Data Processing Agreement
Last updated: 26 June 2026
This Data Processing Agreement (the “DPA”) governs the processing of personal data by [Synnea legal entity name] (“Synnea”, the “Processor”) on behalf of the organisation that subscribes to and uses the Synnea service (the “Customer”, the “Controller”). It forms part of, and is incorporated into, the agreement between the parties for the provision of the Synnea service (the “Terms of Service”). It is intended to satisfy the requirements of Article 28 of the General Data Protection Regulation (Regulation (EU) 2016/679, the “GDPR”) and equivalent data-protection law applicable to the parties.
1. Parties and definitions
This DPA is entered into between the Customer, acting as the controller of the personal data processed through the Synnea service, and Synnea, acting as the processor of that personal data on the Customer’s behalf. Synnea provides a multi-tenant, business-to-business software-as-a-service platform for interface, redundancy and failure-mode management on marine and offshore installations (the “Service”).
Capitalised terms used but not defined in this DPA have the meaning given to them in the Terms of Service or in Applicable Data Protection Law.
- “Applicable Data Protection Law” means the GDPR and any national or supplementary data-protection law applicable to the processing of personal data under this DPA, in each case as amended or replaced from time to time.
- “Controller”, “Processor”, “Data Subject”, “Personal Data”, “Processing”, “Personal Data Breach” and “Supervisory Authority” have the meanings given to them in the GDPR.
- “Customer Content” means the data the Customer and its authorised users submit to, store in or generate through the Service, including the register (organisations, installations, systems, interfaces and vendors), uploaded documents, comments, activity logs and notifications.
- “Customer Personal Data” means the personal data contained within Customer Content that Synnea processes on behalf of the Customer under this DPA.
- “Sub-processor” means any third party engaged by Synnea to process Customer Personal Data on Synnea’s behalf in connection with the Service.
- “Standard Contractual Clauses” means the standard data-protection clauses adopted by the European Commission for the transfer of personal data to processors established in third countries.
2. Scope, order of precedence and duration
This DPA applies to all processing of Customer Personal Data carried out by Synnea on behalf of the Customer in the course of providing the Service. The details of the processing are set out in Annex 1.
This DPA forms part of the Terms of Service. In the event of a conflict between this DPA and the Terms of Service on a matter relating to the processing of Customer Personal Data, this DPA prevails. Where this DPA incorporates the Standard Contractual Clauses by reference and a conflict arises in respect of an international transfer, the Standard Contractual Clauses prevail over this DPA.
This DPA takes effect when the Customer accepts the Terms of Service or first uses the Service, whichever is earlier, and remains in force for as long as Synnea processes Customer Personal Data on the Customer’s behalf, after which the provisions on return or deletion of data in Section 9 apply.
3. Roles and processing on documented instructions
As between the parties, the Customer is the controller and Synnea is the processor of Customer Personal Data. The Customer determines the purposes and means of the processing and is responsible for the lawfulness of the personal data it provides and of its instructions.
Synnea processes Customer Personal Data only on the Customer’s documented instructions, including with regard to international transfers, unless Synnea is required to process by Union or Member State law to which it is subject, in which case Synnea will inform the Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
The Customer’s instructions are set out in, and limited to, this DPA, the Terms of Service, the configuration and features of the Service, and the Customer’s use of the Service (including the data the Customer chooses to enter and the actions its authorised users take). Any additional or alternative instruction must be agreed in writing.
Synnea will inform the Customer if, in its opinion, an instruction infringes Applicable Data Protection Law. In that case Synnea may suspend performance of the affected instruction until the Customer confirms, amends or withdraws it, without liability for the suspension.
4. Confidentiality
Synnea ensures that persons authorised to process Customer Personal Data are subject to an appropriate obligation of confidentiality, whether a contractual duty or a statutory obligation. Synnea limits access to Customer Personal Data to personnel who need it to provide, maintain and support the Service, on a least-privilege basis.
5. Security of processing
Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk to the rights and freedoms of natural persons, Synnea implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 of the GDPR. A summary of the measures in place is set out in Annex 2.
Synnea may update its technical and organisational measures from time to time, provided that the updated measures do not materially reduce the overall level of protection of Customer Personal Data.
6. Sub-processors
The Customer grants Synnea general written authorisation to engage the Sub-processors listed in Annex 3 to process Customer Personal Data in connection with the Service.
Where Synnea engages a Sub-processor, it does so under a written contract that imposes on the Sub-processor data-protection obligations that are, in substance, equivalent to those set out in this DPA, in particular providing sufficient guarantees to implement appropriate technical and organisational measures. Synnea remains fully liable to the Customer for the performance of each Sub-processor’s obligations.
Synnea will inform the Customer in advance of any intended addition or replacement of a Sub-processor, giving the Customer a reasonable opportunity to object on reasonable, data-protection-related grounds. If the Customer objects and the parties cannot resolve the objection, the Customer may, as its sole remedy, terminate the affected part of the Service in accordance with the Terms of Service.
7. Assistance to the Controller
Taking into account the nature of the processing, Synnea assists the Customer by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Customer’s obligation to respond to requests from Data Subjects exercising their rights under Chapter III of the GDPR (including access, rectification, erasure, restriction, portability and objection). Where a Data Subject contacts Synnea directly, Synnea will, unless legally prohibited, refer the request to the Customer.
Taking into account the nature of the processing and the information available to Synnea, Synnea assists the Customer in ensuring compliance with its obligations under Articles 32 to 36 of the GDPR, including security of processing, notification of personal data breaches, communication of breaches to Data Subjects, data-protection impact assessments and prior consultation with a Supervisory Authority.
Synnea may charge a reasonable fee for assistance that goes beyond the standard functionality of the Service or that is unusual in scope or frequency, as permitted under the Terms of Service.
8. Personal data breach
Synnea notifies the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification will describe, to the extent known and reasonably available to Synnea, the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects.
Where not all information is available at the time of the initial notification, Synnea will provide it in phases as it becomes available. Synnea cooperates with the Customer and takes reasonable steps to assist the Customer in investigating, mitigating and remediating the breach, including providing information the Customer reasonably needs to meet its own notification obligations to a Supervisory Authority or to Data Subjects. Synnea’s notification is not, and may not be construed as, an acknowledgement of fault or liability.
9. Return or deletion of data
On termination or expiry of the Service, the Customer may, within the period and using the export functionality made available through the Service, retrieve a copy of its Customer Content. At the Customer’s choice, Synnea will return the Customer Personal Data to the Customer or delete it.
Unless the Customer instructs otherwise in writing, Synnea will delete or render inaccessible Customer Personal Data within [data-retention period after termination — e.g. 30 days] of termination or expiry, and will procure that its Sub-processors do the same, except to the extent that storage is required by Union or Member State law, in which case Synnea will protect the confidentiality of the retained data and process it only as required by that law. Routine backups are deleted in the ordinary course of Synnea’s backup-retention cycle.
10. Audits and information
Synnea makes available to the Customer the information reasonably necessary to demonstrate compliance with the obligations set out in Article 28 of the GDPR and this DPA, and allows for and contributes to audits, including inspections, conducted by the Customer or an independent auditor mandated by the Customer.
Audits are subject to reasonable prior written notice, are limited to once in any twelve-month period (save where required by a Supervisory Authority or following a Personal Data Breach), take place during normal business hours, must not unreasonably disrupt Synnea’s operations, and are subject to appropriate confidentiality undertakings. Synnea may satisfy an audit request by providing relevant certifications, audit reports or summaries of its controls where these reasonably address the Customer’s request.
11. International transfers
Synnea hosts and processes Customer Personal Data within the European Union / European Economic Area, with the primary database located in the EU region (eu-north-1). Synnea will not transfer Customer Personal Data to a country outside the EU/EEA that is not subject to an adequacy decision unless it has put in place an appropriate transfer mechanism under Chapter V of the GDPR.
Where any such transfer occurs, the parties agree that appropriate safeguards apply, including the Standard Contractual Clauses [SCC module and dated reference], together with any supplementary measures required to ensure an essentially equivalent level of protection. The Customer authorises Synnea to enter into the Standard Contractual Clauses with its Sub-processors on the Customer’s behalf where necessary to give effect to such transfers.
12. Liability
Each party’s liability arising out of or in connection with this DPA is subject to the exclusions and limitations of liability set out in the Terms of Service, which apply to this DPA as if set out in full here. Nothing in this DPA limits or excludes liability that cannot be limited or excluded under Applicable Data Protection Law.
13. Governing law
This DPA is governed by and construed in accordance with [governing law — Norway], and the parties submit to the jurisdiction set out in the Terms of Service, in each case without prejudice to any mandatory rights of Data Subjects or the competence of a Supervisory Authority under Applicable Data Protection Law.
14. Annex 1 — Details of the processing
The following table sets out the subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects, as required by Article 28(3) of the GDPR.
| Item | Description |
|---|---|
| Subject matter | Provision of the Synnea service: a multi-tenant platform for interface, redundancy and failure-mode management on marine and offshore installations, including hosting and processing of the Customer Content the Customer submits. |
| Duration | For the term of the Service and until Customer Personal Data is returned or deleted in accordance with Section 9 of this DPA. |
| Nature and purpose | Storage, hosting, organisation, retrieval, display, transmission, backup, support and deletion of Customer Content for the purpose of providing, maintaining, securing and supporting the Service. The data is predominantly technical and engineering data (vessel, DP and FMEA data), with limited personal data. |
| Types of personal data | Customer users’ names, email addresses, roles and account/authentication identifiers; activity logs, comments and notifications attributable to identifiable individuals; and any personal data the Customer chooses to include within records, uploaded documents or vendor/contact details. No special categories of personal data are intended to be processed. |
| Categories of data subjects | The Customer’s authorised users and personnel; and any individuals (such as vendor, client or third-party contacts) whom the Customer references in records or documents. |
| Frequency of processing | Continuous, for the duration of the Customer’s use of the Service. |
15. Annex 2 — Technical and organisational measures
Synnea maintains the technical and organisational measures summarised below, which may be updated from time to time provided the overall level of protection is not materially reduced.
| Measure | Description |
|---|---|
| Tenant isolation | Strict separation of each customer’s data is enforced at the database layer using PostgreSQL Row-Level Security, so that a customer’s data is accessible only within that customer’s tenant. |
| Privileged operations | Privileged or cross-cutting operations are performed through controlled SECURITY DEFINER routines with defined authorisation logic, rather than by broad direct access to data. |
| Encryption in transit | All connections to the Service are encrypted using HTTPS / TLS. |
| Data residency | The primary database is hosted in the European Union (EU region eu-north-1), providing EU data residency for Customer Content. |
| Access control | Role-based access controls and least-privilege principles restrict access to Customer Personal Data to authorised personnel for defined purposes. |
| Logging and monitoring | Audit and activity logging within the product records relevant actions; application error and performance monitoring uses masked, error-only session replay with no default collection of personal data. |
| Resilience and backup | Managed database infrastructure provides backups and recovery capabilities to support availability and restoration of Customer Content. |
16. Annex 3 — Approved sub-processors
The Customer authorises Synnea to engage the following Sub-processors to process Customer Personal Data in connection with the Service. The marketing website host processes no Customer Content and is therefore not listed.
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Managed PostgreSQL database, authentication and file storage — core data storage, authentication and document storage for the Service. | European Union (eu-north-1) |
| Vercel | Application hosting and global content-delivery / edge network — serving the Service to authorised users. | Global edge network; primary processing in the EU/EEA [confirm region configuration] |
| Sentry | Error monitoring and performance diagnostics with masked, error-only session replay and no default collection of personal data — diagnostics and service reliability. | European Union (EU-hosted) |
17. Contact
Questions about this DPA, requests relating to the processing of Customer Personal Data, and notices under this DPA can be sent to hello@synnea.no.