Last updated: August 2026
1.Chapter I: Definitions and General Provisions
Article (1) Purpose of the Agreement
This Data Processing Agreement ("Agreement") sets out the terms under which Zyntra Digital ("the Processor") processes personal data on behalf of the client ("the Controller") within the framework of the ZynDesk platform services. This Agreement supplements the Terms and Conditions and prevails over them in the event of any conflict with respect to the processing of personal data.
Article (2) Definitions
For the purposes of this Agreement, the following terms have the meanings set out opposite each:
- "Personal Data": any information relating to an identified or identifiable natural person.
- "Processing": any operation performed on Personal Data such as collection, storage, modification, retrieval, disclosure, or deletion.
- "Controller": the client who determines the purposes and means of processing Personal Data.
- "Processor": Zyntra Digital, which processes Personal Data on the instructions of the Controller.
- "Sub-processors": third parties to whom Zyntra Digital delegates part of its processing operations.
- "Data Subjects": the natural persons to whom the Personal Data relates.
2.Chapter II: Nature and Purposes of Processing
Article (3) Processing Details
The Processor shall process Personal Data for the following specified purposes:
- Storing and managing the accounting firm's client data within the CRM system.
- Processing employee data and attendance and leave records.
- Archiving financial and tax documents and making them available for review.
- Generating reports and statistics relating to firm operations.
- Sending notifications and reminders relating to tax deadlines.
Article (4) Categories of Personal Data Processed
The categories of Personal Data that may be processed by the Processor under this Agreement include:
- User identity data: name, email address, phone number, and job title.
- Firm client data: client names and their financial, tax, and commercial data.
- Employee data: attendance and leave records, qualifications, and salaries if entered by the Controller.
- Technical data: IP addresses and usage logs for security purposes.
3.Chapter III: Processor Obligations
Article (5) Core Obligations
The Processor shall:
- Process Personal Data solely in accordance with the written instructions of the Controller, and notify the Controller immediately if it considers that any such instruction infringes applicable law.
- Ensure that Personal Data is kept confidential and not disclosed to third parties without explicit authorization or a legal obligation.
- Implement all technical and organizational measures necessary to protect Personal Data against unauthorized access, damage, or loss.
- Assist the Controller in responding to Data Subject requests relating to their rights.
Article (6) Security Breach Notification
The Processor shall notify the Controller within 48 hours of discovering any security breach that may pose a risk to the rights and freedoms of Data Subjects. Notification shall include: a description of the nature, scope, and likely impact of the breach, and the measures taken to mitigate its effects.
4.Chapter IV: Sub-processors
Article (7) List of Sub-processors
The Controller hereby acknowledges, under this Agreement, the engagement of the following current sub-processors:
| Sub-processor | Purpose | Data Location |
|---|---|---|
| Google Firebase | Databases and authentication | European Union (eur3) |
| Cloudinary | File and image storage | Global (CDN) |
| Resend | Email sending | European Union |
| Render | Server hosting | Frankfurt, Germany |
| Vercel | Front-end hosting | Global (CDN) |
The Processor shall notify the Controller at least 30 days before adding any new sub-processor or replacing any of the current sub-processors.
5.Chapter V: Data Subject Rights
Article (8) Controller Obligations
The Controller alone bears responsibility for responding to Data Subject requests relating to their legal rights of access, rectification, erasure, objection, and restriction of processing. The Processor shall provide the Controller with the technical support necessary to respond to such requests within 30 days of their receipt.
6.Chapter VI: Security Measures
Article (9) Technical and Organizational Safeguards
The Processor applies a range of security measures including in particular:
- Encryption of data in transit using TLS 1.3 and at rest using AES-256.
- Application of the least-privilege principle and mandatory two-factor authentication for all production environments.
- Automatic daily backups with periodic recovery testing.
- Periodic security reviews and regular risk assessment.
- Training of Company staff on data protection best practices.
7.Chapter VII: Data Transfers
Article (10) Transfer of Data Outside the Region
User data is stored primarily in European Union data centers. Some data may be transferred outside the EU subject to appropriate legal safeguards in accordance with applicable regulations. The Controller may enquire about the storage locations of their data at any time at: info@zyndesk.app.
8.Chapter VIII: Term and Termination
Article (11) Duration of Processing
This Agreement remains in force for the duration of the Controller's subscription to the ZynDesk platform. Upon termination of the subscription, the Processor shall make the Controller's data available for export for 30 days and then permanently delete it within 90 days of the termination date, unless applicable law requires it to be retained for a longer period.
Article (12) Enquiries Regarding the Agreement
For any enquiries relating to this Agreement or to request a signed copy, please contact: info@zyndesk.app