This agreement sets out how we handle personal data on behalf of the organizations that use SynaiConnect. It is the Art. 28 processor agreement, and it forms part of our Terms and Conditions.
1.Scope and roles
This Data Processing Agreement (“DPA”) forms part of the Terms and Conditions between Synai Core Technologies LLC of 8164 Ibis Cove Circle, Naples, FL 34119, United States(“we”, the processor) and the organization using SynaiConnect (“you”, the controller). It applies whenever we process personal data on your behalf under the GDPR, the UK GDPR, or comparable law.
You are the controller of your member records: you decide what to collect, who on your staff may see it, and how long to keep it. We process it only on your instructions and never for our own purposes. Where we act as controller instead — your administrators’ account details, billing, support correspondence, and the operational logs we keep to run and secure the Service — this DPA does not apply and our Privacy Policy governs.
Accepting the Terms accepts this DPA. If your own procurement process needs a counter-signed copy, write to legal@synaiconnect.com.
2.Our instructions from you
We process personal data only to provide the Service as described in the Terms and the Privacy Policy, and to comply with law. The subject matter, duration, nature and purpose of the processing, the categories of data and of data subjects are set out in our Privacy Policy §3 and §4.
If we believe an instruction from you would breach data protection law, we will tell you and may pause that processing rather than carry it out. If we are required by law to process data in a way your instructions do not cover, we will tell you before doing so unless the law forbids us from saying.
3.Confidentiality and staff
Access to your data is limited to personnel who need it to run or support the Service, each under a duty of confidentiality that survives the end of their engagement. We do not sell personal data and do not use your member data to train models.
4.Security measures
Art. 32 measures we maintain:
- Encryption in transit and at rest.
- Tenant isolation enforced in the database itself (row-level security), not only in application code.
- Role-based access control at the level of individual permissions, so you can grant a staff member the ability to view the directory without the ability to export or delete from it.
- Audit logging of changes to member records, with the detailed payload and any IP address removed after 90 days.
- Automated enforcement of the retention periods in our Privacy Policy §7, so they are applied by a scheduled job rather than by hand.
- Error monitoring configured to mask text and block media in any recording.
5.Helping you meet your own obligations
We provide the tools for you to answer data-subject requests yourself rather than routing them through us, which is faster for the member and keeps the decision with the controller:
- Erasure — a member can delete their own account in the app or from our account deletion page, and your administrators can delete a member from the directory. Both run the same permanent erasure.
- Access and portability — on request we produce a member’s data as a machine-readable bundle (JSON plus spreadsheet files). Ask us at the address in §11 and we will run it for you; self-service is coming.
- Correction — members edit their own profile; administrators can edit any field.
We will also assist you, at your reasonable request, with data protection impact assessments and with prior consultation of a supervisory authority.
6.Sub-processors
You authorise us to engage the sub-processors below. We remain responsible for their performance and impose data protection terms on each of them no less protective than this DPA.
Changes. We will give you at least 30 days’ notice before adding or replacing a sub-processor. If you reasonably object on data protection grounds within that period, tell us — we will work with you to find an alternative, and if none exists you may terminate the affected part of the Service without penalty.
| Sub-processor | Purpose | Country |
|---|---|---|
| Supabase | Database, authentication and file storage | United States |
| Vercel | Application hosting and content delivery | United States |
| Amazon Web Services | Media storage and processing, transactional email, background job queues, live video | United States |
| Stripe | Payment and donation processing | United States |
| Twilio | SMS and voice messaging | United States |
| The Campaign Registry | SMS sender registration required by US mobile carriers | United States |
| Vapi | Automated voice calling, including call recordings and transcripts | United States |
| GetStream | In-app chat and activity feeds | United States |
| OpenAI | Assistive drafting, translation, and message triage | United States |
| Google (Gemini API) | Live caption translation and caption context | United States |
| Soniox | Live speech-to-text and speech synthesis for captions | United States |
| Speechmatics | Live speech-to-text for captions | United Kingdom |
| ElevenLabs | Speech synthesis for translated captions | United States |
| Google Firebase | Mobile push notification delivery only | United States |
| Cookiebot (Usercentrics) | Cookie consent management and consent records | Denmark |
| Sentry | Error monitoring and crash diagnostics | United States |
7.International transfers
Most of our sub-processors are in the United States, as the table above shows. Where we transfer personal data out of the EEA, the UK or Switzerland, we rely on the European Commission’s Standard Contractual Clauses (and the UK Addendum where the UK GDPR applies), together with the technical measures in §4.
We will provide a copy of the relevant transfer terms on request to legal@synaiconnect.com.
8.Personal data breaches
We will notify you without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting your data. The notice will describe what we know at the time — the nature of the breach, the categories and approximate number of records and data subjects affected, the likely consequences, and the measures taken or proposed — and we will follow up as the picture becomes clearer. Notifying your supervisory authority and, where required, your members remains your decision as controller; we will give you the information you need to make it.
9.Return and deletion on termination
When your subscription ends you have 30 days to export your data, during which your administrators keep read and export access. After that we delete it within 90 days, except where law requires us to keep something — donation records being the usual case.
Deleted data is removed from active systems immediately and ages out of encrypted backups on their normal rotation. On written request we will confirm deletion.
10.Audits and information rights
On request, and no more than once a year, we will complete a reasonable security questionnaire and provide the evidence needed to demonstrate compliance with this DPA.
Where a questionnaire leaves a documented finding unresolved, or a supervisory authority requires it, you may audit the relevant processing on reasonable notice, during business hours, in a way that does not compromise the confidentiality of our other customers’ data. We would rather commit to something we can honour than grant an unqualified on-site right we could not.
11.Contact
Data protection questions: office@synaiconnect.com. Contractual questions about this DPA: legal@synaiconnect.com. Postal address: 8164 Ibis Cove Circle, Naples, FL 34119, United States. We have not appointed a Data Protection Officer; enquiries go to the addresses above.