Last updated 2026-05-08

Data Processing Addendum

This Data Processing Addendum ("DPA") forms part of the Services Agreement between Syncora and the Controller and governs the Processing of Personal Data by Syncora on Controller's behalf. Capitalized terms not defined here are defined in Section 1 or in the Services Agreement.

Section 1

Definitions

For the purposes of this Data Processing Addendum ("DPA"), capitalized terms have the meanings set forth below. Terms not defined herein have the meanings given in the Services Agreement.

  • "Controller" means the customer entity that determines the purposes and means of the Processing of Personal Data.
  • "Processor" means Syncora, which Processes Personal Data on behalf of the Controller.
  • "Personal Data" means any information relating to an identified or identifiable natural person processed in connection with the Services.
  • "Sub-processor" means any third party engaged by the Processor to Process Personal Data on the Controller's behalf.
  • "Data Subject" means the individual to whom Personal Data relates.
  • "GDPR" means Regulation (EU) 2016/679.
  • "CCPA" means the California Consumer Privacy Act, as amended by the CPRA.
  • "BIPA" means the Illinois Biometric Information Privacy Act, 740 ILCS 14/.
  • "AI Act" means the Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence.

Section 2

Subject matter and duration of Processing

Syncora Processes Personal Data on behalf of Controller in connection with workforce management Services, including scheduling, time and attendance tracking, leave administration, payroll preparation, performance management, onboarding, and AI governance. Processing occurs for the term of the Services Agreement and any period required by applicable law for retention or wind-down.

Section 3

Nature and purpose of Processing

Processing comprises automated and human-in-the-loop operations supporting workforce operations. AI inference is subject to the Building Constitution Pillars (Explainability, Bias Mitigation, Human-in-the-Loop, Transparency). All decisions affecting an employee record are logged in an immutable audit trail retained for seven (7) years, in accordance with regulatory expectations under GDPR Art. 22, NYC Local Law 144, and AI Act Art. 12.

Section 4

Categories of Data Subjects

  • Employees of the Controller's organization.
  • Contractors and contingent workers engaged by the Controller.
  • Applicants and candidates who interact with the Controller's hiring workflows.
  • Managers, HR personnel, and administrators who operate the Services on the Controller's behalf.

Section 5

Categories of Personal Data

  • Identifiers (name, email, employee ID, government-issued ID where required for I-9 / right-to-work).
  • Contact information (phone, address).
  • Employment details (job title, department, manager, employment status, compensation).
  • Time and attendance records, scheduling data, leave balances.
  • Performance data and review records.
  • Biometric authentication events, captured only where the Data Subject has provided written, informed, BIPA-compliant consent.
  • Location data, where geofence-based clock-in is configured and the Data Subject has been notified.
  • Accommodation requests, which are firewalled from AI decision pipelines per Building Constitution Pillar 4 and applicable disability law.

Section 6

Sub-processors

Controller authorizes Syncora to engage Sub-processors as listed in the live registry at /sub-processors. Syncora provides Controller with no less than thirty (30) days' prior written notice (which may be by email or via the registry) of any addition or replacement of a Sub-processor, during which Controller may object on reasonable grounds related to data protection.

Section 7

Security measures

Syncora implements and maintains technical and organizational measures consistent with industry standards. Current posture is published live at /security. Measures include, at minimum:

  • Encryption at rest using AES-256.
  • Encryption in transit using TLS 1.3.
  • Zero-trust access controls with least-privilege role enforcement.
  • SOC 2 is scoped but not yet audited. No auditor is engaged and no report exists.
  • ISO/IEC 42001 (AI Management System) work has not started. Syncora holds no certificate.
  • Continuous monitoring of access logs and audit trails.

Section 8

International transfers

Where Personal Data originating in the European Economic Area, the United Kingdom, or Switzerland is transferred to a jurisdiction not subject to an adequacy decision, the parties shall rely on the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), the UK International Data Transfer Addendum (IDTA), or another lawful transfer mechanism. Data residency is selectable per customer where supported by Syncora's deployment topology.

Section 9

Data Subject rights

Syncora provides Controller with reasonable assistance — by appropriate technical and organizational measures, insofar as possible — for the fulfillment of Controller's obligations to respond to Data Subject requests for access, rectification, erasure, restriction of Processing, data portability, objection, and the right not to be subject to a decision based solely on automated Processing under GDPR Art. 22, NYC Local Law 144 (AEDT), Colorado SB 26-189 (ADMT), and analogous state AI bias laws.

Section 10

Personal Data Breach

Syncora notifies Controller without undue delay and in any event within twenty-four (24) hours after becoming aware of a Personal Data Breach. Notification shall include, to the extent then known, the nature of the Breach, categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to address the Breach, consistent with GDPR Art. 33.

Section 11

Audit and inspection rights

Controller may audit Syncora's compliance with this DPA no more than once per calendar year, on no less than sixty (60) days' prior written notice, during normal business hours, and in a manner that does not unreasonably interfere with Syncora's operations. Syncora shall make available, on request, the security and compliance documentation it then holds. Syncora holds no SOC 2 report and no ISO/IEC certification as of the date of this DPA, and does not represent that any such report or certificate exists or will be issued by a given date. Where Syncora later obtains a third-party attestation, it may offer that attestation in lieu of an on-site inspection where reasonable.

Section 12

Return or deletion of data

Within thirty (30) days of termination or expiration of the Services Agreement, Syncora shall, at Controller's election, return or delete all Personal Data Processed on Controller's behalf. Backups expire on a standard ninety (90) day rotation. Controller may extend retention for the period reasonably required to satisfy a documented legal hold.

Section 13

AI Governance addendum

Syncora maintains the following AI governance scoring and registries, all of which are accessible to Controller:

  • BAGI — Building Artificial Intelligence Governance Index — composite scoring across Explainability, Bias, HITL, and Transparency dimensions.
  • AGRF — AI Governance Risk Framework — pre-deployment risk assessment per workflow.
  • GATE — Governance Approval and Testing Engine — pre-production model gate.
  • AIRS — AI Risk Scoring — runtime per-decision risk classification.
  • ConstitutionRule registry — codified rules enforcing Pillar requirements.

Controller has access to AIDecision logs, BiasAudit results, OverrideEvent records, and the ConstitutionRule registry for any decision affecting an employee. Meaningful human review is available for any automated decision affecting an employee, in accordance with GDPR Art. 22 and the AI Act.

Section 14

Liability, indemnification, governing law

The terms of liability, indemnification, governing law, and dispute resolution applicable to this DPA are those set forth in the Master Services Agreement between the parties. In the event of a conflict between this DPA and the Master Services Agreement with respect to the Processing of Personal Data, this DPA controls.

By using Syncora, Controller agrees to the terms of this DPA. For execution as a binding addendum, contact james.waddell@cognitivewx.info.