Skip to main content

Legal

Data Processing Agreement

Our commitment to GDPR-compliant data processing. This DPA governs how Syntask processes personal data on your behalf.

Last updated: April 2026

This Data Processing Agreement ("DPA") forms part of the agreement between Syntask Oy ("Processor", "we", "us") and the customer ("Controller", "you") for the use of Syntask services. This DPA is entered into in accordance with the EU General Data Protection Regulation (GDPR), Regulation (EU) 2016/679.

1. Definitions

  • "Personal Data" means any information relating to an identified or identifiable natural person processed by Syntask on behalf of the Controller
  • "Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, and deletion
  • "Sub-processor" means any third party engaged by Syntask to process Personal Data

2. Data Controller & Processor Roles

For the purposes of this DPA:

  • You (the Customer) are the Data Controller. You determine the purposes and means of processing personal data within the Syntask platform.
  • Syntask Oy is the Data Processor. We process personal data solely on your instructions and for the purpose of providing the Syntask services.

Syntask does not independently determine the purposes or means of processing Customer Data. We process data only as instructed by the Controller and as necessary to provide the contracted services.

3. Scope of Processing

Syntask processes the following categories of personal data on behalf of the Controller:

  • Data subjects: Customer's employees, end users, and business contacts as uploaded to the platform
  • Data categories: Names, email addresses, job titles, company information, and operational data as configured by the Controller
  • Processing purposes: Operational Decision Intelligence — generating prioritized, evidence-backed recommendations from Controller data, together with the supporting evidence, reports and explanations that accompany them
  • Duration: For the term of the service agreement plus the data retention period specified below

4. Processor Obligations

Syntask shall:

  • Process Personal Data only on documented instructions from the Controller
  • Ensure that persons authorized to process Personal Data are bound by confidentiality obligations
  • Implement appropriate technical and organizational security measures (see our Security page)
  • Assist the Controller in fulfilling data subject rights requests
  • Notify the Controller without undue delay (and within 48 hours) after becoming aware of a Personal Data breach
  • Delete or return all Personal Data upon termination of the service agreement, at the Controller's choice

5. Sub-processors

Syntask uses the following sub-processors to deliver our services:

Sub-processor Purpose Location
Hetzner Online GmbH Cloud hosting & infrastructure Finland, EU
Cloudflare, Inc. CDN, DDoS protection, DNS Global (EU processing)
Postmark (ActiveCampaign) Transactional email delivery USA (EU SCCs)
OpenAI AI model inference (no data retention) USA (EU SCCs)

We will notify the Controller at least 30 days before engaging any new sub-processor, allowing the Controller to object.

6. International Data Transfers

Where Personal Data is transferred outside the European Economic Area (EEA), Syntask ensures appropriate safeguards:

  • EU Standard Contractual Clauses (SCCs): All non-EU sub-processors are bound by the latest EU Commission-approved SCCs
  • Transfer Impact Assessments: We conduct assessments for each data transfer to ensure adequate protection
  • Primary processing in EU: All primary data processing and storage occurs within the EU (Finland)

7. Data Retention

  • Active accounts: Data is retained for the duration of the service agreement
  • Account termination: Customer data is deleted within 30 days of account termination, unless a longer retention is required by law
  • Backups: Backup copies are purged within 90 days of account termination
  • Aggregated data: Anonymized, aggregated data that cannot identify individuals may be retained for statistical and service-improvement purposes

8. Audits

The Controller has the right to audit Syntask's compliance with this DPA. Audits may be conducted by the Controller or an independent third-party auditor, with reasonable advance notice and during normal business hours. Syntask will provide reasonable cooperation and access to relevant records.

9. Contact for DPA Requests

For questions about this DPA, to request a signed copy, or to exercise your rights as a Data Controller:

  • Email: [email protected]
  • Address: Syntask Oy (Y-Tunnus: 3483513-7), Otakaari 7, 02150 Espoo, Finland

Signed DPA copies are available upon request for Enterprise plan customers at no additional charge.

Start a 90-Day Proof of Value Call