This Data Processing Agreement (the "DPA") is part of the Terms of Service (the "Agreement") between Neivan Technology Holdings, LLC ("Neivan") and the customer that agreed to them (the "Customer"). It applies whenever Neivan processes personal data on the Customer's behalf in providing the Synapse platform (the "Service").
Accepting the Agreement accepts this DPA. A Customer that wants a countersigned copy can email [email protected]. If this DPA conflicts with the rest of the Agreement about personal data, this DPA controls.
2.1 The Customer is the controller of Customer Personal Data (or, where the Customer is itself a processor for someone else, a processor), and Neivan is its processor (or subprocessor). Where the Customer acts for another controller, it confirms it has that controller's authority to engage Neivan.
2.2 For data Neivan controls for its own purposes — account administration, billing, security and abuse prevention — our Privacy Policy applies instead of this DPA.
3.1 Neivan processes Customer Personal Data only on the Customer's documented instructions, unless the law requires otherwise (in which case we tell the Customer first, unless the law forbids it).
3.2 The Customer's instructions are the Agreement, this DPA, and the Customer's own configuration of the Service — including which apps it connects, what agents may do, approval settings, observation and Recorder settings, AI provider choices and retention settings.
3.3 We will tell the Customer if we believe an instruction breaks Data Protection Laws.
3.4 The Customer is responsible for the lawfulness of Customer Personal Data and its instructions, including having a lawful basis and giving every notice and obtaining every consent the law requires.
Everyone Neivan authorizes to process Customer Personal Data is bound by confidentiality obligations and has access only as needed to provide and support the Service.
5.1 Neivan maintains appropriate technical and organizational measures to protect Customer Personal Data, described in Annex II and our Security Overview. We will not materially reduce the overall level of security during the term of the Agreement.
5.2 The Customer is responsible for its own use of the Service: who it gives access to, the roles and permissions it sets, the apps it connects, and its users' credentials.
6.1 Authorization. The Customer authorizes Neivan to use the Subprocessors on our Subprocessor List. Neivan places data-protection obligations on each Subprocessor no less protective than this DPA, and remains responsible for their performance.
6.2 AI providers. When an AI feature runs, the prompt and the content needed for that request are sent to an AI provider on the Subprocessor List. Customer Personal Data is not used to train that provider's models or any Neivan model. AI providers a Customer reaches with its own API key are the Customer's own providers, not Neivan's Subprocessors.
6.3 Changes. Before a new Subprocessor starts processing Customer Personal Data, Neivan will update the Subprocessor List and email the Customer's account owner at least 30 days in advance. If we must replace a Subprocessor sooner to protect the security or continuity of the Service, we will notify the Customer as soon as reasonably possible.
6.4 Objections. The Customer may object in writing to [email protected] during the notice period on reasonable data-protection grounds. We will try in good faith to address the objection; if we cannot, the Customer may terminate the affected part of the Service without penalty and receive a refund of prepaid fees for the unused period.
7.1 The Service lets users export, correct and delete their own personal data (Settings → Privacy & observation). Where the Customer cannot answer a request with those tools, Neivan will provide reasonable help.
7.2 If a data subject contacts Neivan directly about Customer Personal Data, we will not respond on the merits except on the Customer's instructions or as the law requires, and will promptly pass the request to the Customer where we can identify it.
Neivan will give reasonable help with the Customer's data protection impact assessments and consultations with regulators, taking into account the information available to us.
Neivan will notify the Customer without undue delay, and no later than 72 hours after confirming a Personal Data Breach, with the information reasonably available to help the Customer meet its own notification duties, and will take reasonable steps to contain and fix it. A notification is not an admission of fault.
If Neivan receives a legally binding request from a public authority for Customer Personal Data, we will notify the Customer unless the law forbids it, challenge requests we believe are unlawful or overbroad, and disclose only the minimum the law requires.
Neivan and its Subprocessors process Customer Personal Data in the United States, and the Service is currently offered to customers in the United States. If Customer Personal Data subject to the EU GDPR, UK GDPR or Swiss FADP is transferred to the United States under the Agreement, the parties incorporate the European Commission's Standard Contractual Clauses (Module Two, or Module Three where the Customer is a processor), with the UK International Data Transfer Addendum and Swiss amendments as applicable, completed with the details in Annexes I and II.
Neivan will make available the information reasonably needed to show compliance with this DPA, starting with our security documentation. Neivan has not yet completed an independent security audit. The Customer may audit compliance no more than once a year (or after a Personal Data Breach, or where a regulator requires it), with reasonable advance notice, during business hours, under a confidentiality agreement, and without access to other customers' data.
13.1 While the Agreement is in effect, the Customer can export Customer Data with the tools in the Service.
13.2 After the Agreement ends, Neivan will delete Customer Personal Data within 30 days of the Customer's request, and may delete it at any time after 90 days following the end of the Agreement. Neivan may keep a copy only where the law requires, and only for as long as it requires; this DPA continues to protect anything kept.
Where the CCPA applies, Neivan will: process Customer Personal Data only for the business purposes in the Agreement; not sell or share it; not retain, use or disclose it outside the direct business relationship with the Customer; not combine it with personal information from other sources except as the CCPA allows; provide the same level of protection the CCPA requires of the Customer; and tell the Customer if it can no longer meet these obligations. The Customer may take reasonable steps to stop and remedy unauthorized use. Neivan certifies that it understands and will comply with these restrictions.
Each party's liability under this DPA is subject to the limitations in the Agreement. This DPA is governed by the same law and dispute terms as the Agreement, except where Data Protection Laws or the Standard Contractual Clauses require otherwise.
Parties. Controller (data exporter): the Customer. Processor (data importer): Neivan Technology Holdings, LLC, 14817 SW 41st St, Davie, FL 33331, USA; contact [email protected].
Subject matter and purpose. Providing, securing and supporting the Service on the Customer's instructions: hosting and storing Customer Data, running AI agents, skills and workflows, reading from and acting in apps the Customer connects, and — when enabled — observing work to find tasks worth automating.
Duration. The term of the Agreement plus the period in Section 13.
Data subjects. The Customer's Authorized Users; and people whose personal data is in Customer Data or in the Customer's connected apps, such as the Customer's customers, contacts and job candidates.
Categories of personal data.
| Category | Examples |
|---|---|
| Identity and account | Name, email, role, department, permissions |
| Compensation | Salary or hourly rate, where the Customer records it |
| Personal knowledge | Writing samples, and audio or video recordings and their transcripts used to capture a person's expertise |
| Observation data | Activity from connected apps (such as sender, recipients, time and subject line — not message bodies or file contents); from the Recorder, window titles, control names and optional screenshots |
| Connected-app data | Emails, calendar entries, files, CRM, accounting and social-media data the Customer's agents access |
| AI interactions | Prompts, instructions and Output |
| Technical | IP address, device and usage logs |
Sensitive data. The Service does not require special categories of personal data. Compensation, recordings and screenshots are handled with restricted access. A Customer that chooses to process special categories does so under its own responsibility.
Frequency. Continuous, while the Agreement is in effect.
| Area | Measures |
|---|---|
| Encryption | HTTPS (TLS 1.2+) with HSTS; encryption at rest by our infrastructure providers; stored credentials additionally encrypted with AES-256-GCM |
| Tenant separation | Row-level security on every customer data table |
| Access control | Role-based permissions checked on the server; session inactivity limits, and every session ends after 7 days without use and 30 days after sign-in; approval settings for agent actions |
| Authentication | Multi-factor authentication (authenticator app) available to every user, required at sign-in once a person has set it up, and able to be required by an organization for all its members; a code entered within the last 10 minutes for sensitive changes by a person who uses multi-factor authentication; an automated-abuse check (Cloudflare Turnstile) on sign-in, sign-up and password reset; passwords of at least 12 characters with lower-case, upper-case, digit and symbol, with passwords known from data breaches refused; invitation links that expire after 48 hours and are stored only as a hash |
| Staff access | Limited to staff who operate the Service; multi-factor authentication required for every staff account on our operations console; read-only, time-limited and audit-logged support access to customer accounts |
| Logging | Audit log of administrative and security-relevant actions whose entries cannot be edited; error monitoring |
| Observation safeguards | Off by default; per-person consent; on-device masking of text patterns that look like personal data or secrets; retention limits |
| Backups | Automated daily database backups by our database provider, with the last 7 days kept; point-in-time recovery not enabled; files in file storage not included in database backups; written backup and recovery procedure |
| Incident response | Written incident-response plan; notification as in Section 9 |
| Planned | Point-in-time recovery and restore drills; independent penetration test and security audit |
The current list is published at /legal/subprocessors and forms part of this DPA.