Legal

Data Processing Agreement

The Article 28 processor agreement: how we handle personal data on behalf of organizations using SynaiConnect, and what we commit to.

Last updated: August 18, 2026

This agreement sets out how we handle personal data on behalf of the organizations that use SynaiConnect. It is the Art. 28 processor agreement, and it forms part of our Terms and Conditions.

1.Scope and roles

This Data Processing Agreement (“DPA”) forms part of the Terms and Conditions between Synai Core Technologies LLC of 8164 Ibis Cove Circle, Naples, FL 34119, United States(“we”, the processor) and the organization using SynaiConnect (“you”, the controller). It applies whenever we process personal data on your behalf under the GDPR, the UK GDPR, or comparable law.

You are the controller of your member records: you decide what to collect, who on your staff may see it, and how long to keep it. We process it only on your instructions and never for our own purposes. Where we act as controller instead — your administrators’ account details, billing, support correspondence, and the operational logs we keep to run and secure the Service — this DPA does not apply and our Privacy Policy governs.

Accepting the Terms accepts this DPA. If your own procurement process needs a counter-signed copy, write to legal@synaiconnect.com.

2.Our instructions from you

We process personal data only to provide the Service as described in the Terms and the Privacy Policy, and to comply with law. The subject matter, duration, nature and purpose of the processing, the categories of data and of data subjects are set out in our Privacy Policy §3 and §4.

If we believe an instruction from you would breach data protection law, we will tell you and may pause that processing rather than carry it out. If we are required by law to process data in a way your instructions do not cover, we will tell you before doing so unless the law forbids us from saying.

3.Confidentiality and staff

Access to your data is limited to personnel who need it to run or support the Service, each under a duty of confidentiality that survives the end of their engagement. We do not sell personal data and do not use your member data to train models.

4.Security measures

Art. 32 measures we maintain:

  • Encryption in transit and at rest.
  • Tenant isolation enforced in the database itself (row-level security), not only in application code.
  • Role-based access control at the level of individual permissions, so you can grant a staff member the ability to view the directory without the ability to export or delete from it.
  • Audit logging of changes to member records, with the detailed payload and any IP address removed after 90 days.
  • Automated enforcement of the retention periods in our Privacy Policy §7, so they are applied by a scheduled job rather than by hand.
  • Error monitoring configured to mask text and block media in any recording.

5.Helping you meet your own obligations

We provide the tools for you to answer data-subject requests yourself rather than routing them through us, which is faster for the member and keeps the decision with the controller:

  • Erasure — a member can delete their own account in the app or from our account deletion page, and your administrators can delete a member from the directory. Both run the same permanent erasure.
  • Access and portability — on request we produce a member’s data as a machine-readable bundle (JSON plus spreadsheet files). Ask us at the address in §11 and we will run it for you; self-service is coming.
  • Correction — members edit their own profile; administrators can edit any field.

We will also assist you, at your reasonable request, with data protection impact assessments and with prior consultation of a supervisory authority.

6.Sub-processors

You authorise us to engage the sub-processors below. We remain responsible for their performance and impose data protection terms on each of them no less protective than this DPA.

Changes. We will give you at least 30 days’ notice before adding or replacing a sub-processor. If you reasonably object on data protection grounds within that period, tell us — we will work with you to find an alternative, and if none exists you may terminate the affected part of the Service without penalty.

Sub-processorPurposeCountry
SupabaseDatabase, authentication and file storageUnited States
VercelApplication hosting and content deliveryUnited States
Amazon Web ServicesMedia storage and processing, transactional email, background job queues, live videoUnited States
StripePayment and donation processingUnited States
TwilioSMS and voice messagingUnited States
The Campaign RegistrySMS sender registration required by US mobile carriersUnited States
VapiAutomated voice calling, including call recordings and transcriptsUnited States
GetStreamIn-app chat and activity feedsUnited States
OpenAIAssistive drafting, translation, and message triageUnited States
Google (Gemini API)Live caption translation and caption contextUnited States
SonioxLive speech-to-text and speech synthesis for captionsUnited States
SpeechmaticsLive speech-to-text for captionsUnited Kingdom
ElevenLabsSpeech synthesis for translated captionsUnited States
Google FirebaseMobile push notification delivery onlyUnited States
Cookiebot (Usercentrics)Cookie consent management and consent recordsDenmark
SentryError monitoring and crash diagnosticsUnited States

7.International transfers

Most of our sub-processors are in the United States, as the table above shows. Where we transfer personal data out of the EEA, the UK or Switzerland, we rely on the European Commission’s Standard Contractual Clauses (and the UK Addendum where the UK GDPR applies), together with the technical measures in §4.

We will provide a copy of the relevant transfer terms on request to legal@synaiconnect.com.

8.Personal data breaches

We will notify you without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting your data. The notice will describe what we know at the time — the nature of the breach, the categories and approximate number of records and data subjects affected, the likely consequences, and the measures taken or proposed — and we will follow up as the picture becomes clearer. Notifying your supervisory authority and, where required, your members remains your decision as controller; we will give you the information you need to make it.

9.Return and deletion on termination

When your subscription ends you have 30 days to export your data, during which your administrators keep read and export access. After that we delete it within 90 days, except where law requires us to keep something — donation records being the usual case.

Deleted data is removed from active systems immediately and ages out of encrypted backups on their normal rotation. On written request we will confirm deletion.

10.Audits and information rights

On request, and no more than once a year, we will complete a reasonable security questionnaire and provide the evidence needed to demonstrate compliance with this DPA.

Where a questionnaire leaves a documented finding unresolved, or a supervisory authority requires it, you may audit the relevant processing on reasonable notice, during business hours, in a way that does not compromise the confidentiality of our other customers’ data. We would rather commit to something we can honour than grant an unqualified on-site right we could not.

11.Contact

Data protection questions: office@synaiconnect.com. Contractual questions about this DPA: legal@synaiconnect.com. Postal address: 8164 Ibis Cove Circle, Naples, FL 34119, United States. We have not appointed a Data Protection Officer; enquiries go to the addresses above.