Data Processing Agreement (DPA Summary)
This Draft Data Processing Agreement Summary ("DPA Summary") outlines the contractual terms under which [Syntropy AI Global LLC] ("Processor" / "Service Provider") processes Personal Data on behalf of our B2B Customers ("Controller" / "Business").
1. Role of the Parties & Processing Instructions
When your business uses our software, you are the Data Controller and we are your Data Processor. We only process your data to deliver the software services you contracted for.
In accordance with GDPR Article 28 and the CCPA/CPRA, Customer is the Data Controller (or Business) and [Syntropy AI Global LLC] is the Data Processor (or Service Provider). We process Customer Personal Data solely on documented instructions from Customer—including to provide, maintain, secure, and support the subscribed software modules—and never "sell" or "share" Customer Personal Data for cross-context behavioral advertising.
2. Annex I Summary: Details of Data Processing
This table summarizes what data is processed, whose data it is, and how long processing lasts under our standard DPA.
Our formal DPA includes the following statutory processing specifications:
| DPA Element | Standard Specification |
|---|---|
| Subject Matter & Duration | Provision of Syntropy AI Global SaaS and Custom Software services for the duration of the active Order Form plus the post-termination data export window. |
| Nature & Purpose of Processing | Cloud hosting, offline-to-online device synchronization, inventory reconciliation, CRM pipeline routing, and customer technical support. |
| Categories of Data Subjects | Customer’s authorized employees/cashiers, store managers, sales representatives, B2B prospects/leads, and retail loyalty contacts. |
| Categories of Personal Data | Names, business emails, phone numbers, role titles, employee shift scan IDs, CRM lead form submissions, and system audit logs. (Excludes raw payment card PAN/CVV). |
3. Annex II Summary: Technical & Organizational Security Measures (TOMs)
We contractually commit to encrypting data in transit and at rest, isolating tenant data, enforcing access controls, and notifying you promptly if a confirmed data breach ever occurs.
[Syntropy AI Global LLC] maintains Technical and Organizational Measures (TOMs) including TLS 1.2/1.3 encryption in transit, AES-256 encryption at rest, multi-tenant logical isolation, Role-Based Access Control (RBAC), daily encrypted backups with Point-in-Time Recovery (PITR), and personal data breach notification without undue delay (and within `[48 / 72 hours]` of confirmation).
4. Sub-processors, Audits & International Transfers (SCCs)
Our DPA includes EU/UK Standard Contractual Clauses (SCCs) for cross-border transfers, links to our Sub-processors list, and provides audit/deletion rights.
Sub-processors: Customer authorizes engagement of the sub-processors listed at /legal/sub-processors. We enter into written agreements with each sub-processor imposing data protection obligations no less protective than our DPA.
International Transfers: The DPA incorporates the EU Standard Contractual Clauses (SCCs) and UK International Data Transfer Addendum by reference.
Requesting a Signed Copy: To request a countersigned PDF of our full Data Processing Agreement, email privacy@[yourdomain.com] or legal@[yourdomain.com].