Data Processing Addendum
Last updated: June 11, 2026
This Data Processing Addendum (“DPA”) supplements the agreement between the customer (“Controller”) and Synaptis Technologies LLC (“Processor”, “we”) and governs the processing of personal data that Synaptis performs on the Controller’s behalf in connection with our services. This DPA is incorporated by reference into the applicable order form or subscription agreement (“Agreement”). To execute a countersigned copy of this DPA, contact trust@synaptisusa.com.
1. Definitions
- “Personal Data” means any information relating to an identified or identifiable natural person as defined under applicable Data Protection Laws.
- “Data Protection Laws” means all applicable data-protection legislation including GDPR (EU) 2016/679, UK GDPR, and equivalent laws.
- “Processing” has the meaning given under applicable Data Protection Laws.
- “Sub-processor” means any third party engaged by the Processor to process Personal Data on the Controller’s behalf.
- “Standard Contractual Clauses” or “SCCs” means the clauses adopted by the European Commission for international data transfers.
2. Scope and Instructions
The Processor will process Personal Data only on documented instructions from the Controller, including for transfers of Personal Data to a third country, unless required to do so by applicable law. The Processor will inform the Controller of that legal requirement before processing unless prohibited from doing so by law.
2.1 Subject Matter and Nature
Processing of personal data submitted to or generated within the Services, including account data, clinical documentation, and usage logs, for the purpose of providing the Services.
2.2 Duration
For the term of the Agreement, plus any retention period required by law or as set out in our data-retention policy.
2.3 Categories of Data Subjects
- Healthcare professionals using the Services;
- Patients whose data is processed through clinical workflows (if applicable);
- Representatives and employees of the Controller.
2.4 Categories of Personal Data
- Identifiers: name, email, user ID, IP address;
- Professional information: organization, role, provider credentials;
- Clinical data: structured notes, transcripts, and records where the Controller’s use case involves clinical documentation.
3. Processor Obligations
The Processor shall:
- Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including at minimum encryption at rest (AES-256) and in transit (TLS 1.3+), access controls, and regular security assessments;
- Ensure that personnel authorized to process Personal Data are bound by confidentiality obligations;
- Not engage Sub-processors without prior written authorization from the Controller, unless the Controller has given general written authorization (see Section 5);
- Assist the Controller with data-subject rights requests (access, erasure, portability, restriction) by providing relevant data within 10 business days of request;
- Notify the Controller without undue delay (and in any event within 72 hours) of becoming aware of a Personal Data breach;
- At the end of the Agreement, delete or return all Personal Data unless retention is required by law.
4. Controller Obligations
The Controller is responsible for ensuring it has a lawful basis for processing Personal Data and for notifying data subjects in accordance with applicable Data Protection Laws. The Controller shall not instruct the Processor to process data in a manner that would violate applicable law.
5. Sub-processors
The Controller grants general written authorization to use the Sub-processors listed on our Subprocessor List, which is updated periodically. We will notify the Controller at least 30 days before adding or replacing a material Sub-processor. The Controller may object to a new Sub-processor within 14 days of notification by emailing trust@synaptisusa.com.
6. International Transfers
Where the processing of Personal Data involves a transfer to a country outside the EEA or United Kingdom without an adequacy decision, we will rely on:
- Standard Contractual Clauses (Module 2: Controller to Processor) as adopted by the European Commission; or
- An equivalent approved transfer mechanism under UK GDPR; or
- A Transfer Impact Assessment (TIA) where required.
Enterprise customers may request a countersigned SCC addendum by contacting trust@synaptisusa.com.
7. Audits
Upon written request and at least 30 days’ notice, the Processor will contribute to audits or inspections conducted by the Controller or a mandated auditor. The Processor may alternatively provide its most recent third-party audit report (SOC 2 Type II, penetration test summary) in satisfaction of an audit request.
8. HIPAA Relationship
For customers subject to HIPAA, this DPA is supplemental to any HIPAA Business Associate Agreement (BAA) executed between the parties. In the event of a conflict between this DPA and the BAA with respect to Protected Health Information, the BAA will govern.
9. Term and Termination
This DPA is co-terminus with the Agreement. Obligations that by their nature survive termination (including breach notification, data deletion, confidentiality, and audit rights) will survive.