Data Processing Agreement

Last updated: 21 August 2026 · Version 1.0

This DPA forms part of the Terms of Service between SynqOS Ltd and the Customer and satisfies UK GDPR Article 28.

1. Parties

Processor: SynqOS Ltd, 2 Edmund Court, Sheffield, United Kingdom. Company number: 17338012. Email: hello@synqos.co.uk

Controller: The Customer as identified in their SynqOS account.

2. Subject matter and duration

SynqOS Ltd processes personal data on behalf of the Customer solely to provide the SynqOS service for the duration of the active subscription. On termination, personal data is deleted within 30 days unless retention is required by law.

3. Nature and purpose of processing

Processing activities include:

  • Storing venue operational data submitted by the Customer
  • Sending operational data to AI analysis services to generate briefings and recommendations
  • Generating marketing content, social media posts and email campaigns at the Customer's direction
  • Syncing with third-party platforms (Meta, Google, booking systems, Stripe) at the Customer's direction
  • Returning results, reports and recommendations to the Customer's dashboard

4. Types of personal data processed

  • Customer names and email addresses
  • Booking history and session data
  • Review content and customer feedback
  • Payment references (not full card details — held by Stripe)
  • Any other personal data the Customer chooses to connect via integrations

5. Categories of data subjects

The Customer's venue guests, end customers, and staff members whose data the Customer submits to the SynqOS service.

6. Controller obligations

The Customer (as data controller) confirms:

  • They have a valid lawful basis under UK GDPR to process the personal data submitted to SynqOS.
  • They are responsible for obtaining any consents required from their end customers.
  • They are responsible for handling data subject rights requests from their own customers.
  • They will only submit personal data to SynqOS that is necessary for the service.
  • They will notify SynqOS of any instructions that would cause SynqOS to breach applicable data protection law.

7. Processor obligations

SynqOS Ltd confirms:

  • We will process personal data only on the Customer's documented instructions (delivering the service as described).
  • We will ensure persons authorised to process personal data are bound by appropriate confidentiality obligations.
  • We will implement appropriate technical and organisational measures to protect personal data, including TLS encryption in transit, AES-256 encryption at rest, and row-level security isolating each customer's data.
  • We will assist the Customer in complying with data subject rights requests where technically possible.
  • We will notify the Customer without undue delay (and within 72 hours where possible) of any personal data breach affecting their data.
  • We will make available all information necessary to demonstrate compliance with this DPA upon reasonable request.
  • We will delete or return all personal data on termination of the service, within 30 days.

8. Sub-processors

The Customer authorises SynqOS to engage the following sub-processors. SynqOS will notify the Customer of any material changes to this list with at least 14 days' notice.

Sub-processorPurposeTransfer mechanism
Supabase Inc (USA)Database and authenticationIDTA
Stripe Inc (USA)Payment processingIDTA
n8n GmbH (EU)Workflow automationSCCs
Google LLC — Gemini API (USA)AI analysis of operational dataIDTA
Anthropic PBC — Claude API (USA)AI model calls via LovableIDTA

All sub-processors are contractually prohibited from using personal data for any purpose other than providing their services to SynqOS. Neither Google (Gemini API) nor Anthropic (Claude API) use API data to train their AI models.

9. International transfers

Where personal data is transferred outside the UK, SynqOS relies on the UK International Data Transfer Agreement (IDTA) or EU Standard Contractual Clauses with the UK Addendum, as specified in the sub-processor table above.

10. Security measures

SynqOS maintains the following technical and organisational measures:

  • Encryption in transit (TLS 1.2+) and at rest (AES-256)
  • Row-level security ensuring each customer's data is isolated
  • Passwords hashed with bcrypt
  • Access controls restricted to authorised personnel
  • Regular security reviews of the platform and sub-processors

11. Audit rights

The Customer may request a summary of SynqOS's data protection practices once per year at no charge by emailing hello@synqos.co.uk. SynqOS will respond within 30 days.

12. Governing law

This DPA is governed by the laws of England and Wales. Disputes are subject to the exclusive jurisdiction of the courts of England and Wales.

13. Contact

Data protection queries: hello@synqos.co.uk

Full Terms of Service: synqos.co.uk/terms

Note for enterprise customers: If your organisation requires a countersigned DPA rather than accepting these terms online, contact hello@synqos.co.uk. We will provide a standalone document for signature within 5 business days.