SyncWork
ProductPricingIndustriesSecurity
Sign In
ProductPricingIndustriesSecurity
Sign In

Product

  • Modules
  • Industries
  • Pricing
  • Security

Company

  • About Us
  • Contact

Legal

  • Terms of Service
  • Privacy Policy
  • Cookie Policy
  • Data Processing Agreement
  • Sub-processors
SyncWorkSyncWork© 2026 Syncs Digital Inc. All rights reserved.
Legal

Data Processing Agreement

Last updated: May 9, 2026

On this page

  • For Business Customers
  • 1. Definitions
  • 2. Scope and Purpose
  • 3. Data Processing Principles
  • 4. Data Location and Transfers
  • 5. Sub-processors
  • 6. Security Measures
  • 7. Data Subject Rights
  • 8. Data Breach Notification
  • 9. Audit Rights
  • 10. Applicable Data Protection Laws
  • 11. Governing Law
  • 12. Duration and Termination
  • 13. Contact Information

For Business Customers

This Data Processing Agreement (DPA) applies to business customers who process personal data using SyncWork services. For GDPR compliance, this DPA governs how SyncWork (as Data Processor) handles personal data on behalf of your organization (as Data Controller).

1. Definitions

"Personal Data" means any information relating to an identified or identifiable natural person.

"Data Controller" means the entity that determines the purposes and means of processing Personal Data (typically your organization).

"Data Processor" means the entity that processes Personal Data on behalf of the Data Controller (SyncWork).

"Sub-processor" means any third party engaged by SyncWork to process Personal Data.

2. Scope and Purpose

This DPA applies when SyncWork processes Personal Data on your behalf in connection with the SyncWork services. This DPA is entered into pursuant to, and forms part of, the Terms of Service ("Agreement").

2.1 Processing Purposes

SyncWork will only process Personal Data for the following purposes:

  • Providing, operating, and maintaining the SyncWork platform and its features
  • Processing AI-powered features (document analysis, OCR, search, recommendations)
  • Sending service-related communications (notifications, alerts)
  • Providing customer support and resolving technical issues
  • As necessary to comply with applicable laws
  • As otherwise agreed in writing with you

2.2 Categories of Data Subjects

  • Customer employees and authorized users of the Services
  • Customer's own clients, contacts, and end users whose data is uploaded to the Services
  • Individuals whose personal data is contained in documents uploaded to the Services

2.3 Categories of Personal Data

  • Contact Information: Names, email addresses, phone numbers, mailing addresses
  • Account Data: Usernames, profile information, authentication credentials
  • Usage Data: Service usage logs, feature interactions, IP addresses
  • Content Data: Documents, files, messages, and other content uploaded to the Services
  • Financial Data: Invoices, billing records, payment-related information stored within the Services

3. Data Processing Principles

SyncWork will:

  • Process Personal Data only on your documented instructions
  • Ensure that personnel processing Personal Data are bound by confidentiality obligations
  • Implement appropriate technical and organizational security measures
  • Assist you in responding to data subject requests
  • Delete or return Personal Data upon termination of services
  • Make available information necessary to demonstrate compliance

4. Data Location and Transfers

Important:SyncWork's infrastructure is hosted primarily in the United States. Your data will be transferred to, stored, and processed in the U.S. and other jurisdictions where our sub-processors operate.

Your data may be subject to the laws of those jurisdictions, including the USA PATRIOT Act and the CLOUD Act. For transfers from the EEA/UK, we rely on Standard Contractual Clauses (SCCs), Module 2 (Controller-to-Processor), per EU Commission Implementing Decision (EU) 2021/914. Under PIPEDA Principle 4.1.3, we use contractual obligations to ensure a comparable level of protection for all cross-border transfers.

5. Sub-processors

SyncWork engages the following categories of sub-processors to provide the services:

CategoryPurposeLocation
Cloud infrastructure, hosting & storageApplication servers, managed database, CDN, and encrypted object storageUnited States and European Union
Email & SMS deliveryTransactional email, notifications, and SMS verification codesUnited States
Payment processingSubscription billing, payment-method verification, and payoutsUnited States
AI processingDocument analysis and intelligent assistanceUnited States

We will notify you at least 30 days in advance of any intended changes to sub-processors by email to your account's billing contact. If you have a reasonable objection to a new sub-processor, you may notify us in writing within 15 days of receiving our notice. We will work with you to find a commercially reasonable alternative. If no resolution is possible, you may terminate the affected Services without penalty.

For the current full list of sub-processors, see our List of Sub-processors.

6. Security Measures

SyncWork implements the following security measures:

  • Encryption of data in transit (TLS 1.2+) and at rest (AES-256)
  • Multi-factor authentication for administrative access
  • Ongoing security assessments, including continuous automated security review of every code change
  • Access controls based on the principle of least privilege
  • Audit logging of system access and data modifications
  • Incident response and breach notification procedures

7. Data Subject Rights

SyncWork will assist you in responding to requests from data subjects exercising their rights under applicable data protection laws, including:

  • Right of access
  • Right to rectification
  • Right to erasure ("right to be forgotten")
  • Right to data portability
  • Right to object to processing
  • Right to restrict processing

8. Data Breach Notification

In the event of a Personal Data breach, SyncWork will notify you without undue delay (and in any event within 72 hours) after becoming aware of the breach. The notification will include:

  • Description of the nature of the breach
  • Categories and approximate number of data subjects affected
  • Likely consequences of the breach
  • Measures taken or proposed to address the breach

9. Audit Rights

Upon reasonable notice and subject to appropriate confidentiality obligations, you may audit SyncWork's compliance with this DPA. SyncWork will make available relevant information and allow for audits conducted by you or an independent auditor.

10. Applicable Data Protection Laws

This DPA is designed to comply with the following data protection laws as applicable:

  • GDPR — Regulation (EU) 2016/679 (General Data Protection Regulation)
  • UK GDPR — The UK General Data Protection Regulation as incorporated into UK law
  • PIPEDA — Personal Information Protection and Electronic Documents Act (S.C. 2000, c. 5)
  • BC PIPA — Personal Information Protection Act (SBC 2003, c. 63)
  • CCPA/CPRA — California Consumer Privacy Act as amended by the California Privacy Rights Act

Where there is a conflict between this DPA and applicable data protection law, the applicable law prevails.

11. Governing Law

This DPA is governed by the laws of the Province of British Columbia and the federal laws of Canada applicable therein, without regard to conflict of law principles. For data subjects in the EEA, the applicable provisions of the GDPR and the Standard Contractual Clauses take precedence where they offer greater protection.

12. Duration and Termination

This DPA is effective for the duration of your use of SyncWork services and forms part of the Terms of Service. Upon termination, SyncWork will delete or return all Personal Data within 30 days, unless retention is required by applicable law.

13. Contact Information

For questions about this DPA or data protection matters:

Syncs Digital Inc.

Data Protection Officer

Jurisdiction: British Columbia, Canada

Email: dpo@syncwork.space

Related documents

See our Terms of Service, Privacy Policy, Sub-processors list, and Security overview.

Talk to legalAll legal documents