This Data Processing Agreement (“DPA”) forms part of the Terms of Service between the Customer and NearSync and applies where NearSync processes personal data on the Customer’s behalf. It is designed to support obligations under the GDPR and comparable data protection laws.
For self-hosted (BYOK) deployments, the Customer operates its own database and infrastructure, so NearSync generally does not process production personal data; this DPA applies to any personal data NearSync does process in the course of providing support and software.
Roles
For customer content in a Managed workspace, the Customer is the controller and NearSync is the processor. Where NearSync engages another party to process personal data, that party acts as a sub-processor. NearSync processes personal data only on the Customer’s documented instructions, including as set out in the Terms and this DPA.
Scope of processing
- Subject matter: provision of the NearSync platform.
- Duration: the term of the subscription, plus deletion or return afterwards.
- Nature and purpose: hosting, storage, and processing of records to operate the features the Customer uses.
- Types of data: contact and identity details, business records, communications, and any personal data the Customer chooses to store.
- Data subjects: the Customer’s staff, clients, contacts, and other individuals in its records.
Processor obligations
NearSync will: process personal data only on documented instructions; ensure personnel are bound by confidentiality; implement appropriate technical and organisational measures; assist the Customer with data-subject requests and with security, breach, and impact-assessment obligations; and, at the Customer’s choice, delete or return personal data at the end of the service.
Security measures
NearSync maintains measures including:
- Encryption in transit (TLS 1.3) and at rest (AES-256).
- Tenant isolation via organisation identifiers and Row-Level Security.
- Least-privilege access controls and authentication for staff.
- Audit logging of access to production systems.
- Regular patching and dependency updates, and monitoring for errors and anomalies.
Sub-processors
The Customer authorises NearSync to engage the sub-processors listed below. NearSync imposes data protection obligations on each and remains responsible for their performance.
| Sub-processor | Purpose | Primary region |
|---|---|---|
| Supabase | Managed database, auth, storage | Configured per deployment |
| Vercel | Application and website hosting | Global edge |
| Stripe | Billing and payments | Global |
| Google Cloud (Vertex AI / Gemini) | AI features and embeddings | Global |
| OpenAI, Anthropic | AI model providers | Global |
| Resend | Transactional email | Global |
| Twilio | Voice and SMS, where enabled | Global |
| Sentry | Error monitoring | Global |
NearSync will give notice of intended changes to sub-processors and allow the Customer to object on reasonable data protection grounds.
International transfers
Where personal data is transferred outside its region of origin, NearSync relies on appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms, together with the technical measures above.
Data-subject requests
NearSync will promptly notify the Customer of a request it receives from a data subject relating to the Customer’s content, and will assist the Customer in responding, taking into account the nature of the processing.
Personal-data breaches
NearSync will notify the Customer without undue delay after becoming aware of a personal-data breach affecting the Customer’s content, and will provide information reasonably available to help the Customer meet its own notification obligations.
Deletion and return
On termination, and at the Customer’s choice, NearSync will delete or return the Customer’s personal data within a reasonable period, except where retention is required by law.
Audits
NearSync will make available information reasonably necessary to demonstrate compliance with this DPA and will contribute to audits on reasonable prior notice, subject to confidentiality and the security of other customers.
Contact
Data protection contact: privacy@nearsync.ai.
Questions about this document? Write to legal@nearsync.ai. Company details are on the Imprint.