Data Processing Agreement
This Data Processing Agreement (the “DPA”) forms part of, and is incorporated by reference into, the Terms & Conditions (the “Agreement”) between SynorixAI OÜ (registry code 17519396, VAT EE103005151, Telliskivi tn 57, 10412 Tallinn, Estonia — “Synorix”, the “Processor”) and the Customer (the “Controller”). It governs the processing of Personal Data by Synorix on the Controller’s behalf under Article 28 of Regulation (EU) 2016/679 (“GDPR”). Where the Agreement and this DPA conflict on the subject matter of data protection, this DPA prevails.
1. Definitions
Capitalised terms not defined here have the meaning given in the Agreement. “Personal Data”, “processing”, “controller”, “processor”, “data subject”, “personal data breach” and “supervisory authority” have the meanings given in the GDPR. “Sub-processor” means a third party engaged by Synorix to process Personal Data on the Controller’s behalf. “Customer Personal Data” means Personal Data within Customer Data that Synorix processes on the Controller’s behalf to provide the Service.
2. Roles and scope
For Customer Personal Data, the Controller is the controller and Synorix is the processor. Synorix is an orchestration and integration platform and does not develop, own or operate its own foundation AI models. Whether a connected AI model provider or other Third-Party Service is a Synorix Sub-processor depends on how the connection is made:
- Platform-key routing — where the Controller uses Synorix’s own platform-supplied credentials to reach an AI model provider (no Controller-supplied API key connected for that provider), Synorix engages that provider as its own Sub-processor for the Customer Personal Data it processes on that path, and Synorix remains responsible for it under clause 6 and Annex III.
- Customer-key (“bring your own key”) routing — where the Controller connects its own account or API key for a provider, that provider acts under its own terms as the Controller’s own processor or as an independent controller; it is not a Synorix Sub-processor, and Synorix is not responsible for its processing.
Automatic cross-provider fallback. On platform-key routing, Synorix’s routing layer may automatically substitute a different model provider listed in Annex III if the Controller’s selected provider is unavailable or fails a request. The Controller is deemed to have authorised routing to any provider named in Annex III; Synorix does not give a separate per-request notice when this occurs. Synorix acts as processor for the Customer Personal Data it hosts, transmits and coordinates in providing the Service, and for the Sub-processors it itself engages (Annex III).
3. Processing on documented instructions
Synorix processes Customer Personal Data only on the Controller’s documented instructions, including as set out in the Agreement, this DPA and the Controller’s configuration and use of the Service, unless required by EU or Member State law — in which case Synorix will, where legally permitted, inform the Controller before processing. Synorix will inform the Controller if, in its opinion, an instruction infringes the GDPR or other data protection law. The subject matter, duration, nature and purpose of processing, and the categories of Personal Data and data subjects, are set out in Annex I.
4. Confidentiality
Synorix ensures that persons authorised to process Customer Personal Data are bound by an appropriate obligation of confidentiality and process the data only as instructed.
5. Security of processing
Synorix implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, in accordance with Article 32 GDPR. These measures are described in Annex II and include, where applicable, pseudonymisation and encryption, egress-side masking of personal data before it is sent to cloud AI providers, access controls, and measures to ensure confidentiality, integrity, availability and resilience.
6. Sub-processors
The Controller grants Synorix general authorisation to engage Sub-processors for defined parts of the Service (for example hosting and infrastructure providers). Synorix maintains a current list of Sub-processors in Annex III and will give the Controller prior notice of any intended addition or replacement, allowing the Controller a reasonable period to object on reasonable data-protection grounds. Synorix imposes on each Sub-processor data protection obligations no less protective than those in this DPA and remains fully liable to the Controller for its Sub-processors’ performance.
7. Assistance to the Controller
Taking into account the nature of the processing, Synorix assists the Controller by appropriate technical and organisational measures, insofar as possible, in fulfilling the Controller’s obligation to respond to requests to exercise data-subject rights (Articles 12–23 GDPR). Synorix also assists the Controller in ensuring compliance with Articles 32–36 GDPR (security, breach notification, data protection impact assessments and prior consultation), taking into account the nature of processing and the information available to Synorix.
8. Personal data breach
Synorix notifies the Controller without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and provides the information reasonably necessary for the Controller to meet its obligations under Articles 33 and 34 GDPR. Synorix does not notify supervisory authorities or data subjects on the Controller’s behalf unless required by law or separately instructed.
9. International transfers
Synorix’s own core hosting infrastructure is located in the EU/EEA by default. That does not mean every Sub-processor in Annex III is EU-based: several AI model and platform-operations Sub-processors Synorix engages for platform-key routing are located outside the EU/EEA (see Annex III for the current list and each Sub-processor’s location). Where Customer Personal Data is transferred outside the EU/EEA to a Sub-processor Synorix engages, that transfer is subject to an appropriate safeguard under Chapter V GDPR (such as the European Commission’s Standard Contractual Clauses); Annex III states, for each Sub-processor, whether that safeguard has been confirmed as executed or is still pending — Synorix does not represent a safeguard is in place where it is marked pending. Where the Controller instructs Synorix to connect an AI provider or other Third-Party Service using the Controller’s own credentials (customer-key routing), or otherwise located outside the EU/EEA, the Controller is responsible for the transfer arising from that choice and for the corresponding safeguard.
10. Return or deletion
On termination of the Service, and at the Controller’s choice, Synorix returns or deletes all Customer Personal Data and deletes existing copies, unless EU or Member State law requires storage. The Controller may export its Customer Data for the period stated in the Agreement before deletion.
11. Audits
Synorix makes available to the Controller the information necessary to demonstrate compliance with Article 28 GDPR and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor it mandates. Audits are conducted on reasonable prior notice, no more than once per year (save where required by a supervisory authority or following a personal data breach), during business hours, and subject to confidentiality, so as not to unreasonably disrupt Synorix’s operations. Synorix may satisfy audit requests by providing relevant certifications or third-party audit reports where available.
12. Liability
Each party’s liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement. This DPA does not limit any liability that cannot be limited under applicable data protection law.
13. Term
This DPA takes effect when the Controller accepts the Agreement and remains in force for as long as Synorix processes Customer Personal Data on the Controller’s behalf. Clauses that by their nature should survive termination (including confidentiality and deletion obligations) survive.
Annex I — Details of processing
- Subject matter — provision of the Synorix orchestration platform to the Controller.
- Duration — for the term of the Agreement and any post-termination export/deletion period.
- Nature and purpose — hosting, storing, transmitting, orchestrating and coordinating Customer Data (including routing requests to the AI models and Third-Party Services the Controller connects) to provide the Service.
- Categories of Personal Data — account and user identifiers and contact details; authentication and configuration data; content the Controller and its Users submit to or process through the Service, which may contain Personal Data determined by the Controller; usage and diagnostic logs. Special categories of data are not intended to be processed and should not be submitted unless the Controller has ensured a lawful basis and appropriate safeguards.
- Categories of data subjects — the Controller’s administrators, employees and authorised Users, and any individuals whose Personal Data is contained in the content the Controller processes through the Service.
Annex II — Technical and organisational measures
- Encryption of data in transit and, where applicable, at rest; secrets and credentials stored encrypted.
- Egress-side detection and masking of personal data before content is sent to cloud AI providers, with restoration on return, so raw personal data is minimised on cloud paths.
- Role- and tenant-based access controls, authentication via an identity provider, and least-privilege access.
- Network isolation between tenants and per-tenant data scoping.
- Logging, monitoring and audit trails of access and significant actions.
- Secure development practices, dependency and secret scanning, and change control.
- Backup, and measures to ensure the ongoing confidentiality, integrity, availability and resilience of systems, with the ability to restore availability after an incident.
- Personnel confidentiality obligations and security awareness.
The specific measures in force may evolve as the state of the art advances, provided the level of security is not reduced.
Annex III — Sub-processors
Synorix engages the following categories of Sub-processor to provide the Service:
- Cloud hosting and infrastructure providers (compute, storage, networking) — EU/EEA intended; specific provider and region to be confirmed (see the named list).
- Platform operations tooling (for example product analytics, transactional email, and logging/monitoring) configured to minimise Personal Data.
- AI model providers engaged by Synorix on platform-key routing (see clause 2) — the providers Synorix itself contracts with to route the Controller’s requests when the Controller uses Synorix’s platform-supplied credentials rather than its own, including for chat/reasoning inference, embeddings, text-to-speech and web-search grounding. Automatic cross-provider fallback among these providers is described in clause 2.
The current, specific, named list — each Sub-processor’s name, purpose, data categories, location and transfer mechanism (including which safeguards are confirmed executed and which are still pending) — is published at synorix.ai/subprocessors and updated with prior notice under clause 6. That page is the authoritative, current version of this Annex III; it is currently marked DRAFT pending final legal confirmation of each Sub-processor’s executed DPA/SCC.
Third-party AI model providers and other Third-Party Services that the Controller itself chooses to connect using the Controller’s own credentials (customer-key / “bring your own key” routing) are not Synorix Sub-processors; they act under their own terms as the Controller’s processors or as independent controllers, per clause 2.
Contact
Questions about this DPA or data protection: SynorixAI OÜ · [email protected] · Telliskivi tn 57, 10412 Tallinn, Estonia.