Data Processing Addendum.
GDPR-aligned DPA covering Synq's role as a processor of personal data on behalf of the businesses building on the platform. Plain-language summary below; counter-signed legal version on request from hello@aerosol.so.
The plain-language summary
Who plays what role
Your business is the data controller for your end-users. Synq is the data processor — we handle identity data on your instructions, only for the purposes of operating the identity platform.
Subject matter
Personal data processed: identifiers (email, name, profile picture), authentication metadata (sign-in timestamps, IPs), connection identifiers (Google/Apple/etc. sub claims, wallet addresses), and any additional claims the user chooses to grant via OIDC consent.
How we protect it
Encryption at rest (AES-256-GCM for secrets), encryption in transit (TLS), strict access controls, audit logging of staff actions, regular reviews of subprocessor list. See the trust & security page.
Subprocessors
See the subprocessors list for the current set. We notify customers before adding any new subprocessor that processes personal data.
Data subject rights
End-users have direct self-service rights inside Synq: connection review, App revocation, account deletion (with a grace window before being made permanent). Controllers can also export per-user data via the platform API.
This is the plain-language summary as of 2026. The counter-signed DPA is available on request and is the binding text.
Need a counter-signed DPA?.
hello@aerosol.so with the company name and signing contact. Most signatures land within a business day.
