SYNQ INTELLIGENCE LTD · STATUTORY COMPLIANCE
This Data Processing Agreement ("DPA") forms a legally binding addendum to the Service Agreement / Master Services Agreement between Trafalgar Education and Synq Intelligence Ltd.
This Agreement fulfills the statutory requirements of Article 28(3) of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, governing the processing of personal data in connection with the SYNQ Social Density Engine, Cohort Retention Models, and Forward Deployed Engineering (FDE) operational intelligence services.
privacy@synq.eiIn this Agreement, unless the context requires otherwise, terms defined in the UK GDPR and Data Protection Act 2018 have the same meanings:
2.1 Relationship of the Parties: The parties acknowledge and agree that for the purposes of Applicable Data Protection Law, Trafalgar Education is the Data Controller and Synq Intelligence Ltd is the Data Processor in respect of Controller Personal Data.
2.2 Details of Processing: The subject matter, duration, nature, and purpose of the processing, along with the categories of Personal Data and Data Subjects, are specified in Schedule 1 of this Agreement.
Synq Intelligence Ltd shall:
4.1 Point-of-Ingestion Pseudonymisation: SYNQ guarantees that student, parent, and member identifiers ingested from Trafalgar Education's booking platforms, management information systems, or scheduling tools are pseudonymised at the point of ingestion using cryptographic SHA-256 one-way hashing.
4.2 Zero Unencrypted PII Storage: SYNQ shall not store raw, unencrypted direct identifiers (such as full student names, contact telephone numbers, home addresses, or payment card details) within its operational analytics cluster.
4.3 Baseline Hash Fingerprinting: For Phase 0 audits and Phase 1 RCT pilots, baseline churn and density fingerprints are cryptographically locked to ensure scientific verifiability and tamper-evident auditability without exposing individual data subject records.
5.1 General Authorization: Trafalgar Education grants SYNQ general authorization to engage the Sub-processors listed in Schedule 3 of this Agreement.
5.2 Changes to Sub-processors: SYNQ shall give Trafalgar Education at least thirty (30) days' prior written notice of any intended appointment of a new Sub-processor or replacement of an existing Sub-processor, providing Trafalgar Education the opportunity to object to such changes on reasonable data protection grounds.
5.3 Flow-Down Obligations: Where SYNQ engages a Sub-processor, SYNQ shall impose data protection obligations no less onerous than those set out in this DPA by way of a written contract. SYNQ remains fully liable to Trafalgar Education for the performance of each Sub-processor's obligations.
6.1 Assisting the Controller: Taking into account the nature of the processing, SYNQ shall assist Trafalgar Education by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of Trafalgar Education's obligations to respond to requests exercising Data Subject rights under Chapter III of the UK GDPR (including access, rectification, erasure, restriction, objection, and data portability).
6.2 Direct Data Subject Inquiries: If SYNQ receives a request directly from a Data Subject concerning Controller Personal Data, SYNQ shall promptly notify Trafalgar Education and shall not respond directly to the Data Subject without Trafalgar Education's prior written authorization, unless legally compelled to do so.
7.1 Notification Window: SYNQ shall notify Trafalgar Education in writing without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a confirmed Personal Data Breach affecting Controller Personal Data.
7.2 Breach Details: The notification shall contain, at a minimum:
7.3 Mitigation & Cooperation: SYNQ shall take immediate commercial and technical steps to mitigate the effects of any Personal Data Breach and provide full reasonable cooperation to Trafalgar Education in investigating and resolving the incident.
SYNQ shall provide reasonable assistance to Trafalgar Education with any data protection impact assessments (Article 35 UK GDPR) and prior consultations with supervisory authorities (such as the UK Information Commissioner's Office - ICO, Article 36 UK GDPR) that Trafalgar Education reasonably considers necessary in relation to the Services.
9.1 End of Services: Upon termination or expiry of the Services or at the written request of Trafalgar Education, SYNQ shall, at the choice of Trafalgar Education, securely delete or return all Controller Personal Data, and delete existing copies unless applicable UK or EU law requires continued retention.
9.2 Certification: Upon request, SYNQ shall provide written certification of the irreversible deletion and cryptographic zeroing of all operational replicas and cache files.
10.1 Demonstrating Compliance: SYNQ shall make available to Trafalgar Education all information necessary to demonstrate compliance with the obligations laid down in Article 28 of the UK GDPR.
10.2 Audit Facilitation: SYNQ shall allow for and contribute to audits, including inspections, conducted by Trafalgar Education or an independent certified auditor mandated by Trafalgar Education, upon reasonable prior notice (minimum 14 business days) and during normal business hours, subject to reasonable confidentiality and security procedures.
11.1 Primary Storage Location: All primary database storage, application nodes, and processing infrastructure utilized for Trafalgar Education are located within the United Kingdom (UK) and the European Economic Area (EEA).
11.2 Safeguards for Restricted Transfers: SYNQ shall not transfer Controller Personal Data to any country outside the UK or EEA that is not recognized as providing an adequate level of protection by the relevant UK authorities unless appropriate safeguards (such as the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses) are executed.
This DPA and any non-contractual obligations arising out of or in connection with it shall be governed by and construed in accordance with the laws of England and Wales. The courts of London, England shall have exclusive jurisdiction to settle any dispute or claim arising out of or in connection with this DPA.
| Subject Matter of Processing | The processing of booking schedules, attendance logs, and student participation records to provide experience intelligence, cohort retention analytics, social density metrics, and term-over-term churn predictions for Trafalgar Education locations. |
|---|---|
| Duration of Processing | For the duration of the Phase 0 Baseline Audit, Phase 1 Pilot Agreement, and any active Master Services Agreement / License term, plus any retention period mandated by law. |
| Nature and Purpose of Processing |
|
| Categories of Data Subjects |
|
| Types of Personal Data |
|
| Special Categories of Data | None. No special category data (health data, biometric data, racial/ethnic origin, religious beliefs) is requested, ingested, or processed by SYNQ. |
SYNQ implements and maintains technical and organisational measures that comply with Article 32 of the UK GDPR, including:
| Domain | Technical Measure Implemented |
|---|---|
| Cryptographic Pseudonymisation | Direct user identifiers are hashed using SHA-256 with distinct salt routines prior to graph indexing. Raw PII is never persisted in analytics data structures. |
| Encryption in Transit | All data transmitted across public and private networks is encrypted using Transport Layer Security (TLS 1.3 / TLS 1.2 minimum) with strong cipher suites. |
| Encryption at Rest | All storage volumes, database tables, and backup snapshots are encrypted at rest using AES-256 encryption. |
| Access Control & RBAC | Strict Role-Based Access Control (RBAC) and principle of least privilege. Production database access requires Multi-Factor Authentication (MFA) and is restricted to authorized Forward Deployed Engineers. |
| Tamper-Evident Baselines | Baseline cohort calculations are signed with SHA-256 fingerprint hash locks, guaranteeing reproducible and auditable reporting at pilot gate reviews. |
| Resilience & Backups | Automated point-in-time database snapshots stored in geographically redundant EU/UK cloud zones with tested disaster recovery protocols. |
| Vulnerability Management | Continuous automated static analysis, dependency scanning, and periodic third-party penetration testing. |
As of the Effective Date, the following Sub-processors are approved for the provision of cloud infrastructure, data persistence, and security services:
| Sub-processor Name | Processing Activity | Infrastructure Location | Transfer Safeguard |
|---|---|---|---|
| Supabase Inc. / AWS | Managed relational database persistence and encrypted storage | United Kingdom (London Region) / EU (Frankfurt) | UK Adequacy / Standard Data Protection Clauses |
| Amazon Web Services (AWS EMEA) | Cloud compute cluster & containerized execution nodes | United Kingdom (eu-west-2) / Ireland (eu-west-1) | UK Adequacy / ISO 27001 Certified |
| Cloudflare, Inc. | DDoS protection, Web Application Firewall (WAF), and edge routing | Global Edge Network (UK/EEA Data Processing Addendum) | UK IDTA / EU Standard Contractual Clauses |
| GitHub Inc. (Microsoft) | Source code repositories, deployment pipelines, CI/CD | United States / EU (Encrypted code only, zero customer PII) | UK Adequacy / Data Privacy Framework |
IN WITNESS WHEREOF, the parties hereto have caused this Data Processing Agreement to be duly executed by their authorized representatives as of the Effective Date.