controller may object within the notice period on reasonable data-protection grounds by email to legal@syncropic.com. The parties will discuss the objection in good faith. If Syncropic cannot resolve it within 30 days, the Controller may terminate the affected Service by written notice and Syncropic will refund any prepaid fees for the remainder of the term.
5.4 Syncropic has in place, or is putting in place with each Subprocessor, by written contract, data-protection obligations that provide at least the same level of protection as this DPA, and remains fully liable to the Controller for the performance of each Subprocessor's obligations. The Subprocessor List states, for each Subprocessor, whether those terms are in effect or pending.
5.5 Where the Controller supplies its own key for an AI model provider, that provider is the Controller's own processor, not a Subprocessor of Syncropic. Syncropic's role for such requests is limited to transmitting them from the Controller's workspace to that provider on the Controller's instruction; the prompts and responses stored in the workspace remain Customer Data under this DPA.
6. Security
Syncropic implements and maintains the technical and organisational measures described in Annex II, which are appropriate to the risk having regard to the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing, in accordance with Article 32 of the GDPR and UK GDPR. Syncropic may update Annex II from time to time, but not in a way that materially reduces the overall protection of Customer Data during the term.
7. Assistance to the Controller
7.1 Taking into account the nature of the processing, Syncropic will assist the Controller by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Controller's obligation to respond to requests from data subjects exercising their rights. The Service's own export, access, correction (by adding a corrected record), erasure and workspace-closure features are the primary means of doing so. Individual records cannot be edited or deleted one at a time once created; erasure, where available, applies to content that the Controller's erasure settings cover, and closing the workspace deletes everything. If Syncropic receives a request directly from a data subject relating to Customer Data, it will refer the data subject to the Controller and tell the Controller, without responding on the merits unless the Controller asks it to or the law requires it.
7.2 Syncropic will assist the Controller in meeting its obligations under Articles 32 to 36 of the GDPR and UK GDPR (security, breach notification, data protection impact assessments and prior consultation with a supervisory authority), taking into account the nature of the processing and the information available to Syncropic.
7.3 Assistance is provided at no charge where the Controller can meet its obligation through the Service's own features, or where the assistance takes Syncropic no more than a few hours. Where a request requires materially more effort, Syncropic may charge reasonable costs and will tell the Controller before incurring them.
8. Return and deletion
8.1 During the term the Controller may export all Customer Data at any time using the Service's export feature. Where Syncropic terminates the Service, the Controller has 30 days after termination to do so, as provided in the Terms. Where the Controller closes its workspace, it should export first, because deletion begins on closure.
8.2 When the Controller closes its workspace, at the end of the 30-day period after a termination by Syncropic, or earlier at the Controller's written request, Syncropic will delete the Controller's workspace and its storage within 7 days, and backup copies will expire within 30 days after that, unless Data Protection Law or another law that applies to Syncropic requires retention, in which case Syncropic will keep the data only for as long as and to the extent required and will continue to protect it under this DPA.
8.3 Individual records cannot be edited or deleted one at a time once created. Where the erasure feature is available, Customer Data concerns an identified person, and the Controller's erasure settings cover that content, it makes the content permanently unreadable everywhere it was stored or published and leaves a permanent marker that the erasure took place. Syncropic will confirm deletion in writing on request.
9. Personal data breach
Syncropic will notify the Controller without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Data. The notice will describe, to the extent the information is reasonably available at that time, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point, and Syncropic will supplement it as further information becomes known. Syncropic will cooperate reasonably with the Controller's own notifications and investigation. A notice under this section is not an admission of fault.
10. Information and audit
10.1 On written request no more than once per year (and additionally after a personal data breach affecting the Controller's Customer Data, or where a supervisory authority requires it), Syncropic will make available the information necessary to demonstrate compliance with Article 28 of the GDPR and UK GDPR, including completed security questionnaires and the current Annex II.
10.2 If that information is reasonably insufficient, the Controller, or an independent auditor it appoints who is bound by confidentiality and is not a competitor of Syncropic, may audit Syncropic's compliance with this DPA on at least 30 days' written notice, during business hours, no more than once per year, without disrupting the Service, and at the Controller's cost. An audit covers Syncropic's own controls and documentation; assurance about Subprocessors is provided through their audit reports and certifications. Where Syncropic obtains a third-party audit report or certification in future, providing it satisfies this section.
10.3 Syncropic will cooperate with a supervisory authority that has jurisdiction over the Controller, and will tell the Controller if an audit or inspection by a supervisory authority concerns Customer Data.
11. International transfers
11.1 The Controller's workspace is hosted in the United States, and Subprocessors process Customer Data in the locations stated on the Subprocessor List. The Controller authorises those transfers.
11.2 Where Customer Data protected by the GDPR, the UK GDPR or Swiss law is transferred to a country that has not been found to provide adequate protection, the transfer is governed by the transfer mechanism in Annex III: the SCCs, the UK Addendum and the Swiss adaptations, as applicable. Annexes I and II of this DPA serve as the corresponding annexes to the SCCs.
11.3 If a transfer mechanism relied on under this DPA is invalidated or replaced, the parties will cooperate in good faith to put an alternative lawful mechanism in place promptly, and Syncropic may amend Annex III to adopt a replacement mechanism approved by the European Commission or the UK Information Commissioner on notice to the Controller.
12. Liability
Each party's liability arising out of or relating to this DPA is subject to the limitations and exclusions in the Terms, including the separate cap that the Terms provide for breaches of the confidentiality and data-protection obligations in this DPA. Nothing in this section limits a party's liability to data subjects or supervisory authorities under Data Protection Law, or any liability that cannot be limited by law.
13. Term and general
13.1 This DPA applies for as long as Syncropic processes Customer Data, including the deletion period in section 8.
13.2 Syncropic may update this DPA to reflect changes in Data Protection Law or in the Service on at least 30 days' notice by email to the workspace owner, provided the change does not materially reduce the protection of Customer Data. The current version, with its date, is published alongside the Terms.
13.3 The governing-law and dispute provisions of the Terms apply to this DPA, except that the SCCs are governed as stated in Annex III. If any part of this DPA is unenforceable, the rest remains in effect.
Annex I: Description of the processing
A. Parties
Data exporter (Controller): the customer that accepted the Terms, identified by the account and workspace it controls, acting as a controller (or, where it acts for its own customers, as a processor). Contact: the workspace owner's account email.
Data importer (Processor): Syncropic Inc., a Delaware Public Benefit Corporation, United States, acting as a processor (or subprocessor). Contact: legal@syncropic.com.
B. Description of the processing
- Categories of data subjects: the Controller's members who are natural persons (employees, contractors and collaborators), the people under whose authority the Controller's automated members act, and any individuals whose personal data the Controller or its members place in records, threads, runs, files or prompts to the assistant.
- Categories of personal data: identifiers and contact details; professional and workplace information; communications and work content; and any other personal data the Controller chooses to store in its workspace. Syncropic does not control and does not inspect what a Controller puts in a record.
- Special categories of data: not intended. The Controller must not store special categories of data (Article 9), or data about criminal convictions (Article 10), unless it has a lawful basis to do so and has told Syncropic in writing, so that additional measures can be agreed.
- Frequency of the transfer: continuous, for as long as the Service is used.
- Nature of the processing: hosting, storing, backing up, transmitting, displaying to authorised members and recipients, exporting, deleting, and relaying prompts to and responses from AI model providers when the assistant is invoked.
- Purpose of the processing: to provide the Service to the Controller as described in the Terms, and for no other purpose.
- Duration: the term of the Service plus the deletion period in section 8.
- Transfers to Subprocessors: as stated on the Subprocessor List, for the service, category of data and location stated there.
C. Competent supervisory authority
Where the Controller is established in an EU or EEA member state, the supervisory authority of that establishment. Where the Controller is not established in the EU or EEA but has appointed a representative under Article 27 of the GDPR, the supervisory authority of the member state in which the representative is established. Otherwise, the supervisory authority of the member state in which the data subjects are located, determined in accordance with Clause 13 of the SCCs. For UK data, the Information Commissioner.
Annex II: Technical and organisational security measures
Syncropic maintains measures in each of the following categories. This annex states what is assured; detailed mechanisms are available to a Controller under a security questionnaire or a confidentiality agreement.
- Isolation between customers. Each Controller's workspace and its storage are isolated from every other customer's. Nothing crosses between workspaces except by a permission the Controller grants.
- Encryption in transit. Every external connection to and from the Service is encrypted.
- Encryption at rest. Workspace storage and backups are encrypted at rest by Syncropic's hosting and storage providers.
- Access control. Access to a workspace requires credentials scoped to a member and to the threads that member may reach. Syncropic staff access to Customer Data is limited to what is needed to operate and support the Service and is protected by multi-factor authentication.
- Credential separation. Keys, tokens and other secrets are stored separately from Customer Data and are never written into records.
- Restricted automated members. Automated members act under restricted permissions, with access limited to what they were explicitly given and with their spend and duration bounded.
- Integrity and backups. Stored Customer Data carries integrity checks, is backed up daily with rotation, and the ability to restore is tested.
- Logging and monitoring. Operational telemetry is limited to what is needed for reliability and security and is retained for no more than 30 days.
- Vulnerability and change management. Dependencies are monitored for published vulnerabilities, changes are tested before release, and a security contact is published (legal@syncropic.com, as stated in the Privacy Policy).
- Personnel and confidentiality. Everyone with access to Customer Data is bound by confidentiality obligations. Syncropic is currently operated by a single person; any contractor with access signs confidentiality terms before receiving it.
- Incident response. A documented process for detecting, assessing and responding to security incidents, including the breach notification in section 9.
- Deletion. Deletion follows the periods in section 8, including for backups.
Syncropic does not currently hold a third-party security certification or audit report and does not claim one.
Annex III: Transfer mechanism
A. EU Standard Contractual Clauses
For transfers of Customer Data protected by the GDPR, the SCCs are incorporated into this DPA and completed as follows:
- Module: Module Two (controller to processor) where the Controller is a controller; Module Three (processor to processor) where the Controller is a processor for its own customers.
- Clause 7 (docking clause): included.
- Clause 9 (use of subprocessors): Option 2, general written authorisation, with the notice period in section 5.2 of this DPA (30 days).
- Clause 11 (redress): the optional language is not included.
- Clause 13 (supervision): the supervisory authority identified in Annex I.C.
- Clause 17 (governing law): Option 1, the law of Ireland.
- Clause 18 (choice of forum and jurisdiction): the courts of Ireland.
- Annex I of the SCCs: Annex I of this DPA.
- Annex II of the SCCs: Annex II of this DPA.
- Annex III of the SCCs (list of subprocessors): the Subprocessor List.
The parties acknowledge that Syncropic is directly subject to the GDPR for some of its processing under Article 3(2). Pending the adoption by the European Commission of standard contractual clauses for that situation, the parties agree that the SCCs apply to transfers of Customer Data as set out above.
B. UK International Data Transfer Addendum
For transfers of Customer Data protected by the UK GDPR, the UK Addendum is incorporated into this DPA and completed as follows: Table 1 (parties) is Annex I.A; Table 2 (selected SCCs, modules and clauses) is the SCCs as completed in Part A above; Table 3 (appendix information) is Annexes I, II and the Subprocessor List; Table 4 (ending the Addendum when the approved Addendum changes): the importer may end the Addendum as set out in section 19 of the Addendum.
C. Switzerland
For transfers of Customer Data protected by the Swiss Federal Act on Data Protection, the SCCs apply with these adaptations: references to the GDPR are read as references to the Swiss Act; the competent supervisory authority under Clause 13 is the Swiss Federal Data Protection and Information Commissioner; references to a "member state" include Switzerland, so that Swiss data subjects may exercise their rights in Switzerland; and the SCCs protect the data of legal entities to the extent the Swiss Act does.
D. Other jurisdictions
Where another Data Protection Law requires a specific transfer mechanism, the parties will agree an appropriate one in writing, and section 11.3 applies.