> For the complete documentation index, see [llms.txt](https://legal.synap.ac/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://legal.synap.ac/data-processing-agreement-dpa.md).

# Data Processing Agreement (DPA)

LAST UPDATED: 29th September 2026

This Data Processing Addendum, including its schedules and the Standard Contractual Clauses ("DPA"), is made by and between Synap Learning Limited, a private limited company registered in England & Wales ("Synap"), and the customer identified in the applicable Agreement ("Customer"), pursuant to Synap's Terms of Service and/or another written or electronic agreement between the parties ("Agreement").

This DPA forms part of the Agreement and governs Synap's processing of Personal Data under the Agreement.

### **1. Definitions.**

Any capitalized term used but not defined in this DPA has the meaning provided in the Agreement.

i. **"Account Data"** means Personal Data relating to Customer's commercial and administrative relationship with Synap, including the names and business contact details of Customer personnel and Authorised Users, account administration and authentication information, billing information, support communications, and security and service-usage records. Account Data does not include Customer Data merely because the same individual appears in both datasets.

ii. **"Affiliate"** means any entity that controls, is controlled by, or is under common control with an entity, where "control" means ownership of, or the right to control, more than 50% of the voting securities of that entity.

iii. **"Applicable Data Protection Legislation"** means the privacy and data-protection laws applicable to the relevant processing under the Agreement, including, where applicable, the GDPR, UK GDPR and Data Protection Act 2018, Swiss Federal Act on Data Protection, California Consumer Privacy Act, Australian Privacy Act 1988, Thailand Personal Data Protection Act and South Africa's Protection of Personal Information Act, in each case as amended, superseded or replaced.

iv. **"Authorised User"** means a person Customer authorises to access or administer the Services.

v. **"Controller"** means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of processing Personal Data.

vi. **"Customer Data"** means Personal Data processed by Synap as a Processor on behalf of Customer in connection with the Services.

vii. **"End User"** means an individual who accesses or uses the Services under Customer's account, including a candidate, learner, employee, marker, proctor, educator, manager or sub-administrator.

viii. **"Data Privacy Framework"** or **"DPF"** means, as applicable to a particular transfer, the EU–US Data Privacy Framework, the UK Extension to the EU–US Data Privacy Framework or the Swiss–US Data Privacy Framework administered by the United States Department of Commerce, in each case as amended, replaced or superseded.

ix. **"Europe"** means the European Economic Area ("EEA"), United Kingdom ("UK") and Switzerland.

x. **"GDPR"** means Regulation (EU) 2016/679.

xi. **"Personal Data"** means any information relating to an identified or identifiable natural person, or any equivalent concept defined by Applicable Data Protection Legislation.

xii. **"Personal Data Breach"** means a breach of security leading to the accidental or unlawful destruction, loss, alteration or unauthorised disclosure of, or access to, Customer Data. It excludes an unsuccessful attempt that does not compromise Customer Data.

xiii. **"Privacy Policy"** means Synap's then-current privacy policy for the Services, available at <https://legal.synap.ac/privacy-policy>.

xiv. **"Processor"** means an entity which processes Personal Data on behalf of a Controller.

xv. **"Processing"**, **"Process"** and **"processed"** have the meanings given to them by Applicable Data Protection Legislation.

xvi. **"Restricted Transfer"** means a transfer of Personal Data for which Applicable Data Protection Legislation requires an adequacy decision, appropriate safeguards or another lawful Transfer Mechanism.

xvii. **"Standard Contractual Clauses"** or **"SCCs"** means: (a) for the GDPR, the standard contractual clauses in the Annex to European Commission Implementing Decision (EU) 2021/914 ("EU SCCs"); (b) for the UK GDPR, the EU SCCs together with the International Data Transfer Addendum issued by the Information Commissioner's Office under section 119A of the Data Protection Act 2018 ("UK Addendum"); and (c) for the Swiss Federal Act on Data Protection, the EU SCCs as recognised and adapted for Switzerland, in each case as updated, amended or replaced.

xviii. **"Sub-processor"** means a third-party Processor engaged by Synap or a Synap Affiliate to process Customer Data in connection with the Services. It excludes Synap personnel acting under Synap's authority.

xix. **"Third Party Request"** means a request, correspondence, inquiry or complaint from a data subject, regulatory authority or other third party.

xx. **"Transfer Mechanism"** means an adequacy decision or regulation, an applicable DPF, the SCCs, approved binding corporate rules, or another mechanism lawfully permitting a Restricted Transfer under Applicable Data Protection Legislation.

### **2. Applicability and Scope.**

i. Applicability. This DPA applies to Synap's processing of Customer Data on behalf of Customer and, where expressly stated, to Account Data for which Synap acts as an independent Controller.

ii. Scope. The subject matter of the data processing is the provision of the Services, and the processing will be carried out for the duration of the Agreement. Schedule 1 (Details of Processing) sets out the nature and purpose of the processing, the types of Personal Data Synap processes and the categories of data subjects whose Personal Data is processed.

iii. Synap as a Processor. The parties acknowledge and agree that regarding the processing of Customer Data, Customer may act either as a controller or processor and Synap is a processor. Synap will process Customer Data in accordance with Customer’s instructions as set forth in Section 3 (Customer Instructions).

iv. Synap as a Controller of Account Data. The parties acknowledge that, regarding the processing of Account Data, Customer is a controller and Synap is an independent controller, not a joint controller with Customer. Synap will process Account Data as a controller to: (a) manage the commercial and administrative relationship with Customer; (b) operate, support and improve the Services; (c) authenticate Authorised Users and detect, prevent or investigate security incidents, fraud and misuse; (d) comply with Synap's legal or regulatory obligations; and (e) otherwise act as described in the Privacy Policy and permitted by Applicable Data Protection Legislation.

### **3. Synap as a Processor – Processing Customer Data.**

**i. Customer Instructions.** Customer appoints Synap to process Customer Data only on Customer's documented instructions: (a) as set out in the Agreement and this DPA and as necessary to provide, secure and support the Services; (b) as otherwise agreed in writing; and (c) through Customer's and its Authorised Users' use and configuration of the Services (the **"Permitted Purposes"**). These instructions include applicable international transfers. If applicable law requires other processing, Synap will inform Customer before processing unless legally prohibited from doing so.

**ii. Lawfulness of Instructions.** Customer will ensure that its instructions and use of the Services comply with applicable law and do not cause Synap to breach Applicable Data Protection Legislation. Synap will inform Customer if it reasonably believes an instruction infringes applicable law.

**iii. Additional Instructions.** Instructions outside the Agreement or this DPA must be agreed in writing, including by email or another agreed electronic channel.

**iv. Minors.** Where Customer uses the Services for individuals who are minors under applicable law, Customer will comply with applicable requirements concerning data protection, biometric data and parental or guardian rights.

### **4. Purpose Limitation.**

Synap will process Customer Data only for the Permitted Purposes and as described in Schedule 1.

### **5. Compliance.**

Customer shall be responsible for ensuring that:

a) all such notices have been given, and all such authorizations have been obtained, as required under Applicable Data Protection Legislation, for Synap (and its Affiliates and Sub-processors) to process Customer Data as contemplated by the Agreement and this DPA;

b) it has complied, and will continue to comply, with all applicable laws relating to privacy and data protection, including Applicable Data Protection Legislation; and

c) it has, and will continue to have, the right to transfer, or provide access to, Customer Data to Synap for processing in accordance with the terms of the Agreement and this DPA.

### **6. Confidentiality.**

Synap will ensure that persons authorised to process Customer Data are subject to contractual or statutory confidentiality obligations and process it only as authorised.

### **7. Sub-processors.**

#### i. Sub-processor register and authorisation

The [Subprocessors List & Management Policy](https://legal.synap.ac/subprocessors-list-and-management-policy) (the **"Sub-processor Page"**) is incorporated into this DPA by reference. It identifies Synap's Sub-processors, their category, processing purpose, relevant locations and safeguards.

Customer gives Synap general written authorisation to engage the Core and Operational Support Sub-processors listed on the Sub-processor Page as at the effective date of the Agreement, and to add or replace them in accordance with paragraph iii. A Customer request or approval for an activity using a Customer-Approved Support Sub-processor constitutes a documented instruction to use that provider for the activity.

Providers that process only Account Data for Synap's own business and administrative purposes are not Sub-processors under this DPA. If such a provider processes Customer Data on Customer's behalf, it will be treated as a Sub-processor for that processing.

#### ii. Optional Feature Sub-processors

An **"Optional Feature Sub-processor"** is used only where Customer or an Authorised User affirmatively enables, requests or configures the relevant optional feature. Synap will make available the provider's identity, processing purpose, principal categories of Customer Data, relevant processing locations and applicable transfer safeguards before or when the feature is enabled.

Customer's affirmative enablement, request or configuration of the feature constitutes specific written authorisation, given electronically, for Synap to engage the identified Optional Feature Sub-processor. Synap is not required to notify Customers that have not enabled the feature when an Optional Feature Sub-processor is added to the Sub-processor Page.

Where Customer has already enabled an optional feature, Synap will obtain specific authorisation for a replacement or additional provider, or follow paragraph iii, before that provider processes Customer Data.

#### iii. Contractual safeguards, notice and objection

a. Synap will bind each Sub-processor by written obligations providing at least the level of data protection required of Synap under this DPA, to the extent applicable to the services performed. Synap remains responsible for its Sub-processors as required by Applicable Data Protection Legislation.

b. Except where paragraph ii permits specific authorisation, Synap will give Customer at least thirty (30) calendar days' prior notice before a new or replacement Sub-processor begins processing Customer Data. Notice will be sent to the Account Owner email address recorded in Customer's Synap portal. If an immediate change is reasonably necessary to address a security incident, legal or regulatory requirement, or provider service discontinuation, Synap will give as much advance notice as reasonably practicable and explain the shorter period.

c. Customer may object during the applicable notice period on reasonable grounds relating to the protection of Customer Data. The parties will work in good faith to address the objection, including by considering a commercially reasonable alternative. If no reasonable resolution is available, Customer may stop using the affected feature or terminate the affected Services without an early-termination charge before the new Sub-processor begins processing Customer Data.

### **8. Impact Assessments and Consultations.**

Synap shall, to the extent required by Applicable Data Protection Legislation, provide Customer with reasonable assistance (at Customer's cost and expense) with data protection impact assessments or prior consultations with data protection authorities that Customer is required to carry out under such legislation.

### **9. Security.**

i. Synap has in place and will maintain throughout the term of this Agreement appropriate technical and organizational measures designed to protect Customer Data against Personal Data Breaches.

ii. These measures shall at a minimum comply with applicable law and include the measures identified in Schedule 2 (Technical and Organizational Security Measures).

iii. Synap may update the security measures to reflect technical and operational developments, provided that the overall security of the Services is not materially reduced.

iv. Upon becoming aware of a Personal Data Breach involving Customer Data processed by Synap on behalf of Customer under this DPA, Synap will notify Customer without undue delay. To the extent known and reasonably available, the notification will describe the nature of the breach, the categories and approximate numbers of affected data subjects and records, the likely consequences, the measures taken or proposed to address and mitigate it, and a contact point for further information. Synap may provide this information in phases without undue further delay as its investigation progresses and will provide reasonable cooperation to enable Customer to meet its notification obligations under Applicable Data Protection Legislation.

v. Synap's notification of or response to a Personal Data Breach shall not be construed as an acknowledgement by Synap of any fault or liability with respect to the Personal Data Breach.

vi. Customer is responsible for: (a) configuring and using the Services in a manner appropriate to the risks associated with Customer Data; (b) securing the authentication credentials, systems and devices it uses to access the Services; and (c) maintaining copies of Customer Data that the Services make available for export where Customer's own continuity or record-retention requirements require such copies. This paragraph does not reduce Synap's security, availability, backup, return or deletion obligations under the Agreement or this DPA.

### **10. Return or Deletion of Customer Data.**

During the term, Customer may use the available Service functionality to export or delete Customer Data. On termination or expiry of the Agreement, Synap will, at Customer's election, return or delete Customer Data in its possession or control without undue delay and no later than thirty (30) days after termination or expiry, unless applicable law requires retention.

Deletion from active systems will be completed within that period. Residual copies in encrypted backups will be placed beyond ordinary use, protected from further processing and overwritten in accordance with Synap's documented backup-rotation schedule, ordinarily within ninety (90) days, unless applicable law requires longer retention. If Synap retains Customer Data because the law requires it, Synap will isolate and protect that data and process it only for the legally required purpose.

### **11. Audits.**

i. Synap will make available to Customer the information reasonably necessary to demonstrate compliance with this DPA and the obligations applicable to processors under Applicable Data Protection Legislation. Synap may satisfy this obligation in the first instance through current independent audit reports, certifications, security documentation and responses to reasonable due-diligence questions.

ii. Where that information is not reasonably sufficient, Customer may conduct an audit itself or through an independent auditor bound by confidentiality. Customer must give reasonable advance notice, conduct the audit during normal UK business hours, limit it to systems and records relevant to Customer Data, and avoid unnecessary disruption or access to another customer's data. Ordinarily, Customer may exercise this audit right once in any twelve-month period.

iii. The frequency limit in paragraph ii does not apply where an audit is reasonably required following a Personal Data Breach affecting Customer Data, a reasonable and documented concern that Synap is materially failing to comply with this DPA, or a request or instruction from a competent supervisory authority.

iv. Customer will bear its own audit costs and Synap's reasonable costs of providing assistance beyond the information described in paragraph i. Synap will bear its own reasonable costs where an audit identifies material non-compliance by Synap. Nothing in this Section limits a competent supervisory authority's powers.

### **12. International Transfers and Data Residency.**

**i. Hosting region.** The hosting region agreed with Customer is the primary location of Customer's application database and stored files. Synap will not move them to a different hosting region without Customer's agreement. Limited processing elsewhere may occur for support, security, communications or other ancillary services, or through a Sub-processor listed on the Sub-processor Page, subject to this DPA and an applicable Transfer Mechanism.

**ii. Transparency.** The Sub-processor Page identifies relevant processing locations and optional services. Customer is responsible for selecting a hosting region and configuration appropriate to its requirements.

**iii. Order of Transfer Mechanisms.** Where more than one Transfer Mechanism is available for a Restricted Transfer, the following order applies:

a. an applicable adequacy decision or regulation, including an applicable DPF;

b. the applicable SCCs, including the UK Addendum or Swiss adaptations;

c. approved binding corporate rules or another recognised Transfer Mechanism; and

d. where legally available and appropriate, a statutory exception or derogation.

Synap may maintain an additional Transfer Mechanism as a fallback. If the primary mechanism ceases to be valid or applicable, Synap will apply the next available mechanism before continuing the affected Restricted Transfer.

**iv. Data Privacy Framework.** Synap may rely on an applicable DPF for a transfer to a United States recipient while the recipient's active certification covers the relevant framework and data. Synap will periodically verify certification status and use another valid Transfer Mechanism if the DPF is unavailable or inapplicable.

**v. EU SCCs.** Where a Restricted Transfer governed by the GDPR is not covered by an applicable adequacy decision or DPF, the EU SCCs are incorporated into this DPA and completed as follows:

a. Module One applies where Customer transfers Account Data to Synap and each party acts as an independent Controller for that data.

b. Module Two applies where Customer is a Controller and Synap is a Processor.&#x20;

c. Module Three applies where Customer is a Processor and Synap is a Sub-processor.

d. Clause 7 applies; in Clause 9, Option 2 applies and the notice period is the period stated in Section 7; and the optional wording in Clause 11 does not apply.

e. For Modules One, Two and Three, Option 1 in Clause 17 applies and the EU SCCs are governed by Irish law. Under Clause 18(b), the courts of Ireland have jurisdiction. This applies only to the EU SCCs and does not alter the governing law of the Agreement.

f. Annex I is completed by Schedule 1, Annex II by Schedule 2 and, for Modules Two and Three, Annex III by Schedule 3.

**vi. UK transfers.** Where a Restricted Transfer governed by the UK GDPR is not covered by applicable UK adequacy regulations, the EU SCCs completed under paragraph v apply with the UK Addendum in Schedule 4.

**vii. Swiss transfers.** Where a Restricted Transfer governed by the Swiss Federal Act on Data Protection is not covered by an applicable adequacy decision or the Swiss–US DPF, the EU SCCs apply with the adaptations required by Swiss law. The competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner, and data subjects in Switzerland may bring proceedings in Switzerland.

**viii. Changes and successor frameworks.** If a Transfer Mechanism is amended, replaced, superseded, invalidated or no longer available, its lawful successor will apply automatically where permitted. Otherwise, Synap may implement a lawful replacement on reasonable notice, provided that the protection required by Applicable Data Protection Legislation is not reduced. The parties will execute any documentation reasonably required to give effect to it.

### **13. Co-operation and Data Subject Rights.**

**i. Data subject requests.** Taking into account the nature of the processing, Synap will provide reasonable assistance to enable Customer to respond to requests by data subjects exercising rights under Applicable Data Protection Legislation. If Synap receives a request relating to Customer Data directly from a data subject, Synap will not substantively respond on Customer's behalf unless Customer instructs it to do so or the law requires it. Where Synap can reasonably identify the relevant Customer, Synap will promptly forward the request or direct the data subject to that Customer. Synap may take reasonable steps to verify the requester's identity before disclosing information.

**ii. Regulatory and third-party requests.** If either party receives a Third Party Request concerning processing for which the other party is responsible, it will promptly notify the other party where legally permitted. The parties will cooperate in good faith to the extent reasonably necessary to respond and to meet their respective legal obligations.

### **14. Miscellaneous.**

i. If there is a conflict, the order of precedence is: (a) the mandatory terms of the applicable Transfer Mechanism, for the relevant Restricted Transfer; (b) this DPA; (c) the Agreement; and (d) the Privacy Policy.

ii. Except to the extent prohibited by Applicable Data Protection Legislation or inconsistent with the SCCs or UK Addendum, claims arising under this DPA are subject to the exclusions and limitations of liability in the Agreement.

iii. Nothing in this DPA restricts the rights of a data subject or the powers of a competent supervisory authority.

iv. Each party is responsible for the laws applicable to its own processing and will cooperate in good faith where overlapping requirements apply.

v. Synap may update this DPA where reasonably necessary to comply with a change in Applicable Data Protection Legislation or an approved transfer mechanism. Synap will give reasonable notice of a material change and will not reduce the overall protection of Customer Data during the term except where required by law.

vi. Except as amended by this DPA, the Agreement remains in force.

vii. Synap's access to Customer Data is solely for the purposes permitted by the Agreement and this DPA and is not consideration for the Services.

viii. To the extent permitted by law, neither party is responsible for an administrative fine imposed on the other party for that other party's infringement of Applicable Data Protection Legislation. This does not limit liability to a data subject or supervisory authority, or liability that cannot lawfully be excluded.

This DPA takes effect when incorporated into the Agreement or on another date agreed in writing. No separate signature is required.

### **15. AI Systems and the EU AI Act.**

i. Features involving automated analysis, computer vision or machine learning may constitute an "AI system" under Regulation (EU) 2024/1689 (the **"EU AI Act"**), depending on their intended purpose and use. Synap will assess and comply with obligations applicable to it as provider or deployer.

ii. As at the date of this DPA, the EU AI Act requirements for high-risk systems listed in Annex III, including certain systems used to monitor or detect prohibited behaviour during tests in educational or vocational settings, are scheduled to apply from 2 December 2027. Synap maintains a proportionate compliance programme in preparation for applicable requirements.

iii. Synap will provide information reasonably necessary to understand an AI-assisted feature's intended purpose, principal outputs and human-oversight requirements. Unless expressly stated in the applicable product documentation, such features are intended to assist human review, not make final determinations of cheating, misconduct, identity or another comparably significant outcome, and are not intended to infer emotions or intentions from biometric data. Customer is responsible for its deployment, configuration and use of the feature and for obligations applicable to its decisions.

### **Schedule 1**

**DETAILS OF PROCESSING**

**Annex I**

**A. LIST OF PARTIES**

**Data exporter**

| Field               | Details                                                           |
| ------------------- | ----------------------------------------------------------------- |
| Name                | The party identified as Customer in the Agreement and this DPA    |
| Address             | As set out in the Agreement                                       |
| Contact details     | As set out in the Agreement                                       |
| Relevant activities | The activities described in Annex I.B below                       |
| Signature and date  | Deemed executed when Customer enters into the Agreement           |
| Role                | Controller or Processor, as applicable to the relevant processing |

**Data importer**

| Field               | Details                                                                               |
| ------------------- | ------------------------------------------------------------------------------------- |
| Name                | Synap Learning Limited (company number 08862590)                                      |
| Address             | Castleton Mill, Castleton Close, Leeds, England, LS12 2DR                             |
| Contact details     | Synap Privacy Team — <legal@synap.ac>                                                 |
| Relevant activities | The activities described in Annex I.B below                                           |
| Signature and date  | Deemed executed when Synap enters into the Agreement                                  |
| Role                | Processor or Sub-processor for Customer Data; independent Controller for Account Data |

**B. DESCRIPTION OF PROCESSING AND TRANSFERS**

| Processing detail                                      | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| ------------------------------------------------------ | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Category A — Account and service administration**    | <p><strong>Data subjects:</strong> Customer personnel, Authorised Users and business contacts. <br><br><strong>Personal Data Processed:</strong> names, business contact details, account roles, authentication and security records, billing and support information, and service-usage records. <br><br><strong>Purpose:</strong> contract and account administration, billing, support, service improvement, security, abuse prevention and compliance with law. Synap ordinarily acts as an independent Controller for this category.</p>                                                        |
| **Category B — Core assessment and learning services** | <p><strong>Data subjects:</strong> candidates, learners, employees, customers, markers, proctors, educators, managers and other End Users. <br><br><strong>Personal Data Processed:</strong> identifiers and contact details; authentication data; IP address and device/browser information; assessment enrolments, responses, marks, results, feedback and activity records; and information Customer chooses to collect using configurable fields. <br><br><strong>Purpose:</strong> to provide and support the assessment, exam, training and learning functionality configured by Customer.</p> |
| **Category C1 — Remote proctoring and media capture**  | <p><strong>Data subjects:</strong> End Users taking or preparing to take an activity for which Customer enables proctoring. <br><br><strong>Personal Data Processed:</strong> webcam video or still images, microphone audio, screen recordings, room or environment scans, timestamps, proctor notes, integrity flags and associated event metadata. <br><br><strong>Purpose:</strong> to help Customer deter, detect and review suspected cheating, fraud or other conduct affecting assessment integrity.</p>                                                                                     |
| **Category C2 — Device and session monitoring**        | <p><strong>Data subjects:</strong> End Users taking or preparing to take a monitored or locked-down activity. <br><br><strong>Personal Data Processed:</strong> operating system, browser and version, network and device information; open tabs, applications or processes where the enabled feature supports this; session events and activity logs. <br><br><strong>Purpose:</strong> to provide the lockdown and monitoring configuration selected by Customer and identify events relevant to assessment integrity.</p>                                                                         |
| **Category C3 — Identity-document and selfie capture** | <p><strong>Data subjects:</strong> End Users for whom Customer enables an identity check. <br><br><strong>Personal Data Processed:</strong> images or video of an identity document and the End User's face; document fields; capture-quality, document-presence, face-presence and liveness outputs; and reviewer decisions. <br><br><strong>Purpose:</strong> to enable Customer to review identity evidence and check that suitable evidence was captured.</p>                                                                                                                                    |
| **Category C4 — Biometric face comparison**            | <p><strong>Data subjects:</strong> End Users for whom Customer enables face comparison. <br><br><strong>Personal Data:</strong> facial images, biometric templates or measurements derived from them, match or confidence scores, liveness outputs and reviewer decisions. <br><br><strong>Purpose:</strong> to assess whether the person shown in a selfie or live capture is likely to be the person shown in an identity document or reference image.</p>                                                                                                                                         |
| **Category C5 — Gaze and attention estimation**        | <p><strong>Data subjects:</strong> End Users for whom Customer enables gaze or attention analysis. <br><br><strong>Personal Data Processed:</strong> video frames and measurements or estimates such as facial or eye landmarks, head position, gaze direction, periods away from the screen, timestamps, confidence scores and associated flags. <br><br><strong>Purpose:</strong> to identify configured gaze and attention patterns for Customer's authorised reviewers to consider in context.</p>                                                                                               |
| **Category C6 — Automated and AI-assisted review**     | <p><strong>Data subjects:</strong> End Users whose activity Customer configures for automated analysis. <br><br><strong>Personal Data Processed:</strong> the underlying Customer Data submitted to the enabled feature and generated indicators, classifications, similarity scores, confidence scores, flags, summaries or prioritisation outputs. <br><br><strong>Purpose:</strong> to assist Customer's authorised reviewers by highlighting measurable events or patterns that satisfy configured criteria or confidence thresholds.</p>                                                        |

**Special-category and other sensitive data.** Biometric data processed for the purpose of uniquely identifying an individual is special-category data under Article 9 GDPR; treatment under other laws depends on their applicable definitions. Other captured material may reveal protected characteristics. Customer is responsible for the applicable lawful basis and condition, privacy notice, impact assessment, necessity and proportionality.

**Incidental capture.** Room scans, webcam, microphone and screen recordings may capture bystanders, private surroundings, accessibility or medical equipment, conversations, notifications or other unrelated content. Synap processes this material only as incidental to the Customer-configured feature and does not use it to infer protected characteristics.

**Frequency.** Processing is continuous for Categories A and B and occurs when Customer or an Authorised User enables and uses the relevant Category C feature.

**Instructions and transparency.** Customer's configuration forms part of its documented instructions. Feature-specific and just-in-time notices supplement, but do not replace, Customer's privacy notice or lawful basis.

**Human and automated review.** Customer Data may be reviewed by authorised Customer or Synap personnel, a Sub-processor or an automated system, as configured. Automated outputs support review and may be incomplete or incorrect without context. Customer is responsible for final decisions and any legally required human oversight.

**Retention.** Customer controls the retention of Customer Data through the Services and its documented instructions, subject to feature-specific defaults and maximum periods displayed in the Services, an Order Form or other documentation supplied before the feature is enabled. Identity and biometric evidence is retained only for the configured review period and is then deleted or redacted in accordance with the applicable feature settings. On termination or expiry, Section 10 applies. Backup copies are isolated from ordinary use and overwritten according to Synap's documented backup-rotation schedule.

**Sub-processors.** Each Sub-processor may process only the categories of Customer Data and for the purposes necessary to provide its identified service, for the period it is engaged and subject to Section 7 and Schedule 3.

**C. COMPETENT SUPERVISORY AUTHORITY**

For the EU SCCs, the competent supervisory authority is determined in accordance with Clause 13: ordinarily the authority for the EEA country in which the data exporter is established; if the exporter is not established in the EEA, the authority for its Article 27 representative or, where no representative is required, the authority in an EEA country in which relevant data subjects are located. For the UK Addendum, the competent supervisory authority is the UK Information Commissioner's Office. For Swiss transfers, it is the Swiss Federal Data Protection and Information Commissioner.

**Schedule 2**

**TECHNICAL AND ORGANIZATIONAL SECURITY MEASURES**

**Annex II**

Synap maintains an ISO27001 certification, the relevant supporting documentation for which can be found on our Trust center at <https://trust.synap.ac>. In addition, further details of Synap's technical and organizational security measures to protect Customer Data are available at:

* <https://legal.synap.ac/security-policy>
* <https://legal.synap.ac/data-breach-management-policy>
* <https://legal.synap.ac/privacy-policy>

Where applicable, this Schedule 2 will serve as Annex II to the Standard Contractual Clauses. The following table provides more information regarding the technical and organizational security measures set forth below.

| Technical and Organizational Security Measure                                                                                                                                                 | Evidence of Technical and Organizational Security Measure                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Measures of pseudonymisation and encryption of personal data                                                                                                                                  | <ul><li>All data sent to or from Synap is encrypted in transit using TLS 1.2 or higher.</li><li>Customer Personal Data is encrypted at rest using 256-bit AES encryption</li><li>Where appropriate, Personal Data is pseudonymised so that only the minimum required fields are stored, processed or transferred.</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| Measures for ensuring ongoing confidentiality, integrity, availability and resilience of processing systems and services                                                                      | <ul><li>Synap has implemented a formal procedure for handling security events. When security events are detected, they are escalated to an emergency alias, relevant parties are paged, notified, and assembled to rapidly address the event. After a security event is contained and mitigated, relevant teams write up a post-mortem analysis, which is reviewed in person and distributed across the company and includes action items that will make the detection and prevention of a similar event easier in the future.</li><li>Customer's primary application database and stored files are hosted in the EU (Ireland) or the US according to Customer's assigned region. Disaster-recovery backups may use a different availability zone or region but remain within the same selected data-residency boundary (European Union or United States). Limited ancillary processing may occur elsewhere as described in Section 12 and the Sub-processor Page.</li><li>Synap uses AWS and MongoDB to provide scalable compute, storage, database, networking and security infrastructure designed for high availability.</li><li>Synap's data security, high availability, and built-in redundancy are designed to ensure application availability and protect information from accidental loss or destruction. Synap's Disaster Recovery plan incorporates geographic failover. Subscription Service restoration is within commercially reasonable efforts and is performed in conjunction with AWS’ ability to provide adequate infrastructure at the prevailing failover location. All of Synap's recovery and resilience mechanisms are tested regularly and processes are updated as required.</li><li>Synap's availability is monitored 24/7 via automated alerts, with senior on-call engineers being alerted as soon as an issue is detected.</li><li>Synap has no direct reliance on specific office locations to sustain operations. All operational access to production resources can be exercised - by authorized employees - at any location on the Internet. Synap leverages a range of best-of-breed technologies and other critical cloud tools to deliver uninterrupted remote work for all employees.</li><li>Encrypted backups are created and retained in accordance with Synap's documented backup and disaster-recovery procedures.</li></ul> |
| Measures for ensuring the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident                                 | <ul><li>Synap's mission-critical infrastructure is designed to meet a Recovery Time Objective of 30 minutes, and a Recovery Point Objective of 60 minutes.</li><li>Synap has a documented Incident Response / Disaster Management policy which is tested regularly.</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| Processes for regularly testing, assessing, and evaluating the effectiveness of technical and organizational measures in order to ensure the security of the processing                       | <ul><li>Synap regularly tests their security systems and processes to ensure they meet the requirements of this security policy. Synap maintains a CyberEssentials certification, a copy of which is available on request.</li><li>Application security testing. Synap uses automated tools to scan applications, source code and dependencies for vulnerabilities on a regular basis. Independent penetration testing is performed at least annually, and identified vulnerabilities are prioritised and remediated using a documented risk-based process.</li><li>Synap uses industry-leading tools to assess our source code and open source dependencies for vulnerabilities</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| Measures for user identification and authorisation                                                                                                                                            | <ul><li>All access to systems processing Customer Data is protected by Multi Factor Authentication (MFA). Customer Administrator accounts can also be protected with MFA.</li><li>Synap restricts access to Customer Data to only those people with a “need-to-know” for a Permitted Purpose and following least privileges principles.</li><li>Synap regularly reviews at least every 180 days the list of people and systems with access to Customer Data and removes accounts upon termination of employment or a change in job status that results in employees no longer requiring access to Customer Data.</li><li>Synap mandates and ensures the use of system-enforced “strong passwords” in accordance with the best practices (described below) on all systems hosting, storing, processing, or that have or control access to Customer Data and will require that all passwords and access credentials are kept confidential and not shared among personnel.</li><li>Password best practices implemented by Synap's organisational password manager. Passwords must meet the following criteria: a. contain at least 10 characters; b. must contain lowercase and uppercase letters, numbers, and a special character; c. cannot be part of a vendor provided list of common passwords.</li><li>Synap does not operate any internal corporate network. All access to Synap resources is protected by strong passwords and MFA.</li><li>Synap monitors their production systems and implements and maintains security controls and procedures designed to prevent, detect, and respond to identified threats and risks.</li><li>Strict privacy controls exist in the application code that are designed to ensure data privacy and to prevent one customer from accessing another customer’s data (i.e., logical separation).</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| Measures for the protection of data during transmission                                                                                                                                       | <ul><li>Encryption of data in transit via TLS 1.2 or higher</li><li>Pseudonymisation and/or data minimisation as appropriate</li><li>Redaction or masking of sensitive information where supported by the relevant feature and configuration</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| Measures for the protection of data during storage                                                                                                                                            | <ul><li>Intrusion Prevention. Synap implements and maintains a working network firewall to protect data accessible via the Internet and will keep all Customer Data protected by the firewall at all times.</li><li>Databases, including backups, are encrypted with AES-256.</li><li>Synap operates a documented, risk-based vulnerability and patch-management process and applies security updates according to their severity, exploitability and operational impact.</li><li>Security Awareness Training. Synap requires annual security and privacy training for all employees with access to Customer Data.</li><li>Synap uses anti-malware software and keeps the anti-malware software up to date. Customer instances are logically separated and attempts to access data outside allowed domain boundaries are prevented and logged.</li><li>Endpoint security software</li><li>System inputs recorded via log files</li><li>Access Control Lists (ACL)</li><li>Multi-factor Authentication (MFA)</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| Measures for ensuring physical security of locations at which personal data are processed                                                                                                     | <ul><li>Synap's services and data are hosted in AWS facilities in the EU (Ireland) or the US according to Customer's assigned region and are protected by AWS's physical and environmental security controls.</li><li>Synap personnel do not have physical access to AWS data centres. Physical access is controlled by AWS in accordance with its audited security programme.</li><li>Synap restricts logical production access to authorised personnel with a documented business need, using least-privilege and time-bound access where appropriate.</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Measures for ensuring events logging                                                                                                                                                          | <ul><li>See “Measures for the protection of data during storage” above.</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| Measures for ensuring system configuration, including default configuration                                                                                                                   | <ul><li>Change and Configuration Management. Synap uses continuous automation for application and operating systems deployment for new releases. Integration testing and unit testing are done upon every build with safeguards in place for availability and reliability. Synap has a process for critical emergency fixes that can be deployed to Customers within minutes. As such Synap can roll out security updates as required based on criticality.</li><li>Access Control Policy and Procedures</li><li>Change Management Procedures</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| Measures for internal IT and IT security governance and management                                                                                                                            | <ul><li>Information-security management procedures informed by guidance from the UK National Cyber Security Centre (NCSC), including the Cyber Essentials framework</li><li>Information security policy</li><li>Data Breach Management Policy</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| Measures for certification/assurance of processes and products                                                                                                                                | <ul><li>ISO27001 certification, with continuous monitoring and endpoint protection in place. More information available at <https://trust.synap.ac></li><li>External penetration testing performed at least annually</li><li>Disaster recovery / Data breach simulation exercises with an external agency performed annually</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| Measures for ensuring data minimisation                                                                                                                                                       | <ul><li>Data collection is limited to the purposes of processing (or the data that the Customer chooses to provide).</li><li>Security measures are in place to provide only the minimum amount of access (least privilege) necessary to perform required functions.</li><li>Return and deletion are governed by Section 10 of this DPA.</li><li>More information about how Synap processes personal data is set forth in the Privacy Policy available at <a href="https://legal.synap.ac/privacy-policy"><https://legal.synap.ac/privacy-policy></a>, and our Candidate/End User privacy policy available at <a href="https://legal.synap.ac/candidate-privacy-policy"><https://legal.synap.ac/candidate-privacy-policy></a></li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| Measures for ensuring data quality                                                                                                                                                            | <ul><li>Synap has a process that allows data subjects to exercise their privacy rights (including a right to amend and update their Personal Data), as described in Synap's Privacy Policy.</li><li>See “Measures for ensuring ongoing confidentiality, integrity, availability and resilience of processing systems and services” above.</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| Measures for ensuring limited data retention                                                                                                                                                  | <ul><li>See “<em>Measures for ensuring data minimization</em>” above.</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| Measures for ensuring accountability                                                                                                                                                          | <ul><li>Synap has implemented data protection policies</li><li>Synap follows a compliance by design approach</li><li>Synap maintains documentation of its processing activities</li><li>Synap has designated personnel responsible for privacy and data-protection governance</li><li>Synap maintains the certifications and assurance activities identified under “Measures for certification/assurance of processes and products” above.</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| Measures for allowing data portability and ensuring erasure                                                                                                                                   | <ul><li>Secure Disposal. Return or deletion. Synap will delete Customer Data from active systems without undue delay and, where a deletion request is technically complete and valid, no later than 30 days. Residual encrypted backup copies are isolated from ordinary use and overwritten under Synap's documented backup-rotation schedule, ordinarily within 90 days.</li><li>Archival copies. Where applicable law requires Synap to retain Customer Data, Synap isolates and protects it from ordinary use and processes it only for the legally required purpose.</li><li>Synap has a process that allows data subjects to exercise their privacy rights (including a right to amend and update their Personal Data), as described in Synap's Privacy Policy.</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| Technical and organizational measures to be taken by the \[sub]-processor to provide assistance to the controller and, for transfers from a processor to a \[sub]-processor, to the Customer. | <ul><li>Vendor & Services Providers. Prior to engaging new third-party service providers or vendors who will have access to Synap Data, Synap conducts a risk assessment of vendors’ data security practices.</li><li>Synap will restrict the onward sub-processor’s access to Customer Data only to what is strictly necessary to provide the Services, and Synap will prohibit the sub-processor from processing the Personal Data for any other purpose.</li><li>Synap imposes contractual data protection obligations, including appropriate technical and organizational measures to protect personal data, on any sub-processor it appoints that require such sub-processor to protect Customer Data to the standard required by Applicable Data Protection Legislation.</li><li>See Subprocessors List & Management Policy, available at <a href="https://legal.synap.ac/subprocessors-list-and-management-policy"><https://legal.synap.ac/subprocessors-list-and-management-policy></a></li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |

**Schedule 3**

**LIST OF SUB-PROCESSORS**

**Annex III**

For Modules Two and Three of the EU SCCs, Option 2 in Clause 9 applies. The authorised Sub-processors, their locations, services and relevant processing activities are listed at <https://legal.synap.ac/subprocessors-list-and-management-policy>.

Changes to the list are governed by Section 7 of this DPA. Synap will provide at least thirty (30) calendar days' prior notice of a new or replacement Sub-processor, except where use of that Sub-processor requires Customer to affirmatively enable an optional feature and the relevant information is provided before or when the feature is enabled.

**Schedule 4**

**UK INTERNATIONAL DATA TRANSFER ADDENDUM**

This Schedule incorporates the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner's Office under section 119A of the Data Protection Act 2018.

**Part 1: Tables**

**Table 1 — Parties and start date**

| Field         | Exporter                                                                                      | Importer                                                                                                    |
| ------------- | --------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------- |
| Start date    | The effective date of this DPA                                                                | The effective date of this DPA                                                                              |
| Party details | Customer, at the address and with the company details stated in the Agreement                 | Synap Learning Limited (company number 08862590), Castleton Mill, Castleton Close, Leeds, England, LS12 2DR |
| Key contact   | As stated in the Agreement                                                                    | Synap Privacy Team — <legal@synap.ac>                                                                       |
| Signature     | Customer is deemed to sign this Addendum by entering into an Agreement incorporating this DPA | Synap is deemed to sign this Addendum by entering into the Agreement                                        |

**Table 2 — Selected SCCs, modules and clauses**

The "Approved EU SCCs" are the EU SCCs identified in Section 1 of this DPA, including their Appendix Information, as completed by this DPA.

The following modules apply according to the parties' roles in the relevant Restricted Transfer:

* Module One: Controller to Controller, for Account Data where applicable.
* Module Two: Controller to Processor.
* Module Three: Processor to Processor.

Module Four does not apply. Clause 7 applies. For Modules Two and Three, Option 2 in Clause 9 applies using the notice period in Section 7 of this DPA. The optional wording in Clause 11 does not apply.

**Table 3 — Appendix information**

| EU SCC appendix                                 | Location              |
| ----------------------------------------------- | --------------------- |
| Annex IA: List of parties                       | Schedule 1, Annex I.A |
| Annex IB: Description of transfer               | Schedule 1, Annex I.B |
| Annex IC: Competent supervisory authority       | Schedule 1, Annex I.C |
| Annex II: Technical and organisational measures | Schedule 2            |
| Annex III: List of Sub-processors               | Schedule 3            |

**Table 4 — Ending the Addendum when the Approved Addendum changes**

Neither party may end this Addendum solely under section 19 of the Mandatory Clauses when the Approved Addendum changes. This does not affect any termination right under the Agreement or applicable law.

**Part 2: Mandatory Clauses**

Part 2: Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with section 119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of those Mandatory Clauses, is incorporated into and forms part of this Schedule 4.

**Schedule 5**

**UNITED STATES DATA PROTECTION TERMS**

### **1. Application and interpretation**

This Schedule applies only to the extent that a United States privacy, education-record or biometric-privacy law applies to the relevant processing. Terms defined by an applicable law have the meanings given by that law. If this Schedule conflicts with the remainder of the DPA, this Schedule controls only for the processing governed by that law.

### **2. US state comprehensive privacy laws**

Where Customer is a "controller" and Synap is a "processor", or the equivalent roles apply under a US state comprehensive privacy law, Synap will:

a. process Personal Data only on Customer's instructions and for the limited purposes described in the Agreement, this DPA and Schedule 1;

b. ensure that each person processing the data is subject to a duty of confidentiality;

c. maintain reasonable administrative, technical and organisational security measures appropriate to the nature of the data;

d. engage Sub-processors only in accordance with Section 7 and impose materially equivalent data-protection obligations on them;

e. provide reasonable assistance with authenticated consumer-rights requests, data-protection assessments, security obligations and regulator inquiries, taking account of the nature of the processing and information available to Synap;

f. delete or return Personal Data as provided in Section 10; and

g. make available information reasonably necessary to demonstrate compliance and permit assessments in accordance with Section 11.

Customer determines the purposes and means of processing and is responsible for providing required notices, obtaining any required consent, responding to consumers and ensuring that its instructions comply with applicable law.

### **3. California Consumer Privacy Act**

To the extent that the California Consumer Privacy Act, as amended by the California Privacy Rights Act (**"CCPA"**), applies and Customer is a "business", Synap will act as a "service provider" or "contractor", as applicable.

The specific business purposes for which Customer discloses Personal Information to Synap are to provide, secure, support and improve the Customer-configured Services described in the Agreement and Schedule 1. Customer discloses Personal Information to Synap only for those limited and specified purposes.

Synap will:

a. not Sell or Share Personal Information;

b. not retain, use or disclose Personal Information outside the direct business relationship with Customer or for any purpose other than the specified business purposes, except as otherwise permitted by the CCPA;

c. not combine Personal Information received from or on behalf of Customer with Personal Information received from another person or collected through Synap's own interaction with a consumer, except as permitted by the CCPA;

d. comply with obligations applicable to service providers or contractors and provide the same level of privacy protection required by the CCPA;

e. notify Customer if Synap determines that it can no longer meet those obligations;

f. permit Customer, subject to Section 11, to take reasonable and appropriate steps to help ensure that Synap uses Personal Information consistently with Customer's obligations and to stop and remediate unauthorised use; and

g. reasonably assist Customer with consumer requests, risk assessments and cybersecurity-audit information to the extent required by the CCPA and reasonably available to Synap.

Synap certifies that it understands and will comply with the restrictions in this Section. Where Synap receives deidentified information, it will take reasonable measures to prevent reidentification, publicly commit to maintaining the information in deidentified form and not attempt to reidentify it except as permitted by law.

### **4. FERPA**

This Section applies only where Customer is an educational agency or institution subject to the Family Educational Rights and Privacy Act (**"FERPA"**) and Customer provides Synap with personally identifiable information from education records.

Where Customer relies on FERPA's school-official exception, Customer designates Synap as a school official with a legitimate educational interest in providing the Services. Synap will:

a. remain under Customer's direct control, exercised through the Agreement, this DPA, Customer's documented instructions and Service configuration, with respect to the use and maintenance of the relevant education records;

b. use personally identifiable information from education records only to perform the institutional service or function described in the Agreement and for the purposes for which Customer disclosed it;

c. not redisclose that information except to an authorised Sub-processor bound by consistent restrictions, as instructed by Customer, or as otherwise permitted by FERPA;

d. restrict access to personnel and Sub-processors with a legitimate need to perform the Services;

e. provide reasonable assistance to enable Customer to facilitate a parent or eligible student's lawful access to or correction of education records maintained by Synap; and

f. delete or return the information in accordance with Section 10.

Customer is responsible for determining whether a FERPA exception applies, identifying Synap appropriately in its annual FERPA notice where required, and ensuring that its disclosure and instructions comply with FERPA.

### **5. United States biometric privacy laws**

This Section applies to the extent that Synap processes a biometric identifier, biometric information or biometric data governed by an applicable United States biometric-privacy law, including the Illinois Biometric Information Privacy Act, Texas Business and Commerce Code Chapter 503, Washington Revised Code Chapter 19.375, or a successor or similar law (**"US Biometric Laws"**).

Each party will comply with the obligations directly applicable to it. Customer, as the party determining whether to enable the feature and the purposes for which it is used, is responsible for determining whether a notice, written release, consent or other authorisation is required and for obtaining it before capture or processing begins. Synap will provide reasonably available information about the feature to support Customer's notice.

Synap will:

a. process covered biometric information only to provide the Customer-configured identity or integrity feature and on Customer's documented instructions;

b. not sell, lease, trade or otherwise profit from covered biometric information;

c. not disclose or redisclose covered biometric information except to an authorised Sub-processor necessary to provide the feature, as instructed or authorised by Customer or the individual, or as otherwise required or permitted by applicable law;

d. protect covered biometric information using reasonable care and at least the same degree of protection Synap applies to other confidential and sensitive information;

e. retain covered biometric information only for the configured and documented purpose and delete it under the applicable retention settings and Section 10, and in all cases no later than required by applicable law; and

f. maintain and make publicly available a retention and destruction policy where an applicable US Biometric Law requires it.

The definitions under the applicable US Biometric Law control.

### **6. Other US requirements**

If another US federal or state privacy law applies to Customer's use of the Services and requires additional processor or service-provider terms, the parties will reasonably cooperate to enter into the necessary terms. Synap may update this Schedule under Section 14 to reflect amendments, successor laws and newly effective generally applicable requirements, provided that the update does not materially reduce the protection of Customer Data.
