Legal
Data Processing Agreement
Last updated 17 August 2026
This Data Processing Agreement ("DPA") forms part of and is incorporated into the Terms of Service between Ossyntra, trading as Ossyntra ("we", "us", "our", the "Processor"), and the customer organisation that uses the Service ("you", the "Controller"). It applies where Ossyntra processes Personal Data contained in Customer Data on your behalf in providing the Service.
1. Roles and scope
For the purposes of this DPA, you are the data controller and we are the data processor. We process Personal Data in Customer Data only on your documented instructions, which consist of the instructions necessary to provide the Service as described in the Terms, and any further instructions you give through the platform's configuration options.
We do not process Customer Data for our own purposes, except as necessary to provide, secure and support the Service and to comply with our legal obligations. We will not process Personal Data for marketing purposes or sell any Personal Data.
2. Categories of data and subjects
The Customer Data you upload may contain personal data relating to your customers, suppliers, employees, candidates and other contacts — for example names, email and postal addresses, phone numbers, financial records and employment information. You are responsible for having a lawful basis to upload that data and for informing the individuals concerned.
3. Security measures
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- Encryption — in transit using TLS and at rest using AES-256.
- Tenant isolation — enforced at the database level so that one workspace cannot access another's data.
- Access control — role-based permissions, least-privilege access for our staff, and optional multi-factor authentication for workspace users.
- Audit logging — append-only records of significant activity within each workspace.
- Rate limiting and abuse protection — to guard against automated attacks and account abuse.
- Resilience and backups — managed infrastructure with rolling backups and disaster recovery procedures.
4. Sub-processors
We engage third-party service providers to deliver components of the Service. Each sub-processor is bound by written terms that impose data protection obligations no less protective than those in this DPA. Current categories of sub-processor include:
- Cloud hosting and database — to host the application and store Customer Data.
- Merchant of record — Paddle — for subscription billing and payment processing.
- Email and communications — for transactional and notification email delivery.
- Error monitoring and analytics — for diagnosing faults and measuring product usage.
- AI model providers — where you use AI features; request content is sent to generate a response and is not used to train third-party models.
We will give you reasonable advance notice of any intended addition or replacement of a sub-processor, giving you the opportunity to object. A current list of named sub-processors is available on request from hello@ossyntra.com.
5. International transfers
Customer Data may be processed outside the country where it was collected, including outside the UK and EEA. Where this occurs we rely on appropriate safeguards, such as UK or EU Standard Contractual Clauses, or an applicable adequacy decision, and we require our sub-processors to do the same.
6. Your obligations
You warrant that you have the legal right to instruct us to process Customer Data, that you have provided any necessary notices to and obtained any necessary consents from the individuals whose Personal Data is contained in it, and that your use of the Service complies with applicable data protection law.
7. Data subject rights and assistance
We will provide reasonable assistance to you in responding to requests from individuals to exercise their rights (access, rectification, erasure, restriction, objection, portability and withdrawal of consent) to the extent we hold relevant data within Customer Data. Where a request is sent directly to us, we will redirect it to you as the controller unless we are legally required to respond.
We will also provide reasonable assistance with data protection impact assessments and prior consultation with supervisory authorities where required, taking into account the nature of the processing and the information available to us.
8. Personal data breach
We will notify you without undue delay, and in any event within 72 hours, of becoming aware of a personal data breach affecting your Customer Data. The notification will describe the nature of the breach, the likely consequences and the measures we have taken or propose to take to address it and mitigate its effects. It is your responsibility to assess whether the breach is notifiable to the relevant supervisory authority or affected individuals.
9. Retention and deletion
We retain Customer Data for as long as your account is active. After termination, Customer Data remains available for export for 30 days and is then deleted or anonymised, except where we must keep records longer to meet legal, tax or accounting obligations. Backups are cycled out on a rolling schedule.
10. Audits
We make available to you, on reasonable notice and at your cost, information necessary to demonstrate our compliance with this DPA. Where a more detailed audit is required, you may instruct a qualified third-party auditor subject to confidentiality obligations, provided that the audit does not unreasonably interfere with our operations or access another tenant's data.
11. Sub-processor changes and notice
We will give you reasonable advance notice of any intended change to our sub-processors. You may object to a new sub-processor on reasonable data-protection grounds by notifying us in writing; we will work with you in good faith to resolve the objection, which may include not transferring Customer Data to that sub-processor or, if that is not possible, allowing you to suspend or terminate the affected part of the Service.
12. Term and termination
This DPA applies for the duration of your use of the Service and continues to the extent necessary to process Customer Data while it is retained after termination as described above. On termination and expiry of the retention period, we will delete or anonymise all Customer Data.
13. Contact
For questions about this DPA or to exercise any right under it, contact hello@ossyntra.com.