Legal
Data Processing
Addendum
How Syncplify processes personal data on behalf of a customer, and the terms that govern it.
Effective
24 August 2026
Last Updated
3 September 2026
Version
1.1
1. Scope and roles
This Data Processing Addendum (this "DPA") forms part of the Terms of Service between Syncplify, Inc. ("Syncplify", "Processor") and the customer that holds an SFTP.cloud account (the "Customer", "Controller"). It applies where Syncplify processes Personal Data on the Customer’s behalf in providing the Service.
"Data Protection Law" means all laws applicable to the processing of Personal Data under this DPA, including Regulation (EU) 2016/679 (the "GDPR"), the UK GDPR and the Data Protection Act 2018, the Swiss Federal Act on Data Protection, and applicable United States state privacy laws. "Personal Data", "processing", "controller", "processor", "data subject", and "personal data breach" have the meanings given in the GDPR.
The Customer is the controller and Syncplify is the processor in respect of the Personal Data described in Annex I. Where the Customer is itself a processor acting for a third party controller, the Customer warrants that it has authority to give the instructions in this DPA on that controller’s behalf.
Syncplify does not persist Customer Data to storage it operates and cannot read its contents. The Personal Data processed under this DPA consists principally of Service Metadata and account data.
The parties acknowledge that files transferred through the Service move between the Customer’s storage and the Customer’s users through the channel established by the Storage Connector, and are not persisted to storage operated by Syncplify. Any Personal Data contained within those files is not processed by Syncplify within the meaning of this DPA, other than as a transient relay of encrypted traffic Syncplify cannot read. This DPA therefore concerns the categories of Personal Data set out in Annex I and no others.
2. Processing instructions
Syncplify will process Personal Data only on documented instructions from the Customer, including with regard to international transfers, unless required to do otherwise by law to which Syncplify is subject. Where such a requirement applies, Syncplify will inform the Customer before processing, unless the law prohibits it on important grounds of public interest.
The Terms of Service, this DPA, and the Customer’s use of the features and settings of the Service constitute the Customer’s complete documented instructions. Additional instructions outside their scope require agreement between the parties, and Syncplify may charge for the reasonable cost of following them.
Syncplify will inform the Customer if, in its opinion, an instruction infringes Data Protection Law. Syncplify is not obliged to carry out a legal review of the Customer’s instructions.
The Customer warrants that it has a lawful basis for the processing it instructs, that it has provided all required notices to data subjects, and that its instructions comply with Data Protection Law.
3. Confidentiality of personnel
Syncplify ensures that persons authorized to process Personal Data are bound by an appropriate duty of confidentiality, whether by contract or by statute, that survives the end of their engagement. Access is limited to those personnel who need it to provide the Service, and is granted on a least privilege basis.
4. Security measures
Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk to data subjects, Syncplify implements and maintains the technical and organizational measures set out in Annex II.
Syncplify may update those measures over time, provided the update does not materially reduce the overall level of security. The Customer is responsible for the security of the components it controls, including the Storage Connector, its storage, its network, and its own user access.
5. Sub-processors
The Customer gives Syncplify general written authorization to engage sub-processors. The sub-processors engaged at the effective date of this DPA are listed in Annex III.
Syncplify will give the Customer at least thirty (30) days' notice before adding or replacing a sub-processor, by email to the account's administrative contact. The Customer may object on reasonable data protection grounds within that period. Where the sub-processor is one Syncplify cannot exclude for an individual Customer, such as its cloud infrastructure provider, and the parties cannot resolve the objection, the Customer may terminate the affected subscription with effect from the date of the objection, and that is the Customer's sole remedy.
Syncplify will impose on each sub-processor data protection obligations no less protective than those in this DPA, and remains fully liable to the Customer for the performance of each sub-processor's obligations.
6. Assistance with data subject rights
Taking into account the nature of the processing, Syncplify will assist the Customer by appropriate technical and organizational measures, insofar as this is possible, in fulfilling the Customer’s obligation to respond to requests to exercise data subject rights.
Where Syncplify receives a request directly from a data subject in relation to Personal Data processed on the Customer’s behalf, it will not respond to it other than to acknowledge receipt and direct the data subject to the Customer, and will inform the Customer without undue delay.
7. Personal data breach
Syncplify will notify the Customer without undue delay, and in any event within forty-eight (48) hours of becoming aware of a personal data breach affecting the Customer.
The notification will describe, to the extent known at the time: the nature of the breach and the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed to address it and to mitigate its effects; and a contact point for further information. Where the full information is not available at once, Syncplify will provide it in phases without undue further delay.
Syncplify will assist the Customer in meeting the Customer’s own obligations to notify supervisory authorities and data subjects. Notification is not, and must not be construed as, an acknowledgment of fault or liability.
8. Assistance with assessments and consultation
Syncplify will provide the Customer with reasonable assistance in carrying out data protection impact assessments and in any prior consultation with a supervisory authority, in each case only in relation to processing carried out by Syncplify and taking into account the information available to it. Syncplify may charge for assistance that goes beyond providing the documentation it already maintains.
9. Deletion and return
On termination of the Service, and at the Customer’s choice, Syncplify will delete or return the Personal Data it processes on the Customer’s behalf, and delete existing copies, unless law requires it to retain them. Where the Customer elects return, Syncplify will provide that data in a commonly used, machine-readable format. Because Syncplify holds no Customer files, this obligation applies to account data and Service Metadata.
Absent a written instruction from the Customer within thirty (30) days of termination, Syncplify will delete the Personal Data in accordance with the retention periods in the Privacy Policy. Data held in routine backups is deleted on the expiry of the backup cycle, and remains subject to this DPA until it is.
10. Audits and information
Syncplify will make available to the Customer the information necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates.
The Customer agrees that this obligation is satisfied in the first instance by Syncplify providing its then-current third party audit reports, certifications, and completed security questionnaires. Where those do not reasonably address the Customer’s question, the Customer may request an audit on at least thirty (30) days’ written notice, no more than once in any twelve (12) month period unless required by a supervisory authority or following a personal data breach.
An audit must be conducted during business hours, must not unreasonably disrupt Syncplify’s operations, must be subject to confidentiality obligations, and must not include access to any other customer’s data. The Customer bears the cost of its own audits, except where the audit reveals a material breach of this DPA by Syncplify.
11. International transfers
Syncplify is established in the United States. Where this DPA involves a transfer of Personal Data from the European Economic Area, the United Kingdom, or Switzerland to a country not benefiting from an adequacy decision, the parties agree as follows.
- The Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914 are incorporated into this DPA by reference and apply to the transfer. Module Two applies where the Customer is a controller. Module Three applies where the Customer is a processor.
- For the purposes of Clause 7, the docking clause applies. For Clause 9, Option 2, general written authorization, applies, with the notice period stated in section 5. For Clause 11, the optional independent dispute resolution language does not apply. For Clause 17, the governing law is the law of Ireland. For Clause 18(b), the forum is the courts of Ireland.
- Annex I, Annex II, and Annex III of this DPA populate Annexes I, II, and III of the Standard Contractual Clauses.
- For transfers subject to the UK GDPR, the UK International Data Transfer Addendum to the Standard Contractual Clauses applies, with Tables 1 to 3 populated by the corresponding parts of this DPA, and Table 4 selecting "neither party".
- For transfers subject to Swiss law, references to the GDPR are read as references to the Swiss Federal Act on Data Protection, the competent authority is the Swiss Federal Data Protection and Information Commissioner, and "member state" is read so as not to deprive data subjects in Switzerland of their right to sue in their place of habitual residence.
Where a valid alternative transfer mechanism applies to a transfer, that mechanism applies instead of the Standard Contractual Clauses to the extent of the conflict.
12. Liability and precedence
Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the Terms of Service. Nothing in this DPA limits a data subject’s rights under Data Protection Law or a party’s liability to a supervisory authority.
In the event of a conflict, the Standard Contractual Clauses prevail over this DPA, this DPA prevails over the Terms of Service, and the Terms of Service prevail over the Privacy Policy, in each case in respect of the processing of Personal Data.
13. Term
This DPA takes effect when the Customer accepts the Terms of Service and continues until Syncplify has ceased all processing of Personal Data on the Customer’s behalf. Sections that by their nature should survive, including sections 3, 9, 10, and 12, survive termination.
Annex I: Details of processing
| Item | Detail |
|---|---|
| Controller | The Customer, as identified in its SFTP.cloud account |
| Processor | Syncplify, Inc., registered office: 2711 Centerville Rd., Suite 400, Wilmington, DE 19808, USA. Contact: privacy@sftp.cloud |
| Subject matter | Provision of the SFTP.cloud managed file transfer service |
| Duration | The term of the Terms of Service, plus the retention periods in the Privacy Policy |
| Nature and purpose | Hosting the control plane, authenticating users, relaying transfers, generating operational records, providing support, and securing the Service |
| Categories of data subject | The Customer’s administrators, its Authorized Users, and its external transfer partners |
| Categories of personal data | Identification and contact data; account credentials and authentication events; connection and session records including source IP address; configured storage endpoints; transfer volumes and timings; administrative actions; support correspondence; billing contact data |
| Special category data | None. The Service is not designed to process special category data in Syncplify systems |
| Frequency of transfer | Continuous, for the duration of the Terms of Service |
| Competent supervisory authority | To be completed by the Customer, in accordance with Clause 13 of the Standard Contractual Clauses |
Annex II: Technical and organizational measures
Syncplify implements at least the following measures.
| Area | Measure |
|---|---|
| Architecture | Customer files are not persisted to Syncplify-operated storage. Syncplify holds no credentials to Customer storage. The Storage Connector opens outbound connections only, so no inbound path to Customer infrastructure is exposed |
| Encryption in transit | TLS 1.2 or higher for all control plane traffic; SSH or TLS for the transfer channel |
| Encryption at rest | Encryption at rest for all data Syncplify holds, using AES-256 |
| Access control | Role-based access on a least privilege basis; multi-factor authentication required for administrative access; access reviewed at least quarterly |
| Pseudonymisation | Service Metadata is keyed to account identifiers rather than to direct identifiers wherever operationally possible |
| Logging and monitoring | Administrative actions and authentication events are logged; logs are monitored for anomalies and retained per the Privacy Policy |
| Resilience | Redundant infrastructure across three failure domains within the hosting region; daily off-site backups; documented restoration procedures; backups tested at least annually |
| Secure development | Code review before merge; dependency and vulnerability scanning; separation of development, staging, and production environments |
| Vulnerability management | Published disclosure channel; remediation targets of 7 days for critical, 30 days for high, and 90 days for medium severity findings; annual third party penetration testing |
| Personnel | Background screening where lawful; confidentiality obligations; security training at onboarding and at least annually |
| Vendor management | Security and data protection review before engagement; written contracts imposing equivalent obligations |
| Incident response | Documented incident response plan with defined roles, severity levels, and the notification path in section 7 of this DPA |
| Deletion | Documented deletion procedures aligned to the retention periods in the Privacy Policy, including expiry of backup cycles |
| Physical security | Production infrastructure is hosted with Akamai Technologies. Physical and environmental controls are inherited from that provider, whose certifications are available on request |
Annex III: Sub-processors
The following sub-processors are engaged at the effective date.
| Sub-processor | Purpose | Location |
|---|---|---|
| Akamai Technologies, Inc. (Akamai Cloud, formerly Linode) | Cloud infrastructure and hosting | United States (Chicago, Illinois) |
| Stripe, Inc. | Payment processing | United States |
| Block, Inc. (Square) | Payment processing | United States |
| Intuit Inc. (QuickBooks) | Payment processing and invoicing | United States |
| Help Scout PBC | Customer support and ticketing | United States |
| AC PM, LLC (Postmark) | Transactional email delivery | United States |
| Amazon Web Services, Inc. | Transactional email delivery (failover) | United States |
Questions about this DPA, or requests for a signed copy, may be sent to privacy@sftp.cloud.
Syncplify, Inc., a Delaware corporation