Legal

Data Processing Addendum

Effective date: 23 July 2026

How we process your end-users' personal data as your processor — our obligations, sub-processors, transfer safeguards, and breach and deletion commitments.

Draft for review. This document reflects how Zynth Auth actually operates and the frameworks it aligns to, but it is not legal advice and has not yet been reviewed by counsel. Terms are subject to change before general availability.

This DPA governs our processing of personal data on your behalf. It complements our Terms of Service and Privacy Policy.

1. Roles and scope

This Data Processing Addendum ("DPA") forms part of the agreement between you (the "Controller") and Zynth Media (the "Processor") for Zynth Auth. It applies where we process personal data of your end-users on your behalf — the identities, credentials, and access records your organization manages in the platform.

You determine the purposes and means of that processing; we process it only to provide the Service and on your documented instructions, including as configured through the product.

2. Nature of processing

  • Subject matter: identity and access management for your end-users and agents.
  • Duration: for the term of your use of the Service.
  • Categories of data subject: your workforce, customers, and machine/agent identities.
  • Categories of personal data: identifiers (email, name), authentication data (hashed credentials, MFA/passkey material), and access/security event logs.

3. Our obligations as processor

  • Process personal data only on your documented instructions, including for international transfers.
  • Ensure personnel authorized to process the data are bound by confidentiality.
  • Implement appropriate technical and organizational security measures (see below).
  • Assist you, taking into account the nature of processing, in responding to data-subject requests and in meeting your security, breach-notification, and impact-assessment obligations.
  • Delete or return personal data at the end of the engagement, as described below.
  • Make available information necessary to demonstrate compliance and allow for reasonable audits.

4. Security measures

We maintain a defense-in-depth security program: encryption in transit and at rest; tenant isolation enforced at the database with row-level security; Argon2id password hashing; least-privilege database roles; a tamper-evident, hash-chained audit log; egress network controls; and a signed, digest-pinned software supply chain. The Service is designed to fail closed. These measures are described further in our Privacy Policy and Trust Centre.

5. Sub-processors

You provide a general authorization for us to engage the sub-processors below to help deliver the Service. Each is bound by data-protection terms consistent with this DPA. We will give notice of any intended addition or replacement so you may object on reasonable data-protection grounds.

Sub-processorPurposeLocation
DigitalOceanCloud hosting & infrastructure for the managed offeringSingapore (APAC region)
ResendTransactional email (verification, password reset, invitations)United States
PayPalPayment processing for paid plans (card data never touches our systems)United States
Google (used only if enabled)Social sign-in — only when an end-user chooses to authenticate with GoogleUnited States
GitHub (used only if enabled)Social sign-in — only when an end-user chooses to authenticate with GitHubUnited States
Fireworks AI (used only if enabled)AI assistant for the documentation site (not part of the core auth data path)United States

6. International transfers

The managed offering is hosted in Singapore (APAC). Where a sub-processor processes personal data outside your region, we rely on appropriate transfer safeguards, such as standard contractual clauses. If you self-host, personal data remains within your own infrastructure and no transfer to us occurs.

7. Data-subject requests

The platform provides built-in tools — the Privacy & Data centre — for access, export, rectification, and erasure of end-user data, so you can respond to data-subject requests directly. Where you need additional assistance, we will provide it taking into account the nature of the processing.

8. Personal data breaches

We will notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information reasonably available to help you meet your own notification obligations. The platform's detection and audit spine is designed to surface such events quickly.

9. Deletion and return

On termination, and at your choice, we will delete or return the personal data we process on your behalf, and delete existing copies unless retention is required by law. For self-hosted deployments, deletion is under your control.

10. Contact

For any question about this DPA or to raise a data-protection matter, contact security@zynthmedia.com.

Questions about this document? Contact sales@zynthmedia.com. See all legal documents.