Data processing addendum
Effective 22 August 2026
This addendum forms part of the SynPulse Terms of Service when a customer uses SynPulse to process personal data for which that customer is the controller. The customer is the controller and SynPulse is the processor unless applicable law assigns different roles.
Instructions and purpose
SynPulse processes account identity, contacts, outreach content, engagement records, suppression data, and connected-provider metadata only to provide, secure, support, and improve the subscribed service and as otherwise documented or lawfully instructed by the customer.
Confidentiality and security
Personnel and contractors with access are bound by confidentiality. SynPulse maintains proportionate technical and organizational measures, including access control, tenant isolation, encryption in transit and for provider secrets at rest, logging controls, backups, vulnerability management, and incident response.
Service partners and transfers
The customer authorizes the service partners on the published list. SynPulse remains responsible for their data-processing obligations and uses lawful transfer mechanisms where personal data crosses borders. A customer may object to a material new service partner on reasonable data protection grounds before the announced change takes effect.
Assistance and incidents
Taking account of the nature of processing, SynPulse assists with data subject requests, impact assessments, regulator consultations, and compliance evidence reasonably available to it. SynPulse will notify the customer without undue delay after confirming a personal-data breach affecting customer data.
Return and deletion
During the subscription, owners can export supported workspace data. After termination, SynPulse returns or deletes customer data on request, except where retention is legally required or data remains temporarily in protected backups until normal expiry.
Audit
On reasonable written request, SynPulse provides relevant security and compliance information. If that is insufficient, the parties may agree to a scoped independent audit that protects other customers and does not unreasonably disrupt the service.