This Data Processing Agreement applies to Managed apps. It is incorporated into the Terms of Service and forms part of the agreement between you and Synci.
Parties and scope
1.1 This Data Processing Agreement ("DPA") is entered into between the developer identified in the Synci account or partner agreement ("Controller") and Tonning, doing business as Synci, org. no. 930076066, Nordbø 15, 5009 Bergen, Norway ("Synci" or "Processor").
1.2 This DPA applies to the processing of personal data by Synci on behalf of Controller in connection with Controller's Managed app or apps under the Synci Terms of Service or a partner agreement (together the "Agreement"). It forms part of the Agreement. In the event of conflict between this DPA and the Agreement regarding the processing of personal data, this DPA prevails.
1.3 This DPA does not apply to Standard OAuth apps, where Synci processes data of its own consumer users as controller.
Definitions
Terms such as "personal data", "processing", "controller", "processor", "sub-processor", "data subject", "personal data breach" and "supervisory authority" have the meanings given in Regulation (EU) 2016/679 ("GDPR"). "End User" means a natural person registered by Controller as a Managed user. "End User Data" means personal data of End Users processed by Synci on Controller's behalf, including financial data as described in Annex A. "Connectivity Provider" means a third-party account information or data provider through which Synci obtains End User Data, such as GoCardless. "Direct Provider Mode" has the meaning in clause 12.
Roles
3.1 Controller is the controller and Synci is the processor of End User Data.
3.2 Synci is an independent controller, not a processor, for the following activities only ("Synci Controller Activities"):
- (a) securing and monitoring the platform, including access logging, intrusion detection and incident investigation;
- (b) selecting and managing sub-processors;
- (c) fraud and abuse prevention, including enforcing acceptable use and Connectivity Provider requirements;
- (d) billing, accounting and business records relating to Controller;
- (e) producing aggregated, anonymised statistics that do not identify any End User;
- (f) sending a single notification to End Users where Controller's app is suspended or removed and can no longer access their connections;
- (g) any activity Synci is required by law to perform as controller.
Portal sign-in emails (one-time codes) and connection status emails are sent as processor on Controller's instructions: the former as part of operating the portal Controller has directed the End User to, the latter only where Controller has enabled them.
Synci Controller Activities do not include using End User Data for product development, analytics beyond (e), profiling, or marketing.
3.3 Connectivity Providers obtain End User Data under their own licences and their own end-user terms, which End Users accept directly. They act as independent controllers alongside Controller and Synci. They are not Synci's sub-processors, and Synci is not responsible for their processing.
3.4 The parties do not intend to be joint controllers. Neither party will represent to any End User or authority that the parties jointly determine the purposes and means of processing.
Description of processing
The subject matter, duration, nature, purpose, categories of data and categories of data subjects are set out in Annex A.
Controller's obligations
5.1 Controller is responsible for the lawfulness of the processing it instructs, including having a valid lawful basis for each End User, providing End Users with the information required by GDPR Arts. 13 and 14, and disclosing Synci and the relevant Connectivity Providers as recipients with links to the Synci Portal Privacy Notice and the Connectivity Providers' terms.
5.2 Controller's instructions to Synci consist of the Agreement, this DPA, and the settings Controller configures for its Managed app (including providers, countries, connection limits, history depth, retention period, enrichment, and End User email notifications). Changes to those settings are documented instructions. Further instructions must be in writing.
5.3 Controller warrants that its instructions comply with applicable law and will not require Synci to breach any Connectivity Provider agreement.
Synci's obligations as processor
6.1 Instructions. Synci processes End User Data only on Controller's documented instructions, unless required to do otherwise by EU or Member State law or by Norwegian law applicable to Synci, in which case Synci informs Controller before processing unless the law prohibits it. Synci informs Controller without undue delay if it considers an instruction infringes the GDPR or other data protection law.
6.2 Confidentiality. Synci ensures that persons authorised to process End User Data are bound by confidentiality obligations and process the data only as needed to perform the Agreement.
6.3 Security. Synci implements the technical and organisational measures in Annex C and maintains them at a level appropriate to the risk, taking into account the state of the art, the costs of implementation and the nature of the data. Synci may update Annex C provided the overall level of security is not reduced.
6.4 Data subject requests. Taking into account the nature of the processing, Synci assists Controller with appropriate technical and organisational measures in responding to requests from End Users exercising their rights under Chapter III of the GDPR. Synci provides API and portal functions for access, export, disconnection and deletion. If an End User contacts Synci directly with a request concerning End User Data, Synci notifies Controller within 5 working days and does not respond on the merits except on Controller's instruction, save for requests concerning Synci Controller Activities.
6.5 Assistance with compliance. Synci assists Controller, at Controller's reasonable request and taking into account the information available to Synci, in meeting Controller's obligations under GDPR Arts. 32 to 36, including data protection impact assessments and prior consultation. Synci may charge reasonable fees for assistance that goes beyond providing existing documentation and standard platform functions.
6.6 Information. Synci makes available to Controller the information necessary to demonstrate compliance with GDPR Art. 28, as described in clause 10.
Sub-processors
7.1 Controller gives general authorisation for Synci to engage sub-processors. The current list is in Annex B to this DPA, published at synci.io/dpa.
7.2 Synci gives Controller at least 30 days' prior notice of any intended addition or replacement of a sub-processor, by email to the account contact and by updating the published list. Controller may object in writing within that period on reasonable data protection grounds. If the parties cannot resolve the objection within 30 days of the objection, either party may terminate the affected Managed app services on written notice, without penalty, and clause 9 applies.
7.3 Synci imposes on each sub-processor, by written contract, data protection obligations at least as protective as those in this DPA, and remains fully liable to Controller for the sub-processor's performance.
Personal data breach
8.1 Synci notifies Controller without undue delay after becoming aware of a personal data breach affecting End User Data. Notification is sent to the account contact and any breach contact specified in a partner agreement or order form.
8.2 The notification describes, to the extent known at the time, the nature of the breach, the categories and approximate number of End Users and records concerned, the likely consequences, the measures taken or proposed, and a Synci contact point. Information may be provided in phases.
8.3 At Controller's request, Synci assists Controller in meeting its obligations under GDPR Arts. 33 and 34, including providing the information Controller needs for its notification to the supervisory authority and, where Controller requests it, drafting the notification and End User communications for Controller's approval. Synci does not notify supervisory authorities or End Users on Controller's behalf unless Controller instructs it in writing.
8.4 Synci's notification is not an acknowledgement of fault or liability.
Deletion and return
9.1 On deletion of an End User or connection by Controller through the API, Synci deletes the associated End User Data from production systems immediately, revokes all tokens for that End User, and purges the data from backups within 30 days, except for data that must be retained under clause 9.4.
9.2 On termination or expiry of the Agreement or the Managed app services, Controller may elect, by written notice before the termination date, to have End User Data returned in a structured, machine-readable format via the API or export, deleted, or both. Absent an election, Synci deletes. Synci completes deletion within 30 days after the termination date.
9.3 On request, Synci confirms deletion in writing.
9.4 Synci may retain End User Data only to the extent and for as long as required by EU, Member State or Norwegian law, or as reasonably necessary for Synci Controller Activities under clause 3.2(a), (c) and (d), and continues to protect such data under this DPA.
Audit
10.1 Synci makes available to Controller, on request and no more than once in any 12-month period unless a supervisory authority requires otherwise or a breach has occurred, the following: a description of the security measures in Annex C, the current sub-processor list, Synci's information security policy, and responses to a reasonable written security questionnaire.
10.2 If, after reviewing the materials in 10.1, Controller reasonably considers that further verification is required to meet its obligations under GDPR Art. 28(3)(h), Controller or an independent auditor bound by confidentiality may conduct an audit. Audits require at least 30 days' written notice, take place during business hours, are limited in scope to the processing of End User Data, and may not unreasonably interfere with Synci's operations or access data of other customers. Remote audit is used where sufficient.
10.3 Controller bears its own audit costs. Synci may charge reasonable fees for audits exceeding 2 person-days of Synci time per audit, unless the audit reveals a material breach of this DPA.
10.4 Where Synci obtains a third-party security certification or assessment report covering the relevant processing, Synci may provide it in satisfaction of 10.1 and, to the extent it covers the matters in question, 10.2.
International transfers
11.1 Synci processes End User Data within the EEA, except where a sub-processor in Annex B is located outside the EEA.
11.2 Any transfer of End User Data to a third country by Synci or its sub-processors is made only under an adequacy decision, the Standard Contractual Clauses adopted by the European Commission, or another valid transfer mechanism under Chapter V of the GDPR. Controller authorises Synci to enter into the Standard Contractual Clauses with sub-processors on Controller's behalf where required.
11.3 For transfers to the United States, Synci relies on the Standard Contractual Clauses. Where a sub-processor is also certified under the EU-US Data Privacy Framework, Synci treats that certification as supplementary to, and not a substitute for, the Standard Contractual Clauses.
Direct Provider Mode
12.1 Some Connectivity Providers require a direct, verified relationship between the End User and the party that holds the Connectivity Provider's consent, and do not permit an intermediary acting solely as processor. Synci may designate such a Connectivity Provider as operating in "Direct Provider Mode".
12.2 For connections established through a Connectivity Provider in Direct Provider Mode:
- (a) the End User enters Synci's own end-user terms and receives Synci's own privacy notice for that connection, in addition to the Portal Terms;
- (b) Synci is the controller for establishing, verifying, maintaining and terminating the End User's consent and connection with that Connectivity Provider, and for complying with that Connectivity Provider's requirements;
- (c) Synci remains Controller's processor for the onward provision of End User Data to Controller and for all processing performed on Controller's instructions after the data is obtained;
- (d) Controller's privacy notice must reflect (a) to (c) for that provider.
12.3 Synci notifies Controller in writing at least 30 days before applying Direct Provider Mode to a Connectivity Provider that Controller has enabled, or before making a new Connectivity Provider available only in that mode. Controller may disable the provider for its Managed app at any time. Applying Direct Provider Mode is not a breach of this DPA and does not by itself make the parties joint controllers.
12.4 Direct Provider Mode applies only to the Connectivity Providers listed as such in Annex B. It does not alter the roles in clause 3 for any other provider or processing.
Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement, except to the extent such limitation is not permitted by the GDPR. Administrative fines imposed on a party by a supervisory authority for that party's own breach are borne by that party.
Term, assignment and changes
14.1 This DPA applies for as long as Synci processes End User Data on Controller's behalf and until deletion under clause 9 is complete.
14.2 Synci may assign this DPA together with the Agreement to a company that acquires the Synci business, including a limited company established on incorporation of the current sole proprietorship, on written notice to Controller. The assignee assumes all obligations under this DPA.
14.3 Synci may update this DPA where required by changes in law, regulatory guidance or Connectivity Provider requirements, or where the change does not reduce the protection of End User Data. Synci gives Controller at least 30 days' notice of material changes, by email to the account contact of every account that operates a Managed app. Each version, its date and a summary of what changed are listed under Version history below. Where a signed partner agreement incorporates a specific version of this DPA, that version applies until the parties agree otherwise.
Governing law
This DPA is governed by Norwegian law and the venue provisions of the Agreement apply, without prejudice to the mandatory application of the GDPR.
Annex A: Description of processing
| Item | Description |
|---|---|
| Subject matter | Collection, storage, enrichment and delivery of End Users' financial account data to Controller's Managed app |
| Duration | For the term of the Agreement and until deletion under clause 9 |
| Nature | Retrieval from Connectivity Providers via API, storage, normalisation, optional enrichment, delivery via API and webhooks, deletion |
| Purpose | Enabling Controller to provide its own service to End Users; determined by Controller |
| Categories of data subjects | End Users registered by Controller; joint account holders and counterparties appearing in transaction data |
| Categories of personal data | Email address and name supplied by Controller, Controller's own reference for the End User; account identifiers, names and types; account holder names, IBANs and card numbers (redacted in API responses unless Controller holds the sensitive:read scope); balances; transactions (date, amount, currency, counterparty, description, optional enrichment); holdings; connection status and consent metadata; portal technical data (IP, user agent, acceptance timestamp, sign-in code events) |
| Scope of access | Controller's app receives data from every account the End User connects, without per-account selection by the End User; Controller is responsible for informing End Users of this |
| Special categories | Not intentionally processed. Transaction descriptions may incidentally reveal special-category data; Controller is responsible for its lawful basis for such data |
| Retention | As configured by Controller per Managed app; default 60 days (Basic) or 730 days (Pro) of transaction history; deletion per clause 9 |
Annex B: Sub-processors and Connectivity Providers
Sub-processors
| Name | Service | Location | Transfer mechanism |
|---|---|---|---|
| DigitalOcean | The Synci backend API, database and backups: the system of record for End User Data | EU | EEA |
| Vercel | Hosting and delivery of the portal, including the server-side layer through which API responses pass | US | Standard Contractual Clauses (2021) |
| Cloudflare | Network protection and security | US | Standard Contractual Clauses (2021) |
| Resend, with Mailgun as backup | Transactional email to End Users: portal sign-in codes, and connection status emails where enabled by Controller | US | Standard Contractual Clauses (2021) |
| Google Workspace | Synci's support mailbox, where an End User writes in | US | Standard Contractual Clauses (2021) |
| Featurebase | Synci's support helpdesk, where an End User writes in | EU | EEA |
| Ntropy | Transaction enrichment where enabled by Controller | US entity, EU processing endpoint | Standard Contractual Clauses (2021) |
| Microsoft Azure AI Foundry | Transaction enrichment where enabled by Controller, deployed in Sweden | EU | EEA |
| Laravel Nightwatch | Error and performance monitoring | US | Standard Contractual Clauses (2021) |
Transfers to sub-processors outside the EEA rely on the Standard Contractual Clauses, as set out in clause 11.3. A Data Privacy Framework certification, where the sub-processor holds one, is supplementary to those clauses.
Connectivity Providers (independent controllers, not sub-processors)
| Name | Coverage | Direct Provider Mode |
|---|---|---|
| GoCardless SAS (France) | Bank accounts in the UK and Europe | No |
| SnapTrade, Passiv Inc. (Canada) | Brokerage and crypto exchange accounts | No |
| Akahu Limited (New Zealand) | Bank accounts in New Zealand | No |
Annex C: Technical and organisational measures
Summary. The full Information Security Policy is available under clause 10.1.
- Encryption of End User Data in transit (TLS 1.2 or higher) and at rest; application-level encryption of connection credentials and tokens with a key held separately from the database
- Tenant isolation enforced at the application layer and covered by automated cross-tenant tests
- Role-based access; access to production data limited to named persons with a need to know; multi-factor authentication on all administrative access
- Logging of administrative and data access; log retention up to 12 months
- Outbound webhook requests routed through an isolated egress layer to prevent server-side request forgery
- Documented incident response runbook and incident log; annual risk assessment
- Encrypted backups with tested restore; offline backup of the encryption key
- Sub-processors bound by written data protection terms; security review before onboarding
- Register of processing activities maintained
Version history
| Version | Date | Change |
|---|---|---|
| 1.0 | September 3, 2026 | First published. |