Data Processing Agreement
Last updated: July 6, 2026
1. Introduction and Incorporation
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Synton AI, Inc. ("Synton", the "Processor") and the merchant accepting the Terms (the "Merchant", the "Controller"). It applies automatically, without signature, wherever Synton processes personal data on the Merchant's behalf that is subject to the EU GDPR, UK GDPR, Swiss FADP, or similar data protection laws ("Data Protection Laws").
Merchants who require a countersigned copy for their records can request one at legal@synton.ai.
2. Roles and Scope of Processing
The Merchant is the controller of End Customer Data; Synton is the processor. Where Synton processes merchant account data for its own purposes (billing, security, product improvement), Synton acts as an independent controller as described in the Privacy Policy.
| Item | Description |
|---|---|
| Subject matter | Provision of the Synton AI commerce operating system |
| Duration | The term of the Merchant’s use of the Service, plus the deletion period in Section 9 |
| Nature and purpose | Hosting, storage, analysis, AI-assisted processing, transmission, and display of data to operate the Merchant’s store, storefronts, marketing, analytics, meetings, and operations features |
| Categories of data subjects | The Merchant’s customers, storefront visitors, email subscribers, meeting participants, prospects, and end users |
| Categories of personal data | Identification and contact data (name, email, phone, address); order and transaction data; behavioral data (page views, session recordings, heatmaps) where enabled; communications content (chats, emails, reviews); audio/video and transcripts where meeting features are used; business contact data for prospecting where enabled |
| Special categories | None intended. The Merchant agrees not to direct special-category data into the Service unless separately agreed in writing |
3. Processor Obligations
Synton shall:
- Process End Customer Data only on the Merchant’s documented instructions — given through the Service’s configuration, features, and APIs, the Terms, and this DPA — unless required otherwise by law, in which case Synton informs the Merchant unless prohibited
- Immediately inform the Merchant if, in its opinion, an instruction infringes Data Protection Laws
- Ensure persons authorized to process the data are bound by confidentiality obligations
- Implement the technical and organizational measures described in Section 6
- Assist the Merchant, taking into account the nature of processing, in responding to data subject requests and in meeting its obligations regarding security, breach notification, and data protection impact assessments
- Delete or return personal data at the end of the engagement per Section 9
- Make available information necessary to demonstrate compliance and allow audits per Section 10
4. Merchant Obligations
- The Merchant warrants it has a lawful basis for the End Customer Data it directs into the Service and has provided any legally required notices to its data subjects
- The Merchant is responsible for consent and notice obligations specific to features it enables — including behavioral analytics/session recording on its storefront, meeting and call recording, and marketing outreach
- The Merchant configures retention settings, autonomy levels, and integrations, which constitute processing instructions
5. Sub-processing
The Merchant grants Synton general authorization to engage sub-processors. The current list — including purpose and location — is published at synton.ai/subprocessors. Synton will:
- Impose data protection obligations on each sub-processor no less protective than this DPA
- Remain fully liable to the Merchant for its sub-processors’ performance
- Provide at least 14 days’ advance notice of new sub-processors (via the sub-processors page and its change log, or by email for Enterprise merchants who subscribe to notifications)
- Allow the Merchant to object on reasonable data-protection grounds; if the objection cannot be resolved, the Merchant may terminate the affected features or the agreement and receive a pro-rated refund of prepaid, unused fees
6. Security Measures (Annex II Summary)
- Encryption of data in transit (TLS 1.2+) and encryption at rest for sensitive data, tokens, and stored credentials
- OAuth 2.0 for platform connections; signed, single-use authentication links; role-based access control with least-privilege staff access
- Cryptographic verification of inbound webhooks; audit receipts show whether append-only anchoring succeeded, and only verified anchors are described as tamper-evident
- Sandboxed, permission-capped execution of merchant code and automations; isolated runtimes for hosted storefronts
- Network segmentation, host firewalls, and DDoS mitigation at the edge
- Redundant infrastructure across nodes; backups with defined retention; documented deployment and rollback procedures
- Vulnerability management, security reviews, and monitoring/alerting
- Personnel confidentiality commitments and access revocation on role change
7. Personal Data Breach
Synton will notify the Merchant without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting End Customer Data. The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records affected, likely consequences, and measures taken or proposed. Synton will cooperate with the Merchant and take reasonable steps to mitigate and remediate.
8. International Transfers
Synton's primary infrastructure is located in the European Union. Where processing involves transfer of EU/UK/Swiss personal data to a country without an adequacy decision (including to Synton AI, Inc. in the United States or to sub-processors there):
- The EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (controller-to-processor) and Module Three (processor-to-processor) as applicable, are incorporated by reference, with the Merchant as data exporter and Synton as data importer; optional clause 7 (docking) included; clause 9 option 2 (general authorization, 14 days); clause 17 governed by the law of Ireland; clause 18 courts of Ireland
- For UK transfers, the UK International Data Transfer Addendum to the EU SCCs applies
- For Swiss transfers, the SCCs apply as adapted by the Swiss FDPIC’s requirements
- The descriptions in Section 2 (processing details) and Section 6 (security measures) serve as Annexes I and II to the SCCs; the sub-processor list serves as Annex III
9. Deletion and Return
Upon termination or expiry of the Service, Synton will, at the Merchant's choice, return End Customer Data in a commonly used machine-readable format (export available for 30 days after termination) and thereafter delete it, or delete it directly, except where retention is required by law. Deletion timelines for platform webhooks (for example Shopify shop/redact within 48 hours, customers/redact within 30 days) are honored as published in the Privacy Policy. Data ages out of encrypted backups on a rolling schedule.
10. Audits
Synton will make available documentation reasonably necessary to demonstrate compliance with this DPA (security summaries, sub-processor list, certifications as they are obtained). Where Data Protection Laws grant the Merchant an audit right that cannot be satisfied by documentation, the Merchant may conduct — at most once per 12-month period, on 30 days' notice, during business hours, without disrupting operations, and under confidentiality — an audit via an independent third party that is not a competitor of Synton. Each party bears its own costs.
11. Liability and Precedence
Liability under this DPA is subject to the limitations of liability in the Terms of Service, to the extent permitted by Data Protection Laws. In case of conflict, the SCCs prevail over this DPA, and this DPA prevails over the Terms with respect to processing of personal data.
12. Contact
Data protection inquiries: privacy@synton.ai · Legal: legal@synton.ai