SynectGEO · Legal
Data Processing Agreement
Last updated: 25 July 2026
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between SYNECT LIMITED (“SynectGEO”, “we”, the processor) and the business customer (“you”, the controller). It applies where, in your use of SynectGEO, you submit content (brand names, website URLs, prompts) that may contain personal data for which you are the controller, and we process it on your behalf under GDPR Article 28.
1. Roles & Scope
You are the controller and SYNECT LIMITED is the processor of any personal data contained in the content you submit (“Customer Personal Data”). Each party complies with the GDPR (Regulation (EU) 2016/679) in respect of its role. This DPA does not apply to data for which we are the controller (e.g. your account and billing data), which is governed by our Privacy Policy.
2. Details of Processing
- Subject matter & purpose: processing the content you submit to generate AI-visibility, content, and off-page reports.
- Duration: for the term of your subscription and until deletion under Section 8.
- Nature of processing: collection, storage, transmission to the sub-processors listed in our Privacy Policy, analysis, and generation of reports.
- Types of personal data: any personal data incidentally contained in the brand names, URLs, prompts, or public search results you submit or that the service returns. You must not submit special-category data.
- Categories of data subjects: individuals who may be named or referenced in that content (e.g. authors, employees, spokespeople).
3. Our Obligations as Processor
- Process Customer Personal Data only on your documented instructions (this DPA and your use of the service being those instructions), unless required otherwise by EU or member-state law.
- Ensure persons authorised to process the data are bound by confidentiality.
- Implement appropriate technical and organisational security measures (GDPR Article 32) — including encryption in transit and at rest, access controls, and EU-hosted primary storage.
- Assist you, taking into account the nature of processing, in responding to data-subject requests (Articles 15–22) and in meeting your obligations under Articles 32–36 (security, breach notification, DPIAs).
- Notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data.
- Inform you if, in our opinion, an instruction from you infringes the GDPR or other EU or member-state data-protection law.
4. Sub-Processors
You give general authorisation for us to engage the sub-processors listed in our Privacy Policy. We impose data-protection obligations on each sub-processor no less protective than those in this DPA, and we remain liable for their performance. We will give you a reasonable opportunity to object before adding a new sub-processor that processes Customer Personal Data.
5. International Transfers
Our primary infrastructure is EU-hosted. Where Customer Personal Data is transferred to a sub-processor outside the EEA, the transfer is made under the EU Standard Contractual Clauses or another valid GDPR Chapter V mechanism, as set out in our Privacy Policy.
6. Audit
On reasonable written request and no more than once per year (or after a breach), we will make available information necessary to demonstrate compliance with this DPA and allow for and contribute to audits conducted by you or an auditor you mandate, subject to confidentiality and to not compromising other customers’ data.
7. Data-Subject Requests
If we receive a request from a data subject relating to Customer Personal Data, we will not respond directly (unless legally required) and will forward it to you without undue delay so you can respond as controller.
8. Return & Deletion
On termination, or on your request, we delete or return Customer Personal Data and delete existing copies, unless EU or member-state law requires storage (e.g. tax records). Report data is in any case deleted per the retention schedule in our Privacy Policy.