Data Processing Addendum

Version 1 · Effective June 1, 2026 · Last updated June 1, 2026

Effective date: June 1, 2026 · Last updated: June 1, 2026

This Data Processing Addendum (“DPA”) supplements and forms part of the Terms of Service (the “Agreement”) between Synafe LLC (“Synafe,” “Processor,” “we,” or “us”) and the business customer that accepts the Agreement (“Customer” or “Controller”). It applies only where, and to the extent that, Synafe processes personal data on Customer’s behalf in connection with the Service. If there is a conflict between this DPA and the Agreement with respect to data processing, this DPA controls.

1. Parties and Roles

For personal data that Customer inputs about other individuals (such as staff, residents, families, and vendors), Customer acts as the Controller (or, where applicable, processor on behalf of another controller) and Synafe acts as the Processor (or sub-processor). Customer is responsible for establishing the legal basis for the processing and for the accuracy, quality, and lawfulness of the personal data and of Customer’s instructions.

2. Definitions

Capitalized terms not defined here have the meanings given in the Agreement. “Data Protection Laws” means all privacy and data-protection laws and regulations applicable to the processing of personal data under this DPA, including, as applicable, U.S. state privacy laws (such as the California Consumer Privacy Act as amended), the EU General Data Protection Regulation (“GDPR”), and the UK GDPR. “Personal Data,” “Controller,” “Processor,” “Data Subject,” and “processing” have the meanings given under the applicable Data Protection Laws.

3. Subject Matter and Duration

The subject matter of the processing is the provision of the Service under the Agreement. This DPA takes effect when the Agreement does and continues for the term of the Agreement and for as long as Synafe processes Customer’s personal data, after which the deletion/return obligations in Section 10 apply.

4. Nature and Purpose of Processing

Synafe processes personal data only to provide, operate, secure, support, and maintain the Service as described in the Agreement and as instructed by Customer through its configuration and use of the Service (for example, hosting and rendering calendars, documents, and directories; sending transactional email; and providing AI-assisted features that Customer chooses to use).

5. Types of Personal Data and Categories of Data Subjects

Types of personal data: identifiers and contact details such as names, email addresses, phone numbers, roles, and postal addresses, and other information that Customer chooses to enter into the Service. Customer must not enter Protected Health Information or special-category/sensitive data, as prohibited by the Agreement.

Categories of data subjects: Customer’s staff, residents, families, vendors, and other individuals whose information Customer enters into the Service.

6. Processor Obligations

  • Documented instructions. Synafe processes personal data only on Customer’s documented instructions, including as set out in the Agreement and this DPA, unless required to do otherwise by applicable law (in which case Synafe will, where permitted, inform Customer first).
  • Confidentiality. Synafe ensures that personnel authorized to process the personal data are bound by appropriate confidentiality obligations.
  • Security. Synafe implements appropriate technical and organizational measures designed to protect personal data, taking into account the state of the art, the costs of implementation, and the nature, scope, and purposes of processing — including encryption in transit, access controls, and encryption of stored integration credentials.
  • Data-subject requests. Taking into account the nature of the processing, Synafe will provide reasonable assistance to enable Customer to respond to requests from data subjects to exercise their rights under Data Protection Laws. Synafe will forward to Customer any such request it receives directly that relates to Customer’s personal data.
  • Breach notification. Synafe will notify Customer without undue delay after becoming aware of a personal-data breach affecting Customer’s personal data, and will provide information reasonably available to assist Customer in meeting its own notification obligations.
  • Assistance. Synafe will provide reasonable assistance to Customer with data-protection impact assessments and prior consultations with supervisory authorities, to the extent required by Data Protection Laws and taking into account the information available to Synafe.

7. Sub-Processors

Customer authorizes Synafe to engage sub-processors to process personal data in connection with the Service. Synafe imposes data-protection obligations on its sub-processors that are substantially similar to those in this DPA and remains responsible for their performance. Synafe’s current sub-processors include:

  • Google — authentication and (where Customer connects it) calendar/contact import.
  • Microsoft — authentication and (where Customer connects it) calendar/contact import.
  • OpenAI — processing of AI prompts and content for AI-assisted features.
  • Cloudflare R2 — object storage for images and exported files.
  • Stripe — payment and subscription processing.
  • Email provider (e.g., Resend or an SMTP provider) — transactional email delivery.
  • Hosting and delivery — Oracle Cloud (hosting) and Cloudflare (delivery/security).
  • Upstash — rate-limiting and related operational functions.

Synafe will provide Customer a means to receive notice of intended changes to its sub-processors (for example, by updating this list), giving Customer the opportunity to object on reasonable data-protection grounds.

8. International Transfers

Synafe and its sub-processors may process personal data in the United States and other countries. Where personal data is transferred from a jurisdiction that restricts international transfers, the parties will rely on an appropriate transfer mechanism recognized under the applicable Data Protection Laws, such as the European Commission’s Standard Contractual Clauses (and the UK Addendum, where applicable), which are incorporated by reference where they apply.

9. Audits and Compliance

Synafe will make available to Customer information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to reasonable audits, including inspections, conducted by Customer or an auditor mandated by Customer, subject to reasonable confidentiality, security, scheduling, and frequency limits. Synafe may satisfy this obligation by providing relevant certifications or third-party audit reports where available.

10. Return or Deletion of Data

Upon termination or expiry of the Agreement, Synafe will, at Customer’s choice and request, delete or return the personal data it processes on Customer’s behalf, and delete existing copies, except to the extent retention is required by applicable law or for residual copies in backups that are deleted in the ordinary course within a commercially reasonable period.

11. No Protected Health Information

Consistent with the Agreement, the Service is not designed for and must not be used to process Protected Health Information under HIPAA. Synafe is not a “Business Associate” or “Covered Entity,” does not enter into Business Associate Agreements, and provides no HIPAA-compliant environment. This DPA does not constitute or imply any such agreement.

12. Liability

Each party’s liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Agreement, and any reference in the Agreement to a party’s liability means the aggregate liability of that party under the Agreement and this DPA together.

13. Contact

Questions about this DPA or requests to enter into it? Please reach Synafe LLC through our contact form at /legal/contact.