Syntra Logo
Legal & Trust

Data Processing Addendum

Last updated: 4 July 2026

This Data Processing Addendum sets out the processor terms under which Syntra handles personal data on your behalf when you use the Services, including the security measures we apply, our use of sub-processors, international transfers and how we help you meet data-subject requests.

1.Introduction & scope

This Data Processing Addendum (the "DPA") forms part of, and is incorporated into, the Terms of Service (the "Terms") between SYNTRA LLC ("Syntra", "we", "us" or "our"), of 8 The Green, Dover, Delaware 19901, and the business or individual that uses the Services ("Customer", "you" or "your"). Capitalised terms not defined here have the meanings given in the Terms.

This DPA applies where, and to the extent that, Syntra processes personal data contained in Customer Data on the Customer's behalf in the course of providing the Services. In respect of that personal data, the Customer is the controller (or, where the Customer is itself acting on behalf of a third party, a processor) and Syntra is the processor (or sub-processor). Where Syntra processes personal data as a controller in its own right, that processing is governed by our Privacy Policy and not by this DPA.

2.Definitions

  • Data Protection Laws - all laws and regulations applicable to the processing of personal data under this DPA, including, where applicable, the EU General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR"), the UK GDPR and the Data Protection Act 2018 ("UK GDPR"), and US state privacy laws such as the California Consumer Privacy Act as amended ("CCPA").
  • Personal Data - any information relating to an identified or identifiable natural person that is contained in Customer Data and processed by Syntra on the Customer's behalf under this DPA.
  • Processing - any operation performed on Personal Data, whether or not by automated means, such as collection, recording, storage, use, transmission, disclosure or erasure. Process is construed accordingly.
  • Data Subject - the identified or identifiable natural person to whom the Personal Data relates.
  • Sub-processor - any third party engaged by Syntra to process Personal Data on the Customer's behalf in connection with the Services.
  • Personal Data Breach - a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data processed by Syntra.

3.Roles & processing instructions

The parties acknowledge that, in respect of the Personal Data, the Customer is the controller and Syntra is the processor. Each party will comply with its obligations under the Data Protection Laws that apply to it.

Syntra will process Personal Data only on the Customer's documented instructions, including as set out in the Terms, this DPA and the Customer's configuration and use of the Services, and as necessary to provide, secure and support the Services - unless required to do otherwise by law, in which case Syntra will, where permitted, inform the Customer of that legal requirement before processing. Syntra will promptly inform the Customer if, in its opinion, an instruction infringes the Data Protection Laws. The Customer is responsible for ensuring that its instructions, and the Personal Data it provides, comply with the Data Protection Laws and that it has a lawful basis for the processing.

4.Details of processing

The subject matter, duration, nature, purpose, types of Personal Data and categories of Data Subjects are as follows:

ElementDetails
Subject matterSyntra's processing of Personal Data as necessary to provide the Services to the Customer under the Terms, including the AI Agent that makes and answers calls, sends messages and takes bookings on the Customer's behalf.
DurationFor the term of the Customer's Subscription, plus any period afterwards during which the Personal Data is retained pending return or deletion in accordance with this DPA and the Terms.
Nature & purposeHosting, storage, transmission, analysis and other processing of Personal Data to operate, maintain, secure, support and improve the Services and to generate Output on the Customer's behalf, including handling calls, messages, enquiries and bookings with the Customer's End Users.
Types of Personal DataIdentifiers and contact details (such as names, phone numbers, email and postal addresses); communications content, call recordings, transcripts and message history; appointment, booking and enquiry details; and any other Personal Data the Customer or its End Users choose to include in Customer Data.
Categories of Data SubjectsThe Customer's End Users (such as its customers, clients, patients and contacts) and the Customer's own staff and authorised users.

5.Confidentiality

Syntra will ensure that personnel authorised to process the Personal Data are subject to appropriate obligations of confidentiality, whether a contractual or statutory duty, and will limit access to those personnel who need it to provide, secure or support the Services.

6.Security measures

Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as well as the risk to Data Subjects, Syntra will implement and maintain appropriate technical and organisational measures designed to protect the Personal Data against a Personal Data Breach and to ensure a level of security appropriate to the risk. A description of the measures we apply is set out on our Security page. The Customer is responsible for configuring and using the Services, and for securing its own systems and credentials, in a manner appropriate to its Personal Data.

7.Sub-processing

The Customer authorises Syntra to engage Sub-processors to process the Personal Data in connection with the Services. The Sub-processors we currently use are listed on our Sub-processors page.

Where Syntra engages a Sub-processor, it will impose on that Sub-processor, by written contract, data-protection obligations that are substantially equivalent to those set out in this DPA, and Syntra remains responsible to the Customer for the performance of each Sub-processor's obligations. Syntra will give the Customer reasonable notice of any intended addition or replacement of a Sub-processor, giving the Customer the opportunity to object on reasonable data-protection grounds; if the parties cannot resolve a reasonable objection, the Customer may, as its sole remedy, terminate the affected Services.

8.Data-subject rights

Taking into account the nature of the processing, Syntra will provide reasonable assistance to the Customer, by appropriate technical and organisational measures and insofar as possible, to help the Customer respond to requests from Data Subjects to exercise their rights under the Data Protection Laws (such as rights of access, rectification, erasure, restriction, portability and objection). If Syntra receives such a request directly from a Data Subject relating to the Customer's Personal Data, it will, unless legally prohibited, promptly inform the Customer and will not otherwise respond except on the Customer's instructions.

9.Assistance

Taking into account the nature of the processing and the information available to it, Syntra will provide the Customer with reasonable assistance in ensuring compliance with the Customer's obligations relating to the security of processing, the notification of Personal Data Breaches, the carrying out of data-protection impact assessments, and any prior consultations with supervisory authorities that the Data Protection Laws require.

10.Personal-data-breach notification

Syntra will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting the Personal Data. The notification will, to the extent then known and permitted by law, describe the nature of the breach, its likely consequences and the measures taken or proposed to address it, and Syntra will provide further information as it becomes available. Syntra's notification is not an acknowledgement of fault or liability. The Customer is responsible for any notifications it is required to make to supervisory authorities or Data Subjects.

11.International transfers

The Customer authorises Syntra and its Sub-processors to transfer and process Personal Data outside the country in which it was collected, including to the United States, as necessary to provide the Services. Where Personal Data protected by the GDPR or UK GDPR is transferred to a country that has not been recognised as providing an adequate level of protection, Syntra will ensure that an appropriate transfer safeguard is in place, such as the European Commission's Standard Contractual Clauses (and the UK Addendum, where applicable), which are incorporated into this DPA by reference and take precedence in the event of conflict on transfer matters.

12.Return & deletion

On termination or expiry of the Services, or on the Customer's earlier written request, Syntra will, at the Customer's choice, delete or return the Personal Data it processes on the Customer's behalf, and delete existing copies, unless retention is required by law. As described in the Terms, the Customer may export its Customer Data for a limited period after termination; after that period, Syntra may delete Personal Data in accordance with its standard retention practices. Personal Data held in routine backups is deleted in the ordinary course of Syntra's backup cycle.

13.Audits & information

Syntra will make available to the Customer information reasonably necessary to demonstrate compliance with its obligations under this DPA and will allow for and contribute to reasonable audits, including inspections, conducted by the Customer or an independent auditor it mandates. Audits will be conducted no more than once per year (except where required by a supervisory authority or following a Personal Data Breach), on reasonable prior notice, during business hours, subject to appropriate confidentiality obligations, and in a manner that does not disrupt Syntra's operations or compromise the security or confidentiality of other customers' data. Syntra may satisfy this obligation by providing relevant certifications, audit reports or summaries where available.

14.US state privacy laws

To the extent US state privacy laws such as the CCPA apply, Syntra acts as a service provider (or processor) with respect to the Personal Data. Syntra will not sell or share the Personal Data, will not retain, use or disclose it for any purpose other than providing the Services as specified in the Terms and this DPA (or as otherwise permitted by those laws), and will not combine it with personal information from other sources except as permitted. Syntra certifies that it understands and will comply with these restrictions.

15.Order of precedence

This DPA supplements the Terms. In the event of any conflict between this DPA and the Terms in relation to the processing of Personal Data, this DPA prevails on data-protection matters. Where any Standard Contractual Clauses or other transfer mechanism apply, they prevail over this DPA to the extent of any conflict on transfer matters. In all other respects, the Terms remain in full force and effect.

16.Contact us

If you have any questions about this DPA, or would like a countersigned copy, please contact us. A signed copy of this DPA is available on request.

SYNTRA LLC
8 The Green, Dover, Delaware 19901
hello@syntra.ai

The best investment you’ll make this year

Join the 1% of businesses always open, always earning.