1. Scope
This DPA supplements the SYNTHEX Customer Terms when SYNTHEX processes personal data on behalf of a business customer in connection with the managed content-production service and a processor/service-provider contract is required by applicable law.
Covered processing may include campaigns, source media, transcripts, Brand Kit assets, instructions, deliverables, connected-platform data and related account/support information.
2. Roles
For customer-directed content, the customer acts as controller/business and SYNTHEX acts as processor/service provider to the extent applicable. Each party acts independently for data it processes for its own legal, billing, security, fraud-prevention or relationship-management purposes. The customer is responsible for lawful collection, notices, permissions and instructions for data it supplies.
3. Documented instructions and confidentiality
SYNTHEX will process covered personal data only to provide, secure, support and improve the contracted service in a manner permitted by applicable law, the Customer Terms, this DPA and documented customer instructions, unless law requires otherwise. Authorized persons are subject to confidentiality or comparable duties. SYNTHEX will not sell covered personal data or use it for unrelated cross-context behavioral advertising.
4. Security
SYNTHEX will maintain reasonable administrative, technical and organizational safeguards appropriate to the service, including role-appropriate access, authentication, secure transport where supported, logging, provider review, incident procedures and data minimization. See Security.
5. Subprocessors
The customer grants general authorization for subprocessors listed at Subprocessors. SYNTHEX will use applicable contractual/service-provider safeguards and remain responsible for its own DPA obligations. Where applicable law or an enterprise agreement grants an objection right, objections must be based on reasonable data-protection grounds.
6. Assistance
Taking into account the nature of processing and information available, SYNTHEX will provide commercially reasonable assistance with verified data-subject requests, security obligations, legally required assessments and regulator inquiries relating to covered processing.
7. Personal-data incidents
After becoming aware of a confirmed personal-data breach affecting covered customer data under SYNTHEX control, SYNTHEX will investigate, contain where reasonably possible, preserve appropriate evidence and notify the affected customer without undue delay when notification is required by law or contract.
8. Return and deletion
At the end of the applicable service, SYNTHEX will return or delete covered personal data when reasonably required and technically feasible, subject to legal retention, fraud/security records, unresolved disputes, backups and provider deletion cycles. See Data Retention.
9. Information and audit evidence
SYNTHEX will make available information reasonably necessary to demonstrate compliance, using relevant documentation, subprocessor information and reasonable questionnaires. Audits must be proportionate, protect other customers and confidential systems, and ordinarily use existing documentary evidence before onsite review.
10. International transfers
Covered data may be processed in the United States and other locations where approved providers operate. If a legally required transfer mechanism is necessary for a specific customer, the parties will use an applicable recognized mechanism, including standard contractual clauses where appropriate and actually executed.
11. U.S. state privacy terms
Where SYNTHEX qualifies as a service provider or contractor under applicable U.S. state privacy law, SYNTHEX will retain, use and disclose covered data only for permitted purposes reasonably necessary and proportionate to the contracted service, security, support and legally permitted activities, and will not combine or use it in a manner prohibited for that role.
The Customer Terms govern liability/disputes unless mandatory privacy law requires otherwise. This DPA does not claim certifications, residency guarantees or regulated-industry status that have not been expressly documented.