Data Processing Agreement
Last updated: 21 August 2026 · Version 1.0
This DPA forms part of the Terms of Service between SynqOS Ltd and the Customer and satisfies UK GDPR Article 28.
1. Parties
Processor: SynqOS Ltd, 2 Edmund Court, Sheffield, United Kingdom. Company number: 17338012. Email: hello@synqos.co.uk
Controller: The Customer as identified in their SynqOS account.
2. Subject matter and duration
SynqOS Ltd processes personal data on behalf of the Customer solely to provide the SynqOS service for the duration of the active subscription. On termination, personal data is deleted within 30 days unless retention is required by law.
3. Nature and purpose of processing
Processing activities include:
- Storing venue operational data submitted by the Customer
- Sending operational data to AI analysis services to generate briefings and recommendations
- Generating marketing content, social media posts and email campaigns at the Customer's direction
- Syncing with third-party platforms (Meta, Google, booking systems, Stripe) at the Customer's direction
- Returning results, reports and recommendations to the Customer's dashboard
4. Types of personal data processed
- Customer names and email addresses
- Booking history and session data
- Review content and customer feedback
- Payment references (not full card details — held by Stripe)
- Any other personal data the Customer chooses to connect via integrations
5. Categories of data subjects
The Customer's venue guests, end customers, and staff members whose data the Customer submits to the SynqOS service.
6. Controller obligations
The Customer (as data controller) confirms:
- They have a valid lawful basis under UK GDPR to process the personal data submitted to SynqOS.
- They are responsible for obtaining any consents required from their end customers.
- They are responsible for handling data subject rights requests from their own customers.
- They will only submit personal data to SynqOS that is necessary for the service.
- They will notify SynqOS of any instructions that would cause SynqOS to breach applicable data protection law.
7. Processor obligations
SynqOS Ltd confirms:
- We will process personal data only on the Customer's documented instructions (delivering the service as described).
- We will ensure persons authorised to process personal data are bound by appropriate confidentiality obligations.
- We will implement appropriate technical and organisational measures to protect personal data, including TLS encryption in transit, AES-256 encryption at rest, and row-level security isolating each customer's data.
- We will assist the Customer in complying with data subject rights requests where technically possible.
- We will notify the Customer without undue delay (and within 72 hours where possible) of any personal data breach affecting their data.
- We will make available all information necessary to demonstrate compliance with this DPA upon reasonable request.
- We will delete or return all personal data on termination of the service, within 30 days.
8. Sub-processors
The Customer authorises SynqOS to engage the following sub-processors. SynqOS will notify the Customer of any material changes to this list with at least 14 days' notice.
| Sub-processor | Purpose | Transfer mechanism |
|---|
| Supabase Inc (USA) | Database and authentication | IDTA |
| Stripe Inc (USA) | Payment processing | IDTA |
| n8n GmbH (EU) | Workflow automation | SCCs |
| Google LLC — Gemini API (USA) | AI analysis of operational data | IDTA |
| Anthropic PBC — Claude API (USA) | AI model calls via Lovable | IDTA |
All sub-processors are contractually prohibited from using personal data for any purpose other than providing their services to SynqOS. Neither Google (Gemini API) nor Anthropic (Claude API) use API data to train their AI models.
9. International transfers
Where personal data is transferred outside the UK, SynqOS relies on the UK International Data Transfer Agreement (IDTA) or EU Standard Contractual Clauses with the UK Addendum, as specified in the sub-processor table above.
10. Security measures
SynqOS maintains the following technical and organisational measures:
- Encryption in transit (TLS 1.2+) and at rest (AES-256)
- Row-level security ensuring each customer's data is isolated
- Passwords hashed with bcrypt
- Access controls restricted to authorised personnel
- Regular security reviews of the platform and sub-processors
11. Audit rights
The Customer may request a summary of SynqOS's data protection practices once per year at no charge by emailing hello@synqos.co.uk. SynqOS will respond within 30 days.
12. Governing law
This DPA is governed by the laws of England and Wales. Disputes are subject to the exclusive jurisdiction of the courts of England and Wales.
Note for enterprise customers: If your organisation requires a countersigned DPA rather than accepting these terms online, contact hello@synqos.co.uk. We will provide a standalone document for signature within 5 business days.