Légal
Data Processing Agreement (DPA)
Preamble
This Data Processing Agreement ("DPA") applies to accounting firms using SynkriaOps to maintain accounting for their SME clients. In this context:
- The accounting firm is qualified as the data controller of its clients' accounting data;
- SynkriaOps is qualified as a processor within the meaning of GDPR article 28.
This DPA governs the firm ↔ SynkriaOps relationship. The firm ↔ SME client relationship remains governed by the firm's own accounting engagement agreement.
1. Purpose of processing
SynkriaOps processes accounting, tax, and counterparty data of the firm's SME clients, exclusively on behalf of the firm, for the purposes of:
- Maintenance of accounting in SYSCOHADA revised 2019 format;
- Production of regulatory financial statements;
- Generation of FEC exports for tax controls;
- Reconciliation, bank reconciliation, Mobile Money import;
- Firm billing of its clients (optional module).
2. Data categories processed
- Counterparty identification (name, NIU, address, email, phone);
- Accounting data (vouchers, entries, XAF amounts);
- Imported documents (PDF invoices, bank statements, Mobile Money exports);
- Mobile Money identifiers (phone numbers, merchant codes) encrypted.
3. Data subject categories
- Employees and legal representatives of SME clients;
- Commercial counterparties of SMEs (clients, suppliers, employees);
- Firm staff with tenant access.
4. Duration of processing
Throughout the duration of the commercial agreement between the firm and SynkriaOps. At the end, data is retained for 10 years according to SYSCOHADA art. 24, then deleted (except portability request or specific legal obligation).
5. SynkriaOps obligations as processor
- Process data only on documented instructions from the firm;
- Guarantee confidentiality (contractual commitment from employees and subprocessors);
- Take all technical and organizational measures required by GDPR article 32 (encryption, audit trail, PostgreSQL RLS, PITR backups);
- Notify any data breach within 48 hours of its discovery;
- Assist the firm in responding to data subject rights requests;
- Make available all information necessary to demonstrate compliance;
- Allow audits to be carried out (30-day notice, costs borne by the firm except in case of proven failure).
6. Subprocessors
SynkriaOps uses the subprocessors listed in the Privacy Policy (section 6). Any change is notified to the firm 30 days before entry into force, with the possibility to object in writing (contract termination possible in case of objection).
7. Transfers outside the EU
Some subprocessors are located outside the EU (Neon, Cloudflare, Resend, Anthropic, Sentry, all in the United States). Transfers are governed by Standard Contractual Clauses of the European Commission (decision 2021/914), complemented by additional measures (encryption at rest and in transit, audit trail, strict tenant isolation).
8. Security
SynkriaOps implements the technical and organizational measures described in the Privacy Policy (section 8). Firm-specific measures:
- Strict tenant isolation via PostgreSQL Row Level Security (one tenant can never see another);
- Dedicated audit trail on firm actions (tenant creation/modification, role assignment, cross-tenant access);
- Enhanced authentication available (2FA) for firm accounts.
9. Return and deletion at end of contract
At the end of the commercial relationship between the firm and SynkriaOps:
- The firm can download a complete export of each tenant (Excel + JSON + PDFs) for 90 days after end-of-contract notification;
- After this period, data is deleted unless explicit retention is requested under SYSCOHADA art. 24 legal obligations (10 years).
10. DPO contact
For any question relating to this DPA or data protection:
[email protected]