This Data Processing Agreement (“DPA”) forms part of the Terms of Service between the Customer and NearSync and applies where NearSync processes personal data on the Customer’s behalf. It is designed to support obligations under the GDPR and comparable data protection laws.
For self-hosted (BYOK) deployments, the Customer operates its own database and infrastructure, so NearSync generally does not process production personal data; this DPA applies to any personal data NearSync does process in the course of providing support and software.
Roles
For customer content in a Managed workspace, the Customer is the controller and NearSync is the processor. Where NearSync engages another party to process personal data, that party acts as a sub-processor. NearSync processes personal data only on the Customer’s documented instructions, including as set out in the Terms and this DPA.
Scope of processing
- Subject matter: provision of the NearSync platform.
- Duration: the term of the subscription, plus deletion or return afterwards.
- Nature and purpose: hosting, storage, and processing of records to operate the features the Customer uses.
- Types of data: contact and identity details, business records, communications, and any personal data the Customer chooses to store.
- Data subjects: the Customer’s staff, clients, contacts, and other individuals in its records.
Processor obligations
NearSync will: process personal data only on documented instructions; ensure personnel are bound by confidentiality; implement appropriate technical and organisational measures; assist the Customer with data-subject requests and with security, breach, and impact-assessment obligations; and, at the Customer’s choice, delete or return personal data at the end of the service.
Security measures
NearSync maintains measures including:
- Encryption in transit (TLS 1.3) and at rest (AES-256).
- Tenant isolation via organisation identifiers and Row-Level Security.
- Least-privilege access controls and authentication for staff.
- Audit logging of access to production systems.
- Regular patching and dependency updates, and monitoring for errors and anomalies.
Sub-processors
The Customer authorises NearSync to engage the sub-processors listed below. NearSync imposes data protection obligations on each and remains responsible for their performance.
| Sub-processor | Purpose | Primary region |
|---|---|---|
| Supabase | Managed database, auth, storage | Configured per deployment |
| Vercel | Application and website hosting | Global edge |
| Stripe | Billing and payments | Global |
| Razorpay | Payments, where enabled | India |
| Google Cloud (Vertex AI / Gemini) | AI features and embeddings | Global |
| OpenAI, Anthropic, xAI | AI model providers | Global |
| Mistral, Groq, DeepSeek | Additional AI model providers, only where the Customer configures them with their own credentials | Global |
| Tavily | Web search performed on the Customer’s behalf by AI features | Global |
| Resend | Transactional email | Global |
| Twilio | Voice and SMS, where enabled | Global |
| LiveKit | Real-time audio and video sessions | Global |
| Meta Platforms | WhatsApp Business messaging, where enabled | Global |
| Recall.ai | Meeting recording and transcription, where meeting intelligence is enabled | Global |
| Google (Firebase Cloud Messaging) | Mobile push notification delivery | Global |
| Sentry | Error monitoring | Global |
NearSync will give at least 30 days’ notice of intended changes to sub-processors and allow the Customer to object on reasonable data protection grounds within that period.
AI model providers
NearSync operates the AI features on its own accounts with Google (Vertex AI / Gemini), OpenAI, Anthropic and xAI; those are sub-processors where the corresponding feature is enabled. The platform also supports Mistral, Groq and DeepSeek, but only where the Customer supplies their own credentials for that provider — in which case the Customer directs the transfer, as with a connected integration. A locally hosted model served through Ollama transmits nothing to a third party at all.
Integrations the Customer connects
Separately from the list above, the Customer may connect third-party accounts they hold themselves — CRM, project, accounting, calendar, storage and similar services. Where the Customer does so, they instruct NearSync to exchange data with that service, and the provider is not a NearSync sub-processor. Those services are governed by the Customer’s own agreement with them. The connections available are documented at docs.nearsync.ai, and a Customer can disconnect any of them at any time from the Integrations surface.
International transfers
Where personal data is transferred outside its region of origin, NearSync relies on appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms, together with the technical measures above.
Data-subject requests
NearSync will promptly notify the Customer of a request it receives from a data subject relating to the Customer’s content, and will assist the Customer in responding, taking into account the nature of the processing.
Personal-data breaches
NearSync will notify the Customer without undue delay after becoming aware of a personal-data breach affecting the Customer’s content, and will provide information reasonably available to help the Customer meet its own notification obligations.
Deletion and return
On termination, and at the Customer’s choice, NearSync will delete or return the Customer’s personal data within a reasonable period, except where retention is required by law.
Audits
NearSync will make available information reasonably necessary to demonstrate compliance with this DPA and will contribute to audits on reasonable prior notice, subject to confidentiality and the security of other customers.
Contact
Data protection contact: privacy@nearsync.ai.
Questions about this document? Write to legal@nearsync.ai. Company details are on the Imprint.