Legal
Data Processing Agreement
Our commitment to GDPR-compliant data processing. This DPA governs how Syntask processes personal data on your behalf.
Last updated: April 2026
This Data Processing Agreement ("DPA") forms part of the agreement between Syntask Oy ("Processor", "we", "us") and the customer ("Controller", "you") for the use of Syntask services. This DPA is entered into in accordance with the EU General Data Protection Regulation (GDPR), Regulation (EU) 2016/679.
1. Definitions
- "Personal Data" means any information relating to an identified or identifiable natural person processed by Syntask on behalf of the Controller
- "Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, and deletion
- "Sub-processor" means any third party engaged by Syntask to process Personal Data
2. Data Controller & Processor Roles
For the purposes of this DPA:
- You (the Customer) are the Data Controller. You determine the purposes and means of processing personal data within the Syntask platform.
- Syntask Oy is the Data Processor. We process personal data solely on your instructions and for the purpose of providing the Syntask services.
Syntask does not independently determine the purposes or means of processing Customer Data. We process data only as instructed by the Controller and as necessary to provide the contracted services.
3. Scope of Processing
Syntask processes the following categories of personal data on behalf of the Controller:
- Data subjects: Customer's employees, end users, and business contacts as uploaded to the platform
- Data categories: Names, email addresses, job titles, company information, and operational data as configured by the Controller
- Processing purposes: Operational Decision Intelligence — generating prioritized, evidence-backed recommendations from Controller data, together with the supporting evidence, reports and explanations that accompany them
- Duration: For the term of the service agreement plus the data retention period specified below
4. Processor Obligations
Syntask shall:
- Process Personal Data only on documented instructions from the Controller
- Ensure that persons authorized to process Personal Data are bound by confidentiality obligations
- Implement appropriate technical and organizational security measures (see our Security page)
- Assist the Controller in fulfilling data subject rights requests
- Notify the Controller without undue delay (and within 48 hours) after becoming aware of a Personal Data breach
- Delete or return all Personal Data upon termination of the service agreement, at the Controller's choice
5. Sub-processors
Syntask uses the following sub-processors to deliver our services:
| Sub-processor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Cloud hosting & infrastructure | Finland, EU |
| Cloudflare, Inc. | CDN, DDoS protection, DNS | Global (EU processing) |
| Postmark (ActiveCampaign) | Transactional email delivery | USA (EU SCCs) |
| OpenAI | AI model inference (no data retention) | USA (EU SCCs) |
We will notify the Controller at least 30 days before engaging any new sub-processor, allowing the Controller to object.
6. International Data Transfers
Where Personal Data is transferred outside the European Economic Area (EEA), Syntask ensures appropriate safeguards:
- EU Standard Contractual Clauses (SCCs): All non-EU sub-processors are bound by the latest EU Commission-approved SCCs
- Transfer Impact Assessments: We conduct assessments for each data transfer to ensure adequate protection
- Primary processing in EU: All primary data processing and storage occurs within the EU (Finland)
7. Data Retention
- Active accounts: Data is retained for the duration of the service agreement
- Account termination: Customer data is deleted within 30 days of account termination, unless a longer retention is required by law
- Backups: Backup copies are purged within 90 days of account termination
- Aggregated data: Anonymized, aggregated data that cannot identify individuals may be retained for statistical and service-improvement purposes
8. Audits
The Controller has the right to audit Syntask's compliance with this DPA. Audits may be conducted by the Controller or an independent third-party auditor, with reasonable advance notice and during normal business hours. Syntask will provide reasonable cooperation and access to relevant records.
9. Contact for DPA Requests
For questions about this DPA, to request a signed copy, or to exercise your rights as a Data Controller:
- Email: [email protected]
- Address: Syntask Oy (Y-Tunnus: 3483513-7), Otakaari 7, 02150 Espoo, Finland
Signed DPA copies are available upon request for Enterprise plan customers at no additional charge.