How these annexes work
These annexes form part of the Syncura Data Processing Agreement (the “DPA”), which is itself incorporated into the SaaS Subscription Agreement. The DPA cross-references them at §5.2 and §6.
Annex A is designed to be updated without re-executing the DPA. Subprocessors change; a DPA should not have to be re-signed each time. The DPA obliges Syncura to maintain the list and give notice of material changes, so Annex A is the living document that obligation points at.
Annexes C and D — the EU Standard Contractual Clauses and the UK International Data Transfer Addendum — apply only where Personal Data originates in the European Economic Area, the United Kingdom, or Switzerland. They are not included in this edition. Where such a transfer arises, those mechanisms apply as provided in §7 of the DPA and the completed instruments are supplied with it.
Annex A — Subprocessors
This Annex lists the subprocessors engaged by Syncura to process Personal Data on behalf of Customer, as contemplated by §6 of the DPA.
A.1 Current subprocessors
Amazon Web Services, Inc. (AWS)
Service provided: cloud infrastructure and hosting.
Processing location: United States (US East region).
Transfer safeguard: AWS Data Processing Addendum, incorporated into the AWS Service Terms and applying without separate execution; contractual accountability under PIPEDA.
This list is current as at the Effective Date. Annex A is maintained under §A.2 and is updated by notice rather than by amending the DPA, so it does not require re-execution when a subprocessor changes.
A.2 Notice of changes
Syncura will give Customer at least thirty (30) days' notice before engaging a new subprocessor that will process Personal Data, or replacing an existing one. Notice will identify the subprocessor, the service it provides, and the processing location.
Customer may object on reasonable data-protection grounds within the notice period. The parties will work in good faith to resolve the objection. If it cannot be resolved, Customer may terminate the affected part of the Service without penalty for the remainder of the then-current Subscription Term.
A.3 Responsibility
Syncura remains responsible for the performance of its subprocessors and will impose data protection obligations on them no less protective than those in the DPA.
Annex B — Technical and Organisational Measures
These are the measures referred to in §5.2 of the DPA and, where the EU Standard Contractual Clauses apply, they constitute Annex II to those Clauses.
They are consistent with the practices described in the Syncura Security & Compliance Overview. That document is informational; the measures set out in this Annex are contractual.
B.1 Security governance
- Security is treated as an architectural principle rather than a bolt-on, with responsibility shared across engineering, operations and leadership.
- Least-privilege access, defence-in-depth, separation of customer environments, and continuous monitoring and improvement.
- The security programme is aligned with the SOC 2 Trust Services Criteria (security, availability, confidentiality), ISO/IEC 27001 principles, and the NIST Cybersecurity Framework. Syncura does not hold SOC 2 or ISO 27001 certification. Alignment is not certification.
B.2 Access control and identity
- Role-based access control (RBAC).
- Multi-factor authentication for administrative access.
- Access granted on a least-privilege basis and reviewed periodically.
- Personnel authorised to process Personal Data are bound by written confidentiality obligations that survive the end of their engagement.
B.3 Encryption and key management
- Encryption in transit using industry-standard protocols.
- Encryption at rest for systems storing Customer Data and Outputs.
- Secure key management practices, with keys held separately from the data they protect.
B.4 Segregation and isolation
- Logical isolation between customer environments.
- Segmentation between processing, storage and management systems.
B.5 Availability, resilience and restoration
- Customer Data, including Personal Data, is hosted on managed database infrastructure with a standby replica maintained alongside the primary database.
- Full backups are taken nightly from the standby replica, so that backup activity does not affect the production database.
- Database transaction logs are streamed continuously to object storage (Amazon S3), supporting point-in-time restoration between nightly backups.
- Failover from the primary to the standby database, and restoration from backup, have been tested. Syncura has not established a fixed schedule for restoration testing.
- Syncura has not defined a Recovery Point Objective or a Recovery Time Objective. No RPO or RTO is committed under this Annex or the DPA.
B.6 Data lifecycle, minimisation and retention
- Personal Data is processed only to provide, secure and support the Service, in accordance with the DPA and Customer's documented instructions.
- Defined lifecycle practices covering ingestion, processing, storage, retrieval and deletion.
- Retention is configurable: the applicable period is agreed with Customer during onboarding and may be adjusted on request.
- Only limited non-content metadata is retained beyond the configured period, and only for usage metering, billing, security and service integrity.
- On termination, Personal Data is deleted or returned within thirty (30) days unless a longer period is required by law or agreed in writing.
B.7 Incident detection and response
- Continuous monitoring for suspicious activity.
- Documented incident response procedures with defined escalation paths.
- Notification to Customer without undue delay and in any event within seventy-two (72) hours of becoming aware of a Personal Data breach, with the information Customer needs to meet its own notification obligations.
B.8 Assurance and testing
- Syncura has not, to date, engaged a third party to perform penetration testing or an independent security assessment of the Service. Syncura is evaluating independent security testing; nothing in this Annex constitutes a commitment to perform such testing during the term.
- Syncura will make available information reasonably necessary to demonstrate compliance with the DPA. Formal on-site audits are excluded unless required by Applicable Data Protection Laws.
B.9 Subprocessor management
- Subprocessors are subject to contractual security and confidentiality obligations no less protective than those in the DPA.
- Syncura remains responsible for its subprocessors' performance.
- The current list is maintained in Annex A, with thirty (30) days' notice of material changes.