Legal
Syncura's data protection obligations where it processes Personal Data on a customer's behalf. This DPA forms part of, and is incorporated into, the SaaS Subscription Agreement.
This Data Processing Agreement (“DPA”) forms part of, and is incorporated into, the SaaS Subscription Agreement (the “Agreement”) between Syncura and Customer. This DPA applies where Syncura processes Personal Data on behalf of Customer in connection with the Service.
1. Definitions
“Applicable Data Protection Laws” means all data protection and privacy laws applicable to the processing of Personal Data under the Agreement, including, as applicable, the GDPR, UK GDPR, CCPA/CPRA, and comparable laws.
“Controller” and “Processor” have the meanings given under Applicable Data Protection Laws.
“Personal Data” means any information relating to an identified or identifiable natural person processed by Syncura on behalf of Customer.
“Processing” means any operation performed on Personal Data, as defined under Applicable Data Protection Laws.
2. Roles of the Parties
Customer is the Controller of Personal Data processed under the Agreement. Syncura acts as a Processor (or service provider / processor equivalent under Applicable Data Protection Laws) when processing Personal Data on behalf of Customer.
For the purposes of the CCPA/CPRA, Syncura is a “service provider” and Customer is a “business”. Syncura will not: (a) sell or share Personal Data; (b) retain, use, or disclose Personal Data for any purpose other than performing the Service under the Agreement, or as otherwise permitted by the CCPA/CPRA; (c) use Personal Data for cross-context behavioural advertising; or (d) combine Personal Data with personal information received from another source, except as permitted by the CCPA/CPRA. Syncura will notify Customer if it determines that it can no longer meet these obligations.
3. Scope and Purpose of Processing
Syncura will process Personal Data solely for the purposes of providing, securing, and supporting the Service, in accordance with the Agreement, this DPA, and documented instructions from Customer.
The categories of Personal Data, data subjects, nature of processing, and duration of processing are described in Annex E below.
4. Customer Obligations
Customer represents and warrants that: it has a lawful basis to process and disclose Personal Data to Syncura; it has provided all required notices and obtained any required consents; and its instructions comply with Applicable Data Protection Laws.
Customer is responsible for determining whether the Service is appropriate for processing Personal Data and for configuring the Service in accordance with its compliance obligations.
5. Syncura Obligations
5.1 Confidentiality
Syncura will ensure that personnel authorized to process Personal Data are subject to confidentiality obligations.
5.2 Security Measures
Syncura will implement appropriate administrative, technical, and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. The measures in place as at the Effective Date are described in Annex B (Technical and Organisational Measures).
5.3 Incident Notification
Syncura will notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data breach involving Personal Data processed under this DPA and will provide information reasonably required for Customer to comply with breach notification obligations.
5.4 Assistance
Taking into account the nature of processing, Syncura will provide reasonable assistance to Customer in responding to data subject requests and regulatory inquiries, to the extent required by Applicable Data Protection Laws.
6. Subprocessing
Customer authorizes Syncura to engage subprocessors to process Personal Data on its behalf. Syncura will impose data protection obligations on subprocessors consistent with this DPA and remains responsible for their performance.
Syncura will maintain a list of material subprocessors and provide notice of material changes where required by Applicable Data Protection Laws. The subprocessors engaged as at the Effective Date are listed in Annex A (Subprocessors).
7. International Data Transfers
Personal Data is hosted and processed in the United States (Amazon Web Services, US East region). Consistent with the accountability principle under PIPEDA and comparable laws, Syncura remains responsible for Personal Data processed by its subprocessors and ensures, by contract, a comparable level of protection while the data is processed on its behalf. Where Personal Data originates in the European Economic Area, the United Kingdom, or Switzerland, the EU Standard Contractual Clauses or the UK International Data Transfer Addendum apply, and the completed annexes to those instruments are provided with this DPA.
8. Data Retention and Deletion
Syncura will retain Personal Data only for as long as necessary to provide the Service, comply with legal obligations, or as otherwise permitted under the Agreement. Upon termination or expiration of the Agreement, Syncura will delete or return Personal Data in accordance with the Agreement and applicable law, and in any event within thirty (30) days, unless a longer period is required by law or expressly agreed in writing.
9. Audits
Upon reasonable written request and subject to confidentiality and security requirements, Syncura will make available information reasonably necessary to demonstrate compliance with this DPA. Formal on-site audits are excluded unless required by Applicable Data Protection Laws.
10. Liability
The liability of each party under this DPA is subject to the limitations of liability set forth in the Agreement.
11. Governing Law
This DPA is governed by the governing law specified in the Agreement.
Annex E — Processing Details
Nature of Processing: Automated ingestion, classification, extraction, transformation, and output of documents and data using AI-enabled workflows.
Categories of Data Subjects: Customer employees, contractors, clients, and other individuals whose data is submitted by Customer.
Categories of Personal Data: Identification data, contact information, document contents, and other data submitted by Customer.
Duration of Processing: For the Subscription Term and any additional period permitted under the Agreement or required by law.