Data Processing Agreement (DPA)
Translation for convenience only — This is a translation provided for convenience only. In the event of any discrepancy, the French version alone is legally binding.
This Data Processing Agreement (hereinafter the "DPA" or the "Agreement") supplements SYNAPTIIK's General Terms and Conditions of Sale and Use in accordance with Article 28 of Regulation (EU) 2016/679 (GDPR).
It governs the processing of personal data carried out by SYNAPTIIK (hereinafter the "Processor" or "SYNAPTIIK") on behalf of the professional client using the platform (hereinafter the "Controller" or the "Client").
The Agreement is deemed accepted upon subscribing to the service (clickwrap) for the Solo and Studio plans, and is appended to the electronically signed contract (Yousign) for the Agency and Agency Scale plans.
Article 1 — Definitions
The terms "personal data", "processing", "controller", "processor", "data subject", "personal data breach" and "supervisory authority" have the meaning defined in Article 4 of the GDPR.
Article 2 — Subject matter, nature and purposes of the processing
The Processor is authorized to process, on behalf of the Controller, the personal data necessary to perform the following services:
- hosting of user accounts (clients, collaborators, guests);
- management of projects, briefs, shoot plans, deliveries;
- invoicing and collection on the tenant side (sub-invoicing of the end client);
- Leeza AI assistance — Level 1 (account memory) and Level 2 (anonymized opt-in learning, k-anonymity ≥ 5);
- product analytics (PostHog EU Cloud) subject to end-user consent;
- electronic signature of documents via Yousign;
- transactional email notifications (Resend).
The overall purpose is to make the SYNAPTIIK SaaS service available in accordance with the Terms of Sale. The Processor only processes data on the documented instructions of the Controller.
Article 3 — Term
The Agreement takes effect on the date of subscription to the service and remains in force for the entire duration of the subscription.
Article 4 — Categories of data and data subjects
Categories of data subjects:
- professional users (photographers, videographers, drone operators, tenant administrators);
- internal tenant collaborators (salaried staff, freelance guests);
- end clients (legal and/or natural persons receiving the services);
- one-off guests (guest portal, magic links).
Categories of data:
- identification (name, email, phone number);
- professional data (business registration number, role, company, portfolio);
- produced content (photos, videos, documents, EXIF metadata);
- billing data (services, amounts, payment methods tokenized via Stripe);
- technical data (logs, IP addresses, user-agent, device ID);
- Leeza AI interactions (requests, responses, feedback).
Article 5 — Sub-processors
The Controller authorizes the Processor to use the sub-processors listed in the Privacy Policy §4 (Vercel, Supabase, Stripe, Backblaze, Anthropic, Resend, PostHog, Better Stack, Yousign, Brevo, Cloudflare, Google Workspace, reCAPTCHA/hCaptcha).
Any change of sub-processor is notified to the Controller at least 30 days before it takes effect, by publication on the privacy page and by email for the Agency and Agency Scale plans. The Controller may raise a reasoned objection within this period; failing that, the change is deemed accepted.
Article 6 — Obligations of the Processor
The Processor undertakes to:
- process data only in accordance with the documented instructions of the Controller (these Terms and Conditions and normal use of the platform constituting said instructions);
- ensure that persons authorized to process data are bound by confidentiality (confidentiality undertaking signed by SYNAPTIIK staff);
- take all appropriate technical and organizational measures (Art. 32 GDPR), detailed in Article 7 of this Agreement;
- assist the Controller in fulfilling its obligations (responses to data subject rights, impact assessments, prior consultation of the authority, breach notification);
- provide the Controller with the information necessary to demonstrate compliance with the obligations under Art. 28;
- apply a k-anonymity ≥ 5 rule to any aggregated data potentially transmitted to a sub-processor for product improvement, in addition to standard pseudonymization operations.
Article 7 — Security measures
- TLS 1.2+ encryption in transit;
- AES-256 encryption at rest (database, object storage, backups);
- optional multi-factor authentication for Solo/Studio, mandatory for Agency;
- RBAC access control, tenant-scoped Supabase Row-Level Security;
- logging of admin access with 12-month retention;
- automatic backups with quarterly restoration testing;
- periodic penetration testing (at least annually);
- CVE vulnerability monitoring and patch management with an internal SLA of 72h (critical) / 7 days (high).
Article 8 — Rights of data subjects
The Processor provides technical and organizational assistance to the Controller in responding to requests to exercise rights (Art. 15 to 22 GDPR). An endpoint /api/legal/export-rgpd enables a structured export of data (JSON + CSV + binary media).
Where the Processor receives a request directly from a data subject, it forwards it to the Controller without delay (48 hours maximum).
Article 9 — Retention period and return of data
Upon termination of the subscription, the Processor retains the data for 90 days as a safety period (allowing reactivation or recourse). After this period, the data is deleted, except where a legal obligation applies (invoices retained for 10 years by the accountant / tax authorities).
The Controller has a right to a full export of the data at any time and during the 90 days following termination, in a structured, machine-readable format.
Article 10 — Breach notification
In the event of a personal data breach, the Processor notifies the Controller within 48 hours of becoming aware of it, so as to allow the Controller to notify the supervisory authority within the 72-hour period required by Art. 33 GDPR.
The notification includes: the nature of the breach, the categories and approximate number of data subjects concerned, the categories and approximate volume of data, the likely consequences, and the measures taken or proposed.
Article 11 — Service continuity
The Processor has put in place a documented continuity plan covering in particular:
- the temporary or permanent unavailability of its principal (notarized future protection mandate under Art. 477 of the French Civil Code);
- the backup and restoration of critical access (infrastructure secrets, source code, backups) via a notarized escrow;
- the designation of a trusted person authorized to continue operations or arrange transfer to a successor.
In the event of a major incident jeopardizing service continuity for more than 30 consecutive days, the Processor undertakes to:
- notify the Controller within 72 hours;
- enable a full export of the data within 15 business days;
- ensure secure deletion of data in accordance with Article 9 if the service cannot resume.
The Controller has a right to terminate without notice or penalty in the event of confirmed inability of the Processor to maintain the service.
Public summary of the plan: /legal/continuity.
Article 12 — Audit
The Controller has a right to audit the Processor's compliance with the Agreement. The audit may be carried out at most once a year, by an independent auditor, on 30 days' notice, at its own expense, and in a manner that does not disrupt operations.
Existing third-party certification reports (SOC 2 of key sub-processors, GDPR certifications, recent penetration tests) may be provided in lieu of an on-site audit, at the Controller's discretion.
Article 13 — Transfers outside the EU
Transfers outside the European Union are governed by the standard contractual clauses (Decision 2021/914) and, where the sub-processor is certified, by the EU-US Data Privacy Framework (Decision 2023/1795). Additional safeguards (encryption, pseudonymization) are systematically applied.
Article 14 — Governing law and jurisdiction
This Agreement is governed by French law. Any dispute relating to its interpretation or performance shall, failing an amicable resolution, fall under the exclusive jurisdiction of the Bourg-en-Bresse courts (France).