> For the complete documentation index, see [llms.txt](https://synap.ac/docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://synap.ac/docs/legals/subprocessors-list-and-management-policy.md).

# Subprocessors List & Management Policy

LAST UPDATED: 29th September 2026

This page forms part of Synap's [Data Processing Agreement](https://legal.synap.ac/data-processing-agreement-dpa) (**"DPA"**). It identifies third parties that Synap may use to process **Customer Data** on behalf of a Customer and explains how Synap appoints and manages them.

Terms defined in the DPA have the same meanings here.

## Sub-processor categories

* **Core:** required to provide the Synap platform or standard service communications.
* **Operational Support:** used for routine support, incident response, security work or defect investigation and may receive limited Customer Data where necessary.
* **Optional Feature:** used only when Customer or an Authorised User enables, requests or configures the relevant feature.
* **Customer-Approved Support:** used only for enhanced or ad-hoc support requested or approved by Customer.
* **Account Data Service Providers:** used for Synap's own sales, billing, account management, analytics or administration. These providers are not Sub-processors under the DPA unless they process Customer Data on Customer's behalf.

The authorisation and change-notification rules for each category are set out in Section 7 of the DPA.

## Locations, data residency and transfer safeguards

Locations shown below identify the principal hosting or processing location. A regional hosting selection does not exclude limited ancillary processing elsewhere, including support access, security monitoring, service metadata or transactional email.

The principal AWS and MongoDB workloads are hosted in Ireland for Synap's EU stack and in the United States for its US stack. Backups may be stored or processed in a different availability zone or region for resilience and disaster recovery, but remain within the same selected data-residency boundary (European Union or United States).

Restricted Transfers are governed by Section 13 of the DPA. **DPF** links record a provider's published participation in the applicable Data Privacy Framework. Current status may be checked on the provider's linked statement or the [official US Department of Commerce list](https://www.dataprivacyframework.gov/list). Where the DPF is unavailable or inapplicable, Synap relies on the SCCs, UK Addendum or another lawful Transfer Mechanism.

## Appointment and review procedure

Before appointing a Sub-processor, Synap assesses the provider in proportion to the nature and risk of the processing, including:

1. the processing purpose and categories, sensitivity and volume of Customer Data;
2. legal identity, relevant locations, retention and deletion arrangements;
3. technical and organisational security measures and independent assurance;
4. Restricted Transfer and onward-transfer safeguards;
5. use of further Sub-processors; and
6. incident response, service continuity and exit arrangements.

Sub-processors must be bound by written data-protection and confidentiality obligations consistent with the DPA and applicable law. Synap reviews its Sub-processors at least annually and following material risk, service or legal developments.

## Core Sub-processors

| Provider                                                        | Purpose and Customer Data                                                                                                                            | Principal location / regional behaviour                                                                                                                                                                                                                      | Transfer safeguards and information                                                                                                                                                                                                                           |
| --------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Amazon Web Services (AWS)** — relevant AWS contracting entity | Cloud infrastructure, storage, networking and security services supporting the Synap platform; Customer Data stored in the Customer's assigned stack | EU stack: EU (Ireland). US stack: United States. Regional storage does not exclude limited global support or service metadata processing described in AWS terms                                                                                              | [AWS DPA](https://d1.awsstatic.com/legal/aws-gdpr/AWS_GDPR_DPA.pdf); [AWS DPF statement](https://aws.amazon.com/compliance/eu-us-data-privacy-framework/) (AWS is covered under Amazon.com, Inc.'s certification); SCCs or other DPA mechanism where required |
| **MongoDB** — relevant MongoDB contracting entity               | Managed database services containing platform account, assessment and results data supplied through the Services                                     | Primary database processing is in the same region as the Customer's Synap stack: EU or US. Backups may use a different availability zone or region for resilience and disaster recovery, while remaining within the same selected legal hosting jurisdiction | [MongoDB DPA](https://www.mongodb.com/legal/data-processing-agreement); [MongoDB DPF statement](https://www.mongodb.com/legal/data-privacy-framework-statement); SCCs or other DPA mechanism where required                                                   |
| **Twilio / SendGrid** — relevant Twilio contracting entity      | Delivery of transactional service emails, including recipient address, message content and delivery metadata                                         | United States and other locations described by Twilio; this service is not part of Synap's primary EU/US data-residency boundary                                                                                                                             | [Twilio DPA](https://www.twilio.com/en-us/legal/data-protection-addendum); [Twilio DPF information](https://www.twilio.com/en-us/legal/privacy); SCCs/BCRs or other DPA mechanism where required                                                              |
| **Datadog** — relevant Datadog contracting entity               | Service telemetry, logs, performance and security monitoring. Synap seeks to minimise Customer content and sensitive data in logs                    | Current Synap service processing is in the United States; provider personnel and sub-processors may operate in other disclosed locations                                                                                                                     | [Datadog DPA](https://www.datadoghq.com/legal/data-processing-addendum/); [Datadog privacy and DPF information](https://www.datadoghq.com/legal/privacy/); SCCs or other DPA mechanism where required                                                         |

## Operational Support Sub-processors

These providers may receive limited Customer Data where necessary for support, security, incident response or defect investigation. Data is limited where practicable to pseudonymous identifiers, technical metadata, logs, support communications and relevant bug-report extracts. Exam content or responses, proctoring recordings, identity documents, biometric data, authentication credentials and special-category data must not be included unless specifically necessary, risk-assessed and handled through an approved process.

| Provider                                                                | Operational purpose and Customer Data                                                                                                                                                                                                                  | Principal location / regional behaviour                                                                                                                                                   | Transfer safeguards and information                                                                                                                                                                                                                                                |
| ----------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Slack** — relevant Slack Technologies / Salesforce contracting entity | Internal support, incident, security and engineering communications. May contain pseudonymous Customer or user identifiers, technical metadata, limited logs and support extracts                                                                      | United States and other locations described by Slack. Certain data-residency options may apply to data at rest but do not necessarily cover all metadata, support or ancillary processing | [Slack DPA](https://slack.com/terms-of-service/data-processing); [Slack GDPR, SCC and DPF information](https://slack.com/trust/compliance/gdpr); SCCs or other DPA mechanism where required                                                                                        |
| **GitHub, Inc.**                                                        | Private source-code hosting, issue management, security work and software delivery. Issues or private repositories may contain limited pseudonymous identifiers, technical metadata or bug-report extracts necessary to reproduce and resolve a defect | United States and other locations described by GitHub; product-specific data-location options apply only where selected and documented                                                    | [GitHub Data Protection Agreement](https://github.com/customer-terms/github-data-protection-agreement); [GitHub privacy and DPF information](https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement); SCCs or other DPA mechanism where required |
| **Shortcut Software Company**                                           | Engineering project and defect management. Tickets may contain limited pseudonymous Customer or user identifiers, technical metadata, logs and bug-report extracts                                                                                     | United States                                                                                                                                                                             | [Shortcut GDPR and DPF notice](https://www.shortcut.com/gdpr-privacy/); [Shortcut security information](https://www.shortcut.com/security/); SCCs or other DPA mechanism where required                                                                                            |

## Optional Feature Sub-processors

These providers receive Customer Data only if the relevant feature is affirmatively enabled, requested or configured.

| Provider                                                          | Optional feature and Customer Data                                                                                                                                                                                                                                        | Principal location / regional behaviour                                                                                                            | Transfer safeguards and information                                                                                                                                                                                                                                                             |
| ----------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Rosalyn Inc.**                                                  | Live and AI-assisted proctoring; candidate identity, exam-session, video/audio and proctoring data as configured                                                                                                                                                          | United States                                                                                                                                      | [Rosalyn Trust Center and privacy information](https://www.rosalyn.ai/trust-center); contractual safeguards and SCCs or other DPA mechanism where required                                                                                                                                      |
| **RunPod**                                                        | AI Review inference on Synoptic webcam recordings and associated technical data                                                                                                                                                                                           | EU for EU-hosted Customers; US for US-hosted Customers. EU-hosted footage remains in the EU during inference under Synap's current configuration   | [RunPod DPA](https://www.runpod.io/legal/data-processing-agreement); [RunPod Trust Center](https://trust.runpod.io/); SCCs or other DPA mechanism where required                                                                                                                                |
| **Stripe** — relevant Stripe contracting entity                   | Stripe Identity candidate identity verification, including identity-document images and fields, selfie/video, liveness and verification outputs. Synap may retain images and results according to the configured workflow and retention settings                          | Processing locations depend on the Stripe service and terms; the feature is not represented as EU-only                                             | [Stripe DPA](https://stripe.com/legal/dpa); [Stripe DPF policy](https://stripe.com/legal/data-privacy-framework); SCCs or other DPA mechanism where required                                                                                                                                    |
| **Entrust (Onfido)** — relevant Entrust/Onfido contracting entity | Candidate identity and document verification, including identity-document images and fields, selfie/video, facial-similarity, liveness and verification or fraud outputs. Synap may retain images and results according to the configured workflow and retention settings | EU or US according to the configured regional endpoint; regional selection and ancillary processing remain subject to the applicable Entrust terms | [Entrust Identity Verification Services Agreement](https://www.entrust.com/legal-compliance/terms-conditions/idv/services-agreement); [Entrust product privacy information](https://www.entrust.com/legal-compliance/product-privacy); SCCs or another lawful Transfer Mechanism where required |

## Customer-Approved Support Sub-processors

These providers receive only the Customer Data reasonably necessary for an enhanced exam-support, supervision or troubleshooting activity requested or approved by Customer.

| Provider           | Purpose and data                                                                                                                            | Principal location / regional behaviour                                                                         | Transfer safeguards and information                                                                                                                                                              |
| ------------------ | ------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| **Intercom**       | Customer-approved communications and support case management; only the Customer Data needed for the case                                    | United States / provider's disclosed locations                                                                  | [Intercom DPA](https://www.intercom.com/legal/dpa); [Intercom DPF notice](https://www.intercom.com/legal/data-privacy-framework-notice); SCCs or other DPA mechanism where required              |
| **Twilio Segment** | Customer-approved diagnostic data routing and synchronisation for a support activity                                                        | EU data centre where configured; limited processing may occur in the United States or other disclosed locations | [Twilio DPA](https://www.twilio.com/en-us/legal/data-protection-addendum); [Twilio DPF information](https://www.twilio.com/en-us/legal/privacy); SCCs/BCRs or other DPA mechanism where required |
| **FullStory**      | Customer-approved session capture or replay used to diagnose an issue involving an Authorised User; configured to minimise captured content | United States / provider's disclosed locations                                                                  | [FullStory DPA](https://www.fullstory.com/legal/dpa/); [FullStory DPF information](https://www.fullstory.com/legal/privacy-policy/); SCCs or other DPA mechanism where required                  |

Customer may specifically approve another provider for a particular support activity after receiving the relevant processing information.

## Account Data Service Providers

These providers process Account Data for Synap's business and administrative purposes. Synap acts as Controller for that processing. If a provider processes Customer Data on Customer's behalf, it will instead be treated as a Sub-processor for that processing.

| Provider           | Ordinary business purpose                                                              | Location / privacy information                                                                                                                                                                             |
| ------------------ | -------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Intercom**       | Account communications, customer success and ordinary support                          | US / global; [DPA](https://www.intercom.com/legal/dpa), [DPF notice](https://www.intercom.com/legal/data-privacy-framework-notice)                                                                         |
| **Vitally**        | Customer-success management, onboarding and training administration                    | United States; [privacy information](https://vitally.io/legal/privacy)                                                                                                                                     |
| **Attio**          | Customer-relationship management and account administration                            | United States; [DPA](https://attio.com/legal/attio-data-processing-addendum), [privacy information](https://attio.com/legal/privacy)                                                                       |
| **Twilio Segment** | Routing and synchronisation of Account Data between Synap's business systems           | EU data centre where configured, with other disclosed processing; [Twilio DPA](https://www.twilio.com/en-us/legal/data-protection-addendum), [DPF information](https://www.twilio.com/en-us/legal/privacy) |
| **Calendly**       | Meeting scheduling for sales, training, support and account management                 | United States / global; [Calendly privacy and DPF notice](https://calendly.com/legal/privacy-notice)                                                                                                       |
| **Stripe**         | Payment processing for Synap Customers                                                 | Global; [Stripe DPA](https://stripe.com/legal/dpa), [DPF policy](https://stripe.com/legal/data-privacy-framework)                                                                                          |
| **GoCardless**     | Direct Debit payment processing                                                        | United Kingdom / provider's disclosed locations; [privacy information](https://gocardless.com/privacy/)                                                                                                    |
| **Chargebee**      | Subscription management, invoicing and receipts                                        | United States / global; [privacy and DPF information](https://www.chargebee.com/privacy/)                                                                                                                  |
| **Mixpanel**       | Product analytics concerning logged-in Authorised Users                                | US by default or EU where configured; [Mixpanel DPA and DPF information](https://mixpanel.com/legal/dpa/)                                                                                                  |
| **FullStory**      | Session analytics concerning Authorised Users and diagnosis of common interface issues | United States / provider's disclosed locations; [DPA](https://www.fullstory.com/legal/dpa/), [DPF information](https://www.fullstory.com/legal/privacy-policy/)                                            |

## Affiliates

Synap currently has no Affiliates that process Customer Data. Any future Affiliate acting as a Sub-processor will be listed here and appointed under Section 7 of the DPA.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://synap.ac/docs/legals/subprocessors-list-and-management-policy.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
