Data Processing Agreement (DPA)
Snyte AI Platform Enterprise Services
Effective Date: May 10, 2026
Version: 1.0
Parties
Data Controller: the customer entity identified in the applicable Order Form or Master Service Agreement ("Customer")
Address: as set out in the applicable Order Form
Contact: the privacy contact designated in the applicable Order Form
Data Processor: Snyte, Inc. (d/b/a Snyte)
Address: as set out in the applicable Order Form
Contact: privacy@snyte.ai
1. Definitions
For the purposes of this Data Processing Agreement ("DPA"):
"Affiliate" means any entity that directly or indirectly controls, is controlled by, or is under common control with a party.
"Controller" means the natural or legal person which determines the purposes and means of processing Personal Data.
"Customer Data" means any data, including Personal Data, that Customer or its Authorized Users upload, submit, or otherwise make available through the Service.
"Data Protection Laws" means all applicable laws relating to data protection and privacy, including GDPR, CCPA, and other regional privacy regulations.
"GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council.
"Personal Data" means any information relating to an identified or identifiable natural person.
"Processing" means any operation performed on Personal Data, including collection, use, storage, disclosure, or deletion.
"Processor" means the natural or legal person which processes Personal Data on behalf of the Controller.
"Service" means the Snyte AI business intelligence platform and related services.
"Sub-processor" means any third party engaged by Snyte to process Personal Data.
"Supervisory Authority" means an independent public authority established by an EU Member State.
2. Processing Details
2.1 Subject Matter and Duration
This DPA governs the processing of Personal Data by Snyte as part of providing the Service to Customer under the Master Service Agreement. Processing will continue for the duration of the agreement and applicable retention periods.
2.2 Nature and Purpose of Processing
Snyte processes Personal Data to:
- Provide business intelligence and analytics services
- Generate AI-powered insights and recommendations
- Maintain platform security and performance
- Provide customer support and technical assistance
- Ensure compliance with legal obligations
2.3 Categories of Data Subjects
Personal Data may relate to:
- Customer's employees, contractors, and agents
- Customer's customers and business contacts
- End users of Customer's products and services
- Other individuals whose data is processed through the Service
2.4 Categories of Personal Data
The Personal Data processed may include:
- Identity Data: Names, job titles, employee IDs
- Contact Data: Email addresses, phone numbers, physical addresses
- Professional Data: Company information, department, role
- Usage Data: System access logs, feature usage, interaction patterns
- Technical Data: IP addresses, device information, browser data
- Communication Data: Support tickets, messages, feedback
3. Data Processing Principles
3.1 Processing Instructions
Snyte shall process Personal Data only:
- On documented instructions from Customer (including this DPA)
- As necessary to provide the Service
- As required by applicable law (with notice to Customer where possible)
- As agreed in writing between the parties
3.2 Data Minimization
Snyte shall:
- Process only Personal Data necessary for the specified purposes
- Limit access to Personal Data to personnel who need it
- Implement data retention policies aligned with business purposes
- Regularly review and delete unnecessary Personal Data
3.3 Purpose Limitation
Personal Data shall be processed only for the purposes specified in this DPA and shall not be further processed in a manner incompatible with those purposes.
4. Data Subject Rights
4.1 Facilitating Rights Requests
Snyte shall assist Customer in fulfilling Data Subject rights requests by:
- Providing technical and organizational measures to enable Customer to respond
- Implementing appropriate access controls and data portability features
- Assisting with data rectification, erasure, and restriction requests
- Providing relevant Personal Data within 30 days of request
4.2 Direct Requests
If Snyte receives a Data Subject rights request directly, it shall:
- Promptly notify Customer of the request
- Not respond directly unless legally required
- Provide Customer with necessary information to respond
- Assist Customer in verifying the identity of the Data Subject
4.3 Automated Decision Making
Customer acknowledges that the Service may include AI-powered analytics and insights. Customer remains responsible for:
- Determining appropriate use of automated insights
- Ensuring human oversight of significant decisions
- Providing Data Subjects with information about automated processing
- Implementing appropriate safeguards and review processes
5. Security Measures
5.1 Technical Safeguards
Snyte implements and maintains appropriate technical measures including:
Encryption:
- AES-256 encryption for data at rest
- TLS 1.3 encryption for data in transit
- End-to-end encryption for sensitive communications
- Key management using AWS KMS or equivalent
Access Controls:
- Multi-factor authentication for all system access
- Role-based access control (RBAC) with principle of least privilege
- Regular access reviews and automated deprovisioning
- Privileged access management (PAM) for administrative functions
Network Security:
- Virtual Private Cloud (VPC) isolation
- Network segmentation and microsegmentation
- Intrusion detection and prevention systems (IDS/IPS)
- Web Application Firewall (WAF) protection
Monitoring and Logging:
- Continuous automated security monitoring
- Comprehensive audit logging
- Automated threat detection and alerting
- Regular vulnerability scanning
5.2 Organizational Safeguards
Snyte maintains organizational measures including:
Personnel Security:
- Background checks for all personnel with access to Personal Data
- Security awareness training and regular updates
- Confidentiality agreements for all staff and contractors
- Clear roles and responsibilities for data protection
Data Governance:
- Data classification and handling policies
- Data retention and deletion procedures
- Privacy by design and by default practices
- Regular privacy impact assessments
Incident Management:
- Continuous automated security alerting with an on-call response process
- Documented incident response procedures
- Regular incident response training
- Post-incident review and improvement processes
5.3 Compliance Certifications
Snyte holds no third-party compliance certifications today. Snyte maintains
controls aligned with SOC 2 Type II (certification in progress) and ISO 27001
(certification on the roadmap), and will make attestation reports available
to Customer as and when they are obtained.
6. Sub-processing
6.1 General Authorization
Customer provides general authorization for Snyte to engage Sub-processors necessary to provide the Service, subject to the conditions in this Section.
6.2 Sub-processor Requirements
Snyte shall ensure that Sub-processors:
- Are subject to data protection obligations equivalent to this DPA
- Implement appropriate technical and organizational measures
- Allow Snyte to audit their compliance with data protection obligations
- Notify Snyte immediately of any Personal Data breaches
6.3 Current Sub-processors
The current list of Sub-processors is maintained at: https://snyte.ai/subprocessors
Key Sub-processors include:
- WorkOS: Identity, SSO, and directory services
- Stripe: Payment processing services
- OpenAI: AI model provider for natural-language features
- Anthropic: AI model provider for natural-language features
Cloud hosting and database infrastructure depend on the deployment model
selected by Customer; self-hosted deployments introduce no Snyte-managed
hosting Sub-processor.
6.4 Changes to Sub-processors
Snyte shall:
- Provide 30 days advance notice of new Sub-processors
- Allow Customer to object to new Sub-processors
- Work in good faith to address reasonable objections
- Provide alternative solutions if Customer objects
6.5 Sub-processor Liability
Snyte remains fully liable for Sub-processor compliance with data protection obligations.
7. Data Transfers
7.1 Transfer Mechanisms
For transfers of Personal Data outside the EEA, Snyte relies on:
- Adequacy Decisions: Where available from the European Commission
- Standard Contractual Clauses (SCCs): EU Commission approved clauses
- Binding Corporate Rules: Internal transfer mechanisms
- Other Lawful Transfer Mechanisms: As approved by Supervisory Authorities
7.2 Data Residency Options
Customer may select data residency preferences:
- United States: Primary processing in US AWS regions
- European Union: Primary processing in EU AWS regions
- Multi-Region: Distributed processing with primary region selection
- Custom: Specific geographic requirements by agreement
7.3 Government Access
In the event of government access requests:
- Snyte will notify Customer where legally permissible
- Snyte will challenge overbroad or inappropriate requests
- Snyte will provide only minimum necessary information
- Snyte will document all government access incidents
8. Data Breach Notification
8.1 Notification Timeline
Snyte shall notify Customer of Personal Data breaches:
- Initial Notification: Within 24 hours of becoming aware
- Detailed Report: Within 72 hours with available information
- Final Report: Within 30 days with complete investigation results
8.2 Notification Content
Breach notifications shall include:
- Description of the nature of the breach
- Categories and approximate number of Data Subjects affected
- Categories and approximate number of Personal Data records affected
- Likely consequences of the breach
- Measures taken or proposed to address the breach
- Contact information for obtaining more information
8.3 Customer Obligations
Customer remains responsible for:
- Determining whether to notify Supervisory Authorities
- Notifying affected Data Subjects where required
- Meeting regulatory notification timelines
- Cooperating with Supervisory Authority investigations
8.4 Assistance and Cooperation
Snyte shall:
- Provide reasonable assistance with breach notifications
- Cooperate with Customer's investigation of the incident
- Implement additional safeguards to prevent recurrence
- Document lessons learned and process improvements
9. Data Protection Impact Assessments
9.1 DPIA Assistance
Where Customer is required to conduct a Data Protection Impact Assessment (DPIA), Snyte shall provide reasonable assistance including:
- Technical and organizational measures implemented
- Security certifications and audit reports
- Data flow diagrams and processing documentation
- Risk assessment information and mitigation measures
9.2 High-Risk Processing
If Snyte identifies processing that may pose high risks to Data Subjects, it shall:
- Notify Customer promptly of the identified risks
- Work with Customer to assess the need for a DPIA
- Implement additional safeguards as agreed with Customer
- Document risk mitigation measures
10. Audits and Compliance
10.1 Audit Rights
Customer may audit Snyte's compliance with this DPA through:
- Certification Reports: attestation reports as and when obtained (see Section 5.3)
- Compliance Questionnaires: Annual security assessments
- On-Site Audits: With reasonable notice and scope limitations
- Documentation Review: Policies, procedures, and controls
10.2 Audit Frequency and Scope
- Standard Audits: Annual review of certifications and questionnaires
- Detailed Audits: Upon reasonable request, not more than once per year
- Incident-Triggered Audits: Following significant security incidents
- Regulatory Audits: As required by Supervisory Authorities
10.3 Audit Cooperation
Snyte shall:
- Provide reasonable cooperation during audits
- Make relevant personnel available for interviews
- Provide access to relevant documentation and systems
- Address identified compliance gaps in a timely manner
10.4 Audit Costs
- Customer bears costs for Customer-initiated audits
- Snyte bears costs for remediation of identified compliance gaps
- Third-party audit costs shared based on findings
- Emergency audits following breaches at Snyte's cost
11. Data Retention and Deletion
11.1 Retention Periods
Personal Data shall be retained according to the following schedule:
- Active Account Data: Duration of Service agreement
- Inactive Account Data: 90 days after account termination
- Backup Data: Up to 12 months in encrypted backups
- Log Data: 7 years for security and compliance purposes
11.2 Data Deletion Process
Upon termination or expiration of the Service agreement:
1. 30 Days: Customer data made available for export
2. 90 Days: Active deletion of Customer data from production systems
3. 180 Days: Deletion from backup systems and archives
4. 365 Days: Secure disposal of all storage media
11.3 Deletion Verification
Snyte shall:
- Provide written certification of data deletion
- Maintain records of deletion activities
- Use industry-standard data wiping procedures
- Ensure Sub-processors also delete Customer data
11.4 Legal Hold Exceptions
Data deletion may be delayed if:
- Required to comply with legal obligations
- Subject to litigation hold requirements
- Needed for regulatory investigations
- Other lawful basis for retention exists
Customer will be notified of any retention beyond standard periods.
12. Liability and Indemnification
12.1 Data Protection Liability
Each party's liability for data protection violations shall be governed by:
- The underlying Service Agreement liability provisions
- Applicable Data Protection Laws
- The specific circumstances of any violation
- The party's role as Controller or Processor
12.2 Regulatory Fines and Penalties
- Controller Fines: Customer responsibility for Controller violations
- Processor Fines: Snyte responsibility for Processor violations
- Joint Liability: Shared responsibility based on fault and involvement
- Insurance Coverage: Both parties maintain appropriate cyber liability insurance
12.3 Indemnification
Snyte shall indemnify Customer against third-party claims arising from:
- Snyte's material breach of this DPA
- Snyte's violation of Data Protection Laws in its role as Processor
- Unauthorized disclosure of Personal Data by Snyte or its Sub-processors
13. Term and Termination
13.1 Term
This DPA shall remain in effect for the duration of the Service Agreement and any applicable data retention periods.
13.2 Termination Rights
Either party may terminate this DPA:
- Upon termination of the Service Agreement
- For material breach not cured within 30 days notice
- If required by applicable Data Protection Laws
- Upon mutual written agreement
13.3 Effect of Termination
Upon termination:
- Processing of Personal Data shall cease except as required for data retention
- Data deletion procedures in Section 11 shall apply
- Ongoing obligations (confidentiality, data deletion) shall survive
- Customer remains responsible for any outstanding compliance obligations
14. Governing Law and Disputes
14.1 Governing Law
This DPA shall be governed by the same law as the Service Agreement, except where Data Protection Laws require otherwise.
14.2 Jurisdiction
For EU Data Subjects, Customer may bring claims in:
- Courts of Customer's EU Member State
- Courts where Snyte has an establishment
- Courts of the Data Subject's habitual residence
14.3 Dispute Resolution
The parties shall attempt to resolve disputes through:
1. Direct Negotiation: Good faith discussions between privacy officers
2. Mediation: Binding mediation before qualified data protection mediator
3. Arbitration: As specified in the Service Agreement
4. Court Proceedings: As a last resort in appropriate jurisdiction
15. Amendments and Updates
15.1 Amendment Process
This DPA may be amended:
- By mutual written agreement of the parties
- To reflect changes in applicable Data Protection Laws
- To address new regulatory guidance or requirements
- As part of Service Agreement updates
15.2 Regulatory Updates
Snyte may update this DPA to comply with:
- New or amended Data Protection Laws
- Guidance from Supervisory Authorities
- Changes in transfer mechanism requirements
- Industry best practice developments
15.3 Notice of Changes
Material changes to this DPA shall be communicated:
- 30 Days Advance Notice: For changes affecting Customer obligations
- Immediate Notice: For changes required by law or regulation
- Annual Review: Summary of all changes during the year
- Website Publication: Current version available at https://snyte.ai/dpa
16. Contact Information
Customer Privacy Contact
As designated by Customer in the applicable Order Form.
Snyte Privacy Contacts
Primary Contact:
Email: privacy@snyte.ai
Data Protection Officer:
Email: dpo@snyte.ai
Security Incident Contact:
Email: security@snyte.ai
Signature
Customer:
Name: ________________
Title: ________________
Date: ________________
Signature: ________________
Snyte (Snyte, Inc.):
Name: ________________
Title: ________________
Date: ________________
Signature: ________________
Document Control:
- Version: 1.0
- Classification: Confidential
- Owner: Legal and Privacy Team
- Review Cycle: Annual
- Next Review: May 10, 2027
Exhibit A: Technical and Organizational Measures
A.1 Access Control
- Multi-factor authentication for all system access
- Role-based access control with principle of least privilege
- Regular access reviews and automated deprovisioning
- Privileged access management for administrative functions
A.2 Data Encryption
- AES-256 encryption for data at rest
- TLS 1.3 encryption for data in transit
- End-to-end encryption for sensitive communications
- Managed key storage with rotation procedures
A.3 Network Security
- Virtual Private Cloud (VPC) isolation
- Network segmentation and micro-segmentation
- Intrusion detection and prevention systems
- Web Application Firewall (WAF) protection
A.4 System Monitoring
- Continuous automated security monitoring and alerting
- On-call incident response process
- Automated threat detection and alerting
- Regular vulnerability scanning
A.5 Data Backup and Recovery
- Encrypted automated backups with geographic distribution
- Regular backup testing and restoration procedures
- Business continuity and disaster recovery plans
- Recovery time objective (RTO) of 4 hours, Recovery point objective (RPO) of 1 hour
A.6 Personnel Security
- Background checks for all personnel with data access
- Security awareness training and regular updates
- Confidentiality agreements for all staff and contractors
- Clear data handling roles and responsibilities
Exhibit B: Sub-processor List
| Sub-processor | Service | Data Categories | Location |
|---|---|---|---|
| WorkOS | Identity, SSO, and directory services | Identity and contact data | US |
| Stripe | Payment processing | Billing information | US |
| OpenAI | AI model provider for natural-language features | Query text and related metadata | US |
| Anthropic | AI model provider for natural-language features | Query text and related metadata | US |
Cloud hosting, database, email delivery, and observability providers depend on
the deployment model, enabled integrations, and customer configuration.
Self-hosted deployments introduce no Snyte-managed hosting Sub-processor.
Customers receive the deployment-specific list during procurement or security
review.
Last Updated: July 2, 2026
Current Version: https://snyte.ai/subprocessors