Data Processing Agreement
1. What this agreement is
This Data Processing Agreement ("DPA") governs how Syncetix processes personal data on behalf of merchants who use the Syncetix platform. When your buyers' data - names, addresses, order details, tracking numbers - flows through Syncetix as part of a sync, you (the merchant) are the data controller and Syncetix is the data processor under the EU General Data Protection Regulation (GDPR).
This DPA is incorporated into the Terms of Service at /legal/terms/ by reference and applies automatically to every account - no signature needed. Enterprise customers who need a signed copy can request one. This DPA covers your buyers' data; how Syncetix handles your own account data is described in the Privacy Policy.
2. Details of the processing
Subject matter and purpose
Syncetix processes buyer personal data solely to provide the service you signed up for: importing supplier feeds, publishing listings to your sales channels (such as WooCommerce and eBay), syncing orders and inventory, routing tracking information back to buyers' orders, and generating bookkeeping records.
Duration
Processing lasts as long as your account is active, plus the 30-day deletion window described in Section 9.
Nature of the processing
Collection from your connected channels and email (where you enable it), storage, organisation, matching (for example, matching a tracking number to an order), transmission to your connected channels, and deletion.
Categories of data subjects
- Your buyers - the customers who place orders on your connected sales channels.
Categories of personal data
- Identity: buyer name.
- Contact: email address and phone number, where the sales channel provides them.
- Delivery: shipping and billing address.
- Order contents: items purchased, quantities, prices, order status, refunds and disputes.
- Fulfilment: carrier and tracking numbers.
Syncetix does not process buyer payment card details and does not intentionally process any special categories of data (Article 9 GDPR).
3. Documented instructions only
Syncetix processes buyer data only on your documented instructions. Your instructions are: the Terms of Service, this DPA, and the settings you configure in the app (which channels you connect, which syncs you enable). Syncetix will not process buyer data for its own purposes. If a law of the EU or an EU member state requires Syncetix to process data beyond your instructions, Syncetix will tell you before doing so, unless that law forbids it. If Syncetix believes an instruction violates data protection law, it will tell you and may pause that instruction.
4. Confidentiality
Access to buyer data is limited to people who need it to operate the service, and every such person is bound by a duty of confidentiality - by contract or by statute.
5. Security measures
Syncetix implements appropriate technical and organisational measures under Article 32 GDPR, including:
- Encryption in transit: all connections use TLS.
- Encryption at rest for credentials: stored channel and supplier credentials are encrypted.
- EU hosting: production systems run in a data centre in Germany.
- Tenant isolation: database row-level security enforces separation between merchant accounts at the database layer.
- Access controls: role-based access within accounts, and restricted, authenticated administrative access to production systems.
Syncetix keeps these measures under review and may update them, provided the overall level of protection does not decrease.
6. Sub-processors
You give Syncetix general written authorisation to use the sub-processors listed below. Each one is bound by data protection terms at least as protective as this DPA, and Syncetix remains fully liable to you for their performance.
- Contabo GmbH - hosting and infrastructure - Germany.
- Brevo - transactional email delivery - France.
- Sentry - error monitoring - EU.
- Google - Gmail API for tracking-email scanning - only where you connect your Gmail account to that feature.
Changes: Syncetix will notify you (by email or in-app notice) at least 14 days before adding or replacing a sub-processor. If you object on reasonable data protection grounds and no workaround is found, you may terminate your account and Syncetix will delete your data under Section 9.
7. Helping with data subject requests
If a buyer exercises a GDPR right - access, rectification, erasure, restriction, portability, or objection - the request is yours to answer as controller. Syncetix will help: the app lets you view, correct, and delete buyer records, and where a request needs something the app cannot do, Syncetix will assist within a reasonable time on request. If a buyer contacts Syncetix directly, Syncetix will forward the request to you and will not respond on the merits except as required by law.
8. Personal data breaches
If Syncetix becomes aware of a personal data breach affecting your buyers' data, it will notify you without undue delay, targeting within 72 hours of becoming aware. The notice will describe, as information becomes available, the nature of the breach, the data and data subjects likely affected, the likely consequences, and the measures taken or proposed. Syncetix will cooperate with you on any notification you must make to a supervisory authority or to buyers.
9. Deletion and return on termination
When your account is closed - by you or by Syncetix - your buyer data enters a 30-day retention window. During that window you can export your data or ask for a copy in a common machine-readable format. After 30 days, Syncetix permanently deletes the data from production systems, except where EU or member state law requires longer retention (in which case the data stays protected under this DPA and is deleted when that requirement ends). Backups are purged on their normal rotation schedule.
10. Audit and information rights
On written request, Syncetix will make available the information reasonably necessary to demonstrate compliance with Article 28 GDPR - including descriptions of the security measures above and confirmations of sub-processor terms. Where that information is genuinely insufficient, you may conduct (or mandate an independent auditor to conduct) an audit, at most once per year, on at least 30 days' notice, during business hours, at your cost, and without access to other merchants' data or to information that would compromise platform security.
11. International transfers
Buyer data is stored and processed in the EU. If any processing by Syncetix or a sub-processor involves a transfer of personal data outside the European Economic Area to a country without an adequacy decision, that transfer is made under the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914, Module 2 or Module 3 as applicable), which are incorporated into this DPA by reference, together with any required supplementary measures.
12. General
If this DPA conflicts with the Terms of Service or any other agreement between us on a data protection matter, this DPA wins. Liability under this DPA is subject to the limitations in the Terms of Service, except where GDPR does not allow that. This DPA is governed by the laws of [the operator's jurisdiction - to be confirmed]. Related documents: Privacy Policy, Master Service Agreement, Refund Policy.
13. Contact
Questions about this DPA, sub-processor notices, breach reports, or requests for a signed copy: contact Syncetix support through your account or the contact details published on syncetix.com.