Data Processing Agreement (DPA)
Last Updated: August 13, 2026
This Data Processing Agreement ("DPA") is an addendum to the Terms of Service between SynthHires ("Data Processor" or "Company") and the Customer ("Data Controller"). This DPA governs the processing of Personal Data under the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK GDPR, and the California Consumer Privacy Act ("CCPA").
1. Definitions
- "Controller", "Processor", "Data Subject", "Personal Data", "Processing", and "Personal Data Breach" shall have the meanings given to them in the GDPR.
- "Account Metadata" means the limited Personal Data (such as names, email addresses, and billing details) processed by the Processor to manage the Controller's account.
- "Inference Data" means the data transmitted through the Processor's orchestration engine for analysis by third-party foundation models.
2. Scope and Nature of Processing
2.1. Processing of Account Metadata
The Processor shall process Account Metadata solely for the purpose of providing the Services, managing the account, and ensuring platform security (e.g., Audit Logs).
2.2. Zero Data Retention of Inference Data
The parties explicitly acknowledge that the Processor operates a Zero Data Retention architecture for Inference Data. Inference Data is processed ephemerally in volatile memory and is never persisted to disk. Therefore, the Processor acts as a pure transport/proxy layer for Inference Data. The Controller acknowledges that the Processor cannot retrieve, delete, or modify Inference Data once the ephemeral process has terminated.
3. Obligations of the Processor
3.1. Documented Instructions
The Processor shall process Personal Data only on documented instructions from the Controller, including with regard to transfers of Personal Data to a third country, unless required to do so by Union or Member State law.
3.2. Confidentiality
The Processor shall ensure that persons authorized to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
3.3. Security of Processing
Taking into account the state of the art, the costs of implementation and the nature, scope, context, and purposes of processing, the Processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including inter alia: a. Default Client-Side Encryption for API Credentials. b. Sandboxed, ephemeral Linux runtimes for agent execution. c. Continuous vulnerability scanning and annual SOC 2 Type II audits.
4. Subprocessing (Article 28 GDPR)
4.1. General Authorization
The Controller grants the Processor a general authorization to engage Subprocessors. The Processor maintains an up-to-date list of Subprocessors on its website.
4.2. Subprocessor Obligations
Where the Processor engages a Subprocessor, the same data protection obligations as set out in this DPA shall be imposed on that Subprocessor by way of a contract, providing sufficient guarantees to implement appropriate technical and organizational measures.
5. Data Subject Rights
Taking into account the nature of the processing, the Processor shall assist the Controller by appropriate technical and organizational measures, insofar as this is possible, for the fulfilment of the Controller's obligation to respond to requests for exercising the Data Subject's rights laid down in Chapter III of the GDPR.
6. Personal Data Breaches
In the event of a Personal Data Breach affecting Account Metadata, the Processor shall notify the Controller without undue delay (and in no event later than 48 hours) after becoming aware of the breach. The notification shall contain sufficient information to allow the Controller to meet its obligations under Article 33 of the GDPR.
7. Return or Deletion of Data
Upon termination of the Services, the Processor shall, at the choice of the Controller, delete or return all Account Metadata to the Controller, and delete existing copies unless Union or Member State law requires storage of the Personal Data. (Note: Inference Data is inherently deleted in real-time by the Zero Data Retention architecture).
8. Audits and Inspections
The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 of the GDPR. Upon request, the Processor will provide a summary copy of its most recent SOC 2 Type II audit report under strict NDA.
9. Standard Contractual Clauses (SCCs)
For transfers of Personal Data from the EEA to countries not recognized by the European Commission as providing an adequate level of protection, the parties agree that the Standard Contractual Clauses (Module Two: Transfer controller to processor) shall apply and are hereby incorporated by reference.