DPA
This DPA applies when Synaria Ltd processes personal data on behalf of a CREVORO customer in connection with a customer project.
1. Scope and roles
This Data Processing Addendum (“DPA”) forms part of the CREVORO Terms where CREVORO processes personal data on behalf of a customer. The customer is the controller (or processor acting for another controller) and Synaria Ltd is the processor or subprocessor, as applicable.
For CREVORO’s own account, billing, security and support data, Synaria Ltd acts as controller and the Privacy Policy applies.
Synaria klub, z.s., IČO 24094412, Děčínská 552/1, Střížkov, 180 00 Praha 8, Czech Republic, is CREVORO’s European Union representative and EU compliance contact for the relevant CREVORO activities. It provides an EU contact point for data subjects and supervisory authorities. This appointment does not transfer the controller or processor role away from Synaria Ltd.
2. Processing details
Subject matter: hosting, building, maintaining, securing and operating the customer’s CREVORO project and requested integrations. Duration: for the term of the customer’s project and any limited retention period required for deletion, recovery, security or legal compliance.
Categories of data may include names, contact information, account identifiers, booking or CRM records, order and transaction metadata, messages, uploaded files, IP addresses, technical identifiers and any other personal data the customer chooses to process through the project.
Data subjects may include the customer’s staff, contractors, clients, prospects, members, website visitors, buyers and other individuals whose data is lawfully submitted to the project.
3. Customer instructions and confidentiality
CREVORO processes customer personal data only on documented instructions, including instructions inherent in the customer’s use and configuration of the service, unless law requires other processing.
Persons authorised to process customer personal data are subject to confidentiality obligations and access is limited according to role and operational need.
4. Security measures
CREVORO maintains technical and organisational measures appropriate to the nature and risk of the processing. Measures include access control, role separation, encrypted transport, controlled administrative access, audit events, isolation of build/deployment operations and encryption of sensitive stored credentials where supported.
The customer remains responsible for project-level configuration, user permissions, content, lawful collection of personal data and any security controls that depend on customer choices or third-party systems.
5. Subprocessors
The customer authorises CREVORO to use subprocessors needed to provide the service, including providers of hosting/infrastructure, business email, payment services, automated development/inference and customer-selected integrations.
CREVORO will require subprocessors that process customer personal data to be subject to data-protection obligations appropriate to the service. Where required by applicable law, CREVORO will provide information about material subprocessor changes and a reasonable opportunity to raise a legitimate data-protection objection.
6. International transfers
Where customer personal data is transferred internationally in a manner restricted by applicable data-protection law, CREVORO will use an available lawful transfer mechanism, such as adequacy, the UK IDTA/Addendum, Standard Contractual Clauses or another legally recognised safeguard.
7. Data-subject requests and compliance assistance
Taking into account the nature of processing, CREVORO will provide reasonable assistance to the customer with data-subject requests, security obligations, DPIAs and regulator consultations to the extent required by applicable data-protection law and reasonably possible through the service.
If CREVORO receives a request from a data subject relating primarily to customer-controlled project data, CREVORO may direct the requester to the customer unless law requires CREVORO to respond directly.
8. Personal-data breaches
CREVORO will notify the customer without undue delay after becoming aware of a personal-data breach affecting customer personal data where notification is required under applicable processor obligations. We will provide information reasonably available to support the customer’s assessment and notification duties.
9. Return and deletion
At the end of the service, CREVORO will delete or return customer personal data as required by applicable law and the service’s available export/deletion functions, unless retention is legally required. Residual copies in backups may remain until the relevant backup cycle expires, subject to continued protection and restricted use.
10. Information and audits
CREVORO will make available information reasonably necessary to demonstrate compliance with its processor obligations. Any audit must be proportionate, protect other customers and CREVORO security, avoid unnecessary disruption, and normally use available documentation before requiring an on-site inspection.
Gestore
Synaria LtdCompany No.: 1691155171–75 Shelton Street, Covent Garden,London WC2H 9JQ, United Kingdomhello@crevoro.comIntegrazione della piattaforma UE e conformità
Synaria klub, z.s.IČO: 24094412Děčínská 552/1Střížkov, 180 00 Praha 8, Czech Republic