Data Processing Addendum
Last updated 29 August 2026 · Sympl Analytics LLC, Utah, United States
1. What this is and how it applies
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between Sympl Analytics LLC (“Sympl”, “Processor”) and the customer using the service (“Customer”, “Controller”). It applies whenever Sympl processes personal data on the Customer’s behalf.
It applies automatically — no signature is needed for it to take effect. If your procurement process requires a countersigned copy, or your own DPA template, email symplanalytics@gmail.com and we will sign.
Where this DPA conflicts with the Terms of Service, this DPA governs for matters of personal data processing.
2. Definitions
“GDPR” means Regulation (EU) 2016/679 and, where applicable, the UK GDPR and Data Protection Act 2018. “Controller”, “Processor”, “Data Subject”, “Personal Data”, “Processing” and “Personal Data Breach” have the meanings given in the GDPR. “Sub-processor” means a third party engaged by Sympl to process Customer Personal Data. “Customer Personal Data” means personal data within data the Customer connects to or submits through the service.
3. Roles of the parties
For Customer Personal Data, the Customer is the Controller and Sympl is the Processor. The Customer decides which platforms to connect and for what purpose; Sympl processes what those connections return.
The Customer is responsible for having a lawful basis for the processing it instructs, and for the accuracy of the data it connects.
Separately, Sympl acts as a Controller for data it collects for its own purposes — account records and website fit-check submissions. That processing is governed by our Privacy Policy, not by this DPA.
4. Details of processing (Article 28(3))
Subject matter and purpose. Providing the marketing and sales analytics service: retrieving data from the platforms the Customer connects, standardising it, storing it, and presenting reports, findings and assistant answers to the Customer’s authorised users.
Duration. The term of the Terms of Service, plus the deletion period in section 10.
Nature of the processing. Collection, storage, organisation, structuring, retrieval, analysis, disclosure to the Customer’s own users, and erasure.
Types of Personal Data. Determined by what the Customer connects. Typically:
- CRM contact records — first name, last name, email address, lead source.
- Sales records — deal name, amount, stage, pipeline and close date, which may identify an individual indirectly.
- Search and advertising performance data — search queries, page URLs, campaign metrics. Ordinarily aggregate and non-identifying, though a search query is free text and can contain personal data the Customer does not control.
- Authorised user records — the email addresses of the Customer’s own users of the service.
Categories of Data Subjects. The Customer’s contacts, leads and customers; and the Customer’s own personnel who use the service.
Special category data. The service is not designed for and must not be used to process special categories of personal data under Article 9, or criminal offence data under Article 10.
5. Sympl's obligations
Sympl will:
- process Customer Personal Data only on the Customer’s documented instructions — the Terms of Service, this DPA, and the Customer’s configuration and use of the service constitute those instructions — unless required otherwise by law, in which case Sympl will inform the Customer first unless the law forbids it;
- ensure that anyone authorised to process Customer Personal Data is bound by an obligation of confidentiality;
- implement the technical and organisational measures described in section 12;
- respect the conditions in section 6 for engaging Sub-processors;
- assist the Customer, so far as reasonably possible, in responding to Data Subject requests (section 8);
- assist the Customer in meeting its obligations under Articles 32 to 36, including security, breach notification and data protection impact assessments;
- delete or return Customer Personal Data as set out in section 10; and
- make available the information needed to demonstrate compliance with Article 28, and allow for audits as set out in section 11.
Sympl will inform the Customer if, in its opinion, an instruction infringes data protection law.
6. Sub-processors
The Customer gives general written authorisation for Sympl to engage Sub-processors. Each is bound by written terms imposing data protection obligations no less protective than those in this DPA, and Sympl remains liable to the Customer for their performance.
The current Sub-processors are:
- Supabase — database hosting and user authentication. United States.
- Vercel — application hosting and content delivery. United States.
- Anthropic — generates answers given by the in-product assistant, from the portion of the Customer’s own data relevant to the question asked. United States.
- Windsor.ai — retrieves advertising performance data, for Customers who connect an advertising platform. European Union.
HubSpot, Google and other platforms the Customer connects are not Sub-processors: they are the Customer’s own systems, which the Customer authorises Sympl to read.
Sympl will give the Customer at least 30 days’ notice by email before adding or replacing a Sub-processor. If the Customer reasonably objects on data protection grounds within that period, the Customer may terminate the affected part of the service without penalty and receive a pro-rata refund of prepaid fees.
7. International transfers
Sympl and most of its Sub-processors are located in the United States, and Customer Personal Data is stored there. Where the Customer transfers personal data subject to the GDPR or UK GDPR, the parties agree that the European Commission’s Standard Contractual Clauses (Decision 2021/914), Module Two (Controller to Processor), are incorporated into this DPA by reference and apply to that transfer, together with the UK International Data Transfer Addendum where the UK GDPR applies.
For those clauses: the Customer is the data exporter and Sympl the data importer; the governing law is Ireland and the courts of Ireland have jurisdiction (or, for UK transfers, England and Wales); the optional docking clause applies; and Annexes I and II are populated by sections 4, 6 and 12 of this DPA. Sympl will notify the Customer if it becomes unable to comply with them.
8. Data Subject requests
The service gives the Customer direct access to the personal data it holds, which is usually enough to respond to access, correction and deletion requests without involving Sympl.
Where it is not, Sympl will assist the Customer by appropriate technical and organisational measures, so far as reasonably possible, taking into account the nature of the processing. If a Data Subject contacts Sympl directly about Customer Personal Data, Sympl will not respond substantively and will refer them to the Customer, notifying the Customer promptly.
Assistance of this kind is provided at no additional charge for requests of ordinary scope.
9. Personal Data Breach
Sympl will notify the Customer without undue delay, and in any event within 72 hours, of becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification will describe the nature of the breach, the categories and approximate number of Data Subjects and records affected so far as known, the likely consequences, the measures taken or proposed, and a contact point for further information.
Sympl will provide the Customer with reasonable cooperation and information to allow the Customer to meet its own obligations under Articles 33 and 34. Notification is not an acknowledgement of fault.
10. Deletion and return
The Customer may export its data at any time while its account is active, and for 30 days after termination.
On the Customer’s written request, or within 30 days of termination, Sympl will delete Customer Personal Data from its systems, including stored platform credentials, except where retention is required by law. Deletion is currently performed manually by Sympl on request rather than by a self-service control; the outcome is the same, and Sympl will confirm in writing once it is complete.
Backups held by Sympl’s hosting providers are overwritten on those providers’ ordinary retention cycles. Data in a backup is not restored to active use after deletion.
11. Audits and information
Sympl will make available to the Customer the information reasonably necessary to demonstrate compliance with Article 28, including this DPA, our Privacy Policy, and written responses to a reasonable security questionnaire.
The Customer may audit no more than once in any twelve-month period, or following a Personal Data Breach, on at least 30 days’ written notice, during business hours, without unreasonable disruption, and subject to confidentiality. Sympl may satisfy an audit request by providing documented responses where those reasonably address the Customer’s questions.
Sympl does not currently hold a SOC 2 or ISO 27001 report. We say so plainly rather than leave it to be discovered: if your procurement process requires one, it does not exist yet.
12. Security measures (Annex II)
The measures below are what is actually implemented, described so a reviewer can verify them rather than take them on trust. Where something commonly expected is absent, it is listed as absent.
Encryption. All traffic to the service and between the service and connected platforms runs over HTTPS. Credentials and access tokens for connected platforms are encrypted with AES-256-GCM before being written to the database, using a key held only in the server environment, so the database alone never contains a usable credential. Data at rest is encrypted by the hosting provider.
Tenant separation. Every query is filtered by an account identifier resolved from the authenticated session, never from user-supplied input. The database enforces the same separation independently through row-level security policies. Writes from connected platforms are keyed so that one account’s data cannot overwrite another’s.
Access control. Authentication is handled by a specialist provider; passwords are stored only as hashes and are never visible to Sympl. Credentials for connected platforms are held server-side and never sent to a browser. Administrative access to production is limited to Sympl’s personnel and protected by the hosting providers’ own authentication.
Application hardening. The service sends a Content Security Policy, HSTS, and frame, referrer and content-type protections. Endpoints that accept unauthenticated input are rate limited and size bounded. Internal error detail is logged server-side and never returned to a browser.
Logging. Application and access logs are retained by the hosting provider. Errors are recorded with a reference identifier so an incident can be traced.
Resilience. Hosting and database providers maintain their own backup and recovery arrangements. Sympl does not operate an independent backup regime beyond those.
Currently absent. Multi-factor authentication is not yet available for Customer accounts. There is no formal, documented incident response plan, no independent penetration test, and no SOC 2 or ISO 27001 certification. Sympl is a small organisation without a dedicated security function.
13. US state privacy laws
Where the California Consumer Privacy Act as amended applies, Sympl acts as a Service Provider. Sympl does not sell or share Customer Personal Data as those terms are defined, does not retain, use or disclose it for any purpose other than performing the service, and does not combine it with personal data from other sources except as permitted. Sympl will comply with applicable obligations and provide the same level of protection required by that law. Equivalent terms apply under comparable state laws.
14. General
Each party’s liability under this DPA is subject to the limitations in the Terms of Service. This DPA takes effect when the Customer begins using the service and ends when Sympl has deleted Customer Personal Data under section 10. If any provision is unenforceable, the rest continues in effect.
Questions, signature requests and security questionnaires: symplanalytics@gmail.com.