Data Processing Addendum
Last updated: July 5, 2026
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between Synergy Technologies Inc (“Processor”) and the Customer (“Controller”) and applies where we process personal data on the Controller’s behalf. It is intended to support compliance with the GDPR, UK GDPR, and CCPA/CPRA. This is not a HIPAA Business Associate Agreement — PHI requires a separate BAA and an eligible product tier (see Terms §5).
1. Roles & scope
The Controller determines the purposes and means of processing Customer Personal Data; the Processor processes it only to provide the Services and on the Controller’s documented instructions (including the Terms).
2. Processor obligations
- Process personal data only on documented instructions and as needed to provide the Services.
- Ensure personnel are bound by confidentiality.
- Implement appropriate technical and organizational security measures (encryption in transit/at rest, access controls, logging, backups).
- Assist the Controller, taking into account the nature of processing, with data-subject requests and with security, breach-notification, and impact-assessment obligations.
- Notify the Controller without undue delay after becoming aware of a personal-data breach.
- Delete or return Customer Personal Data at the end of the Services, subject to legal retention.
- Make available information necessary to demonstrate compliance and allow for reasonable audits.
3. Subprocessors
The Controller authorizes the Processor to engage subprocessors (including cloud, storage, GPU, communications, and payment providers) under written terms imposing data-protection obligations no less protective than this DPA. A current list is available on request; we will give notice of material changes and an opportunity to object.
4. International transfers
Where personal data is transferred across borders, the parties will rely on an appropriate transfer mechanism (such as the EU Standard Contractual Clauses), which are incorporated by reference where applicable.
5. CCPA
With respect to California personal information, the Processor acts as a “service provider,” will not sell or share such information, and will not retain, use, or disclose it except to perform the Services or as permitted by the CCPA.
6. Security & breach
Security measures are described in the Privacy Policy and our security documentation. In the event of a breach affecting Customer Personal Data, we will provide information reasonably necessary for the Controller to meet its notification obligations.
7. Liability & term
This DPA is subject to the limitations of liability in the Terms and remains in effect for the duration of the processing. Contact: privacy@synergytech.cloud.