> ## Documentation Index
> Fetch the complete documentation index at: https://docs.graphorlm.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Data Processing Addendum (Template)

> Pre-prepared Data Processing Addendum for customer counter-signature. Incorporates the Trust Center commitments, the no-training clause, pass-through references to upstream DPAs, and Standard Contractual Clauses for international transfer.

<Warning>
  This Data Processing Addendum ("DPA") is a contractual template. Although it is drafted to be enforceable as-is under Brazilian law and to satisfy LGPD art. 39 and GDPR art. 28, you should have your own legal counsel review it before counter-signing. Synapse is happy to discuss reasonable customer redlines via [privacy@graphorlm.com](mailto:privacy@graphorlm.com).
</Warning>

## How to use this template

1. Read the body of the DPA below alongside the [Privacy Policy](/legal/privacy-policy) and the [Terms of Service](/legal/terms-of-service), which it incorporates by reference.
2. Complete the customer-side fields in [Annex 1](#annex-1--description-of-the-processing) and the signature block at the end of this page.
3. Send the counter-signed DPA to [privacy@graphorlm.com](mailto:privacy@graphorlm.com); Synapse counter-signs and returns a fully executed copy within five business days, along with a frozen snapshot of [Annex 3](#annex-3--subprocessors-as-of-signature-date) reflecting the subprocessors in production on the signature date.
4. The executed DPA becomes part of your agreement with Synapse and prevails over inconsistent terms in any underlying agreement to the extent of any conflict on data-processing matters.

A PDF copy of this DPA is available on request via [privacy@graphorlm.com](mailto:privacy@graphorlm.com) for organizations that require a static signed document.

***

## Data Processing Addendum

This Data Processing Addendum ("DPA") is entered into between:

**SYNAPSE INOVAÇÃO E TECNOLOGIA LTDA.**, a company organized under the laws of the Federative Republic of Brazil, with principal place of business in Brazil ("Synapse" or the "Processor"), and

**\[CAMPO — Customer legal name, jurisdiction, registered address, registration/tax identifier]** (the "Customer" or the "Controller"),

each a "Party" and together the "Parties".

This DPA forms part of and is incorporated into the Terms of Service published at `https://docs.graphorlm.com/legal/terms-of-service` and any other agreement between the Parties governing the Customer's use of the Graphor Service (collectively, the "Agreement"). In the event of any conflict between this DPA and the Agreement on data-protection matters, this DPA prevails.

## 1. Definitions

Unless otherwise defined below, terms have the meaning given to them in LGPD, GDPR, the Agreement, the [Privacy Policy](/legal/privacy-policy), or this DPA.

| Term                                           | Meaning                                                                                                                                                                                                               |
| ---------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Applicable Data Protection Law**             | LGPD (Lei nº 13.709/2018 — Brazil), GDPR (Regulation (EU) 2016/679), and any other data protection legislation applicable to the Processing under this DPA.                                                           |
| **Controller**                                 | The natural or legal person that determines the purposes and means of the Processing of Personal Data — for the purposes of this DPA, the Customer.                                                                   |
| **Customer Personal Data**                     | Personal Data that Customer or its end users submit to the Graphor Service, including Customer Content as defined in the Privacy Policy.                                                                              |
| **Personal Data**                              | Any information relating to an identified or identifiable natural person ("Data Subject") that is Processed under this DPA.                                                                                           |
| **Process / Processing**                       | Any operation or set of operations performed on Personal Data, whether or not by automated means — collection, storage, transmission, use, deletion, etc.                                                             |
| **Processor**                                  | The natural or legal person that Processes Personal Data on behalf of the Controller — for the purposes of this DPA, Synapse.                                                                                         |
| **Standard Contractual Clauses** or **"SCCs"** | The Standard Contractual Clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679, as adopted by European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.     |
| **Subprocessor**                               | Any third party engaged by Synapse to Process Customer Personal Data on Synapse's behalf, as listed in [Annex 3](#annex-3--subprocessors-as-of-signature-date) and on the [Subprocessors page](/trust/subprocessors). |
| **Security Incident**                          | A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data.                                                            |

## 2. Scope, roles, and duration

### 2.1 Roles of the Parties

The Customer is the Controller of the Customer Personal Data. Synapse acts as the Processor on the Customer's behalf to provide the Graphor Service. This allocation of roles applies for the purposes of LGPD art. 5º, VI–VII and GDPR art. 4(7)–(8).

### 2.2 Scope of Processing

Synapse Processes Customer Personal Data only as necessary to provide the Graphor Service to the Customer in accordance with the Customer's documented instructions, which are codified in:

* the Agreement;
* the [Trust Center](/trust/overview) and the documents it incorporates;
* this DPA;
* the Customer's configuration of the Service (project settings, API requests).

Any Processing outside the scope above requires the Customer's prior written consent.

### 2.3 Duration

This DPA applies for as long as Synapse Processes Customer Personal Data under the Agreement and survives termination to the extent necessary for the return or deletion obligations in [§13](#13-return-and-deletion-on-termination).

### 2.4 Description of the Processing

The nature, purpose, types of Personal Data, and categories of Data Subjects are described in [Annex 1](#annex-1--description-of-the-processing).

## 3. Processor obligations

### 3.1 Documented instructions

Synapse Processes Customer Personal Data only on the Customer's documented instructions (LGPD art. 39, I / GDPR art. 28(3)(a)). The Agreement, the Trust Center, this DPA, and the Customer's use of the Service constitute the Customer's documented instructions. Synapse will inform the Customer if it believes an instruction violates Applicable Data Protection Law.

### 3.2 Confidentiality

Synapse ensures that all personnel authorized to Process Customer Personal Data are bound by appropriate confidentiality obligations (**LGPD arts. 46–47** — security and confidentiality duty of all treatment agents — and **GDPR art. 28(3)(b)**). The personnel-security controls (MFA, hardware-key second factors, background checks, annual training, onboarding/offboarding checklists) are documented in [Tenant Isolation §7](/trust/tenant-isolation#7-personnel-security).

### 3.3 Security

Synapse implements the technical and organizational measures described in [Annex 2](#annex-2--technical-and-organizational-measures) to protect Customer Personal Data against unauthorized or unlawful Processing and accidental loss, destruction, damage, alteration, or disclosure (LGPD art. 46 / GDPR art. 32).

### 3.4 Assistance with Data Subject rights

Synapse provides reasonable assistance to the Customer in fulfilling Data Subject requests under LGPD art. 18 and GDPR art. 15–22. The customer-callable [DSR API](/trust/data-retention#3-the-dsr-api) satisfies the deletion and access dimensions; other requests are routed via [privacy@graphorlm.com](mailto:privacy@graphorlm.com).

### 3.5 Assistance with Controller obligations

Synapse provides reasonable assistance to the Customer in complying with its obligations under LGPD art. 38 (DPIA), 46 (security), and 48 (breach notification), and GDPR art. 32–36, taking into account the nature of the Processing and the information available to Synapse.

### 3.6 No use of Customer Personal Data for Synapse's purposes

Synapse does not use Customer Personal Data for purposes other than providing the Service to the Customer. **Synapse does not use Customer Content (a subset of Customer Personal Data) to train AI models — neither Synapse's own models nor any of its Subprocessors' models in the inference chain** — this commitment is documented in [Model Use and Training](/trust/model-use-and-training) and is binding on Synapse under this DPA, with pass-through commitments from each Subprocessor cited in [§4.4](#44-subprocessor-obligations-and-pass-through-clauses). Operational telemetry that is incidentally collected to operate and improve the Service is subject to the Brazilian PII mask described in [Data Retention §4](/trust/data-retention#4-observability-traces) and is never used for AI-model training.

## 4. Subprocessors

### 4.1 General authorization

The Customer authorizes Synapse to engage the Subprocessors listed in [Annex 3](#annex-3--subprocessors-as-of-signature-date) and on the public [Subprocessors page](/trust/subprocessors).

### 4.2 Material changes to the subprocessor list

Synapse notifies the Customer at least **30 days before any material change** to the Subprocessor list takes effect, except where an immediate change is required to remediate an active Security Incident. Notification is delivered by email to the privacy contact on file and by update to the [Subprocessors page](/trust/subprocessors) (subscribe at [subprocessors@graphorlm.com](mailto:subprocessors@graphorlm.com)).

### 4.3 Customer objection

The Customer may object in writing within the 30-day window to a proposed Subprocessor change on reasonable data-protection grounds. If the Parties cannot resolve the objection within 30 days, the Customer may terminate the affected portion of the Agreement without penalty and receive a pro-rated refund of any pre-paid Fees for the unused portion of the Subscription term.

### 4.4 Subprocessor obligations and pass-through clauses

Each Subprocessor is bound by data-protection obligations no less protective than those in this DPA, through Synapse's contractual relationship with the Subprocessor. Synapse incorporates by reference the following upstream commitments and is responsible to the Customer for the Subprocessor's performance under those commitments:

* **AWS** — the [AWS Data Processing Addendum](https://aws.amazon.com/compliance/gdpr-center/) governs the AWS Bedrock processing; incorporating SCCs.
* **OpenAI** — the OpenAI DPA governs embedding processing, **with Zero Data Retention enrolled** for the Synapse production org. Synapse commits to (i) audit ZDR enrollment status at least quarterly via the OpenAI dashboard or written confirmation from OpenAI, (ii) notify the Customer **at least 30 days before any planned ZDR disablement** by Synapse, and (iii) notify the Customer **within 24 hours of becoming aware of an unplanned OpenAI-side disablement** of ZDR for the Synapse production org. ZDR loss triggers the Customer's objection right under [§4.3](#43-customer-objection).
* **Cerebras** — the [Cerebras Terms of Use](https://www.cerebras.ai/terms-of-service) and [Privacy Policy](https://www.cerebras.ai/privacy-policy), including the published no-training and zero-retention commitments.
* **Google Cloud Platform** — the [Google Cloud DPA](https://cloud.google.com/terms/data-processing-addendum) for all Google-Cloud-hosted components.
* **Google Analytics 4** (marketing site only, consent-gated) — the [Google Measurement Controller-Controller Data Protection Terms](https://business.safety.google/adscontrollerterms/), which govern Synapse and Google as **independent controllers** for the analytics relationship (distinct from the Google Cloud DPA above). Loaded only after the visitor grants analytics consent; not loaded on the legal routes.
* **Neo4j AuraDB** — the [Neo4j DPA](https://neo4j.com/legal/data-protection-addendum/) for the managed graph store.
* **Stripe** — the [Stripe DPA](https://stripe.com/legal/dpa) for payment processing.
* **Firebase Authentication** — covered under the Google Cloud DPA above.

If a material change to any upstream Subprocessor commitment occurs (for example, a removal of a no-training clause, a change to the international-transfer regime, or a downgrade of an audit certification), Synapse notifies the Customer within 30 days of becoming aware of the change.

### 4.5 Related-party disclosure

Synapse operates two distinct business lines under the same legal entity (the Graphor SaaS product and Synapse's consultancy practice). The relationship is disclosed on [Subprocessors §8](/trust/subprocessors#8-related-party-disclosure). Where Synapse Consultoria projects consume the Graphor Service for end clients, they do so under this same DPA on terms equivalent to any unrelated third-party customer, with no privileged data path and no preferential subprocessor treatment.

## 5. International transfer of Personal Data

### 5.1 Transfer regime

The Customer authorizes Synapse to transfer Customer Personal Data to the regions described in [Data Residency](/trust/data-residency). For Customer Personal Data subject to LGPD or GDPR, the transfer is conducted under one or more of the safeguards in LGPD art. 33 / GDPR art. 44–49:

* The **Standard Contractual Clauses 2021/914** referenced in [Annex 4](#annex-4--international-transfer-instruments) and incorporated by reference, including the modules required for the relevant transfer scenario (Module 2 for controller-to-processor; Module 3 for processor-to-processor onward transfers to Subprocessors).
* The data protection commitments of each upstream Subprocessor (per [§4.4](#44-subprocessor-obligations-and-pass-through-clauses)).
* The technical and organizational measures in [Annex 2](#annex-2--technical-and-organizational-measures).

### 5.2 Region commitment

Synapse Processes Customer Personal Data in `us-central1` (Iowa, USA) and the US AWS Bedrock regions, as documented in [Data Residency](/trust/data-residency). Synapse notifies the Customer at least 30 days before any change to the primary Processing region takes effect.

## 6. Security

Synapse implements and maintains the technical and organizational measures described in [Annex 2](#annex-2--technical-and-organizational-measures), which include encryption at rest (cloud-provider-managed AES-256; customer-managed encryption keys on enterprise request), encryption in transit (TLS 1.2+), logical tenant isolation, per-project API tokens with TTL and audit, and the operational controls inventoried in [Compliance §3](/trust/compliance#3-compensating-controls-inventory).

The measures will be reviewed periodically and updated as the threat landscape, available technology, and Customer expectations evolve. Synapse does not unilaterally reduce the protections below the level agreed at signature.

## 7. Security Incident notification

Synapse notifies the Customer of a confirmed Security Incident affecting Customer Personal Data **within 72 hours of internal confirmation**, per the procedure documented in [Incident Response](/trust/incident-response). The notification includes the five elements specified in [Incident Response §5](/trust/incident-response#5-what-the-notification-contains): what happened, why it happened, the Customer-specific scope, the response actions, and the Customer-side actions recommended.

Synapse publishes a written post-mortem to the affected Customer within **14 days of internal confirmation**, per [Incident Response §6](/trust/incident-response#6-post-mortem).

The 72-hour SLA is a contractual commitment that meets or exceeds the regulatory floors: under **ANPD Resolução CD/ANPD nº 15/2024, art. 6**, the controller-to-ANPD notification must occur within **3 business days** of incident knowledge; under **GDPR art. 33(2)**, the processor must notify the controller "without undue delay" (no fixed window). The art. 33(1) 72-hour clock binds the controller, not the processor.

## 8. Audit

The Customer may audit Synapse's compliance with this DPA on reasonable prior notice (no less than 30 days, except in connection with a Security Incident) and during normal business hours, subject to reasonable confidentiality and scoping commitments. The audit may take one or more of the following forms:

* Review of Synapse's [Trust Center](/trust/overview) and supporting documentation;
* Review of the most recent Synapse audit report (where one is available — see [Compliance §1](/trust/compliance#1-synapses-own-certification-status));
* Review of the most recent Subprocessor audit reports made available under each Subprocessor's NDA terms;
* A reasonable on-site or remote inquiry conducted by the Customer or a qualified independent auditor at the Customer's expense.

Synapse will respond to enterprise security questionnaires within 10 business days, citing the Trust Center pages above for the answers wherever they apply.

## 9. Cooperation with authorities

If Synapse receives a binding legal request from a competent authority for disclosure of Customer Personal Data (subpoena, court order, regulatory inquiry), Synapse will:

* Notify the Customer of the request to the extent legally permitted, allowing the Customer to seek a protective order or other remedy;
* Where notification is prohibited, take reasonable steps to inform the Customer of the request once the prohibition expires;
* Disclose only the minimum data required to comply with the request.

## 10. Data Protection Impact Assessment

On reasonable request, Synapse provides the Customer with information and documentation reasonably necessary for the Customer to complete a Data Protection Impact Assessment (LGPD art. 38) or a Data Protection Impact Assessment / Article 35 DPIA (GDPR art. 35) for processing involving the Graphor Service. A DPIA template is available on request via [privacy@graphorlm.com](mailto:privacy@graphorlm.com).

## 11. Liability

Each Party's liability under this DPA is subject to the limits set out in the Agreement. Where the Agreement contains a liability cap, that cap applies to this DPA, **except** that the cap does **not** apply to:

* Synapse's indemnification obligations for breach of the no-training commitment in [§3.6](#36-no-use-of-customer-personal-data-for-synapses-purposes);
* Synapse's indemnification of the Customer for the Customer's joint-and-several exposure to Data Subjects under **LGPD art. 42 / GDPR art. 82**, to the extent that exposure cannot be contractually limited under Applicable Data Protection Law as a matter of public policy; or
* Statutory damages, regulatory fines, or other liabilities that cannot be contractually limited under Applicable Data Protection Law.

Data Subjects' statutory rights of action against Synapse and the Customer are governed by LGPD art. 42 (with the conditional solidariedade in § 1º, incisos I and II) and GDPR art. 82 directly, not by this DPA; this section addresses only the allocation of liability between the Parties.

## 12. Conflict between this DPA and the Agreement

If there is a conflict between this DPA and the Agreement on data-protection matters, this DPA prevails. A later-signed data-processing instrument between the Parties prevails over this DPA **only if it expressly references this DPA, identifies the specific provisions it amends, and meets or exceeds the protections herein**.

## 13. Return and deletion on termination

Within 30 days of termination of the Agreement, Synapse, at the Customer's election:

* **Returns** the Customer Personal Data in a structured, commonly used, machine-readable format; or
* **Deletes** the Customer Personal Data per the end-to-end cascade in [Data Retention §2](/trust/data-retention#2-the-delete-cascade), retaining only such copies as are required by Applicable Law (notably Brazilian tax and accounting law for billing records — see [Data Retention §6](/trust/data-retention#6-billing-data)).

Synapse provides written confirmation of the chosen action within 10 business days of completion.

## 14. Term and termination

This DPA enters into force on the date of the last signature below and terminates upon termination of the Agreement. The obligations in [§7](#7-security-incident-notification) (Security Incident notification), [§9](#9-cooperation-with-authorities) (cooperation), and [§13](#13-return-and-deletion-on-termination) (return and deletion) survive termination for the period required to fulfil them.

## 15. Governing law and jurisdiction

This DPA is governed by the laws of the Federative Republic of Brazil. Disputes arising out of or in connection with this DPA are resolved per the arbitration procedure in the Terms of Service ([§12.2](/legal/terms-of-service#122-arbitration)) — binding arbitration conducted in Portuguese, in the city of São Paulo, State of São Paulo, Brazil.

***

## Annex 1 — Description of the processing

(To be completed by the Customer at signature.)

| Item                            | Description                                                                                                                                                                                                                                                                                                                                                                                                             |
| ------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Nature of the Processing**    | Ingestion of Customer Personal Data into the Graphor Service; partitioning, chunking, embedding, indexing, retrieval; provision of question-and-answer and structured-data-extraction services on the Customer's behalf.                                                                                                                                                                                                |
| **Purpose of the Processing**   | \[CAMPO — Customer-stated business purpose, e.g. "Internal knowledge management for legal practice X" / "Customer-support content base for product Y" / "Compliance document analysis for division Z"]                                                                                                                                                                                                                  |
| **Categories of Data Subjects** | \[CAMPO — e.g. "Customer's employees and contractors with Service access" / "Customer's end-clients whose documents are ingested" / "Other identifiable persons appearing in the Customer Content"]                                                                                                                                                                                                                     |
| **Types of Personal Data**      | Account Information, Professional Information, Contact Information, Customer Content (as defined in the Privacy Policy), and any Personal Data the Customer chooses to upload as Customer Content. **Special categories** (LGPD art. 11 / GDPR art. 9): Customer is solely responsible for assessing the lawful basis for any upload of special-category Personal Data and for configuring access controls accordingly. |
| **Duration of the Processing**  | For the term of the Agreement, with the post-termination return-or-delete window in [§13](#13-return-and-deletion-on-termination).                                                                                                                                                                                                                                                                                      |
| **Frequency of transfer**       | Continuous, as the Customer uses the Service.                                                                                                                                                                                                                                                                                                                                                                           |

## Annex 2 — Technical and organizational measures

Synapse implements and maintains the technical and organizational measures listed below. The current state of each control is documented in the Trust Center page cited.

| Control area                   | Measure                                                                                                                                                                                                                                                                                                                                                                                                | Documented at                                                                                                                                                                 |
| ------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Encryption at rest             | Cloud-provider-managed AES-256 by default; customer-managed encryption keys available on enterprise request (typical scoping engagement: 4–8 weeks; may carry an incremental fee)                                                                                                                                                                                                                      | [Trust Center Overview §3](/trust/overview#3-encryption-posture)                                                                                                              |
| Encryption in transit          | TLS 1.2+ enforced on every public surface; managed certificates                                                                                                                                                                                                                                                                                                                                        | [Architecture §5](/trust/architecture#5-public-network-surface)                                                                                                               |
| Logical tenant isolation       | Single-tenant logical model with per-layer (API, database, graph store, storage, observability) project-scoped enforcement                                                                                                                                                                                                                                                                             | [Tenant Isolation §1](/trust/tenant-isolation#1-isolation-by-layer)                                                                                                           |
| Identity and access management | Per-project API tokens with TTL + last-used auditing; tier-aware observability access; Project-scoped Synapse-personnel access                                                                                                                                                                                                                                                                         | [Tenant Isolation §2](/trust/tenant-isolation#2-api-tokens), [Tenant Isolation §6](/trust/tenant-isolation#6-things-that-explicitly-do-happen-at-the-synapse-personnel-layer) |
| AI model governance            | Contractual no-training commitments from every active provider; tier-based provider declaration; verbatim citations                                                                                                                                                                                                                                                                                    | [Model Use and Training](/trust/model-use-and-training)                                                                                                                       |
| Data retention and deletion    | Infinite-until-DELETE posture; end-to-end delete cascade; customer-callable DSR API; bounded TTL on observability traces                                                                                                                                                                                                                                                                               | [Data Retention](/trust/data-retention)                                                                                                                                       |
| Security Incident response     | 72-hour notification SLA; 14-day post-mortem commitment                                                                                                                                                                                                                                                                                                                                                | [Incident Response](/trust/incident-response)                                                                                                                                 |
| Subprocessor management        | Versioned subprocessor list; 30-day prior-notice commitment                                                                                                                                                                                                                                                                                                                                            | [Subprocessors](/trust/subprocessors)                                                                                                                                         |
| Vulnerability management       | Dependency scanning in CI; security advisory monitoring; at least annual patch review. **No third-party penetration test has been performed yet** — compensating controls and roadmap in [Compliance §3](/trust/compliance#3-compensating-controls-inventory) and [Incident Response §9](/trust/incident-response#9-security-research-and-vulnerability-disclosure)                                    | [Incident Response §9](/trust/incident-response#9-security-research-and-vulnerability-disclosure)                                                                             |
| Disaster recovery              | Cloud-provider automated backups + point-in-time recovery (7-day window); restore procedure that preserves customer DSR actions                                                                                                                                                                                                                                                                        | [Data Retention §5](/trust/data-retention#5-backups-and-disaster-recovery)                                                                                                    |
| Audit logging                  | Today: API-token last-used metadata, payment-processor billing events, usage metering, DSR delete confirmations. Activity log API + UI + export are roadmap; ad-hoc queries via privacy@ within 10 business days                                                                                                                                                                                       | [Audit Logs](/trust/audit-logs)                                                                                                                                               |
| Personnel security             | MFA-required identity provider for production access; hardware-key second factors for persistent privileges; least-privilege role assignment reviewed annually and on joiner/mover/leaver; documented onboarding and offboarding checklists; confidentiality undertaking on hire surviving termination; annual privacy and secure-coding training with attestation; background checks per jurisdiction | [Tenant Isolation §7](/trust/tenant-isolation#7-personnel-security)                                                                                                           |

## Annex 3 — Subprocessors as of signature date

The Subprocessors authorized at the effective date of this DPA are the providers listed on the [Subprocessors page](/trust/subprocessors). For the purposes of this DPA, the relevant list is frozen at signature and re-published as part of the executed copy of this DPA.

A material change to this list follows the procedure in [§4.2](#42-material-changes-to-the-subprocessor-list).

Current Subprocessor categories (the full per-provider detail is in the Subprocessors page):

* **Cloud infrastructure** — Google Cloud Platform, Amazon Web Services (Bedrock), Neo4j AuraDB.
* **AI model providers** — Anthropic (via AWS Bedrock), OpenAI (embeddings, ZDR enrolled), Cerebras (chunk enrichment + fast tier, zero retention).
* **Payment** — Stripe.
* **Authentication** — Firebase Authentication.
* **Observability** — Self-hosted Langfuse (tier-aware).
* **Marketing-site analytics** — Google Analytics (consent-gated; marketing site only; not loaded on legal routes).

## Annex 4 — International transfer instruments

Two transfer instruments are incorporated by reference, depending on the Customer's place of establishment. **Both Customers and Synapse should identify the applicable Customer establishment at signature and elect the corresponding instrument in the Customer signature block.**

### Annex 4-A — EU / UK / Swiss Customers: EU Standard Contractual Clauses

For transfers of Customer Personal Data subject to GDPR from the European Economic Area, Switzerland, or the United Kingdom to Synapse's Processing locations (the United States and any other non-adequacy jurisdiction), the Parties incorporate by reference the **Standard Contractual Clauses 2021/914**, as adopted by European Commission Implementing Decision (EU) 2021/914 of 4 June 2021, together with the following Module elections:

* **Module 2** (Controller-to-Processor) applies between the Customer (as data exporter) and Synapse (as data importer) for Customer Personal Data Processed under this DPA.
* **Module 3** (Processor-to-Processor) applies between Synapse (as data exporter) and each Subprocessor (as data importer) for onward transfers of Customer Personal Data, through Synapse's contractual relationship with each Subprocessor.

The SCCs apply with the following clarifications:

* **Clause 7** (Docking Clause): not applicable.
* **Clause 9** (Use of Sub-processors): Option 2 (General written authorization), with the 30-day notice window in [§4.2](#42-material-changes-to-the-subprocessor-list) above.
* **Clause 11** (Redress): the optional first sentence (independent-dispute-resolution-body) is not adopted; redress proceeds under the remaining paragraphs of Clause 11, including the Data Subject's right to lodge complaints with the competent supervisory authority of habitual residence.
* **Clause 17** (Governing Law): the law of the EU Member State in which the data exporter is established; if that Member State's law does not permit third-party-beneficiary rights, the law of **Ireland** applies as the standard commercial fallback.
* **Clause 18** (Choice of Forum and Jurisdiction): the courts of the EU Member State whose law governs under Clause 17.

For the UK extension: the **International Data Transfer Addendum to the EU Commission Standard Contractual Clauses** (UK IDTA, published by the UK ICO) is incorporated by reference and prevails in case of conflict with the SCCs for transfers covered by UK GDPR.

**Scope of the Clause 17 / 18 election.** The Clause 17 governing-law election and Clause 18 choice-of-forum election in Annex 4-A govern disputes arising under the SCCs themselves only. Disputes arising under the body of this DPA (separately from the SCCs) are governed by [§15](#15-governing-law-and-jurisdiction) (Brazilian law; arbitration in São Paulo, Portuguese).

### Annex 4-B — Brazilian Customers (ANPD Standard Contractual Clauses)

For transfers of Customer Personal Data subject to LGPD from a Customer established in the Federative Republic of Brazil to Synapse's Processing locations in the United States, the Parties incorporate by reference the **Cláusulas-Padrão Contratuais para Transferência Internacional de Dados Pessoais** approved by ANPD pursuant to **Resolução CD/ANPD nº 19/2024** (Anexo II). The transfer relies on the hypothesis in **LGPD art. 33, II, b** (standard contractual clauses approved by the national authority).

The Cláusulas-Padrão Contratuais are organized in **Seções I–IV** (Seção I — Informações Gerais; Seção II — Cláusulas Mandatórias; Seção III — Medidas de Segurança; Seção IV — Cláusulas Adicionais e Anexos). The role-allocation election in **Cláusula 4 (Responsabilidades das Partes)** is as follows for this engagement:

* **Opção A** (when at least one party acts as Controlador) applies between the Customer (as Controlador / data exporter) and Synapse (as Operador / data importer) for Customer Personal Data Processed under this DPA — covering the same relationship pattern that the EU SCCs assign to Module 2.
* **Opção B** (Operador-a-Operador) applies between Synapse (as Operador / data exporter) and each Subprocessor (as Operador / data importer) for onward transfers of Customer Personal Data — covering the same relationship pattern that the EU SCCs assign to Module 3.

Seção I (Informações Gerais) identifies Synapse Inovação e Tecnologia LTDA. as the data importer, the Customer (named in the signature block) as the data exporter, the Processing region as `us-central1` (Iowa, USA), and the Subprocessors enumerated in [Annex 3](#annex-3--subprocessors-as-of-signature-date).

Seção III (Medidas de Segurança) cross-references the technical and organizational measures in [Annex 2](#annex-2--technical-and-organizational-measures) of this DPA.

Governing law and forum for disputes arising under the Cláusulas-Padrão Contratuais follow [§15](#15-governing-law-and-jurisdiction) of this DPA (Brazilian law; arbitration in São Paulo). The Cláusulas-Padrão Contratuais do not derogate from the Data Subject's right to file complaints with ANPD or with the consumer-protection authorities of habitual residence.

### Annex 4-C — Customers in jurisdictions other than EU / UK / CH / BR

For Customers established in jurisdictions not addressed by Annex 4-A or Annex 4-B, the Parties will agree on the applicable international-transfer instrument at signature based on the relevant local data-protection law; absent local equivalent, the EU SCCs in Annex 4-A apply as a default safeguard with appropriate jurisdiction adaptations.

A copy of the full SCC text, the UK IDTA, and the ANPD Cláusulas-Padrão Contratuais can be obtained on request from [privacy@graphorlm.com](mailto:privacy@graphorlm.com).

***

## Signature blocks

By signing below, the Parties agree to be bound by this DPA.

### For the Processor

**SYNAPSE INOVAÇÃO E TECNOLOGIA LTDA.**

| Field     | Value                                |
| --------- | ------------------------------------ |
| Name      | \[CAMPO — Authorized signatory name] |
| Title     | \[CAMPO — Signatory title]           |
| Signature | \[CAMPO]                             |
| Date      | \[CAMPO]                             |

### For the Controller

**\[CAMPO — Customer legal name]**

| Field                                                                                                       | Value                                                                                                                                                                                       |
| ----------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Name                                                                                                        | \[CAMPO — Authorized signatory name]                                                                                                                                                        |
| Title                                                                                                       | \[CAMPO — Signatory title]                                                                                                                                                                  |
| Signature                                                                                                   | \[CAMPO]                                                                                                                                                                                    |
| Date                                                                                                        | \[CAMPO]                                                                                                                                                                                    |
| Customer place of establishment                                                                             | \[CAMPO — country / state]                                                                                                                                                                  |
| **International transfer instrument elected** (per [Annex 4](#annex-4--international-transfer-instruments)) | ☐ Annex 4-A (EU / UK / Swiss customer — EU SCCs 2021/914) ☐ Annex 4-B (Brazilian customer — ANPD Cláusulas-Padrão Contratuais Res. 19/2024) ☐ Annex 4-C (Other jurisdiction — to be scoped) |

***

## Change history

| Version | Date       | Change                                                                                                                                                                                                                                                                                                                                                                                                                   |
| ------- | ---------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| 1.0     | 2026-06-21 | Initial publication of the DPA template, incorporating the Trust Center commitments, the no-training clause with pass-through references to upstream Subprocessor DPAs (per [Subprocessors §2](/trust/subprocessors#2-cloud-infrastructure-production) and [§3](/trust/subprocessors#3-ai-model-providers)), Standard Contractual Clauses incorporated by reference, and the 72-hour Security Incident notification SLA. |

## Contact

* DPA inquiries, custom redlines, signature-stage questions: [privacy@graphorlm.com](mailto:privacy@graphorlm.com)
* Subscription to DPA template change notifications: [subprocessors@graphorlm.com](mailto:subprocessors@graphorlm.com)
* Customer support: [support@graphorlm.com](mailto:support@graphorlm.com)
