Version 1 · Effective June 1, 2026 · Last updated June 1, 2026
Effective date: June 1, 2026 · Last updated: June 1, 2026
This Data Processing Addendum (“DPA”) supplements and forms part of the Terms of Service (the “Agreement”) between Synafe LLC (“Synafe,” “Processor,” “we,” or “us”) and the business customer that accepts the Agreement (“Customer” or “Controller”). It applies only where, and to the extent that, Synafe processes personal data on Customer’s behalf in connection with the Service. If there is a conflict between this DPA and the Agreement with respect to data processing, this DPA controls.
For personal data that Customer inputs about other individuals (such as staff, residents, families, and vendors), Customer acts as the Controller (or, where applicable, processor on behalf of another controller) and Synafe acts as the Processor (or sub-processor). Customer is responsible for establishing the legal basis for the processing and for the accuracy, quality, and lawfulness of the personal data and of Customer’s instructions.
Capitalized terms not defined here have the meanings given in the Agreement. “Data Protection Laws” means all privacy and data-protection laws and regulations applicable to the processing of personal data under this DPA, including, as applicable, U.S. state privacy laws (such as the California Consumer Privacy Act as amended), the EU General Data Protection Regulation (“GDPR”), and the UK GDPR. “Personal Data,” “Controller,” “Processor,” “Data Subject,” and “processing” have the meanings given under the applicable Data Protection Laws.
The subject matter of the processing is the provision of the Service under the Agreement. This DPA takes effect when the Agreement does and continues for the term of the Agreement and for as long as Synafe processes Customer’s personal data, after which the deletion/return obligations in Section 10 apply.
Synafe processes personal data only to provide, operate, secure, support, and maintain the Service as described in the Agreement and as instructed by Customer through its configuration and use of the Service (for example, hosting and rendering calendars, documents, and directories; sending transactional email; and providing AI-assisted features that Customer chooses to use).
Types of personal data: identifiers and contact details such as names, email addresses, phone numbers, roles, and postal addresses, and other information that Customer chooses to enter into the Service. Customer must not enter Protected Health Information or special-category/sensitive data, as prohibited by the Agreement.
Categories of data subjects: Customer’s staff, residents, families, vendors, and other individuals whose information Customer enters into the Service.
Customer authorizes Synafe to engage sub-processors to process personal data in connection with the Service. Synafe imposes data-protection obligations on its sub-processors that are substantially similar to those in this DPA and remains responsible for their performance. Synafe’s current sub-processors include:
Synafe will provide Customer a means to receive notice of intended changes to its sub-processors (for example, by updating this list), giving Customer the opportunity to object on reasonable data-protection grounds.
Synafe and its sub-processors may process personal data in the United States and other countries. Where personal data is transferred from a jurisdiction that restricts international transfers, the parties will rely on an appropriate transfer mechanism recognized under the applicable Data Protection Laws, such as the European Commission’s Standard Contractual Clauses (and the UK Addendum, where applicable), which are incorporated by reference where they apply.
Synafe will make available to Customer information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to reasonable audits, including inspections, conducted by Customer or an auditor mandated by Customer, subject to reasonable confidentiality, security, scheduling, and frequency limits. Synafe may satisfy this obligation by providing relevant certifications or third-party audit reports where available.
Upon termination or expiry of the Agreement, Synafe will, at Customer’s choice and request, delete or return the personal data it processes on Customer’s behalf, and delete existing copies, except to the extent retention is required by applicable law or for residual copies in backups that are deleted in the ordinary course within a commercially reasonable period.
Consistent with the Agreement, the Service is not designed for and must not be used to process Protected Health Information under HIPAA. Synafe is not a “Business Associate” or “Covered Entity,” does not enter into Business Associate Agreements, and provides no HIPAA-compliant environment. This DPA does not constitute or imply any such agreement.
Each party’s liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Agreement, and any reference in the Agreement to a party’s liability means the aggregate liability of that party under the Agreement and this DPA together.
Questions about this DPA or requests to enter into it? Please reach Synafe LLC through our contact form at /legal/contact.