Dieses Dokument liegt nur auf Englisch vor, und die englische Fassung ist die verbindliche. Die Seite drumherum ist in deiner Sprache, der Vertrag nicht. Bei Fragen auf Deutsch schreib an legal@syncek.com.

Auftragsverarbeitungsvertrag

Die Vereinbarung nach Art. 28 DSGVO, die regelt, wie Syncek personenbezogene Daten in deinem Auftrag verarbeitet.

Zuletzt aktualisiert: 26. August 2026

This Data Processing Addendum ("DPA") supplements the Terms of Service ("Agreement") between Syncek LLC ("Syncek", "Processor") and you or the organization you represent ("Customer", "Controller"). It is accepted on a click-through basis when you accept the Terms: by entering into the Agreement you also enter into this DPA for any Customer Data that constitutes personal information under applicable data-protection law. A counter-signed PDF version is available on request at legal@syncek.com;the click-through and counter-signed versions are legally equivalent.

This DPA is drafted to satisfy Art. 28 of Regulation (EU) 2016/679 (GDPR), Art. 28 of the UK GDPR, and the Swiss Federal Act on Data Protection (FADP). In the event of any conflict between this DPA and the Agreement, this DPA prevails as to the processing of personal information.

Current scope, as of the date above. Syncek is in closed beta and the Service is not yet generally available, so there is not yet any Customer Personal Data processed under this DPA. It is published now so that you can review it before you decide to sign up, and it takes effect for you on the day you enter into the Agreement.

1. Definitions

Capitalized terms not defined here have the meanings given in the Terms of Service. In addition:

  • Applicable Data Protection Law means the GDPR, the UK GDPR, the Swiss FADP, the US state privacy laws listed in Section 13, and any other data-protection law applicable to a party's processing of personal information under the Agreement.
  • Customer Personal Data means personal information (as defined by Applicable Data Protection Law) contained in Customer Data and processed by Syncek on Customer's behalf under the Agreement.
  • Data Subject, Controller, Processor, Sub-processor, Personal Data Breach, and Supervisory Authority have the meanings given in Art. 4 GDPR.
  • EU SCCs means the Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914.
  • UK IDTA means the UK International Data Transfer Addendum to the EU SCCs, issued by the UK Information Commissioner under s.119A of the UK Data Protection Act 2018.

2. Roles and scope

Customer is either the Controller of the Customer Personal Data it uploads, or a Processor acting on behalf of a third-party controller, which is the ordinary case for an agency operating a client book in Syncek. Syncek is in both cases the Processor, or the Sub-processor where Customer is itself a processor; Section 6 selects the SCC module from that same fact. Customer determines the purposes and means of processing and remains responsible for its lawful basis, notice, and data-subject rights toward the individuals whose data it uploads. Where Customer acts as a processor, Customer warrants that the instructions it gives Syncek are consistent with those it has received from its own controller, and remains responsible for that chain.

3. Duration, nature, purpose, and categories of data

  • Duration. This DPA applies for the duration of the Agreement plus any period during which Syncek retains Customer Personal Data under Section 9.
  • Nature and purpose of processing. Hosting, storing, organizing, structuring, retrieving, consulting, adapting, transmitting, backing up, and deleting Customer Personal Data in order to provide the Service (a CRM platform) to Customer.
  • Categories of Data Subjects. Customer's contacts, leads, prospects, customers, vendors, partners, employees, and any other individuals whose information Customer uploads to a Syncek workspace; and Customer's own personnel (workspace members).
  • Categories of Customer Personal Data. Names, email addresses, phone numbers, postal addresses, employer, job title, opportunity/pipeline information, activity and communication logs, notes, uploaded files, and any custom fields Customer configures. Customer is contractually prohibited from uploading special-category data (Art. 9 GDPR), U.S. PHI, PCI card numbers beyond Stripe's scope, or children's data (see the Acceptable Use Policy).

4. Syncek's obligations as Processor (Art. 28(3) GDPR)

  • Documented instructions. Syncek processes Customer Personal Data only on Customer's documented instructions, including those set out in the Agreement, configuration of the Service, and written follow-up instructions: unless required to do otherwise by Union or Member State law, in which case Syncek will inform Customer of that legal requirement before processing, unless prohibited by law. Compulsion under United States law is dealt with separately in the next bullet, because Art. 28(3)(a) does not treat third-country law as an instruction override.
  • Government and law-enforcement requests. Syncek is established in the United States and may receive compulsory requests for Customer Personal Data under US law. If Syncek receives such a request, it will: review it for validity and challenge any request that is overbroad or unlawful; disclose only the minimum data necessary to comply; and notify Customer before disclosure, or as soon afterwards as permitted, unless legally prohibited from doing so. Syncek will provide Customer with the information it needs for its own transfer-impact assessment on request.
  • Unlawful instructions. Syncek will immediately inform Customer if, in its opinion, an instruction infringes the GDPR, the UK GDPR, the Swiss FADP or another provision of Union or Member State data-protection law, and may suspend the affected instruction until Customer confirms, withdraws or amends it. This is the duty in the final paragraph of Art. 28(3) GDPR.
  • Confidentiality. Syncek ensures that persons authorized to process Customer Personal Data are bound by confidentiality obligations.
  • Security. Syncek implements the technical and organizational measures described in Annex II (Section 12 below) to ensure a level of security appropriate to the risk (Art. 32 GDPR).
  • Sub-processors. Section 5.
  • Assistance with Data Subject rights. Taking into account the nature of the processing, Syncek assists Customer by providing features that enable Customer to respond to data-subject requests (access, rectification, erasure, restriction, portability, objection): principally, export and deletion tools within the Service. Where a feature is not sufficient, Syncek will assist by other reasonable means upon written request.
  • Assistance with DPIAs and Supervisory Authority consultations. Upon request, Syncek will assist Customer with Arts. 32-36 GDPR taking into account the information available to Syncek.
  • Breach notification. Syncek will notify Customer without undue delay and, where feasible, within forty-eight (48) hours after becoming aware of a Personal Data Breach affecting Customer Personal Data, providing the information reasonably necessary for Customer to meet its own notification duties under Arts. 33-34 GDPR. That clock starts on awareness, not on the close of an investigation; a first notification may be preliminary, and Syncek follows it with the remaining detail as it is established.
  • Deletion or return. Upon termination of the Agreement, Syncek will delete Customer Personal Data from production systems promptly and from routine backups within thirty (30) days, unless Union or Member State law requires continued storage. Customer may export its data from the Service before deletion.
  • Audit. Syncek will make available to Customer information necessary to demonstrate compliance with Art. 28 GDPR. On reasonable prior written request and no more than once per year (save in the event of a confirmed Personal Data Breach), Customer or an independent auditor mandated by Customer may audit Syncek's compliance; Syncek may satisfy the audit right by providing then-current third-party audit reports or security questionnaires.

5. Sub-processors (Art. 28(2)-(4) GDPR)

Customer provides a general written authorization for Syncek to engage the sub-processors listed on our Sub-processors page, together with any additional sub-processors Syncek notifies under this Section.

Before engaging a new or replacing an existing sub-processor, Syncek will update the sub-processors list and provide at least thirty (30) days' advance notice. Customer may object on reasonable grounds related to data protection by written notice to legal@syncek.com within that 30-day window. If the parties cannot agree on a resolution, Customer may terminate the affected Service on written notice, and Syncek will refund any prepaid fees for services not yet rendered in the terminated portion.

Syncek imposes on each sub-processor, by written contract, the same data-protection obligations as are set out in this DPA, as Art. 28(4) GDPR requires, and remains liable for the acts and omissions of its sub-processors as if they were its own. The Sub-processors page states the same standard.

6. International data transfers (Chapter V GDPR)

Customer Personal Data is stored in the European Union and United States. Where transfers to third countries are required to provide the Service:

  • EU-US Data Privacy Framework. Where the recipient is certified under the EU-US DPF, the transfer is made in reliance on the Commission's adequacy decision of 10 July 2023. If that decision is annulled, suspended, or withdrawn, or if the recipient ceases to be certified, the EU SCCs described in the next paragraph apply automatically to those transfers from that date, with no further action required by either party.
  • EU SCCs. Where the DPF is unavailable and the recipient is outside the EEA or a country with an adequacy decision, the parties hereby enter into the EU SCCs, which are incorporated into this DPA by reference. Which module applies depends on Customer's own role, not on ours: Module Two (Controller-to-Processor) where Customer is the controller of the Customer Personal Data it uploads, and Module Three (Processor-to-Processor) where Customer is itself a processor acting for a third-party controller , which is the ordinary case for an agency operating a client book in Syncek. The selected module is completed as follows: (i) Clause 7 (docking clause) is included; (ii) Clause 9 option 2 (general authorization) applies with a 30-day change-notice period; (iii) Clause 11: no independent dispute-resolution body is designated; (iv) Clause 17 governing law: Option 2, the law of the EU Member State in which Customer is established, falling back to the law of Ireland where Customer's own Member State does not allow third-party beneficiary rights; (v) Clause 18 forum: the courts of Ireland, Clause 18(b) requiring a single named Member State; (vi) Annex I.A lists the parties (Customer as data exporter, Syncek as data importer); (vii) Annex I.B references Section 3 of this DPA; (viii) Annex I.C identifies the competent Supervisory Authority as the authority of the Member State in which Customer is established; (ix) Annex II references Section 12 of this DPA; (x) Annex III references the sub-processors list on our Sub-processors page.
  • UK IDTA. For transfers subject to the UK GDPR, the parties enter into the UK IDTA, which modifies the EU SCCs as necessary to comply with UK law.
  • Swiss FADP. For transfers subject to Swiss law, references to the GDPR in the EU SCCs are read as references to the FADP, the competent authority is the FDPIC, and the clauses protect Swiss residents' rights.
  • Supplementary measures. TLS in transit, encryption at rest, strict role-based access control, audit logging, and transfer-impact assessments where required.

7. Data subject requests

If Syncek receives a request from a Data Subject concerning Customer Personal Data, we will without undue delay inform the Data Subject that Customer is the Controller and will refer the request to Customer, unless Applicable Data Protection Law prohibits such referral.

8. Customer obligations

Customer warrants and undertakes that:

  • it has established, and will maintain throughout the duration of the Agreement, a lawful basis for the processing of Customer Personal Data under Art. 6 GDPR (and, if applicable, Arts. 9-10 GDPR);
  • it has provided the transparency information required by Arts. 13-14 GDPR to Data Subjects;
  • its instructions to Syncek will at all times comply with Applicable Data Protection Law; and
  • it will not upload Customer Personal Data that the Service is not authorized to process under the Agreement or the Acceptable Use Policy.

9. Return and deletion

During the Agreement, Customer can at any time export Customer Personal Data or delete workspace objects using in-product tools. On termination or expiry, Customer may elect in writing, within thirty (30) days, either the return of Customer Personal Data in a structured, commonly used, machine-readable format, or its deletion (Art. 28(3)(g) GDPR). Self-service export stays available throughout that window. Absent an election, Syncek deletes, and certifies deletion in writing on request. Syncek will delete Customer Personal Data from production systems within a reasonable period (typically within thirty (30) days) and from routine backups within thirty (30) days of deletion, matching the rolling backup retention in Section 12. Where Union or Member State law requires continued storage, Syncek will isolate the data, keep it encrypted and inaccessible, and delete it when the requirement lapses.

10. Liability

Each party's liability under this DPA is subject to the aggregate limitation of liability set out in the Agreement. Nothing in this DPA limits liabilities that cannot be excluded under Applicable Data Protection Law, including liability of either party to Data Subjects under Art. 82 GDPR.

11. Governing law; order of precedence; termination

This DPA is governed by the laws of the State of Wyoming, USA, whose state and federal courts have exclusive jurisdiction, subject to the consumer carve-out in the Terms of Service. In the event of conflict between this DPA and the EU SCCs, the EU SCCs prevail; in the event of conflict between this DPA and the Agreement, this DPA prevails as to the processing of personal information. This DPA terminates automatically upon termination of the Agreement, without prejudice to obligations that by their nature survive.

12. Annex II: Technical and organizational measures (Art. 32 GDPR)

  • Encryption. TLS 1.2 or higher for data in transit; AES-256 or equivalent for data at rest. Sensitive customer secrets (API credentials, integration tokens) are encrypted at the application layer using a key-management service.
  • Access control. Role-based access for Syncek personnel with least-privilege defaults, multi-factor authentication, and centralized identity.
  • Confidentiality of personnel. All personnel bound by written confidentiality obligations; access granted on a need-to-know basis and revoked on role change or termination.
  • Data segregation. Logical segregation of customer workspaces at the application layer; row-level tenancy enforced by workspace identifiers on every query.
  • Vulnerability management. Automated dependency and code scanners; patching prioritized by severity; penetration testing cadence published on our Security page.
  • Logging and monitoring. Security and audit logs collected and retained with integrity protections; alerting for anomalous access or authentication.
  • Backup and recovery. Regular automated backups; documented recovery procedures; backup retention limited to thirty (30) days in rolling production backups.
  • Incident response. Formal incident-response plan with roles, escalation paths, and notification to Customer on the timetable in Section 4.
  • Physical security. Provided by our cloud and colocation vendors; certifications (e.g., ISO 27001, SOC 2) documented by each vendor.
  • Organizational measures. Privacy-by-design in feature planning; periodic training for personnel who process Customer Personal Data; written policies on access control, cryptography, and secure development.

13. US state privacy laws

This Section applies where Customer is subject to the California Consumer Privacy Act as amended by the CPRA, or to the comprehensive privacy laws of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana or another US state with equivalent terms. It exists because the CCPA does not infer a service-provider relationship from conduct: it requires it in the contract, and without these covenants a customer's disclosure of personal information to Syncek is arguably a sale, which would make that customer's own privacy disclosures wrong.

For personal information Customer discloses to Syncek, Syncek is a service provider (CCPA) or processor (other states), and Customer is the business or controller. Syncek:

  • will not sell or share that personal information as those terms are defined by the applicable statute, for any consideration or for cross-context behavioral advertising;
  • will not retain, use, or disclose it for any purpose other than the following limited and specified business purposes: hosting, storing, organizing, structuring, retrieving, consulting, adapting, transmitting, backing up and deleting Customer Personal Data in order to operate the Service for Customer; providing technical support; securing the Service and detecting, preventing and investigating security incidents, fraud and unlawful activity; and complying with legal obligations. It will not retain, use or disclose that personal information for any commercial purpose of its own, or outside the direct business relationship between the parties;
  • will not combine it with personal information received from, or on behalf of, any other person, except as the statute permits a service provider to do;
  • will comply with all applicable obligations under those laws and provide the same level of privacy protection for that personal information as those laws require of Customer (Cal. Civ. Code §1798.100(d)(2));
  • grants Customer the right to take reasonable and appropriate steps to ensure that Syncek uses that personal information consistently with Customer's own obligations, including assessments, audits or other technical and operational testing at least once every twelve (12) months. Syncek may satisfy this by providing then-current third-party audit reports or completed security questionnaires;
  • certifies that it understands these restrictions and will comply with them, and will notify Customer promptly if it determines it can no longer meet them;
  • imposes the same restrictions on every sub-processor it engages, and remains responsible for their compliance; and
  • grants Customer the right, on reasonable notice, to take reasonable and appropriate steps to stop and remediate unauthorized use of personal information.

Syncek assists Customer in responding to verifiable consumer requests to know, delete, correct, and opt out, through the same export and deletion tooling described in Section 4. Deidentified data, where used, is maintained without attempting to reidentify it.

14. Contact

Questions about this DPA or to request a counter-signed copy: legal@syncek.com.