Data Processing Agreement
Last updated: January 1, 2025
Overview
This Data Processing Agreement ("DPA") explains how SynqEvent processes your personal data when you use our photo and video sharing platform. We are committed to protecting your privacy and ensuring compliance with applicable data protection laws.
What Data We Process
Account Information
- Email address (for account creation and notifications)
- Name and profile information you provide
- Authentication data and session tokens
Event Content
- Photos and videos you upload to events
- Event details and settings you configure
- Guest uploads to your events
- File metadata (size, upload time, file type)
Usage Data
- Website analytics via Vercel Analytics
- Upload progress and performance data
- QR code scan counts and usage statistics
- Payment transaction data (processed via PayPal)
How We Process Your Data
Legal Basis for Processing
- Contract Performance: To provide our photo sharing service as agreed
- Legitimate Interest: To improve our service and prevent abuse
- Consent: Where you have explicitly agreed to processing
- Legal Compliance: To comply with applicable laws and regulations
Processing Activities
- Storing and organizing your photos and videos
- Sending account verification and notification emails
- Processing payments through secure third-party providers
- Analyzing usage patterns to improve service performance
- Generating QR codes for event access
Third-Party Services
We work with trusted third-party services to provide our platform:
- Amazon Web Services (AWS): Secure cloud storage for photos and videos
- Vercel Analytics: Website performance and usage analytics
- PayPal: International payment processing
- SendGrid: Email delivery for notifications and verification
- Supabase/PostgreSQL: Secure database hosting
All third-party services are selected based on their security standards and data protection compliance.
Data Retention
We retain your data for different periods based on the type of information:
- Event Content: Retained according to your plan's retention period (4 hours to 90 days)
- Account Information: Retained until you delete your account
- Payment Data: Retained for tax and legal compliance (up to 7 years)
- Analytics Data: Aggregated data may be retained indefinitely for service improvement
Your Rights
You have the following rights regarding your personal data:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate or incomplete data
- Erasure: Request deletion of your personal data
- Portability: Download your photos and videos in a standard format
- Restriction: Limit how we process your data
- Objection: Object to processing based on legitimate interests
- Withdraw Consent: Withdraw consent where processing is based on consent
Data Security
We implement appropriate technical and organizational measures to protect your data:
- Encryption of data in transit and at rest
- Secure authentication and session management
- Regular security audits and monitoring
- Access controls and principle of least privilege
- Secure cloud infrastructure with enterprise-grade providers
International Transfers
Your data may be processed in countries outside your region. We ensure appropriate safeguards are in place:
- Data processed by providers with appropriate data protection certifications
- Standard contractual clauses where applicable
- Adequacy decisions for transfers to approved countries
Data Breach Notification
In the unlikely event of a data breach affecting your personal data, we will:
- Notify relevant supervisory authorities within 72 hours where required
- Inform affected users without undue delay if there is high risk to your rights
- Take immediate steps to contain and remedy the breach
- Conduct a thorough investigation and implement preventive measures
Changes to This Agreement
We may update this Data Processing Agreement to reflect changes in our data processing practices or legal requirements. We will notify you of any material changes and update the "Last updated" date above.
Contact Us
For questions about this Data Processing Agreement or to exercise your rights:
- Email: support@synqevent.com
- Website: synqevent.com
- Subject: Data Processing Inquiry