Data Processing Addendum
Last updated: October 2, 2026
This Data Processing Addendum ("DPA") forms part of the Syndai Terms of Service or, where Customer has signed one, the Syndai Master Services Agreement (in either case, the "Agreement") between Eternex, Inc. (dba Syndai) ("Eternex") and Customer, and applies to Eternex's Processing of Personal Data on Customer's behalf in providing the Service. If this DPA conflicts with the Agreement, this DPA controls for the subject matter of Personal Data. Capitalized terms not defined here have the meanings in the Agreement.
1. Definitions
- "Data Protection Laws" means all laws applying to the Processing of Personal Data under this DPA, including, as applicable, the EU/UK GDPR, the California Consumer Privacy Act as amended by the CPRA ("CCPA"), and other U.S. state privacy laws.
- "Personal Data" means information relating to an identified or identifiable natural person contained in Customer Content or otherwise Processed by Eternex on Customer's behalf under the Agreement.
- "Processing" (and "Process") means any operation performed on Personal Data.
- "Subprocessor" means a third party engaged by Eternex to Process Personal Data on Customer's behalf.
- "Security Incident" means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data Processed by Eternex.
- "SCCs" means the European Commission's Standard Contractual Clauses for controller-to-processor transfers (Decision (EU) 2021/914, Module Two), and, for UK transfers, the UK International Data Transfer Addendum.
2. Roles and Scope
2.1 Roles. For Personal Data in scope: Customer is the controller (or, where Customer acts for a Customer Client, a processor acting on that controller's instructions), and Eternex is the processor (or subprocessor). Each party will comply with its own obligations under Data Protection Laws.
2.2 Instructions. Eternex will Process Personal Data only on Customer's documented instructions, which consist of the Agreement, this DPA, and Customer's configuration and use of the Service, unless required to do otherwise by law (in which case Eternex will inform Customer unless legally prohibited). Eternex will inform Customer if, in its opinion, an instruction infringes Data Protection Laws.
2.3 Customer Responsibilities. Customer is responsible for the lawfulness of the Personal Data it submits, for providing required notices and obtaining required consents, and for its instructions. Customer must not submit special-category or sensitive Personal Data to the Service; the Service is a software-delivery platform, not designed for such data.
2.4 Persistent Coding-Run Memory. As part of providing the Service, Eternex retains run-derived context (for example recurring conventions, prior decisions, and task patterns) scoped to the Customer and pinned to the Customer's connected repositories, and recalls it to personalize and improve that Customer's later runs. This is Processing on Customer's documented instructions under Section 2.2, for the sole benefit of that Customer. The memory is tenant-scoped (keyed to the Customer's account and repository), is never pooled across customers or used to improve the Service for other customers, and is not used to train models (Section 4.2); it is not secondary use of Customer's data. This Processing is on by default; Customer may disable it per run through Service configuration. Stored memory is erasable on request (Eternex provides an owner-triggered erasure control), is erased automatically when a User deletes their account, and is deleted on termination under Section 12 (see also Section 6). Persistent memory is stored within Eternex's own systems on the hosting and database Subprocessors listed in Annex 3; no additional Subprocessor receives it.
3. Confidentiality; Personnel
Eternex will ensure that personnel authorized to Process Personal Data are bound by confidentiality obligations and Process it only as needed to provide the Service.
4. Security
4.1 Eternex will implement and maintain appropriate technical and organizational measures to protect Personal Data, as described in Annex 2, taking into account the state of the art, costs, and the nature and risks of the Processing.
4.2 No Training. Consistent with the Agreement, Eternex will not use Personal Data in Customer Content or Output to train or improve AI models, and requires the same of its LLM Subprocessors.
5. Subprocessors
5.1 Authorization. Customer generally authorizes Eternex to engage the Subprocessors listed in Annex 3. Eternex will impose data-protection obligations on Subprocessors no less protective than this DPA and remains liable for their performance.
5.2 Updates and Objection. Eternex will maintain a current Subprocessor list (Annex 3, as updated by notice under this Section) and will give Customer at least 30 days' notice (email to Customer's Notice Address or in-product notice) before adding or replacing a Subprocessor. Customer may object in writing on reasonable data-protection grounds within that period; the parties will work in good faith to resolve the objection, and if they cannot, Customer may terminate the affected Order Form (or, under the Terms of Service, close its account) on notice with a prorated refund of prepaid, unused Fees as its exclusive remedy.
6. Data Subject Requests
Taking into account the nature of the Processing, Eternex will provide reasonable assistance (including appropriate technical and organizational measures) for Customer to respond to data-subject requests under Data Protection Laws (access, deletion, correction, portability, objection). This includes erasure of persistent coding-run memory (Section 2.4): Eternex provides a mechanism to erase a Customer's or User's stored memory on request, and such erasure is a permanent hard deletion. If Eternex receives such a request directly, it will redirect the data subject to Customer and not respond substantively except as legally required.
7. Security Incidents
Eternex will notify Customer without undue delay and in any event within 72 hours after becoming aware of a Security Incident, providing information reasonably available about its nature, the categories and approximate number of data subjects and records concerned, likely consequences, and measures taken or proposed. Eternex will take reasonable steps to contain and remediate the incident. Eternex's notification is not an admission of fault.
8. Assistance
Eternex will provide reasonable assistance with Customer's data-protection impact assessments and consultations with supervisory authorities, to the extent required by Data Protection Laws and related to Eternex's Processing.
9. Audits (Reports-Based)
On written request no more than once per 12 months (or following a Security Incident), Eternex will make available information reasonably necessary to demonstrate compliance with this DPA, consisting of summaries of third-party audit reports, certifications, and security documentation and written responses to reasonable security questionnaires. If this information is insufficient to satisfy a requirement of Data Protection Laws, Customer may request an audit by an independent third-party auditor bound by confidentiality, at Customer's expense, during business hours, with reasonable notice, no more than once per 12 months, and without access to other customers' data.
10. International Transfers
10.1 To the extent Eternex Processes Personal Data subject to the EU/UK GDPR that is transferred to a country without an adequacy decision, the SCCs are incorporated by reference into this DPA, with Customer as data exporter and Eternex as data importer, and:
- Module Two (controller-to-processor) applies (Module Three where Customer is a processor);
- Clause 7 (docking) is included; Clause 9(a) Option 2 (general authorization) with the 30-day notice period in Section 5.2; Clause 11 optional language is not included;
- Clause 17: the SCCs are governed by the law of Ireland; Clause 18: the courts of Ireland;
- Annexes I, II, and III of the SCCs are populated by Annexes 1, 2, and 3 of this DPA (Annex I.A by Annex 1 Part A, Annex I.B by Annex 1 Part B, Annex I.C by Annex 1 Part C); Clause 13: the competent supervisory authority is identified in Annex 1 Part C;
- For UK transfers, the UK Addendum applies with the tables completed as set out in Annex 1 Part D; for Swiss transfers, the SCCs apply as adapted for the FADP.
10.2 If the SCCs or another transfer mechanism is invalidated, the parties will cooperate in good faith to implement a lawful replacement.
10.3 Transfer assessment. The parties have assessed that the transfer mechanism in this Section provides an essentially equivalent level of protection, taking into account the supplementary measures in Annex 2 (including encryption in transit and at rest and per-run sandbox isolation) and the warranties in Clauses 14 and 15 of the SCCs. Eternex will promptly notify Customer if it becomes unable to comply with the SCCs, including because of a change in applicable law or a binding government request for access to Personal Data, and where legally permitted will provide reasonable information about any such request; the parties will then proceed under Section 10.2.
11. CCPA / U.S. State Privacy Terms
To the extent Personal Data includes personal information governed by the CCPA or similar U.S. state laws, Eternex acts as a "service provider"/"processor": Eternex (a) will not sell or share the personal information; (b) will not retain, use, or disclose it for any purpose other than performing the Service under the Agreement or as permitted by the CCPA, including not outside the direct business relationship with Customer; (c) will not combine it with personal information from other sources except as permitted for service providers; (d) certifies that it understands and will comply with these restrictions; and (e) will notify Customer if it can no longer meet its obligations, in which case Customer may take reasonable steps to stop and remediate unauthorized use.
12. Deletion and Return
Upon termination or expiration of the Agreement, or earlier on Customer's written request, Eternex will delete Personal Data Processed on Customer's behalf (or return it, at Customer's option, in a commonly used format), and delete existing copies, within 60 days, except where retention is required by law, in which case Eternex will protect the retained data under this DPA and isolate it from further Processing. Sandbox environments are provisioned per run and destroyed on completion; workspace snapshots and encrypted archives of repository content are retained while the repository remains connected and are deleted per the retention schedule in Annex 1 and, on termination or disconnection, under this Section 12. Persistent coding-run memory (Section 2.4) is hard-deleted on Customer's written erasure request and when a User deletes their account, and is deleted on termination under this Section 12.
13. Liability; Order of Precedence
Each party's liability under or in connection with this DPA is subject to the limitations and exclusions in the Agreement (including, under a Master Services Agreement, the Increased Cap Amount applicable to DPA breaches). This DPA controls over the Agreement as to Personal Data; the SCCs control over this DPA where they apply and conflict.
Annex 1, Part A: List of Parties (SCC Annex I.A)
- Data exporter: Customer, as identified on the applicable Order Form or, absent one, in Customer's Syndai account (name, address, contact person). Activities: use of the Syndai Service under the Agreement. Role: controller (or processor, where Customer acts for a Customer Client).
- Data importer: Eternex, Inc. (dba Syndai), 2261 Market Street STE 24499, San Francisco, CA 94114, USA. Contact person: Eternex Privacy Team, privacy@syndai.ai. Activities: provision of the Syndai Service as described in this DPA. Role: processor (or subprocessor). Signature/date: on the Order Form, or by Customer's acceptance of the Agreement.
Each party's contact name, position, address, and signature/date complete SCC Annex I.A from the Order Form or, absent one, from Customer's account details and its acceptance of the Agreement.
Annex 1, Part B: Description of Processing (SCC Annex I.B)
- Subject matter: Provision of the Syndai AI software-delivery Service under the Agreement
- Duration: The term of the Agreement plus the deletion period in Section 12
- Nature and purpose: Hosting, transmission, and automated analysis and transformation of Customer-connected repository and account content in isolated environments to perform the work the Customer directs across the functions of a one-person company: generating code changes and pull requests, and, using accounts the Customer connects and with each result sent to the Customer to approve before it publishes or sends, producing documentation, posts, media, and outreach drafts; for 30 days after a delivery, checking whether its commits landed on the connected repository's default branch outside the pull request (adoption check, by commit-fingerprint match); retaining and recalling run-derived context scoped to the Customer to personalize and improve that Customer's subsequent runs (persistent coding-run memory, Section 2.4); account management; billing; support; service analytics
- Categories of data subjects: Customer's Users (employees, contractors); individuals whose personal data is incidentally contained in repository content, commit history, or prompts, or is displayed on pages of the Customer's web application rendered during validation; recipients of outreach the Customer directs through the Service; Customer Client personnel where Agency Use applies
- Categories of Personal Data: Account and contact data (name, business email, authentication identifiers); billing data (purchases are sold by Polar, Eternex's merchant of record, which processes payment and tax data as an independent controller; Eternex does not store full card numbers); usage and device data (logs, telemetry, IP addresses); repository and prompt content, which may incidentally contain personal data (e.g., names and emails in commit metadata); screenshots and page-derived text of the Customer's web application rendered during validation (which can show signed-in pages), sent to an LLM Subprocessor for visual design review; all of the above is processed in isolated sandboxes, with workspace snapshots, encrypted archives, and run artifacts/evidence retained per the Retention row below; run-derived context strings retained as persistent coding-run memory scoped to the Customer (Section 2.4)
- Special categories: None intended; Customer must not submit special-category data (Section 2.3)
- Frequency: Continuous during the term, per Customer-initiated runs
- Retention: Sandboxes are provisioned per run and destroyed on completion. Workspace snapshots and encrypted archives of repository content are retained while the repository remains connected (to make runs fast and recoverable) and are deleted per Eternex's documented retention schedule and, on termination of the Agreement or disconnection of the repository, per Section 12 (within 60 days). Persistent coding-run memory (Section 2.4) is retained to personalize that Customer's runs while the account is active, is never pooled across customers, and is hard-deleted on Customer's erasure request and on deletion of a User's account. Account/usage data retained for the term plus the Section 12 deletion window
Annex 1, Part C: Competent Supervisory Authority (SCC Annex I.C)
The competent supervisory authority (SCC Clause 13) is the supervisory authority of the EU member state in which the data exporter is established or, where the exporter is not established in the EU, the supervisory authority of the member state of its EU representative or in which the relevant data subjects are located, as identified on the Order Form or, absent one, as determined under SCC Clause 13.
Annex 1, Part D: UK International Data Transfer Addendum Tables
For transfers subject to the UK GDPR, the UK Addendum applies with its tables completed as follows:
- Table 1 (Parties): Exporter: Customer, per the Order Form (details as in Part A). Importer: Eternex, Inc. (dba Syndai), 2261 Market Street STE 24499, San Francisco, CA 94114, USA; privacy@syndai.ai. Start date: the DPA effective date. Key contacts: per the Order Form (exporter) and privacy@syndai.ai (importer).
- Table 2 (Selected SCCs, Modules and Selected Clauses): The EU SCCs (Decision (EU) 2021/914), Module Two (controller-to-processor) (Module Three where Customer is a processor), as incorporated and completed in Section 10.1 of this DPA.
- Table 3 (Appendix Information): Annex 1A: Part A above. Annex 1B: Part B above. Annex II: Annex 2 of this DPA. Annex III: Annex 3 of this DPA.
- Table 4 (Ending this Addendum when the Approved Addendum Changes): The importer (Eternex) may end the UK Addendum as set out in its Section 19.
Annex 2: Technical and Organizational Security Measures
- Isolation: each run executes in a dedicated, ephemeral sandbox destroyed on completion; no cross-customer sandbox reuse.
- Encryption: TLS 1.2+ in transit; encryption at rest for stored account, usage, and artifact data.
- Access control: role-based access, least privilege, SSO/MFA for Eternex personnel; customer secrets stored in a managed secrets system, never in code.
- Credential handling: repository access via scoped, revocable tokens; Customer can revoke integration access at any time.
- Logging and monitoring: centralized logging, error and anomaly monitoring, audit trails for administrative access.
- Vulnerability management: dependency and vulnerability scanning, timely patching, and security review of changes.
- Personnel: confidentiality obligations, security awareness onboarding, offboarding access revocation.
- Resilience: managed-infrastructure backups and recovery procedures for account/metadata stores; workspace snapshots and encrypted archives of repository content are retained per Annex 1's retention schedule and encrypted at rest.
- Incident response: documented incident-response process supporting the 72-hour notice in Section 7.
- Vendor management: Subprocessors assessed for security posture and bound to written data-protection terms.
Annex 3: Subprocessors
The current list of Subprocessors is published at https://syndai.ai/legal/subprocessors and forms Annex 3 of this DPA, as updated by notice under Section 5.2.
Execution
This DPA takes effect automatically when Customer accepts the Agreement; no separate signature is required. Customers who need a countersigned copy can request one from legal@syndai.ai.