Skip to content
Legal

Data Processing Addendum.

GDPR-aligned DPA covering Synq's role as a processor of personal data on behalf of the businesses building on the platform. Plain-language summary below; counter-signed legal version on request from hello@aerosol.so.

The plain-language summary

Who plays what role

Your business is the data controller for your end-users. Synq is the data processor — we handle identity data on your instructions, only for the purposes of operating the identity platform.

Subject matter

Personal data processed: identifiers (email, name, profile picture), authentication metadata (sign-in timestamps, IPs), connection identifiers (Google/Apple/etc. sub claims, wallet addresses), and any additional claims the user chooses to grant via OIDC consent.

How we protect it

Encryption at rest (AES-256-GCM for secrets), encryption in transit (TLS), strict access controls, audit logging of staff actions, regular reviews of subprocessor list. See the trust & security page.

Subprocessors

See the subprocessors list for the current set. We notify customers before adding any new subprocessor that processes personal data.

Data subject rights

End-users have direct self-service rights inside Synq: connection review, App revocation, account deletion (with a grace window before being made permanent). Controllers can also export per-user data via the platform API.

This is the plain-language summary as of 2026. The counter-signed DPA is available on request and is the binding text.

Need a counter-signed DPA?.

hello@aerosol.so with the company name and signing contact. Most signatures land within a business day.