Data Processing Agreement (DPA)

Last updated: 3 September 2026 · version 1.3

1. Purpose and parties

This data processing agreement ("DPA") is entered into between Syniaps ("the Processor"), publisher of the Syniaps service ("the Service"), and the customer holding an account ("the Customer", acting as "Controller"). It governs, in accordance with Article 28 of the General Data Protection Regulation (GDPR), the processing of the personal data that the Customer entrusts to the Service. It forms an integral part of the Terms of Use and prevails over them in all matters relating to the protection of personal data.

A PDF version of this agreement, intended for customers wishing a counter-signature, is available here: download the DPA (PDF). The online text and the PDF of the same version are identical.

2. Roles and instructions

The Customer determines the purposes and means of the processing of the personal data it imports, synchronizes or enters into the Service: it is the Controller. Syniaps processes this data exclusively to provide the Service and on the Customer's documented instructions; the use of the Service's features (import, synchronization, requests to the assistant, automations) constitutes those instructions. Syniaps informs the Customer if an instruction appears to it to infringe the GDPR.

For the data of its own operation (accounts, billing, technical logs, security), Syniaps acts as controller, under the conditions described in the Privacy Policy.

3. Description of the processing

  • Nature and purpose: hosting, storage, indexing, analysis and restitution of the Customer's content by an artificial intelligence assistant, for the Customer's sole needs; synchronization with the cloud services the Customer connects; execution of the automations the Customer configures.
  • Categories of data: identification and contact data (users, business contacts), content of documents and messages imported or synchronized by the Customer, history of conversations with the assistant, and any personal data the Customer chooses to entrust to the Service.
  • Data subjects: the Customer's users, its employees, customers, prospects, suppliers and more generally any person whose data appears in the content entrusted.
  • Duration: for the entire term of the contract. Data is kept as long as the Customer's account is active, then handled as described in Article 10.

The Service is not designed to host health data within the meaning of the French regulations on the hosting of health data (HDS): the Customer undertakes not to entrust such data to it.

4. Confidentiality

Syniaps warrants that the persons authorized to process the Customer's data are bound by an obligation of confidentiality. Access to the Customer's data by Syniaps staff is limited to what is strictly necessary for operations, security and support, and, for content, only takes place with the Customer's consent as part of a support request it initiates, except where required by law or by a security investigation.

5. Security

Syniaps implements in particular the following technical and organizational measures:

  • encryption of exchanges in transit (TLS);
  • a dedicated server per customer company, hosted in France: one customer's data shares no machine with another's; within the company, each user works in an environment isolated at system level;
  • strong authentication mandatory for all users;
  • encryption at rest of the credentials and secrets entrusted by the Customer (site passwords, access tokens, API keys, session cookies), stored in restricted-access files on servers that are not publicly exposed, never in a database, with the decryption key kept separately from those files;
  • logging of sensitive actions;
  • daily encrypted backups kept off the server, in France (with OVHcloud): data is encrypted before being sent and the decryption key is never stored with the backups;
  • principle of least privilege for the internal components of the Service.

All of the Customer's data and its backups are hosted in France.

6. Sub-processors

The Customer gives Syniaps general authorization to use sub-processors for specific functions of the Service. The up-to-date list appears in the "Processors and transfers" section of the Privacy Policy; as of this version, they are Anthropic (AI models, default provider), OpenAI (real-time voice conversation; ChatGPT models only if the Customer connects a ChatGPT account), Google (Gemini models only if the Customer connects a Google account), Moonshot AI (Kimi models only if the Customer connects a Kimi account), Mistral AI (optional OCR), Stripe (payment), Resend (transactional emails), Cloudflare (delivery and network access control), OVHcloud (hosting of encrypted backups, in France) and the hosting provider of the Service's servers (in France). An alternative AI model provider (OpenAI, Google, Moonshot AI) only intervenes on the Customer's explicit decision, who connects it themselves after being informed and consenting in the interface: it is then a sub-processor chosen by the Customer, whose processing terms apply, and the Customer undertakes, for an individual Google account, to turn off the use of its exchanges for the improvement of Google's products and models. Syniaps imposes on each sub-processor it chooses obligations equivalent to those of this agreement and remains fully liable to the Customer for their performance.

Syniaps informs the Customer of any addition or replacement of a sub-processor (update of the list and, for substantial changes, email to the administrators). The Customer may object on legitimate grounds within 30 days of being informed; failing agreement on an alternative solution, it may terminate the Service under the conditions of the Terms of Use.

7. Transfers outside the European Union

The Customer's data and its backups are hosted in France. Some sub-processors may process data outside the European Union (notably in the United States, for processing by the AI model, payment or the sending of emails; and, if the Customer connects Kimi, at Moonshot AI, outside the European Union); these transfers are governed by the mechanisms provided for in Chapter V of the GDPR: an adequacy decision (including the "Data Privacy Framework") or the European Commission's standard contractual clauses. For an alternative AI model provider it connects itself, the Customer ensures, as data controller, that it has an appropriate transfer mechanism (article 6 above).

8. Assistance to the Controller

Taking into account the nature of the processing, Syniaps assists the Customer, through appropriate technical and organizational measures, in responding to requests to exercise the rights of data subjects (access, rectification, erasure, portability, objection, restriction). Syniaps forwards to the Customer without delay any request that a data subject may address to it directly concerning the Customer's data. Syniaps also assists the Customer, insofar as reasonable, with its obligations under Articles 32 to 36 of the GDPR (security, breach notification, impact assessments).

9. Data breach

Syniaps notifies the Customer of any personal data breach affecting its data without undue delay after becoming aware of it, at the email address of the workspace administrators. The notification describes, to the extent of the information available, the nature of the breach, the categories and approximate volume of data and data subjects concerned, the likely consequences and the measures taken or proposed.

10. Fate of the data at the end of the contract

At the end of the contract (termination or non-conversion of the trial), access to the Service is cut off at the end of the current period, then all of the Customer's data is deleted within 30 days. During this period, the Customer may request the return of its content (synchronized documents in any case remain present in the Customer's cloud services, as the Service never deletes anything there). The Customer may request early deletion at any time. Syniaps may keep beyond that only the data whose retention is required by law (billing in particular), for the applicable statutory period. The copies held in encrypted backups expire on their own by rotation within a maximum of six months after this deletion; they are not used for any other purpose.

11. Audit and documentation

Syniaps makes available to the Customer the information necessary to demonstrate compliance with this agreement, first and foremost this documentation and the Privacy Policy. The Customer may, at most once per 12-month period and subject to 30 days' written notice, conduct or have conducted an audit limited to the scope of this agreement, during business hours, without access to other customers' data and without disrupting the Service; each party bears its own costs.

12. Acceptance, version and changes

This agreement is accepted online when applying to sign up for the Service (checkbox accepting the Terms of Use and the DPA); the date and version accepted are recorded and constitute evidence between the parties. Customers who wish may request a counter-signature of the PDF version at [email protected].

The version number and the date appear at the top of the page. In the event of a substantial change, workspace administrators are notified by email and previous versions remain available on request. Version 1.1 of 9 August 2026 reproduces version 1.0 of 8 July 2026 identically, with the current name of the service (Syniaps). Version 1.2 of 27 August 2026 adds the alternative artificial intelligence providers the Client may choose to connect (section 6) and clarifies the resulting transfer regime (section 7).

Data Processing Agreement (DPA) | Syniaps