Data Processing Agreement (DPA)
GDPR, UK GDPR & DPDP Compliant.
1. Introduction and Scope
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Syncnity (a trade name of Syncnity Team, Proprietor) ("Processor") and the Merchant ("Controller") and governs the processing of personal data by Syncnity on behalf of the Merchant.
This DPA applies when Syncnity processes personal data of EU/EEA residents (under GDPR), UK residents (under UK GDPR), or Indian residents (under the DPDP Act 2023) on behalf of the Merchant.
2. Definitions
- "Personal Data" means any information relating to an identified or identifiable natural person (data subject)
- "Processing" means any operation performed on personal data, including collection, storage, use, and deletion
- "Controller" means the Merchant who determines the purposes and means of processing
- "Processor" means Syncnity, which processes data on behalf of and under instruction from the Controller
- "Sub-processor" means a third party engaged by Syncnity to process data on its behalf
- "GDPR" means EU Regulation 2016/679 (General Data Protection Regulation)
- "UK GDPR" means GDPR as retained in UK law by the European Union (Withdrawal) Act 2018
- "DPDP Act" means India's Digital Personal Data Protection Act 2023
3. Nature and Purpose of Processing
3.1 Subject Matter
Processing of Merchant customer personal data for the purpose of collecting and displaying product reviews.
3.2 Duration
For the duration of the Merchant's subscription to Syncnity, plus any retention period as specified in the Privacy Policy.
3.3 Nature of Processing
- Sending review request emails to Merchant's customers
- Collecting and storing review submissions (text, ratings, photos, videos)
- Displaying reviews on Merchant storefronts via widgets
- Processing review incentives (discount codes)
- Providing review analytics to the Merchant
3.4 Types of Personal Data
Customer names and email addresses; order data (order ID, product information, purchase date); review content (text, star ratings, photos, videos); device and technical data (IP address, browser type).
3.5 Categories of Data Subjects
Customers of the Merchant's Shopify store who have placed orders.
4. Processor Obligations
4.1 Instructions
Syncnity will process personal data only on documented instructions from the Controller (as set out in the Terms and Merchant's app configuration), unless required by applicable law.
4.2 Confidentiality
Syncnity ensures that persons authorized to process personal data are subject to binding confidentiality obligations.
4.3 Security
Syncnity implements appropriate technical and organizational security measures, including: encryption in transit (TLS) and at rest (AES-256); access controls and authentication; regular security testing and vulnerability management; incident response procedures.
4.4 Sub-processors
Syncnity may engage sub-processors. Current sub-processors are listed in Annex A. Syncnity will: inform the Controller of intended changes (30 days notice); impose equivalent data protection obligations on sub-processors; remain liable for sub-processor performance.
4.5–4.8
Data Subject Rights: Syncnity will assist the Controller in responding to requests; the Controller is responsible for responding to data subjects. DPIA: Syncnity will provide reasonable assistance. Deletion or Return: Upon termination, Syncnity will delete or return data as instructed; standard deletion within 90 days of account termination. Audit Rights: Upon reasonable written notice (min. 30 days), Syncnity will make available information necessary to demonstrate compliance and allow audits (subject to confidentiality).
5. Controller Obligations
The Controller (Merchant) is responsible for: establishing a lawful basis for processing; providing appropriate privacy notices; obtaining necessary consents; handling data subject requests from their customers; ensuring their use of the Service complies with applicable law.
6. International Data Transfers
6.1 EU SCCs: For transfers from EU/EEA to India, Syncnity relies on Standard Contractual Clauses (Commission Implementing Decision 2021/914), Module Two (Controller to Processor). By entering into this DPA, both parties agree to be bound by the SCCs. 6.2 UK IDTA: For UK transfers, Syncnity relies on the UK International Data Transfer Agreement, incorporated by reference. 6.3: Supplementary technical measures (e.g. encryption in transit and at rest) protect transferred data.
7. Data Breach Notification
In the event of a personal data breach affecting Merchant customer data, Syncnity will: notify the Controller without undue delay (where feasible within 72 hours); provide available details (nature of breach, categories and approximate number of data subjects, likely consequences, measures taken or proposed); assist the Controller in meeting its notification obligations to supervisory authorities and data subjects.
8. GDPR Article 28 Compliance
This DPA is intended to satisfy Article 28 of the GDPR for controller-processor contracts. If any provision conflicts with GDPR requirements, the GDPR requirements shall prevail.
9. Term and Termination
This DPA is effective for the duration of the Terms of Service. Upon termination of the Terms, this DPA terminates automatically, subject to surviving obligations (data deletion, confidentiality).
10. Governing Law
This DPA is governed by the laws of India, without prejudice to mandatory provisions of GDPR or UK GDPR that may apply to the Controller.
Annex A — Sub-processors
The following sub-processors are currently engaged by Syncnity. [Update with your actual infrastructure providers before publishing.]
- Cloud Infrastructure Provider (e.g., AWS / Google Cloud) — Server hosting, storage, computing — [Country of Processing]
- Transactional Email Provider (e.g., SendGrid / Postmark) — Sending review request emails — United States
- Analytics Provider (e.g., Mixpanel / Amplitude) — Service usage analytics — United States
- Error Monitoring (e.g., Sentry) — Application error tracking — United States
Annex B — Technical and Organizational Measures
Access Controls: Role-based access; multi-factor authentication; regular access reviews and revocation upon offboarding. Encryption: TLS 1.2+ in transit; AES-256 at rest. Availability and Resilience: Regular automated backups; high-availability infrastructure. Testing: Vulnerability scanning and penetration testing; security patching. Physical Security: Data hosted in SOC 2 Type II certified data centers.
Contact for Data Protection Matters
Data Protection Contact: info@syncnity.com
For GDPR inquiries, please include 'GDPR Request' in the subject line.