Data Processing Agreement (DPA)
This template DPA reflects the standard terms Synergy Axella offers customers. If you need a signed copy, email privacy@synergyaxella.com stating your legal entity, controller contact, and country.
1. Subject matter
Synergy Axella (Processor) processes personal data on behalf of the Customer (Controller) solely to provide the Platform.
2. Duration
The DPA is in force for the duration of the underlying subscription agreement plus 90 days for data return/deletion.
3. Categories of data
- Identifiers (email, name, role)
- Operational content authored by users
- Security metadata (login logs, IP, session identifiers)
4. Sub-processors
See the Sub-processors register.
5. Technical & organisational measures (Art. 32)
- TLS 1.2+ for all traffic
- bcrypt password hashing, TOTP MFA for admin accounts
- Role-based access control (RBAC)
- 30-minute inactivity session timeout
- Login rate limiting (5 attempts / 15 min lockout)
- Backups: daily snapshots, tested restore
- Audit logs of authentication events
- Employee confidentiality obligations
6. International transfers
Where transfers outside the EEA occur, they are governed by the EU Standard Contractual Clauses (2021/914).
7. Data subject requests
Synergy Axella will assist the Controller in responding to data subject requests within 15 calendar days of the request.
8. Breach notification
Synergy Axella will notify the Controller of any confirmed personal data breach without undue delay and within 48 hours of discovery.
9. Audit rights
The Controller may audit compliance annually with reasonable notice, or rely on the latest independent audit report (Synergy Axella's ISO 27001 certification target: 2026).
Synergy Axella · [Registered address, Belgium — replace with legal entity's official seat] · VAT: [VAT / BCE-KBO number — replace]
Questions? Contact privacy@synergyaxella.com (DPO: dpo@synergyaxella.com).
Placeholder text — please review with your legal counsel before publication.