Staging · internal review only · content pack v1.0 · not legal advice
Register II · Legal suite

Data Processing Agreement — Key Terms for Counsel

Draft for counsel reviewStructured and consistent with spec v2.18 and the data-protection architecture — not legal advice. Dashed fields are for founder/counsel to complete.

Data Processing Agreement — Key Terms for Counsel

STRUCTURE + DRAFT CLAUSE POINTS · counsel drafts the executable instrument

Parties & hierarchy. Client = controller; Syntra = processor; DPA concluded electronically at tenant creation, prevails over the ToS for personal-data matters; Security Annex and Sub-Processor Register incorporated.

Subject matter / nature / purpose. Hosting and processing of assessment content and evidence documents for economic-substance assessment and documentation; duration = the subscription + deletion window.

Categories. Data subjects: client-group employees, officers, counterparties appearing in business records. Data: professional data in approval logs, minutes, org charts, contracts, interview transcripts (add-on). Instruction: no special categories — the Client instructs users accordingly (in-product guidance is part of the instruction set).

Art. 28(3) obligations. Documented instructions only (the ToS + product settings ARE the instructions); confidentiality of personnel; security per Annex (state-of-the-art: encryption, per-tenant keys, vault sealing incl. against operator access without logged elevation, EU residency incl. backups); sub-processing only per Register with prior notice and objection right; assistance with data-subject rights and Art. 32–36; deletion or return at end (export per ToS §6; deletion certificate); audits — annual audit report / certifications provided, on-site audits at Client cost with notice.

Breach. Notification to the controller without undue delay after becoming aware, with the Art. 33(3) content; log of incidents.

Transfers. None outside the EU by default; if a sub-processor requires it: SCCs + transfer impact assessment, disclosed in the Register.

Anonymisation gateway (AI add-ons). Contractual mirror of the technical control: personal data and client identifiers are tokenised before any external model call; the token map never leaves the tenant; the gateway validator and its logs are part of the security measures. Add-ons are off by default and switchable per tenant.

Calibration telemetry. Separate, optional tenant-level consent: aggregate, anonymised distributions only (scores, gate outcomes, override frequencies), no entity names, amounts or evidence content; withdrawal prospective.

Liability. Follows the ToS cap; Art. 82 allocation between controller and processor per responsibility.