# Terms of Service

Last reviewed: 17th February 2025

Please read these Terms of Service (“Terms”, "Agreement") carefully. By signing up for a Subscription to use Synap's Services, you agree to the terms and conditions of this Agreement. If you are accessing and using the Services on behalf of a company (such as your employer) or other legal entity, you represent and warrant that you have the authority to bind that entity to this Agreement. In that case, "you" and "your" will refer to that entity. We may update this agreement from time to time, in which case we will let you know by posting the updated Agreement on the Site, and/or may also send other communications. It is important that you review this agreement whenever we update it, or you use the Services. Your continued use of or access to the Services constitutes acceptance of those changes. If you don not agree to be bound by the changes, you may not use the Services anymore.

## 1. Definitions

The definitions and rules of interpretation in this clause apply in this agreement

an Admin User refers to any user account created on Synap, that has administrator priviliges over a specific Synap Portal.

an End User refers to any registered user of a Synap Portal, with the exception of Admin Users.

Admin Users and End Users, collectively, may be referred to as Authorised Users.

the Documentation refers to material made available via Synap's designated Help Center, currently located at <https://academy.synap.ac>, as well as other materials that may be offered via the synap.ac website including but not limited to blog posts, articles and FAQs.

the Services refers to Synap's online learning and assessment technologies, including but not limited to the Synap online platform, mobile apps, reporting platform and any other online tools, widgets, plugins and other technologies developed or otherwise provided by Synap.

a Portal refers to a particular Customer's 'instance' of Synap, typically made available via a subdomain at synap.ac, e.g. <https://customer-name.synap.ac>.

### 2. Synap's Services

**2.1. Services Overview.**&#x20;

Synap offers a range of web-based platforms, mobile apps, tools and other services designed to help you create, deliver and analyse various forms of online learning - such as exams, question banks and courses - to your students, employees, customers or other users (collectively, "People"). These Services include:

* the Synap Website ("Website") available at <https://synap.ac> - this is our public website, displaying key information about our products, services and contact information
* the Synap Platform ("Platform") is the platform we make available to our Customers, on a Subscription basis. It consists of a proprietary back-end framework that forms our Server, a web-based platform and a mobile app for iOS and Android devices.
* the Synap Reporting Platform ("Reporting Platform") is a beta tool that allows our Customers' Admin Users to perform bulk operations such as generating user accounts and exporting data.

**2.2. Provision of Services.**&#x20;

Synap's Services, unless otherwise stated, are provided on a subscription basis. Subject to you purchasing a Subscription, and subject to the terms and restrictions set out in this Agreement, we grant you a non-exclusive, non-transferable right, without the right to grant sublicences, for you and your Authorised Users to use our Services and the Documentation during your Subscription Term.

We will use commercially reasonable efforts to make the Services available 24 hours a day, 7 days a week, in a manner substantially in accordance with the Documentation.

If our Services do not conform with the above criteria, we will use commercially reasonable measures to correct it, or to provide the you with an alternative means of accomplishing the desired goal. Such correction or substitution, and the right to terminate your Subscription, are your sole and exclusive remedy for any breach of these obligations.

### 3. Customer Data & Obligations

In order for us to provide you with the best possible service, and to meet our obligations under this Agreement, you must keep your Admin account details up to date. We require that your account has a valid payment method for the duration of your Subscription Term.

You may use the Platform for your own internal business and commercial purposes. However, you must not use the Platform to create derivative works or to build a product that is directly competitive with Synap. You must not attempt to reverse engineer our Services.

You must take commercially reasonable measures to prevent any unauthorised access to, or use of, the Services and/or the Documentation and, in the event of any such unauthorised access or use, promptly notify Synap.

The Customer assumes sole responsibility for the actions of, or claims made by, the Customer's End Users. This includes, but is not limited to compliance with relevant data protection and other laws governing the relationship between The Customer and their end-users

You shall not access, store, distribute or transmit any Viruses, or any material during the course of its use of the Services that:

* is unlawful, harmful, threatening, defamatory, obscene, infringing, harassing or racially or ethnically offensive;
* facilitates illegal activity;
* depicts sexually explicit images;
* promotes unlawful violence;
* is discriminatory based on race, gender, colour, religious belief, sexual orientation, disability; or
* is otherwise illegal or causes damage or injury to any person or property;

Synap reserves the right, without liability or prejudice to its other rights to the Customer, to disable the Customer's access to any material that breaches the provisions of this clause.

Except as may be allowed by any applicable law which is incapable of exclusion by agreement between the parties and except to the extent expressly permitted under this agreement, you shall not:

* attempt to copy, modify, duplicate, create derivative works from, frame, mirror, republish, download, display, transmit, or distribute all or any portion of the Software and/or Documentation (as applicable) in any form or media or by any means; or
* attempt to de-compile, reverse compile, disassemble, reverse engineer or otherwise reduce to human-perceivable form all or any part of the Software; or
* access all or any part of the Services and Documentation in order to build a product or service which competes with the Services and/or the Documentation; or
* use the Services and/or Documentation to provide services to third parties; or
* subject to 20.1, license, sell, rent, lease, transfer, assign, distribute, display, disclose, or otherwise commercially exploit, or otherwise make the Services and/or Documentation available to any third party except the Authorised Users, or
* attempt to obtain, or assist third parties in obtaining, access to the Services and/or Documentation, other than as provided under this 2; or
* introduce or permit the introduction of, any Virus or Vulnerability into Synap's network and information systems.

Please refer to the [Acceptable Use Policy](https://legal.synap.ac/acceptable-use-policy) for more detail.&#x20;

## 4. Storage of Data

Synap does not provide an archiving service. Synap agrees only that it will not intentionally delete any Customer Data from any Service prior to termination of Customer's applicable Subscription Term and expressly disclaims all other obligations with respect to storage.

In the event of any loss or damage to Customer Data, the Customer's sole and exclusive remedy against Synap shall be for Synap to use reasonable commercial endeavours to restore the lost or damaged Customer Data from the latest back-up of such Customer Data maintained by Synap in accordance with our [backup and archiving procedures](https://legal.synap.ac/security-policy).

## 5. Security

Synap agrees to use commercially reasonable technical and organizational measures designed to prevent unauthorized access, use, alteration or disclosure of any Service or Customer Data. Please refer to our [Security Policy](https://legal.synap.ac/security-policy) for more detailed information.&#x20;

## 6. Proprietary Rights & Ownership

6.1. **Synap Technology.** This is a subscription agreement for access to and use of the Services. The Customer acknowledges that it is obtaining only a limited right to the Services and that irrespective of any use of the words "purchase", "sale" or like terms in this Agreement no ownership rights are being conveyed to Customer under this Agreement. The Customer agrees that Synap or its suppliers retain all right, title and interest (including all Intellectual Property Rights) in and to the Services and Documentation, integrations with the Services, and any and all related and underlying technology and documentation and any derivative works, modifications or improvements of any of the foregoing, including as may incorporate Feedback (collectively, "Synap Technology"). Except as expressly set forth in this Agreement, no rights in any Synap Technology are granted to Customer. Further, Customer acknowledges that the Services are offered as an on-line, hosted solution, and that Customer has no right to obtain a copy of any of the Services, except in the format provided by Synap.

6.2. **Customer Data.** The Customer shall retain all right, title and interest in and to all of the Customer Data and shall have sole responsibility for the legality, reliability, integrity, accuracy and quality of all such Customer Data.

6.3. **Personal Data.** In relation to Personal Data entered into the platform - The Customer appoints Synap as a Data Processor. The Customer shall be the Data Controller as well as a Data Processor. Synap will provide the tools and respond to reasonable requests from The Customer as required to meet their obligations under data protection laws such as the GDPR.

6.4. **Feedback & Suggestions.** Synap shall have a royalty-free, worldwide, irrevocable, perpetual license to use and incorporate into the Services any suggestions, enhancement requests, recommendations or other feedback provided by You, your Authorised Users or your End Users relating to the operation of the Services.

## 7. Third Party Integrations & Websites

7.1. **Integration with Third Party Platforms.** The Services may support integrations with certain Third-Party Platforms. In order for the Services to communicate with such Third-Party Platforms, Customer may be required to input credentials in order for the Services to access and receive relevant information from such Third-Party Platforms. By enabling use of the Services with any Third-Party Platform, Customer authorizes Synap to access Customer's accounts with such Third-Party Platform for the purposes described in this Agreement. Customer is solely responsible for complying with any relevant terms and conditions of the Third-Party Platforms and maintaining appropriate accounts in good standing with the providers of the Third-Party Platforms. Customer acknowledges and agrees that Synap has no responsibility or liability for any Third-Party Platform  or how a Third-Party Platform uses or processes Customer Data after such is exported to it.&#x20;

7.2. **Third Party Website Content.** The Customer acknowledges that the Services may enable or assist it to access the website content of, correspond with, and purchase products and services from, third parties via third-party websites and that it does so solely at its own risk. Synap makes no representation, warranty or commitment and shall have no liability or obligation whatsoever in relation to the content or use of, or correspondence with, any such third-party website, or any transactions completed, and any contract entered into by the Customer, with any such third party. Any contract entered into and any transaction completed via any third-party website is between the Customer and the relevant third party, and not Synap. Synap recommends that the Customer refers to the third party's website terms and conditions and privacy policy prior to using the relevant third-party website. Synap does not endorse or approve any third-party website nor the content of any of the third-party website made available via the Services.

## 8. Subscription Term and Renewals.

8.1. **Fees and Payment.** All fees are as set forth in the applicable Order Form and will be paid by Customer within thirty (30) days of invoice, unless (a) Customer is paying via Credit Card (as defined below) or (b) otherwise specified in the applicable Order Form. All fees are non-refundable.

8.2. **Card Payments.** If you are purchasing the Services via credit card, debit card or other payment card ("Credit Card"), the following terms apply:

* **Recurring Billing Authorization.** By providing Credit Card information and agreeing to purchase any Services, Customer hereby authorizes Synap (or its designee) to automatically charge Customer's Credit Card on the same date of each calendar month (or the closest prior date, if there are fewer days in a particular month) during the Subscription Term for all fees accrued as of that date (if any) in accordance with the applicable Order Form. Customer acknowledges and agrees that the amount billed and charged each month may vary depending on Customer's use of the Services and may include subscription fees for the remainder of Customer's applicable billing period and overage fees for the prior month.
* **Foreign Transaction Fees.** Customer acknowledges that for certain Credit Cards, the issuer of Customer's Credit Card may charge a foreign transaction fee or other charges.
* **Invalid Payment.** If a payment is not successfully settled due to expiration of a Credit Card, insufficient funds, or otherwise, Customer remains responsible for any amounts not remitted to Synap and Synap may, in its sole discretion, either (i) invoice Customer directly for the deficient amount, (ii) continue billing the Credit Card once it has been updated by Customer (if applicable) or (iii) terminate this Agreement.
* **Termination of Recurring Billing.** In addition to any termination rights set forth in this Agreement, Customer may terminate the Subscription Term by sending Synap notice of non-renewal to in accordance with Section 7.1 (Subscription Term and Renewals) or, if Customer's Subscription Term is on a monthly basis (or if otherwise permitted by Synap), by terminating via the "Settings" page on the Dashboard, with termination effective at the end of the current Subscription Term. As set forth in Section 2.9 (Trial Subscriptions), if Customer does not enter into a paid Subscription Term following a Trial Period, this Agreement and Customer's right to access and use the Services will terminate at the end of the Trial Period and Customer's Credit Card will not be charged.
* **Payment of Outstanding Fees.** Upon any termination or expiration of the Subscription Term, Synap will charge Customer's Credit Card (or invoice Customer directly) for any outstanding fees for Customer's use of the Services during the Subscription Term, after which Synap will not charge Customer's Credit Card for any additional fees.

8.3. **Overdue Charges & Suspension of Service.** If any charges are not received from You by the due date, then at Our discretion, (a) such charges may accrue late interest at the rate of 1.5% of the outstanding balance per month, or the maximum rate permitted by law, whichever is lower, from the date such payment was due until the date paid, and/or (b) we may suspend Our services to You until such charges are paid in full. We will give You at least 5 days’ prior notice that Your account is overdue.

8.4. **Refunds.** No refunds or credits will be issued for partial or unused periods of service.

8.5. **Subscription Changes & Order Forms.** You agree that by signing or otherwise agreeing to the terms of an Order Form sent to you by an authorised Synap representative, you are agreeing to be bound by the terms of that Order Form. You agree that Synap may modify your Subscription if you agree to it in writing, including by email or our live chat system.

8.6. **Payment Disputes.** We shall not exercise Our rights under Section 8.3 (Overdue Charges & Suspension of Service) if You are disputing the applicable charges reasonably and in good faith and are cooperating diligently to resolve the dispute.

For more information about how we calculate your bill, please read our [Billing Policy](https://legal.synap.ac/billing-and-payment-terms).&#x20;

8.&#x37;**. Free Trials.** We reserve the right to end a free trial early for any reason. If a free trial is cancelled or payment is unsuccessful within 7 days of the trial ending, by default all associated data for the portal will be permanently deleted. Attempts to sign up for multiple free trials for the same project or organisation are against our terms of service and Synap reserves the right to terminate any such accounts without prior notice.&#x20;

## 9. Term & Termination

In the event that you wish to cancel the contract, you must let us know in writing (including by email). Upon cancellation, your subscriptions will be terminated and no further charges will be raised. We reserve the right to charge your card, or raise an invoice for any outstanding charges on your account.

Your Portal and associated Customer Data will be deleted at the end of your Subscription Term, or sooner if you explicitly instruct us to do so. You are solely responsible for ensuring that any data you wish to keep is exported before then.

## 10. Disclaimers & Limitation of Liability

Except as expressly and specifically provided in this agreement, and to the fullest extend permitted by law:

* The Services and the Documentation are provided to the Customer on an "as is" and "as available" basis. We cannot guarantee that your use of the Services will be uninterrupted or error-free, or that it will meet your requirements. We are not responsible for any delays, delivery failures, or any other loss or damage resulting from the transfer of data over the internet and other communications networks, and our Services and Documentation may be subject to limitations, delays and other problems inherent in the use of such networks.
* To the fullest extent permitted by law, we shall not be liable for any loss of profit; loss of business; loss of contract; loss of use; loss of or corruption to data or information; loss of anticipated savings; loss or depletion of goodwill or similar losses; or any special, indirect or consequential loss, costs or damage arising out of or in connection with the Services.
* The Customer assumes sole responsibility for results obtained from the use of the Services and the Documentation by the Customer, and for conclusions drawn from such use. Synap shall have no liability for any damage caused by errors or omissions in any information, instructions or scripts provided to Synap by the Customer in connection with the Services, or any actions taken by Synap at the Customer's direction;
* All warranties, representations, conditions and all other terms of any kind whatsoever implied by statute or common law are, to the fullest extent permitted by applicable law, excluded from this agreement.
* Nothing in these Terms and Conditions shall be construed so as to exclude or limit our liability for death or personal injury caused as a result of negligence or for fraud or fraudulent misrepresentation.

## 11. Indemnity

The Customer shall defend, indemnify and hold harmless Synap against claims, actions, proceedings, losses, damages, expenses and costs (including without limitation court costs and reasonable legal fees) arising out of or in connection with the Customer's use of the Services and/or Documentation, provided that: (i) the Customer is given prompt notice of any such claim; (b) Synap provides reasonable co-operation to the Customer in the defence and settlement of such claim, at the Customer's expense; (c) the Customer is given sole authority to defend or settle the claim.

Synap shall defend the Customer, its officers, directors and employees against any claim that the Customer's use of the Services or Documentation in accordance with this agreement infringes any United Kingdom patent effective as of the Effective Date, copyright, trade mark, database right or right of confidentiality, and shall indemnify the Customer for any amounts awarded against the Customer in judgment or settlement of such claims, provided that: (i) Synap is given prompt notice of any such claim; (b) the Customer does not make any admission, or otherwise attempt to compromise or settle the claim and provides reasonable co-operation to Synap in the defence and settlement of such claim, at Synap's expense; and (c) Synap is given sole authority to defend or settle the claim

In no event shall Synap, its employees, agents and sub-contractors be liable to the Customer to the extent that the alleged infringement is based on: (i) a modification of the Services or Documentation by anyone other than Synap; (ii) the Customer's use of the Services or Documentation in a manner contrary to the instructions given to the Customer by Synap; (iii) the Customer's use of the Services or Documentation after notice of the alleged or actual infringement from Synap or any appropriate authority.

The aformentioned terms state the Customer's sole and exclusive rights and remedies, and Synap's (including Synap's employees', agents' and sub-contractors') entire obligations and liability, for infringement of any patent, copyright, trade mark, database right or right of confidentiality.

## 12. Confidentiality

12.1. **Mutual Non-Disclosure.** Each party may be given access to Confidential Information from the other party in order to perform its obligations under this agreement. The Customer acknowledges that details of the Services, and the results of any performance tests of the Services, constitute Synap's Confidential Information. Synap acknowledges that the Customer Data is the Confidential Information of the Customer.

12.2. **Confidential Information.** A party's Confidential Information shall not be deemed to include information that: (i) is or becomes publicly known other than through any act or omission of the receiving party; (ii) was in the other party's lawful possession before the disclosure; (iii) is lawfully disclosed to the receiving party by a third party without restriction on disclosure; or (iv) is independently developed by the receiving party, which independent development can be shown by written evidence.

12.3. **No Disclosure.** Each party shall: (i) hold the other's Confidential Information in confidence and not make the other's Confidential Information available to any third party, or use the other's Confidential Information for any purpose other than the implementation of this agreement; (b) take all reasonable steps to ensure that the other's Confidential Information to which it has access is not disclosed or distributed by its employees or agents in violation of the terms of this agreement.

12.4. **Exceptions.** A party may disclose Confidential Information to the extent such Confidential Information is required to be disclosed by law, by any governmental or other regulatory authority or by a court or other authority of competent jurisdiction, provided that, to the extent it is legally permitted to do so, it gives the other party as much notice of such disclosure as possible and, where notice of disclosure is not prohibited and is given in accordance with the terms of this Agreement, it takes into account the reasonable requests of the other party in relation to the content of such disclosure.

12.5. **Survival.** The provisions of this section ('Conidentiality') shall survive termination of this agreement, however arising.

## 13. Publicity

Synap may, upon Customer’s prior written consent, use Customer’s name to identify Customer as a Synap customer of the Service, including on Synap public website. Synap agrees that any such use shall be subject to Synap complying with any written guidelines that Customer may deliver to Synap regarding the use of its name and shall not be deemed Customer’s endorsement of the Service.

## 14. General Terms

14.1. **Assignment.** This Agreement will bind and inure to the benefit of each party's permitted successors and assigns. Neither party may assign this Agreement without the advance written consent of the other party, except that either party may assign this Agreement in connection with a merger, reorganization, acquisition or other transfer of all or substantially all of such party's assets or voting securities. Any attempt to transfer or assign this Agreement except as expressly authorized under this Section 16.1 will be null and void.

14.2. **No Third-Party Beneficiaries**. This agreement does not confer any rights on any person or party (other than the parties to this agreement and, where applicable, their successors and permitted assigns) pursuant to the Contracts (Rights of Third Parties) Act 1999.

14.3. **No partnership or agency.** Nothing in this agreement is intended to or shall operate to create a partnership between the parties, or authorise either party to act as agent for the other, and neither party shall have the authority to act in the name or on behalf of or otherwise to bind the other in any way (including, but not limited to, the making of any representation or warranty, the assumption of any obligation or liability and the exercise of any right or power).

14.4. **Force majeure.** Synap shall have no liability to the Customer under this agreement if it is prevented from or delayed in performing its obligations under this agreement, or from carrying on its business, by acts, events, omissions or accidents beyond its reasonable control, including, without limitation, strikes, lock-outs or other industrial disputes (whether involving the workforce of Synap or any other party), failure of a utility service or transport or telecommunications network, act of God, war, riot, civil commotion, malicious damage, compliance with any law or governmental order, rule, regulation or direction, accident, breakdown of plant or machinery, fire, flood, storm or default of suppliers or sub-contractors, provided that the Customer is notified of such an event and its expected duration.

14.5. **Subcontractors.** Synap may use the services of subcontractors and permit them to exercise the rights granted to Synap in order to provide the Services under this Agreement, provided that Synap remains responsible for (i) compliance of any such subcontractor with the terms of this Agreement,(ii) for the overall performance of the Services as required under this Agreement, and (iii) compliance with the terms of the DPA.

14.6. **Notices.** Any notice required to be given under this Agreement shall be in writing and shall be delivered by hand or sent by pre-paid first-class post or recorded delivery post to the other Party at its address set out in this Agreement, or such other address as may have been notified by that Party for such purposes, or sent by email to the other Party’s email address.

14.7. **Entire Agreement.** This Agreement constitutes the entire agreement between both parties and supersedes and extinguishes all previous agreements, promises, assurances, warranties, representations and understandings between them, whether written or oral, relating to its subject matter. Each Party acknowledges that in entering into this Agreement it does not rely on, and shall have no remedies in respect of, any statement, representation, assurance or warranty that is not set out in this Agreement.

14.8. **Modification.** No modification, amendment, or waiver of any provision of this Agreement shall be effective unless in writing and either signed or accepted electronically. To the extent of any conflict or inconsistency between the provisions in the body of this Agreement and any exhibit or addendum hereto or any Order Form, the terms of such exhibit, addendum or Order Form shall prevail.

14.9. **Waiver.** No failure or delay by either party in exercising any right under this Agreement shall constitute a waiver of that right.

14.10. **Severance.** If any provision or part-provision of this agreement is or becomes invalid, illegal or unenforceable, it shall be deemed deleted, but that shall not affect the validity and enforceability of the rest of this agreement.

14.11. **Governing Law & Jurisdiction.** This agreement and any dispute or claim arising out of or in connection with it or its subject matter or formation (including non-contractual disputes or claims) shall be governed by and construed in accordance with the law of England and Wales. Each party irrevocably agrees that the courts of England shall have exclusive jurisdiction to settle any dispute or claim arising out of or in connection with this agreement or its subject matter or formation (including non-contractual disputes or claims).


# Privacy Policy

Last Reviewed: 10th March 2025\
\
We are committed to protecting your personal information and your right to privacy. If you have any questions or concerns about our policy, or our practices with regards to your personal information, please contact us at <james@synap.ac>.\
When you visit our website [https://synap.ac](https://synap.ac/), and use our services, you trust us with your personal information. We take your privacy very seriously. In this privacy notice, we describe our privacy policy. We seek to explain to you in the clearest way possible what information we collect, how we use it and what rights you have in relation to it. We hope you take some time to read through it carefully, as it is important. If there are any terms in this privacy policy that you do not agree with, please discontinue use of our Sites and our services.\
This privacy policy applies to all information collected through our website (such as [https://synap.ac](https://synap.ac/)), and/or any related services, sales, marketing or events (we refer to them collectively in this privacy policy as the "**Sites**").

\
**Please read this privacy policy carefully as it will help you make informed decisions about sharing your personal information with us.**\
\
**1. WHAT INFORMATION DO WE COLLECT?**

\
**Personal information you disclose to us**\
We collect personal information that you voluntarily provide to us when expressing an interest in obtaining information about us or our products and services, or otherwise contacting us. The personal information that we collect depends on the context of your interactions with us and the Sites, the choices you make and the products and features you use. The personal information we collect may include the following:

* **Name and Contact Data.**  We collect your first and last name, email address, postal address, phone number, and other similar contact data.
* **Credentials.**  We collect passwords, password hints, and similar security information used for authentication and account access.
* **Payment Data.** We collect data necessary to process your payment if you make purchases, such as your payment instrument number (such as a credit card number), and the security code associated with your payment instrument. All payment data is stored by our payment processor and you should review its privacy policies and contact the payment processor directly to respond to your questions.

All personal information that you provide to us must be true, complete and accurate. We take reasonable steps to ensure that personal information we process is accurate, complete, and kept up to date where necessary for the purposes for which it is used. We provide tools on-platform that let you manage your personal data and information and encourage you to use these to keep your data up to date, or you can notify us of any changes to such personal information.

**Information automatically collected**\
We automatically collect certain information when you visit, use or navigate the Sites. This information does not reveal your specific identity (like your name or contact information) but may include device and usage information, such as your IP address, browser and device characteristics, operating system, language preferences, referring URLs, device name, country, location, information about how and when you use our Sites and other technical information. This information is primarily needed to maintain the security and operation of our Sites, and for our internal analytics, audit and reporting purposes.

\
Like many companies, we also collect information through cookies and similar technologies. Please refer to our Cookies Policy for more information.&#x20;

\
**Information collected from other sources**\
We may obtain information about you from other sources, such as public databases, joint marketing partners, as well as from other third parties. Examples of the information we receive from other sources include: social media profile information; marketing leads and search results and links, including paid listings (such as sponsored links).

\
**2. HOW DO WE USE YOUR INFORMATION?**\
We process your personal information for these purposes in reliance on our legitimate business interests ("Legitimate Interest"), in order to enter into or perform a contract with you ("Contract"), with your consent ("Consent"), and/or for compliance with our legal obligations ("Legal Reasons"). We indicate the specific processing grounds we rely on next to each purpose listed below.\
We use the information we collect or receive:

* **To facilitate account creation and logon process.** If you choose to link your account with us to a third party account (such as your Google or Facebook account), we use the information you allowed us to collect from those third parties to facilitate account creation and logon process.
* **To send you marketing and promotional communications.** We and/or our third party marketing partners may use the personal information you send to us for our marketing purposes, if this is in accordance with your marketing preferences. You can opt-out of our marketing emails at any time.
* **To send administrative information to you.** We may use your personal information to send you product, service and new feature information and/or information about changes to our terms, conditions, and policies.
* **Fulfill and manage your orders.** We may use your information to fulfill and manage your orders, payments, returns, and exchanges made through the Sites.
* **To post testimonials.** We post testimonials on our Sites that may contain personal information. Prior to posting a testimonial, we will obtain your consent to use your name and testimonial. If you wish to update, or delete your testimonial, please contact us at <james@synap.ac> and be sure to include your name, testimonial location, and contact information.
* **Request Feedback.** We may use your information to request feedback and to contact you about your use of our Sites.
* **To protect our Sites.** We may use your information as part of our efforts to keep our Sites safe and secure (for example, for fraud monitoring and prevention).
* **To enforce our terms, conditions and policies.**
* **To respond to legal requests and prevent harm.** If we receive a subpoena or other legal request, we may need to inspect the data we hold to determine how to respond.
* **For other Business Purposes.** We may use your information for other Business Purposes, such as data analysis, identifying usage trends, determining the effectiveness of our promotional campaigns and to evaluate and improve our Sites, products, services, marketing and your experience.

\
**3. WILL YOUR INFORMATION BE SHARED WITH ANYONE?**\
We may process or share your data that we hold based on the following legal basis:

* **Consent:** We may process your data if you have given us specific consent to use your personal information for a specific purpose.
* **Legitimate Interests:** We may process your data when it is reasonably necessary to achieve our legitimate business interests.
* **Performance of a Contract:** Where we have entered into a contract with you, we may process your personal information to fulfill the terms of our contract.
* **Legal Obligations:** We may disclose your information where we are legally required to do so in order to comply with applicable law, governmental requests, a judicial proceeding, court order, or legal process, such as in response to a court order or a subpoena (including in response to public authorities to meet national security or law enforcement requirements).
* **Vital Interests:** We may disclose your information where we believe it is necessary to investigate, prevent, or take action regarding potential violations of our policies, suspected fraud, situations involving potential threats to the safety of any person and illegal activities, or as evidence in litigation in which we are involved.

More specifically, we may need to process your data or share your personal information in the following situations:

* **Business Transfers.** We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company.
* **Vendors, Consultants and Other Third-Party Service Providers.** We may share your data with third party vendors, service providers, contractors or agents who perform services for us or on our behalf and require access to such information to do that work. Examples include: payment processing, data analysis, email delivery, hosting services, customer service and marketing efforts. We may allow selected third parties to use tracking technology on the Sites, which will enable them to collect data about how you interact with the Sites over time. This information may be used to, among other things, analyze and track data, determine the popularity of certain content and better understand online activity. Unless described in this Policy, we do not share, sell, rent or trade any of your information with third parties for their promotional purposes.

\
**4. WHO WILL YOUR INFORMATION BE SHARED WITH?**     \
We only share and disclose your information with the following third parties. We have categorised each party so that you may be easily understand the purpose of our data collection and processing practices. If we have processed your data based on your consent and you wish to revoke your consent, please contact us.

| Purpose                                   | Entities                                             |
| ----------------------------------------- | ---------------------------------------------------- |
| Advertising                               | Google AdSense and Capterra                          |
| Communicating with Users                  | Intercom, Twilio Inc (Sendgrid & Segment)            |
| Content Optimisation                      | Google Analytics                                     |
| Infrastructure                            | AWS, MongoDB                                         |
| Internal tools & processes                | Google Drive, Shortcut, Slack                        |
| Retargeting Platforms                     | Google Ads Remarketing, Google Analytics Remarketing |
| Sales, Invoicing, eSignatures and Billing | Pipedrive, Stripe, Chargebee, GoCardless, Capchase   |
| Website performance monitoring            | Datadog, Fullstory                                   |

\
**5. DO WE USE COOKIES AND OTHER TRACKING TECHNOLOGIES?**\
We may use cookies and similar tracking technologies (like web beacons and pixels) to access or store information. Specific information about how we use such technologies and how you can refuse certain cookies is set out in our Cookie Policy.

\
**6. IS YOUR INFORMATION TRANSFERRED INTERNATIONALLY?**     \
Our servers are located in the EU (Ireland). If you are accessing our Sites from outside the EU, please be aware that your information may be transferred to, stored, and processed by us in our facilities and by those third parties with whom we may share your personal information, and in other countries.

\
If you are a resident in the European Union, then these countries may not have data protection or other laws as comprehensive as those in your country. We will however take all necessary measures to protect your personal information in accordance with this privacy policy and applicable law.

\
**EU-U.S. Privacy Shield Framework**\
Synap complies with the EU-U.S. Privacy Shield Framework as set forth by the U.S. Department of Commerce regarding the collection, use, and retention of personal information transferred from the European Union to the United States and has certified its compliance with it. As such, Synap Learning Limited is committed to subjecting all personal information received from European Union (EU) member countries, in reliance on the Privacy Shield Framework, to the Framework's applicable Principles. To learn more about the Privacy Shield Framework, visit the [U.S. Department of Commerce’s Privacy Shield List](https://www.privacyshield.gov/list).

Synap Learning Limited is responsible for the processing of personal information it receives, under the Privacy Shield Framework, and subsequently transfers to a third party acting as an agent on its behalf. With respect to personal information received or transferred pursuant to the Privacy Shield Framework, Synap Learning Limited is subject to the regulatory enforcement powers of the U.S. FTC. In certain situations, we may be required to disclose personal information in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.

\
**7. HOW LONG DO WE KEEP YOUR INFORMATION?**\
We will only keep your personal information for as long as it is necessary for the purposes set out in this privacy policy, unless a longer retention period is required or permitted by law (such as tax, accounting or other legal requirements).

\
When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymize it, or, if this is not possible (for example, because your personal information has been stored in backup archives), then we will securely store your personal information and isolate it from any further processing until deletion is possible.

\
**8. HOW DO WE KEEP YOUR INFORMATION SAFE?**\
We have implemented appropriate technical and organisational security measures designed to protect the security of any personal information we process. However, please also remember that we cannot guarantee that the internet itself is 100% secure. Although we will do our best to protect your personal information, transmission of personal information to and from our Sites is at your own risk. You should only access the services within a secure environment. Please read our Security Policy for more information.&#x20;

\
**10. WHAT ARE YOUR PRIVACY RIGHTS?**\
In some regions, you have certain rights under applicable data protection laws. These may include the right (i) to request access and obtain a copy of your personal information, (ii) to request rectification or erasure; (iii) to restrict the processing of your personal information; and (iv) if applicable, to data portability. In certain circumstances, you may also have the right to object to the processing of your personal information. To make such a request, please use the [contact details](https://synap.ac/privacy#contact) provided below. We will consider and act upon any request in accordance with applicable data protection laws.

\
**Cookies and similar technologies:** Most Web browsers are set to accept cookies by default. If you prefer, you can usually choose to set your browser to remove cookies and to reject cookies. If you choose to remove cookies or reject cookies, this could affect certain features or services of our Sites. To opt-out of interest-based advertising by advertisers on our Sites visit <http://www.aboutads.info/choices/>. Please read our Cookies Policy for more information.

\
**11. CONTROLS FOR DO-NOT-TRACK FEATURES**\
Most web browsers and some mobile operating systems and mobile applications include a Do-Not-Track ("DNT") feature or setting you can activate to signal your privacy preference not to have data about your online browsing activities monitored and collected. No uniform technology standard for recognizing and implementing DNT signals has been finalized. As such, we do not currently respond to DNT browser signals or any other mechanism that automatically communicates your choice not to be tracked online. If a standard for online tracking is adopted that we must follow in the future, we will inform you about that practice in a revised version of this Privacy Policy.

\
**13. DO WE MAKE UPDATES TO THIS POLICY?**     \
We may update this privacy policy from time to time. The updated version will be indicated by an updated "Revised" date and the updated version will be effective as soon as it is accessible. If we make material changes to this privacy policy, we may notify you either by prominently posting a notice of such changes or by directly sending you a notification. We encourage you to review this privacy policy frequently to be informed of how we are protecting your information.

\
**14. HOW CAN YOU CONTACT US ABOUT THIS POLICY?**     \
If you have questions or comments about this policy, you may email us at <james@synap.ac> or by post to Synap Learning Limited, Castleton Mill, Leeds, West Yorkshire LS12 2DR, United Kingdom.

\
**HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?**     \
Based on the applicable laws of your country, you may have the right to request access to the personal information we collect from you, change that information, or delete it in some circumstances. To request to review, update, or delete your personal information, please submit a request form by clicking [here](https://app.termly.io/notify/ef178b06-2c05-4051-a4a1-e36ba054fbc3). We will respond to your request within 30 days.


# Support Policy

This Synap Support Policy accompanies the Synap Subscription Terms of Service, available at [https://synap.ac/terms](https://intercom.com/legal/terms-and-policies) or a successor URL (the "Agreement") entered into between you ("Customer") and Synap. Capitalized terms used in this SLA that are not defined herein have the meanings given to them in the Agreement.

### 1.1. Standard Support Services

Synap offers support services in accordance with the following terms:

A. **Routine Support**. Is provided 9.00am - 5.00pm UK-time, Monday-Friday.

B. **Emergency Support.** Is provided 24 hours a day, 7 days a week.

C. **Incident Submission and Customer Cooperation**. The Customer may report errors or abnormal behavior of the Service ("**Incidents**") by contacting Synap in the Service via the Live Chat widget or via email at <support@synap.ac>. Customer will provide information and cooperation to Synap as reasonably required for Synap to provide Support. This includes, without limitation, providing the following information to Synap regarding the Incident:

* Aspects of the Service that are unavailable or not functioning correctly
* Incident's impact on users
* Start time of Incident
* List of steps to reproduce Incident
* Relevant log files or data
* Wording of any error message

D. **Incident Response**. Synap's Support personnel will assign a priority level ("**Priority Level**") to each Incident and seek to provide responses in accordance with the table below.

| **Priority Level** | **Description**                                                                                                                                                 | **Target Response Times** |
| ------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------- |
| Priority 1         | Operation of the Service is critically affected (not responding to requests or serving content) for a large number of users; no workaround available.           | 2 Hours                   |
| Priority 2         | Service is responding and functional but performance is degraded, and/or Incident has potentially severe impact on operation of the Service for multiple users. | 1 Day                     |
| Priority 3         | Non-critical issue; no significant impact on performance of the Service but user experience may be affected.                                                    | 3 Days                    |

E. **Exclusions.** Synap will have no obligation to provide Support to the extent an Incident arises from: (a) use of the Service by Customer in a manner not authorized in the Agreement or the applicable Documentation; (b) general Internet problems, force majeure events or other factors outside of Synap's reasonable control; (c) Customer's equipment, software, network connections or other infrastructure; or (d) third party systems, acts or omissions.

### 1.2.  Enhanced Support Services

We may, at our discretion, offer additional support under our Professional Services Terms, to cover business critical periods or specific requirements. The nature and price of this will be determined by a separate Order Form, and the period of cover will be strictly limited to the dates defined in that document.&#x20;


# Service Level Agreement

This Synap Service Level Agreement ("SLA") accompanies the Synap Subscription Terms of Service, available at <https://synap.ac/terms[^1>] or a successor URL (the "Agreement") entered into between you ("Customer") and Synap. Capitalised terms used in this SLA that are not defined herein have the meanings given to them in the Agreement.

1. **Target Availability.** Synap will use commercially reasonable efforts to make each Service available with an uptime of 99.9% of each calendar month ("Target Availability").
2. **Exclusions.** The calculation of uptime will not include unavailability to the extent due to: (a) use of the Service by Customer in a manner not authorised in this Agreement or the applicable Documentation; (b) general Internet problems, force majeure events or other factors outside of Synap's reasonable control; (c) Customer's equipment, software, network connections or other infrastructure; (d) third party systems, acts or omissions; or (e) Scheduled Maintenance or reasonable emergency maintenance. This SLA does not apply to any services which are considered 'Beta' or 'In Development'.
3. **Scheduled Maintenance.** Means Synap's scheduled routine maintenance of the Services for which Synap notifies Customer at least seventy two (72) hours in advance. Scheduled Maintenance will not exceed eight (8) hours per month. Please note, Scheduled Maintenance such as this is exceedingly rare - we do not routinely do this as in the vast majority of cases where an update is required, we can perform this on a 'rollover' basis without requiring downtime.&#x20;
4. **Remedy for Failure to Meet Target Availability.** If there is a verified failure of a Service to meet Target Availability in two (2) consecutive months, then Customer may terminate the applicable Subscription Term by sending written notice of termination within thirty (30) days after the end of the second such month, in which case Synap will refund to Customer any fees Customer has pre-paid for use of such Service for the terminated portion of the applicable Subscription Term. This termination and refund right is Customer's sole and exclusive remedy, and Synap's sole and exclusive liability, for failure to meet the Target Availability.

### Additional&#x20;

* Synap's Trust Center : <https://trust.synap.ac/>
* Synap's Status Page: <https://synap-learning.statuspage.io/>

[^1]: [https://synap.ac/terms](https://intercom.com/legal/terms-and-policies)


# Professional Services Agreement

This document outlines Synap's standard terms for undertaking any consultancy work.

Synap offers a range of consultancy and support services (collectively "Professional Services"), such as custom development of software and integrations, exam-day support and strategic advice.  The exact nature, scope and duration of these Professional Services will vary, and will be determined by a separate Order Form.

For any such engagement, the following terms, as well as our Subscriber Terms of Service  shall apply, unless explicitly stated otherwise in the associated Order Form.&#x20;

### 1. Performance and Acceptance of Professional Services. <a href="#performance-and-acceptance-of-premier-services" id="performance-and-acceptance-of-premier-services"></a>

**2.1** Both parties agree to cooperate in good faith to achieve satisfactory fulfillment of the Professional Services in a timely and professional manner.

**2.2** Synap will perform the Premier Services through qualified employees and/or subcontractors.

**2.3** Subscriber agrees to provide, at no cost to Synap, timely and adequate assistance and other resources reasonably requested by Synap to enable the performance of the Professional Services. Synap, including its Subcontractors, will not be liable for any deficiency in the performance or effectiveness of Professional Services to the extent such deficiency results from any acts or omissions of Customer, including, but not limited to, Customer's failure to provide Assistance as required hereunder.

**2.4** Synap will control the method and manner of performing all work necessary for completion of Professional Services, including but not limited to the supervision and control of any Professional Services Personnel performing Professional Services. Synap will maintain such a number of qualified Professional Services Personnel and appropriate facilities and other resources sufficient to perform Synap's obligations under the Agreement in accordance with its terms.

**2.5** Deliverables shall be deemed accepted by Subscriber in accordance with the terms of the Order Form and upon execution of the Order Form.

### 2. Change Orders. <a href="#change-orders" id="change-orders"></a>

After execution of an Order Form, the Professional Services to be provided under that Order Form may only be changed through a change order mutually executed by the Parties (“Change Order”). The only exception to this is if, at Synap's sole discretion, we deem the requested change to be minor in nature in which case we may accept written (including email) confirmation between the Customer and an Authorised Synap Representative.&#x20;

### 3. Limitation of Liability & Disclaimer <a href="#intercom-hereby-represents-and-warrants-that" id="intercom-hereby-represents-and-warrants-that"></a>

Synap warrants that:

**(a)** the Professional Services provided pursuant to the Agreement will be performed in a timely and professional manner by Synap, consistent with generally-accepted industry standards; provided that Subscriber’s sole and exclusive remedy for any breach of this warranty will be, at Synap's discretion, re-performance of the Professional Services or return of the portion of the Fees paid to Synap by Customer for the nonconforming portion of the Premier Services; and

**(b)** Synap is under no contractual or other restrictions or obligations which are inconsistent with the execution of the Agreement, or, to its best knowledge, which will interfere with its performance of the Professional Services.

### 4. Third Party Costs & Disbursements <a href="#id-5-rights-to-deliverables-ownership" id="id-5-rights-to-deliverables-ownership"></a>

Where an Order Form provides a quote for any Third Party services (e.g. exam proctoring costs or agency rates), Synap reserves the right to change the quoted price if the price quoted is no longer commercially viable. We will of course make all efforts to avoid this and to communicate any required changes in advance.&#x20;

### 5. Rights to Deliverables; Ownership. <a href="#id-5-rights-to-deliverables-ownership" id="id-5-rights-to-deliverables-ownership"></a>

The Parties hereby agree that the specified Professional Services to be completed pursuant to any Order Form, have as a prerequisite Customer's current subscription to a Synap Service and integration of Customer Data with and into one or more Services, and therefore the Deliverables - unless explicitly stated otherwise in an associated Order Form - are inoperative without an active subscription to a Synap Service. As between the Parties, Synap shall solely and exclusively own all right, title, and interest in the Deliverables, including all derivatives, enhancements and modifications thereof; and Subscriber hereby makes all assignments necessary to accomplish the foregoing ownership. Subject to the terms and conditions hereof, Synap grants Subscriber a non-exclusive, non-transferable, non-sublicensable license to use the Deliverables solely in connection with Subscriber’s permitted use of the Services.


# Cookie Policy

This document outlines how Synap uses Cookies, and related technologies, across our web platforms

This Cookie Policy explains how Synap Learning Limited ("**Company**", "**we**", "**us**", and "**our**") uses cookies and similar technologies to recognize you when you visit our Site at <https://synap.ac>, or when you use our web-based Services (collectively "Websites"). It explains what these technologies are and why we use them, as well as your rights to control our use of them.\
In some cases we may use cookies to collect personal information, or that becomes personal information if we combine it with other information.

\
**What are cookies?**\
Cookies are small data files that are placed on your computer or mobile device when you visit a website. Cookies are widely used by website owners in order to make their websites work, or to work more efficiently, as well as to provide reporting information.\
Cookies set by Us are referred to as "first party cookies". Cookies set by parties other than Us are referred to as "third party cookies". Third party cookies enable third party features or functionality to be provided on or through the website (e.g. like advertising, interactive content and analytics). The parties that set these third party cookies can recognize your computer both when it visits the website in question and also when it visits certain other websites.

\
**Why do we use cookies?**\
We use first and third party cookies for several reasons. Some cookies are required for technical reasons in order for our Websites to operate, and we refer to these as "essential" or "strictly necessary" cookies. Other cookies also enable us to track and target the interests of our users to enhance the experience on our Online Properties. Third parties serve cookies through our Websites for advertising, analytics and other purposes. This is described in more detail below.\
The specific types of first and third party cookies served through our Websites and the purposes they perform are described below (please note that the specific cookies served may vary depending on the specific Synap Website or Service you visit, and whether you are an Admin or an End User of our Services):

\
**How can I control cookies?**\
You have the right to decide whether to accept or reject cookies. You can exercise your cookie rights by setting your preferences in the Cookie Consent Manager. The Cookie Consent Manager allows you to select which categories of cookies you accept or reject. Essential cookies cannot be rejected as they are strictly necessary to provide you with services.\
The Cookie Consent Manager can be found in the notification banner and on our website. If you choose to reject cookies, you may still use our website though your access to some functionality and areas of our website may be restricted. You may also set or amend your web browser controls to accept or refuse cookies. As the means by which you can refuse cookies through your web browser controls vary from browser-to-browser, you should visit your browser's help menu for more information.

\
In addition, most advertising networks offer you a way to opt out of targeted advertising. If you would like to find out more information, please visit <http://www.aboutads.info/choices/> or <http://www.youronlinechoices.com>.

The specific types of first and third party cookies served through our Websites and the purposes they perform are described in the table below (please note that the specific cookies served may vary depending on the specific Online Properties you visit):<br>

**What cookies to you use?**

**‍Necessary cookies**&#x20;

Necessary cookies allow us to offer you the best possible experience when accessing and navigating through our Websites and using their features. For example, these cookies help our infrastructure to load pages quicker, let us recognise that you have created an account and have logged into that account to access the content. Necessary cookies are usually first-party (set by Us), but there are some third-party cookies which we also deem as necessary, e.g. Segment and Intercom, which allows us to provide authenticated in-app chat support to our Admin Users or visitors to our Website.&#x20;

We do not place any non-essential cookies on our End Users devices. However, a Synap Customer may configure their Synap environment so that it does - e.g. a Synap Customer could install Intercom so that they can offer live chat support to their Students. This should be governed by its own Privacy Policy within the Customer's Synap environment.&#x20;

**Analytics cookies**

We use analytics cookies to monitor usage of our Sites. This information helps us plan marketing campaigns, improve our site and develop new features.&#x20;

* Google Analytics
* Google Tag Manager
* Mixpanel
* Fullstory

**Advertising cookies**

We use the following cookies to track information regarding the performance of our advertising campaigns, and for re-targeting purposes

* Google Ads
* Capterra

\
**What about other tracking technologies, like web beacons?**\
Cookies are not the only way to recognize or track visitors to a website. We may use other, similar technologies from time to time, like web beacons (sometimes called "tracking pixels" or "clear gifs"). These are tiny graphics files that contain a unique identifier that enable us to recognize when someone has visited our Websites or opened an e-mail including them. This allows us, for example, to monitor the traffic patterns of users from one page within a website to another, to deliver or communicate with cookies, to understand whether you have come to the website from an online advertisement displayed on a third-party website, to improve site performance, and to measure the success of e-mail marketing campaigns. In many instances, these technologies are reliant on cookies to function properly, and so declining cookies will impair their functioning.

\
**Do you serve targeted advertising?**\
Third parties may serve cookies on your computer or mobile device to serve advertising through our Site. These companies may use information about your visits to this and other websites in order to provide relevant advertisements about goods and services that you may be interested in. They may also employ technology that is used to measure the effectiveness of advertisements. This can be accomplished by them using cookies or web beacons to collect information about your visits to this and other sites in order to provide relevant advertisements about goods and services of potential interest to you. The information collected through this process does not enable us or them to identify your name, contact details or other details that directly identify you unless you choose to provide these.

\
**How often will you update this Cookie Policy?**\
We may update this Cookie Policy from time to time in order to reflect, for example, changes to the cookies we use or for other operational, legal or regulatory reasons. Please therefore re-visit this Cookie Policy regularly to stay informed about our use of cookies and related technologies.\
The date at the top of this Cookie Policy indicates when it was last updated.


# Security Policy

### Overview <a href="#overview" id="overview"></a>

At Synap we take the protection of customer data extremely seriously. This Security Policy describes the organizational and technical measures Intercom implements platform wide designed to prevent unauthorized access, use, alteration or disclosure of customer data. The Synap services operate on Amazon Web Services (“AWS”) infrastructure; this policy describes activities of Intercom within its instance on AWS unless otherwise specified. As you continue to learn more about Synap we recommend you also review our [Terms of Service](/billing-and-payment-terms) and [Privacy Policy](/privacy-policy)

Data processing activities by Synap are undertaken as part of specific requests from our clients - i.e. to provide technical support to users, or if we receive explicit instructions from a client to process data on their behalf (i.e. reporting/data analysis).

Data collected includes users’ name and email address, so that the client can attribute actions taken on the platform to a particular user, and get in touch with them when work is due. No special category data is collected.

### Core Technical Infrastructure

Synap is hosted on Amazon Web Services (AWS) infrastructure within the EU (Dublin). Our database is provided by MongoDB, which is also hosted on AWS in Ireland.

Our databases are backed up every day and kept for 7 days before being deleted. All data - including backups - are encrypted in transit and at rest (HTTPS/AES-256). Card payments are processed by the client’s own payment processing gateway (e.g. Stripe/Paypal)

### Operational Security & Access to Data

Only Synap employees have access to our data, and we will only access identifiable client data upon written request / authorisation from the client, or to fulfill an obligation outlined in our contract with the client. Our offices are controlled by keycard access to all floors and key access to individual offices.

Only select, senior Synap employees have access to admin accounts on AWS, Database hosting and our internal dashboards. We have individual user accounts set up for all team members which provide them with the minimum access they need in order to perform daily tasks (configured with AWS Identity & Access Management controls). All company devices are locked with a password, and where available, multi-factor factor authentication.&#x20;

We hold ISO27001 certification, details of which are available on request.

Secure configuration Our AWS account is configured so that minor or security-critical updates to software are installed automatically. Larger updates with the potential to introduce breaking changes are implemented as soon as possible, pending manual review & testing. We run the servers as immutable deployments and they are only configured to use necessary tools. Multi factor authentication is required for all critical accounts (i.e. those which store data and/or considered critical to operations). HTTPS/SSL is enforced over all connections, and data is encrypted with AES at rest. We have DDoS protection provided by AWS Shield Network security We have set up security policies in AWS which block connections from certain ports, and where appropriate, to only accept connections from certain IP addresses. AWS security check is run weekly which produces a report on potential threats & solutions to them. User education and awareness We provide security training to our staff when they join the organisation, with refreshers throughout the year. Our goal here is to ensure that all staff understand the basics of data security, what is expected/required of them, and how to take sensible steps to reduce the risk of a data/security breach.

### Incident management&#x20;

We have real-time monitoring set up which alerts our engineers as soon as one of our servers is unreachable or otherwise experiencing degraded performance . Secure database backups are taken daily, as well as prior to any major changes. Malware prevention Company devices have anti-malware / anti-virus software installed, and our office network also has protection built into the routers. Monitoring We have real time monitoring set up with Pingdom that measures traffic / impact on services. We also have weekly security routines configured with AWS which look for potential attack vectors / suspicious traffic. Removable media controls We do not use removable media devices. We have a policy in place to securely delete any local files containing user data as soon as they are done with. Home and mobile working Only Synap directors work on anything related to user data / servers etc from home. This takes place on devices with strong passwords, on a secure wifi network with hardware firewalls. Again, all accounts are also locked behind multi factor authentication.

### Cybersecurity Audit & Penetration Testing

Synap holds and maintains ISO27001 certification, details of which can be requested from our [Trust Center](https://trust.synap.ac/)

Synap is a registered data controller with the UK Information Commissioners Office (ICO), under the UK Data Protection Act 2018.

Synap conducts regular internal penetration tests against the OWASP Top 10 criteria, as well as monthly external penetration tests against OWASP Top 10 and a wide variety of other attack vectors. The external penetration tests are conducted by Intruder, a widely used automated tool that checks against over 17,000 known attack vectors.&#x20;

We are committed to resolving any Critical, High or Medium severity issues flagged by penetration testing as soon as possible, usually within days of discovery. We aim to resolve Low priority issues within 1-2 months.&#x20;

### Further Information

More information available on request - please contact James Gupta (Director, Synap) at <james@synap.ac>


# Data Breach Management Policy

This Synap Data Breach Management Policy accompanies the Synap Subscription Terms of Service, available at [https://synap.ac/terms](https://intercom.com/legal/terms-and-policies) or a successor URL (the "Agreement") entered into between you ("Customer") and Synap.

### Overview

Synap is commited to ensuring that all data we process - on behalf of our customers and their end users - is managed appropriately, in accordance with industry best practices, and in compliance with the General Data Protection Regulation (GDPR), the Data Protection Act 2018 (DPA 2018) (collectively referred to as "Data Protection Legislation").&#x20;

Every care is taken to protect personal data and to avoid a breach of such data. This policy outlines the measures Synap takes in response to an incident where data has been processed or disclosed in an unauthorised manner, or where there has been accidental loss, destruction or damage to personal data.&#x20;

Synap employees are made aware of this document and receive training on how to handle personal data and ensure that they are doing so in a way that maintains a high level of security.

### Scope

This document outlines the measures Synap will take in response to a breach of Customer Data - where Customer Data means, any data belonging to a Synap Customer or their End Users. For the avoidance of doubt, this definition includes both 'content' that our Customers create and store on Synap (such as test questions and other e-learning material), and personal data, such as names and email addresses.&#x20;

Unless otherwise specified, the phrase 'data' or 'customer data' refers to both content data and personal data.

This document outlines Synap's approach to data breaches - it is not a comprehensive overview of the security measures we have in place to prevent breaches in the first place. Please refer to our Security Policy for more information about these measures.&#x20;

#### Detecting & Reporting Incidents and Breaches

All Customer Data processed by Synap is encrypted, both in-transit and at-rest, and is stored on Amazon Web Services (AWS) infrastructure, with several layers of security to prevent and detect unauthorised access. For a more detailed overview of these measures, please refer to our Security Policy.&#x20;

Customer Data is only handled by authorised Synap Representatives, who are directly involved in a particular customer's account. Synap Representatives who are handling Customer Data receive training on how to do so securely, and how to identify and respond to potential data breaches.&#x20;

In the event of a suspected - or 'near miss' breach - whether reported via automated tools, or by a Synap Representative, or by a Synap Customer - Synap will launch a priority investigation to confirm or exclude the breach. A senior manager from Synap - and a representative from the Customer's organisation should be informed as soon as possible. If the breach is or suspected to be 'in progress', then a senior engineer from Synap should be contacted immediately with a view to closing the source of the breach as soon as possible.&#x20;

An initial assessment of the suspected breach should be performed and communicated with the Customer. This assessment should include the following information:&#x20;

* Summary of the suspected incident - when did it happen, what is the suspected nature of the breach (accidental loss, malicious intent etc), and what data was involved.&#x20;
* To what extent can we confirm whether the breach did occur? If we cannot confirm it, what further investigations are necessary?
* Is the breach still occurring, and if so what immediate steps are needed to stop it?
* The nature of the data in question - e.g. is it personally identifiable data, e-learning material. If data is personally identifiable, then who are the people who have been affected, and what are the potential harms?&#x20;
* If the breach is an accidental loss, what are the recovery options? (time of latest backup etc)
* If the breach is malicious, is it possible or likely that an unauthorised individual now has access to unencrypted Customer Data? What are the potential implications of this and how can they be minimised
* Is there an obligation to report the breach to the UK Information Commissioner's Office (ICO)?

#### Step 1: Containment and Recovery

1. The Data Protection Manager will ascertain the severity of the breach, whether any personal data is involved and whether the breach is still occurring.
2. If the breach is still occurring, the Data Protection Manager will establish what steps need to be taken immediately to minimise the effect of the breach and contain the breach from further data loss (e.g. restricting access to systems, closing down a system, encryption key rotation).&#x20;
3. The Data Protection Manager will consider and implement appropriate steps required to recover any data loss where possible and limit damage caused (e.g. use of backups to restore data; changing passwords etc.)
4. The Data Protection Manager will consult with a Synap Director to determine if the severity and likely impact of the breach deems it necessary to inform the ICO. At the same time, depending on the nature of the breach, the Data Protection Manager may seek expert or legal advice and/or the Police if it is believed that illegal activity has occurred or likely to occur.
5. Where a significant breach has occurred, and Synap is acting as a data controller, the Data Protection Officer will inform the ICO within 72 hours of the discovery of the breach. Where Synap is acting as a data processor on behalf of a customer, Synap will instead notify the customer (as the data controller) without undue delay, and provide them with the necessary information to assess and fulfil any legal obligations to notify the ICO or affected data subjects.&#x20;
   1. For the avoidance of doubt, Synap will not notify any third party, including the ICO, in relation to a breach of customer-controlled personal data without prior written instruction from the customer, unless required to do so by applicable law.
6. The decision taken as to the reasons why a data breach is either reported or not reported is documented by the Data Protection Manager.
7. All the key actions and decisions are fully documented and logged in our Incident Management Log.

#### Assessment of Risk

Further actions may be needed beyond immediate containment of the data breach. A further assessment of the risks associated with the breach should be undertaken to identify whether any potential adverse consequences for individuals are likely to occur and the seriousness of these consequences. The Data Protection Manager will consider the points arising from the following questions:

1. What type and volume of data is involved?
2. How sensitive is the data? Could the data breach lead to distress, financial or even physical harm?
3. What events have led to the data breach? What has happened to the data?
4. Has the data been unofficially disclosed, lost or stolen? Were preventions in place to prevent access/misuse? (e.g. encryption)
5. How many individuals are affected by the data breach?
6. Who are the individuals whose data has been compromised?
7. What could the data tell a third party about the individual? Could it be misused regardless of what has happened to the data?
8. What actual/potential harm could come to those individuals? E.g. physical safety; emotional wellbeing; reputation; finances; identity theft; one or more of these and other private aspects to their life
9. Are there wider consequences to consider?
10. Are there others that might advise on risks/courses of action?

#### Step 3: Evaluation and Response&#x20;

When the response to a data breach has reached a conclusion, the Data Protection Manager will undertake a full review of both the causes of the breach and the effectiveness of the response. If through the review, systematic or ongoing problems associated with weaknesses in internal processes or security measures have been identified as a cause of the data breach, then appropriate action plans will be drafted, actioned and monitored to rectify any issues and implement recommendations for improvements.&#x20;

#### Implementation of these Procedures&#x20;

The Data Protection Manager will ensure that staff are aware of these procedures for reporting and managing data breaches. Data Protection training for all staff is mandatory, including new employees and all staff will undertake refresher training annually. If staff have any queries or questions relating to these procedures, they should discuss this with the Data Protection Manager.


# Subprocessors List & Management Policy

Like most online platforms, Synap is a data processor and engages certain onward subprocessors that may process personal data submitted to Synap's services by the Customer. These subprocessors are listed below, with a description of the service and the location where data is hosted. This list may be updated by Synap from time to time.

### Procedure for Appointing New Subprocessors

Synap takes great care when appointing new subprocessors - particularly if that subprocessor is going to be handling End-User or Customer Data. On the whole, our preference is to look for in-house solutions which can be housed directly in our existing AWS infrastructure, so that we are minimising the extent to which data is transferred between different providers.&#x20;

When Synap is considering the appointment of a new subprocessor, the following criteria should be met:

1. The need for using a subprocessor should be established, and a case must be made why the desired functionality cannot be achieved, or would not be commercially viable, using Synap's own infrastructure.&#x20;
2. The types and volume of data that the subprocessor would be processing should be established - this should include at a minimum, whether the subprocessor would be processing personal data of our customers or their end-users, the confidential information / intellectual property of our customers, and/or any 'special category' data.&#x20;
3. The proposed subprocessor should be evaluated by Synap's Data Protection Manager, to determine whether such processing would be lawful (in accordance with the General Data Protection Regulation and Data Protection Act 2018), and in line with industry best practice. Specifically, we would look to ascertain:
   1. Does the subprocessor encrypt data, in-transit and at-rest, and are these measures in line with current industry standards?
   2. Is the subprocessor a valid legal entity, operating in a country with equivalent comparable data protection standards to the United Kingdom / European Union? If the subprocessor is not based in the UK/EU, do they warrant that data from EU customers on their platform, will be processed in accordance with the GDPR?
   3. What can be ascertained and verified about the subprocessor's reputation and standing within the industry? For example, are they a recognised market leader, are they used by other reputable companies, and do they have a history of publicised data breaches?
   4. What other options are available for tools of this category? Who are the subprocessor's competitors and are there any significant differences between them, from a data security perspective?
   5. What subprocessors does the proposed subprocessor use themselves, and do these meet the above criteria?&#x20;
   6. What would be the impact on business continuity and our customers' data if the subprocessor were, either temporarily or permanently, taken offline, or if they suffered a data breach?&#x20;

Synap's Data Protection Manager should use the above information to determine the risks and benefits of using the proposed subprocessor, along with an opinion on whether or not they meet the standard we require.&#x20;

### Review of Existing Subprocessors

Synap regularly reviews the use of, and agreements we have in place with our subprocessors. This takes place at a minimum every 12 months, however in practice this is more frequent given the evolving nature of cloud services and data protection law.&#x20;

When re-evaluating an existing subprocessor, the same general principles as outlined in the 'Appointment' section above should be followed.&#x20;

### Subprocessor List

#### For All Synap Service Users

We use the following subprocessors for all Synap Users - including End-Users (e.g. Students/Candidates) as well as Admin Users. &#x20;

* Amazon Web Services EMEA (EU) - AWS are a leading provider of cloud hosting services. We use their infrastructure to deliver the Synap platform. [DPA](https://d1.awsstatic.com/legal/aws-gdpr/AWS_GDPR_DPA.pdf).&#x20;
* MongoDB (EU) - MongoDB provide cloud database solutions, we license their technology for use in on AWS infrastructure. [DPA](https://www.mongodb.com/legal/dpa).&#x20;
* Sendgrid (US) - Owned and operated by Twilio, Sendgrid is a leading provider of email delivery services. We use Sendgrid to send automated emails from the Synap platform (e.g. password resets requests, welcome emails and other notification-related emails).[ Info](https://www.rosalyn.ai/trust).
* Datadog (US) - Datadog is a cloud-based log ingestion service which allows us to monitor requests being made to our system, and analyse server capacity. [DPA](https://www.datadoghq.com/legal/data-processing-addendum/).

#### Optional Subprocessors

The following subprocessors are used on an opt-in basis, e.g. if you explicitly choose to use a certain part of the Synap platform

* **Rosalyn Inc (US)** - Rosalyn is a provider of live, AI-powered proctoring services. We integrate with their platform to offer a seamless proctored exam experience. Where Rosalyn is used, this is clearly indicated on your platform so you have the option of using or not using Rosalyn as you deem appropriate. [Privacy Policy](https://www.rosalyn.ai/trust-center). <br>

#### Exam Support / Ad-Hoc Subprocessors

From time to time, Synap Customers may request that Synap takes a more hands-on approach to managing or supervising their exams, for example to deliver exam-day support, and/or to monitor issues.&#x20;

In these circumstances, with the consent of the Customer Synap may also use the following subprocessors, or other subprocessors if approved or requested by the Customer:

* Intercom (US) - A web-based chat and customer support provider
* Segment (US, with EU data center) - A customer data infrastructure tool that helps us to keep our customer data in sync and secure across different tools that we use
* FullStory (US) - A session recording tool that helps us to understand how admin users are interacting with the Synap platform, and to identify common issues

#### For Synap Admin Users Only

For Admin users of a Synap Service, we use additional subprocessors so that we can provide you with appropriate support and other services.

* Intercom (US) - A web-based chat and customer support provider
* Vitally (US)  - A CRM tool that allows our team to administer training, onboarding and general support to our Customers (e.g. admin users of the Synap platform)
* Attio (US) - A CRM tool that allows our team to administer training, onboarding and general support to our Customers (e.g. admin users of the Synap platform)
* Segment (US, with EU data center) - A customer data infrastructure tool that helps us to keep our customer data in sync and secure across different tools that we use
* Calendly (US) - A meeting-booking tool that helps our team to easily schedule meetings with our customers for training, support and account management purposes
* Stripe (US) - Payment processor used to process Credit/Debit card payments for Synap Customers
* GoCardless (US) - Payment processor used to process Direct Debit payments for Synap Customers
* Chargebee (US) - Subscription management tool that helps us to manage our Customer information and issue invoices and receipts
* Mixpanel (US) - A web platform analytics tool for analysing how logged-in (admin) users interact with the Synap platform
* FullStory (US) - A session recording tool that helps us to understand how admin users are interacting with the Synap platform, and to identify common issues

### Affiliates List

Synap's Data Processing Agreement makes reference to Synap Affiliates, defined as organisations controlled by, controlling or under common control in relation to Synap Learning Limited. At the time of writing, Synap does not have any Affiliate companies. If this changes in future (e.g. in the event Synap is acquired by, or acquires another company, or Synap establishes a a company in another jurisdiction), then notice will be given in accordance with our DPA and the Affiliate company will be listed here.


# Data Processing Agreement (DPA)

LAST UPDATED: 5th JUNE 2023

This Data Processing Addendum, including its annexes and the Standard Contractual Clauses, ("DPA") is made by and between Synap Learning Limited, a private limited company registered in England & Wales (“Synap”), and The Customer ("Customer"), pursuant to Synap's Terms of Service, Privacy Policy and/or other written or electronic agreement between the parties (as applicable) ("Agreement").

This DPA forms part of the Agreement and sets out the terms that apply when Personal Data is processed by Synap under the Agreement. The purpose of the DPA is to ensure such processing is conducted in accordance with applicable laws and with due respect for the rights and freedoms of individuals whose Personal Data is processed.

**1. Definitions. Any capitalized term used but not defined in this DPA has the meaning provided to it in the Agreement.**

i. **"Account Data"** means Personal Data that relates to Customer’s relationship with Synap, including to access Customer’s account and billing information, identity verification, maintain or improve performance of the Services, provide support, investigate and prevent system abuse, or fulfill legal obligations.

ii. **"Affiliate"** means any entity controlled by, controlling or under common control by an entity, where "control" means ownership of or the right to control greater than 50% of the voting securities of such entity.

iii. **"Applicable Data Protection Legislation"** refers to laws and regulations applicable to Synap's processing of personal data under the Agreement, including but not limited to (a) the GDPR, (b) in respect of the UK, the GDPR as saved into United Kingdom law by virtue of section 3 of the United Kingdom's European Union (Withdrawal) Act 2019 (**"UK GDPR"**) and the Data Protection Act 2018 (together, **"UK Data Protection Laws"**), (c) the Swiss Federal Data Protection Act and its implementing regulations (**"Swiss DPA"**), (d) the California Consumer Privacy Act (**"CCPA"**), (e) Australian Privacy Principles and the Australian Privacy Act (1988), (f) the Thailand Personal Data Protection Act (**"PDPA"**), and (g) South Africa's Protection of Personal Information Act (**"POPIA"**) in each case, as may be amended, superseded or replaced.

v. **"Controller"** or **"controller"** means the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data.

vi. **"Customer Data"** means personal data that relates to Customer’s relationship with Synap, including Personal Data that Synap processes as a Processor on behalf of Customer.

vii. **"Europe"** means for the purposes of this DPA the European Economic Area (**"EEA"**), United Kingdom (**"UK"**) and Switzerland.

viii. **"GDPR"** means Regulation 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation).

ix. **"Personal Data"** or **"personal data"** means any information, including personal information, relating to an identified or identifiable natural person (“data subject”) or as defined in and subject to Applicable Data Protection Legislation.

x. “**Privacy Policy**” means the then-current privacy policy for the Services available at <https://legal.synap.ac/privacy-policy>.

xi. **"Processor"** or **"processor"** means the entity which processes Personal Data on behalf of the Controller.

xii. **"Processing"** or **"processing"** (and **"Process"** or **"process"**) means any operation or set of operations performed upon Personal Data, whether or not by automated means, means any operation or set of operations that is performed upon Personal Data, whether or not by automatic means, such as collection, recording, securing, organization, storage, adaptation or alteration, access to, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, blocking, erasure, or destruction.

xiii. **"Restricted Transfer"** means: (i) where the GDPR applies, a transfer of personal data from the EEA to a country outside of the EEA which is not subject to an adequacy determination by the European Commission; (ii) where the UK GDPR applies, a transfer of personal data from the UK to any other country which is not based on adequacy regulations pursuant to Section 17A of the Data Protection Act 2018; and (iii) where the Swiss DPA applies, a transfer of personal data to a country outside of Switzerland which is not included on the list of adequate jurisdictions published by the Swiss Federal Data Protection and Information Commissioner.

xiv. **"Security Breach"** means a breach of security leading to any accidental, unauthorized or unlawful loss, disclosure, destruction, loss, alteration, unauthorized disclosure of, or access to Customer Data transmitted, stored or otherwise processed by Synap. A Security Incident shall not include an unsuccessful attempt or activity that does not compromise the security of Customer Data, including (without limitation) pings and other broadcast attacks of firewalls or edge servers, port scans, unsuccessful log-on attempts, denial of service attacks, packet sniffing (or other unauthorized access to traffic data that does not result in access beyond headers) or similar incidents.

xv. **"Standard Contractual Clauses"** or **"SCCs"** means (i) where the GDPR applies, the standard contractual clauses annexed to the European Commission's Implementing Decision (EU) 2021/914 of 4 June 2021 standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council, available at <https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32021D0914&from=EN> ("EU SCCs"); (ii) where the UK GDPR applies, the applicable standard data protection clauses adopted pursuant to Article 46(2)(c), or (d) where the UK GDPR means the International Data Transfer Addendum to the EU Standard Contractual Clauses issued by the Information Commissioner's Office under s.119A(1) of the Data Protection Act 2018, as such Addendum may be revised under Section 18 therein ("UK SCCs") and (iii) where the Swiss DPA applies, the applicable standard data protection clauses issued, approved or recognized by the Swiss Federal Data Protection and Information Commissioner (the "Swiss SCCs") (in each case, as updated, amended or superseded from time to time).

xvi. **"Sub-processor"** or **"sub-processor"** means (a) Synap, when Synap is processing Customer Data and where Customer is itself a processor of such Customer Data, or (b) any third-party Processor engaged by Synap or its Affiliates to assist in fulfilling Synap's obligations under the Agreement and which processes Customer Data. Sub-processors may include third parties or Synap Affiliates but shall exclude Synap employees, contractors or consultants.

xvii. **"Third Party Request"** means any request, correspondence, inquiry, or complaint from a data subject, regulatory authority, or third party.

xviii. "UK Addendum" means the International Data Transfer Addendum to the EU Standard Contractual Clauses issued by the Information Commissioner's Office under s.119A(1) of the Data Protection Act 2018, as such Addendum may be revised under Section 18 therein. This is found in Schedule 4 below.

**2. Applicability and Scope.**

i. Applicability. This DPA will apply only to the extent that Synap processes, on behalf of Customer, Personal Data to which Applicable Data Protection Legislation applies.

ii. Scope. The subject matter of the data processing is the provision of the Services, and the processing will be carried out for the duration of the Agreement. Schedule 1 (Details of Processing) sets out the nature and purpose of the processing, the types of Personal Data Synap processes and the categories of data subjects whose Personal Data is processed.

iii. Synap as a Processor. The parties acknowledge and agree that regarding the processing of Customer Data, Customer may act either as a controller or processor and Synap is a processor. Synap will process Customer Data in accordance with Customer’s instructions as set forth in Section 3 (Customer Instructions).

iv. Synap as a Controller of Account Data. The parties acknowledge that, regarding the processing of Account Data, Customer is a controller and Synap is an independent controller, not a joint controller with Customer. Synap will process Account Data as a controller (a) in order to manage the relationship with Customer; (b) carry out Synap's core business operations; (c) in order to detect, prevent, or investigate security incidents, fraud, and other abuse or misuse of the Services; (d) identity verification; (e) to comply with Synap's legal or regulatory obligations; and (f) as otherwise permitted under Applicable Data Protection Legislation and in accordance with this DPA, the Agreement, and the Privacy Policy.

**3. Synap as a Processor – Processing Customer Data.**

i. Customer Instructions. Customer appoints Synap as a processor to process Customer Data on behalf of, and in accordance with, Customer’s instructions (a) as set forth in the Agreement, this DPA, and as otherwise necessary to provide the Services to Customer (which may include investigating security incidents, and detecting and preventing exploits or abuse); (b) as necessary to comply with applicable law, including Applicable Data Protection Legislation; and (c) as otherwise agreed in writing between the parties (“Permitted Purposes”).

ii. Lawfulness of Instructions. Customer will ensure that its instructions comply with Applicable Data Protection Legislation. Customer acknowledges that Synap is neither responsible for determining which laws are applicable to Customer’s business nor whether Synap's Services meet or will meet the requirements of such laws. Customer will ensure that Synap's processing of Customer Data, when done in accordance with Customer’s instructions, will not cause Synap to violate any applicable law, including Applicable Data Protection Legislation. Synap will inform Customer if it becomes aware, or reasonably believes, that Customer’s instructions violate applicable law, including Applicable Data Protection Legislation.

iii. Additional Instructions. Additional instructions outside the scope of the Agreement or this DPA will be mutually agreed to between the parties in writing.

**4. Purpose Limitation.** \
Synap will process Personal Data in order to provide the Services in accordance with the Agreement. Schedule 1 (Details of Processing) of this DPA further specifies the nature and purpose of the processing, the processing activities, the duration of the processing, the types of Personal Data and categories of data subjects.

**5. Compliance.** \
Customer shall be responsible for ensuring that: a) all such notices have been given, and all such authorizations have been obtained, as required under Applicable Data Protection Legislation, for Synap (and its Affiliates and Sub-processors) to process Customer Data as contemplated by the Agreement and this DPA; b) it has complied, and will continue to comply, with all applicable laws relating to privacy and data protection, including Applicable Data Protection Legislation; and c) it has, and will continue to have, the right to transfer, or provide access to, Customer Data to Synap for processing in accordance with the terms of the Agreement and this DPA.

**6. Confidentiality.**

i. Confidentiality Obligations of Synap Personnel.

a. Synap requires all employees to acknowledge in writing, at the time of hire, they will adhere to terms that are in accordance with Synap's security policy and to protect Customer Data at all times. Synap requires all employees to sign a confidentiality statement at the time of hire.

b. Synap will ensure that any person that it authorizes to process Customer Data (including its staff, agents, and subcontractors) shall be subject to a duty of confidentiality (whether in accordance with Synaop's confidentiality obligations in the Agreement or a statutory duty).

ii. Responding to Third Party Requests. In the event any Third Party Request is made directly to Synap in connection with Synap's processing of Customer Data, Synap will promptly inform Customer and provide details of the same, to the extent legally permitted. Synap will not respond to any Third Party Request, without prior notice to Customer and an opportunity to object, except as legally required to do so or to confirm that such Third Party Request relates to Customer.

**7. Sub-processors.**

i. Authorization for Sub-processing. \
Customer agrees that (a) Synap may engage Sub-processors as listed at <https://legal.synap.ac/subprocessors-list-and-management-policy> (the "Sub-processor Page") which may be updated from time to time.

ii. Current Sub-processors and Notification of Sub-processor Additions.

a. Customer understands that effective operation of the Services may require the transfer of Customer Data to Synap Affiliates, or to Synap's Sub-processors, see Schedule 3. Customer hereby provides general authorization to Synap engaging additional third-party Sub-processors to process Customer Data within the Services for the Permitted Purposes.

b. Synap may, by giving reasonable notice to the Customer, add to the Sub-processor Page. Synap will notify Customer if it intends to add or replace Sub-processors from the Sub-Processor Page at least 10 days prior to any such changes. Customer will be notified via the email address listed as the Account Owner on Customer's Synap portal. If Customer objects to the appointment of an additional Sub-processor within thirty (30) calendar days of such notice on reasonable grounds relating to the protection of the Personal Data, then Synap will work in good faith with Customer to find an alternative solution. In the event that the parties are unable to find such a solution, Customer may terminate the Agreement at no additional cost.

**8. Impact Assessments and Consultations.** \
Synap shall, to the extent required by Applicable Data Protection Legislation, provide Customer with reasonable assistance (at Customer's cost and expense) with data protection impact assessments or prior consultations with data protection authorities that Customer is required to carry out under such legislation.

**9. Security.**

i. Synap has in place and will maintain throughout the term of this Agreement appropriate technical and organizational measures designed to protect Customer Data against Security Breaches.

ii. These measures shall at a minimum comply with applicable law and include the measures identified in Schedule 2 (Technical and Organizational Security Measures).

iii. Customer acknowledges that the security measures are subject to technical progress and development and that Synap may update or modify the security measures from time to time, provided that such updates and modifications do not result in the degradation of the overall security of the Services purchased by the Customer.

iv. Synap will ensure that any person authorized to process Customer Data (including its staff, agents, and subcontractors) shall be subject to a duty of confidentiality.

v. Upon becoming aware of a Security Breach involving Customer Data processed by Synap on behalf of Customer under this DPA, Synap shall notify Customer without undue delay and shall provide such information as Customer may reasonably require, including to enable Customer to fulfil its data breach reporting obligations under Applicable Data Protection Legislation.

vi. Synap's notification of or response to a Security Breach shall not be construed as an acknowledgement by Synap of any fault or liability with respect to the Security Breach.

vii. Customer is solely responsible for its use of the Service, including (a) making appropriate use of the Service to ensure a level of security appropriate to the risk in respect of Customer Data; (b) securing the account authentication credentials, systems and devices Customer uses to access the Service; and (c) backing up Customer Data.

**10. Return or Deletion of Customer Data.** \
Upon termination or expiry of this Agreement, Synap will (at Customer's election) delete or return to Customer all Customer Data (including copies) in its possession or control as soon as reasonably practicable and within a maximum period of 30 days of termination or expiry of the Agreement, save that this requirement will not apply to the extent that Synap is required by applicable law to retain some or all of the Customer Data, or to Customer Data it has archived on back-up systems, which Customer Data Synap will securely isolate and protect from any further processing, except to the extent required by applicable law.

**11. Audits.**

i. The parties acknowledge that when Synap is acting as a processor on behalf of Customer, Customer must be able to assess Synap's compliance with its obligations under Applicable Data Protection Legislation and this DPA.

ii. Synap shall make available to Customer all information reasonably necessary to demonstrate compliance with this DPA and the obligations under Article 28 of the GDPR. While it is the parties' intention ordinarily to rely on the provision of the documentation to demonstrate Synap's compliance with this DPA and the provisions of Article 28 of the GDPR, Synap shall permit Customer (or its appointed third party auditors) to carry out an audit at Customer’s cost and expense (including without limitation the costs and expenses of Synap) of Synap's processing of Customer Data under the Agreement following a Security Breach suffered by Synap, or upon the instruction of a data protection authority acting pursuant to Applicable Data Protection Legislation. Customer must give Synap reasonable prior notice of such intention to audit, conduct its audit during normal (UK) business hours, and take all reasonable measures to prevent unnecessary disruption to Synap's operations. Any such audit shall be subject to Synap's security and confidentiality terms and guidelines and may only be performed a maximum of once annually. If Synap declines to follow any instruction requested by Customer regarding audits, Customer is entitled to terminate the Agreement.

iii. Synap uses external auditors to verify the adequacy of its security measures with respect to its processing of Customer Data. A description of Synap's certifications and standards for audit can be found at <https://legal.synap.ac/security-policy>.

**12. Transfer Mechanisms.**

i. Location of Processing. Customer acknowledges that Synap and its Sub-processors may transfer and process personal data to and in Europe and other locations in which Synap, its Affiliates or its Sub-processors maintain data processing operations, as more particularly described in the Sub-processor Page. Synap shall ensure that such transfers are made in compliance with Applicable Data Protection Legislation and this DPA.

ii. Transfer Mechanism. The parties agree that when the transfer of personal data from Customer (as "data exporter") to Synap (as "data importer") is a Restricted Transfer and Applicable Data Protection Legislation require that appropriate safeguards are put in place, such transfer shall be subject to the appropriate Standard Contractual Clauses, which shall be deemed incorporated into and form part of this DPA, as follows:

a. In relation to transfers of Customer Data that is protected by the GDPR, the EU SCCs shall apply, completed as follows:

1. Module Two or Module Three will apply (as applicable);
2. in Clause 7, the optional docking clause will apply;
3. in Clause 9, Option 2 will apply, and the time period for prior notice of Sub-processor changes shall be as set out in section 7.ii.b of this DPA;
4. in Clause 11, the optional language will not apply;
5. in Clause 17, Option 1 will apply, and the EU SCCs will be governed by the laws of England & Wales, or, if required by Applicable Data Protection Legislation, by the courts of the EU Member State in which the data exporter is estblished and otherwise in.&#x20;
6. in Clause 18(b), disputes shall be resolved before the courts of England & Wales, or, if required by Applicable Data Protection Legislation, by the courts of the EU Member State in which the data exporter is established and otherwise in&#x20;
7. Annex I of the EU SCCs shall be deemed completed with the information set out in Schedule 1 to this DPA; and
8. Subject to section 9.iii of this DPA, Annex II of the EU SCCs shall be deemed completed with the information set out in Schedule 2 to this DPA;

b. In relation to transfers of Account Data protected by the GDPR and processed in accordance with Section 2.iv of this DPA, the EU SCCs shall apply, completed as follows:

1. Module One will apply;
2. in Clause 7, the optional docking clause will apply;
3. in Clause 11, the optional language will not apply;
4. in Clause 17, Option 1 will apply, and the EU SCCs will be governed by the laws of England & Wales;
5. in Clause 18(b), disputes shall be resolved before the courts of England & Wales;
6. Annex I of the EU SCCs shall be deemed completed with the information set out in Schedule 1 to this DPA; and
7. Subject to section 9.iii of this DPA, Annex II of the EU SCCs shall be deemed completed with the information set out in Schedule 2 to this DPA;

c. In relation to transfers of personal data protected by the UK GDPR or Swiss DPA, the EU SCCs as implemented under sub-paragraphs (a) and (b) above will apply with the following modifications:

1. references to "Regulation (EU) 2016/679" shall be interpreted as references to UK Privacy Laws or the Swiss DPA (as applicable);
2. references to specific Articles of "Regulation (EU) 2016/679" shall be replaced with the equivalent article or section of UK Privacy Laws or the Swiss DPA (as applicable);
3. references to "EU", "Union", "Member State" and "Member State law" shall be replaced with references to "UK" or "Switzerland", or "UK law" or "Swiss law" (as applicable);
4. the term "member state" shall not be interpreted in such a way as to exclude data subjects in the UK or Switzerland from the possibility of suing for their rights in their place of habitual residence (i.e., the UK or Switzerland);
5. Clause 13(a) and Part C of Annex I are not used and the "competent supervisory authority" is the UK Information Commissioner or Swiss Federal Data Protection Information Commissioner (as applicable);
6. references to the "competent supervisory authority" and "competent courts" shall be replaced with references to the "Information Commissioner" and the "courts of England and Wales" or the "Swiss Federal Data Protection Information Commissioner" and "applicable courts of Switzerland" (as applicable);
7. in Clause 17, the Standard Contractual Clauses shall be governed by the laws of England and Wales or Switzerland (as applicable); and
8. with respect to transfers to which UK Privacy Laws apply, Clause 18 shall be amended to state "Any dispute arising from these Clauses shall be resolved by the courts of England and Wales. A data subject may bring legal proceeding against the data exporter and/or data importer before the courts of any country in the UK. The Parties agree to submit themselves to the jurisdiction of such courts", and with respect to transfers to which the Swiss DPA applies, Clause 18(b) shall state that disputes shall be resolved before the applicable courts of Switzerland.

d. To the extent that and for so long as the EU SCCs as implemented in accordance with sub-paragraph (a)-(c) above cannot be used to lawfully transfer Customer Data and Account Data in accordance with the UK GDPR to Synap, the UK SCCs shall be incorporated into and form an integral part of this DPA and shall apply to transfers governed by the UK GDPR. For the purposes of the UK SCCs, the relevant annexes, appendices or tables shall be deemed populated with the information set out in Schedules 1 and 2 of this DPA.

1. in relation to data that is protected by the UK GDPR, the EU SCCs will apply as follows: (i) apply as completed in accordance with paragraph 7(a) above; and (ii) be deemed amended as specified by Part 2 of the UK Addendum, which shall be deemed incorporated into and form an integral part of this DPA. In addition, tables 1 to 3 in Part 1 of the UK Addendum shall be completed respectively with the information set out in Schedule I and Schedule II of this DPA and table 4 in Part 1 of the UK Addendum shall be deemed completed by selecting "neither party".

e. It is not the intention of either party to contradict or restrict any of the provisions set forth in the Standard Contractual Clauses and, accordingly, if and to the extent the Standard Contractual Clauses conflict with any provision of the Agreement (including this DPA) the Standard Contractual Clauses shall prevail to the extent of such conflict.

iii. Alternative Transfer Mechanism. To the extent that Synap adopts an alternative data export mechanism (including any new version of or successor to the Standard Contractual Clauses adopted pursuant to Applicable Data Protection Legislation) (**"Alternative Transfer Mechanism"**), the Alternative Transfer Mechanism shall upon notice to Customer and an opportunity to object, apply instead of any applicable transfer mechanism described in this DPA (but only to the extent such Alternative Transfer Mechanism complies with Applicable Data Protection Legislation applicable to Europe and extends to territories to which Customer Data and Account Data is transferred).

**13. Co-operation and Data Subject Rights.**

i. Data Subject Rights. Synap shall, taking into account the nature of the processing, provide reasonable assistance to Customer where possible and at Customer's cost and expense, to enable Customer to respond to requests from a data subject seeking to exercise their rights under Applicable Data Protection Legislation. In the event that such request is made directly to Synap, if Synap can, through reasonable means, identify the Customer as the controller of the Personal Data of a data subject, Synap shall promptly inform Customer of the same

ii. Co-operation. In the event that either party receives (a) any request from a data subject to exercise any of its rights under Applicable Data Protection Legislation or (b) any Third Party Request relating to the processing of Account Data or Customer Data conducted by the other party, such party will promptly inform the other party in writing. The parties agree to co-operate, in good faith, as necessary to respond to any Third Party Request and fulfill their respective obligations under Applicable Data Protection Legislation.

**14. Miscellaneous.**

i. If there is a conflict between the Agreement and this DPA, the terms of this DPA will prevail. The order of precedence will be: (a) this DPA; (a) the Agreement; and (c) the Privacy Policy. To the extent there is any conflict between the Standard Contractual Clauses, and any other terms in this DPA, the Agreement, or the Privacy Policy, the provisions of the Standard Contractual Clauses will prevail.

ii. Any claims brought in connection with this DPA will be subject to the terms and conditions, including, but not limited to, the exclusions and limitations set forth in the Agreement.

iii. In no event does this DPA restrict or limit the rights of any data subject or of any competent supervisory authority.

iv. In the event (and to the extent only) of a conflict (whether actual or perceived) among Applicable Data Protection Legislation, the parties (or relevant party as the case may be) shall comply with the more onerous requirement or standard which shall, in the event of a dispute in that regard, be solely determined by Synap.

v. Notwithstanding anything else to the contrary in the Agreement and without prejudice to Sections 2(iii) and 2 (iv), Synap reserves the right to make any modification to this DPA as may be required to comply with Applicable Data Protection Legislation.

vi. Except as amended by this DPA, the Agreement will remain in full force and effect.

vii. Notwithstanding anything in the Agreement or any order form entered in connection therewith, the parties acknowledge and agree that Synap access to Customer Data does not constitute part of the consideration exchanged by the parties in respect of the Agreement.

viii. Notwithstanding anything to the contrary in this DPA or in the Agreement (including, without limitation, either party’s indemnification obligations), neither party will be responsible for any GDPR fines issued or levied under Article 83 of the GDPR against the other party by a regulatory authority or governmental body in connection with such other party’s violation of the GDPR.

ix. Notwithstanding anything to the contrary in this DPA or in the Agreement (including, without limitation, either party’s indemnification obligations), neither party will be responsible for any UK GDPR fines issued or levied under Article 83 of the UK GDPR against the other party by a regulatory authority or governmental body in connection with such other party’s violation of the UK GDPR.

The parties have caused this DPA to be executed by their authorized representatives, and this DPA, including its annexes and the Standard Contractual Clauses, will be effective on the date both parties have signed it.

| Signed on behalf of Customer | Signed on behalf of Synap |
| ---------------------------- | ------------------------- |
| Company Legal Name:          | Synap Learning Limited    |
| Signed:                      | Signed:                   |
| Name:                        | Name:                     |
| Title:                       | Title:                    |
| Date:                        | Date:                     |

**Schedule 1**

**DETAILS OF PROCESSING**

**Annex I**

**A. LIST OF PARTIES**

Data exporter(s): \[*Identity and contact details of the controller(s) /data exporter(s) and, where applicable, of its/their data protection officer and/or representative in the European Union*]

| Name of Data exporter:                                           | The party identified as the "Customer" in the Agreement and this DPA                           |
| ---------------------------------------------------------------- | ---------------------------------------------------------------------------------------------- |
| Address:                                                         | As set forth in the Agreement                                                                  |
| Contact person’s name, position, and contact details:            | As set forth in the Agreement                                                                  |
| Activities relevant to the data transferred under these Clauses: | See Annex 1(B) below                                                                           |
| Signature and date:                                              | This Annex I shall automatically be deemed executed when the Agreement is executed by Customer |
| Role (controller/processor):                                     | Controller or Processor                                                                        |

Data importer(s): \[*Identity and contact details of the processor(s) /data importer(s), including any contact person with responsibility for data protection*]

| Name:                                                            | As set forth in the Agreement                                                                |
| ---------------------------------------------------------------- | -------------------------------------------------------------------------------------------- |
| Address:                                                         | As set forth in the Agreement                                                                |
| Contact person’s name, position, and contact details:            | Synap Privacy Team – \[<legal@synap.ac>]\(<legal@synap.ac>)                                  |
| Activities relevant to the data transferred under these Clauses: | See Annex 1(B) below                                                                         |
| Signature and date:                                              | This Annex I shall automatically be deemed executed when the Agreement is executed by Synap. |
| Role (controller/processor):                                     | Processor                                                                                    |

**B. DESCRIPTION OF PROCESSING/ TRANSFER**

| Categories of Data Subjects whose personal data is transferred                                          | <p>Module One<br>Customer’s employees and individuals authorized by Customer to access Customer’s Synap account in an administrative capacity<br><br>Module Two<br>Customer's 'end users' (e.g. students, employees, customers) and/or other persons authorized by Customer to access Customer's Synap account in a 'student' / end-user capacity</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| ------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Categories of Personal Data transferred                                                                 | <p>Module One<br>Account Data which constitutes Personal Data, such as name and contact information as well as Customer billing address.<br><br>Module Two<br>Any Customer Data processed by Synap in connection with the Services and which could constitute any type of Personal Data included in Synap assessment activities, including, without limitation, username, password, email address, IP address. Other personal data may also be collected as defined by Customer via 'custom attributes' but subject to the clause below ("Sensitive data"), Customer warrants that such fields and functionality will not be used to collect sensitive or special category data. </p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| Sensitive data transferred (if applicable) and applied restrictions or safeguards                       | Synap does not knowingly collect (and Customer shall not submit) any sensitive data or any special categories of data (as defined under Applicable Data Protection Legislation).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| Frequency of the transfer                                                                               | Continuous.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Nature and purpose(s) of the data transfer and Processing                                               | <p><strong>Module One</strong><br>Personal data contained in Account Data will be processed to manage the account, including to access Customer’s account and billing information, for identity verification, to maintain or improve the performance of the Services, to provide support, to investigate and prevent system abuse, or to fulfill legal obligations.<br><br><strong>Module Two</strong><br>Personal Data contained in Customer Data will be subject to the following basic processing activities:<br><br>Synap provides an online assessment platform which Customer can use to deliver exams and other learning activities to their End Users. This service will consist of providing a platform for the Customer to use in order to use for training, education, assessment and/or other purposes in accordance with Customer's business goals.<br><br>Synap will process personal data as necessary to provide the Services under the Agreement. Synap does not sell Customer’s Personal Data or Customer end users’ Personal Data and does not share such end users’ Personal Data with third parties for compensation or for those third parties’ own business interests.<br><br>Additional details about Synap's products and services can be found at <a href="https://synap.ac"><https://synap.ac></a></p> |
| Retention period (or, if not possible to determine, the criterial used to determine the period)         | <p><strong>Module One</strong><br>Synap will process Account Data as long as required (a) to provide the Services to Customer; (b) for Synap's lawful and legitimate business needs; or (c) in accordance with applicable law or regulation. Account Data will be stored in accordance with the <a href="https://legal.synap.ac/privacy-policy">Privacy Policy</a>.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
|                                                                                                         | <p><strong>Modules Two and Three</strong><br>Upon termination or expiry of this Agreement, Synap will (at Customer's election) delete or return to Customer all Customer Data (including copies) in its possession or control as soon as reasonably practicable and within a maximum period of 30 days of termination or expiry of the Agreement, save that this requirement will not apply to the extent that Synap is required by applicable law to retain some or all of the Customer Data, or to Customer Data it has archived on back-up systems, which Customer Data Synap will securely isolate and protect from any further processing, except to the extent required by applicable law.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| For transfers to (sub-) processors, also specify subject matter, nature, and duration of the processing | <p>Module Two only<br>Synap will restrict the onward sub-processor’s access to Customer Data only to what is strictly necessary to provide the Services, and Synap will prohibit the sub-processor from processing the Personal Data for any other purpose.<br><br>Synap imposes contractual data protection obligations, including appropriate technical and organizational measures to protect personal data, on any sub-processor it appoints that require such sub-processor to protect Customer Data to the standard required by Applicable Data Protection Legislation.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| Identify the competent supervisory authority/ies in accordance with Clause 13                           | Where the EU GDPR applies, the competent supervisory authority shall be (i) the supervisory authority applicable to the data exporter in its EEA country of establishment or, (ii) where the data exporter is not established in the EEA, the supervisory authority applicable in the EEA country where the data exporter's EU representative has been appointed pursuant to Article 27(1) GDPR, or (iii) where the data exporter is not obliged to appoint a representative, the supervisory authority applicable to the EEA country where the data subjects relevant to the transfer are located. Where the UK GDPR applies, the UK Information Commissioner's Office.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |

**Schedule 2**&#x20;

**TECHNICAL AND ORGANIZATIONAL SECURITY MEASURES**

**Annex II**

Further details of Synap's technical and organizational security measures to protect Customer Data are available at:

* <https://legal.synap.ac/security-policy>
* <https://legal.synap.ac/data-breach-management-policy>
* <https://legal.synap.ac/privacy-policy>

Where applicable, this Schedule 2 will serve as Annex II to the Standard Contractual Clauses. The following table provides more information regarding the technical and organizational security measures set forth below.

| Technical and Organizational Security Measure                                                                                                                                                 | Evidence of Technical and Organizational Security Measure                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Measures of pseudonymisation and encryption of personal data                                                                                                                                  | <ul><li>All data sent to or from Synap is encrypted in transit using TLS 1.2 or higher.</li><li>Customer Personal Data is encrypted at rest using 256-bit AES encryption</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| Measures for ensuring ongoing confidentiality, integrity, availability and resilience of processing systems and services                                                                      | <ul><li>Synap has implemented a formal procedure for handling security events. When security events are detected, they are escalated to an emergency alias, relevant parties are paged, notified, and assembled to rapidly address the event. After a security event is contained and mitigated, relevant teams write up a post-mortem analysis, which is reviewed in person and distributed across the company and includes action items that will make the detection and prevention of a similar event easier in the future.</li><li>All Customer Data is permanently stored in Europe and is backed up for disaster recovery.</li><li>Synap relies on Amazon Web Services (AWS), a reputable Infrastructure-as-a-Service provider, as well as MongoDb, a reputable Database-as-a-Service provider. Synap leverages their portfolio of services to ensure Services run reliably. Synap benefits from the ability to dynamically scale up, or completely re-provision its infrastructure resources on an as-needed basis, across multiple geographical areas, using the same vendor, tools, and APIs. Synap's own infrastructure scales up and down on demand as part of day-to-day operations and does so in response to any changes in our customers’ needs. This includes not just compute resources, but storage and database resources, networking, security, and DNS. Every component in Synap's infrastructure is designed and built for high availability.</li><li>Synap's data security, high availability, and built-in redundancy are designed to ensure application availability and protect information from accidental loss or destruction. Synap's Disaster Recovery plan incorporates geographic failover. Subscription Service restoration is within commercially reasonable efforts and is performed in conjunction with AWS’ ability to provide adequate infrastructure at the prevailing failover location. All of Synap's recovery and resilience mechanisms are tested regularly and processes are updated as required.</li><li>Synap's availability is monitored 24/7 via automated alerts, with senior on-call engineers being alerted as soon as an issue is detected. </li><li>Synap has no direct reliance on specific office locations to sustain operations. All operational access to production resources can be exercised - by authorized employees - at any location on the Internet. Synap leverages a range of best-of- breed technologies and other critical cloud tools to deliver uninterrupted remote work for all employees.</li><li>Automatic, encrypted backups are taken hourly, daily, weekly and monthly and stored securely.</li></ul> |
| Measures for ensuring the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident                                 | <ul><li>Synap's mission-critical infrastructure is designed to meet a Recovery Time Objective of 30 minutes, and a Recovery Point Objective of 60 minutes. </li><li>Synap has a documented Incident Response / Disaster Management policy which is tested regularly. </li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Processes for regularly testing, assessing, and evaluating the effectiveness of technical and organizational measures in order to ensure the security of the processing                       | <ul><li>Synap regularly tests their security systems and processes to ensure they meet the requirements of this security policy. Synap maintains a CyberEssentials certification, a copy of which is available on request.</li><li>Application Scans. Synap performs periodic (but no less than once per month) application vulnerability scans and pentration tests. Vulnerabilities shall be remediated on a risk basis.</li><li>Synap uses industry-leading tools to assess our source code and open source  dependencies for vulnerabilities</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| Measures for user identification and authorisation                                                                                                                                            | <p></p><ul><li>All access to systems processing Customer Data is protected by Multi Factor Authentication (MFA). Customer Administrator accounts can also be protected with MFA. </li><li>Synap restricts access to Customer Data to only those people with a “need-to-know” for a Permitted Purpose and following least privileges principles.</li><li>Synap regularly reviews at least every 180 days the list of people and systems with access to Customer Data and removes accounts upon termination of employment or a change in job status that results in employees no longer requiring access to Customer Data.</li><li>Synap mandates and ensures the use of system-enforced “strong passwords” in accordance with the best practices (described below) on all systems hosting, storing, processing, or that have or control access to Customer Data and will require that all passwords and access credentials are kept confidential and not shared among personnel.</li><li>Password best practices implemented by Synap's organisational password manager. Passwords must meet the following criteria: a. contain at least 10 characters; b. must contain lowercase and uppercase letters, numbers, and a special character; c. cannot be part of a vendor provided list of common passwords.</li><li>Synap does not operate any internal corporate network. All access to Synap resources is protected by strong passwords and MFA.</li><li>Synap monitors their production systems and implements and maintains security controls and procedures designed to prevent, detect, and respond to identified threats and risks.</li><li>Strict privacy controls exist in the application code that are designed to ensure data privacy and to prevent one customer from accessing another customer’s data (i.e., logical separation).</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| Measures for the protection of data during transmission                                                                                                                                       | <ul><li>See “<em>Measures of pseudonymisation and encryption of personal data</em>” above.</li><li>See <a href="https://legal.synap.ac/security-policy"><https://legal.synap.ac/security-policy></a></li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| Measures for the protection of data during storage                                                                                                                                            | <ul><li>Intrusion Prevention. Synap implements and maintains a working network firewall to protect data accessible via the Internet and will keep all Customer Data protected by the firewall at all times.</li><li>Synap keeps its systems and software up to date with the latest upgrades, updates, bug fixes, new versions, and other modifications necessary to ensure security of the Customer Data.</li><li>Security Awareness Training. Synap requires annual security and privacy training for all employees with access to Customer Data.</li><li>Synap uses anti-malware software and keeps the anti-malware software up to date. Customer instances are logically separated and attempts to access data outside allowed domain boundaries are prevented and logged.</li><li>Endpoint security software</li><li>System inputs recorded via log files</li><li>Access Control Lists (ACL)</li><li>Multi-factor Authentication (MFA)</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| Measures for ensuring physical security of locations at which personal data are processed                                                                                                     | <ul><li>Physical Access Control. Synap's services and data are hosted in AWS’ facilities in Europe and protected by AWS in accordance with their security protocols.</li><li>Access only to approved personnel.</li><li>All personnel who need data center access must first apply for access and provide a valid business justification. These requests are granted based on the principle of least privilege and are time-bound. Requests are reviewed and approved by authorized personnel, and access is revoked after the requested time expires.</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| Measures for ensuring events logging                                                                                                                                                          | <ul><li>See “Measures for the protection of data during storage” above.</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| Measures for ensuring system configuration, including default configuration                                                                                                                   | <ul><li>Change and Configuration Management. Synap uses continuous automation for application and operating systems deployment for new releases. Integration testing and unit testing are done upon every build with safeguards in place for availability and reliability. Synap has a process for critical emergency fixes that can be deployed to Customers within minutes. As such Synap can roll out security updates as required based on criticality.</li><li>Access Control Policy and Procedures</li><li>Change Management Procedures</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| Measures for internal IT and IT security governance and management                                                                                                                            | <ul><li>Information security management procedures in accordance with the UK National Crime and Cybersecurity Center (NSCC) CyberEssentials Framework and Certification</li><li>Information security policy</li><li>Data Breach Management Policy</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| Measures for certification/assurance of processes and products                                                                                                                                | <ul><li>See <a href="https://legal.synap.ac/security-policy"><https://legal.synap.ac/security-policy></a></li><li>CyberEssentials Certification: <a href="https://registry.blockmarktech.com/certificates/b5109b99-aae2-4584-a11a-f0e662bde534/"><https://registry.blockmarktech.com/certificates/b5109b99-aae2-4584-a11a-f0e662bde534/></a></li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| Measures for ensuring data minimisation                                                                                                                                                       | <ul><li>Data collection is limited to the purposes of processing (or the data that the Customer chooses to provide).</li><li>Security measures are in place to provide only the minimum amount of access (least privilege) necessary to perform required functions.</li><li>Upon termination or expiry of this Agreement, Synap will (at Customer's election) delete or return to Customer all Customer Data (including copies) in its possession or control as soon as reasonably practicable and within a maximum period of 30 days of termination or expiry of the Agreement, save that this requirement will not apply to the extent that Synap is required by applicable law to retain some or all of the Customer Data, or to Customer Data it has archived on back-up systems, which Customer Data Synap will securely isolate and protect from any further processing, except to the extent required by applicable law.</li><li>More information about how Synap processes personal data is set forth in the Privacy Policy available at <a href="https://legal.synap.ac/privacy-policy"><https://legal.synap.ac/privacy-policy></a>, and our Candidate/End User privacy policy available at <a href="https://legal.synap.ac/candidate-privacy-policy"><https://legal.synap.ac/candidate-privacy-policy></a> </li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Measures for ensuring data quality                                                                                                                                                            | <ul><li>Synap has a process that allows data subjects to exercise their privacy rights (including a right to amend and update their Personal Data), as described in Synap's Privacy Policy.</li><li>See “Measures for ensuring ongoing confidentiality, integrity, availability and resilience of processing systems and services” above.</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| Measures for ensuring limited data retention                                                                                                                                                  | <ul><li>See “<em>Measures for ensuring data minimization</em>” above.</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Measures for ensuring accountability                                                                                                                                                          | <ul><li>Synap has implemented data protection policies</li><li>Synap follows a compliance by design approach</li><li>Synap maintains documentation of your processing activities</li><li>Synap has appointed a data protection officer</li><li>Synap adheres to relevant codes of conduct and signing up to certification schemes (see “Measures for certification/assurance of processes and products” above).</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| Measures for allowing data portability and ensuring erasure                                                                                                                                   | <ul><li>Secure Disposal. Return or Deletion. Synap will permanently and securely delete all live (online or network accessible) instances of the Customer Data within 90 days upon Customer’s in-app deletion request.</li><li>Archival Copies. When required by law to retain archival copies of Customer Data for tax or similar regulatory purposes, this archived Customer Data is stored as a “cold” or offline (i.e., not available for immediate or interactive use) backup stored in a physically secure facility.</li><li>Synap has a process that allows data subjects to exercise their privacy rights (including a right to amend and update their Personal Data), as described in Synap's Privacy Policy.</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| Technical and organizational measures to be taken by the \[sub]-processor to provide assistance to the controller and, for transfers from a processor to a \[sub]-processor, to the Customer. | <ul><li>Vendor & Services Providers. Prior to engaging new third-party service providers or vendors who will have access to Synap Data, Synap conducts a risk assessment of vendors’ data security practices.</li><li>Synap will restrict the onward sub-processor’s access to Customer Data only to what is strictly necessary to provide the Services, and Synap will prohibit the sub-processor from processing the Personal Data for any other purpose.</li><li>Synap imposes contractual data protection obligations, including appropriate technical and organizational measures to protect personal data, on any sub-processor it appoints that require such sub-processor to protect Customer Data to the standard required by Applicable Data Protection Legislation.</li><li>See Subprocessors List & Management Policy, available at <a href="https://legal.synap.ac/subprocessors-list-and-management-policy"><https://legal.synap.ac/subprocessors-list-and-management-policy></a></li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |

**Schedule 3**

**LIST OF SUB-PROCESSORS**

**Annex III**

In Clause 9 of the 2021 Standard Contractual Clauses, Option 2 will apply and the time period for prior notice of sub-processor changes will be as set forth in Section 7.ii (Current Sub-processors and Notification of Sub-processor Changes) of this DPA.

Customer agrees that (a) Synap may engage Synap and Sub-processors as listed at <https://legal.synap.ac/subprocessors-list-and-management-policy> - (the "Sub-processor Page").

Synap may, by giving reasonable notice to the Customer, add or make changes to the Sub-processor Page. Synap will notify Customer if it intends to add or replace Sub-processors from the Sub-Processor Page at least 10 days prior to any such changes. Customer will be notified via the email address listed as the Account Owner on Customer's Synap portal. If Customer objects to the appointment of an additional Sub-processor within thirty (30) calendar days of such notice on reasonable grounds relating to the protection of the Personal Data, then Synap will work in good faith with Customer to find an alternative solution. In the event that the parties are unable to find such a solution, Customer may terminate the Agreement at no additional cost.

**Schedule 4**

**UK Addendum to the EU Commission Standard Contractual Clauses**

1. Date of this Addendum: This Addendum is effective from the same date as the DPA.
2. Background: The Information Commissioner considers this Addendum to provide appropriate safeguards for the purposes of transfers of personal data to a third country or an international organisation in reliance on Articles 46 of the UK GDPR and, with respect to data transfers from controllers to processors and/or processors to processors.
3. Interpretation of this Schedule 4. Where this Addendum uses terms that are defined in the Annex those terms shall have the same meaning as in the Annex. In addition, the following terms have the following meanings:

| This Addendum           | This Addendum to the Clauses                                                                                                                                                                                  |
| ----------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| The Annex               | The Standard Contractual Clauses set out in the Annex of Commission Implementing Decision (EU) 2021/914 of 4 June 2021.                                                                                       |
| UK Data Protection Laws | All laws relating to data protection, the processing of personal data, privacy and/or electronic communications in force from time to time in the UK, including the UK GDPR and the Data Protection Act 2018. |
| UK GDPR                 | The United Kingdom General Data Protection Regulation, as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018.    |
| UK                      | The United Kingdom of Great Britain and Northern Ireland.                                                                                                                                                     |

4. This Addendum shall be read and interpreted in the light of the provisions of UK Data Protection Laws, and so that it fulfils the intention for it to provide the appropriate safeguards as required by Article 46 GDPR.
5. This Addendum shall not be interpreted in a way that conflicts with rights and obligations provided for in UK Data Protection Laws.
6. Any references to legislation (or specific provisions of legislation) means that legislation (or specific provision) as it may change over time. This includes where that legislation (or specific provision) has been consolidated, re-enacted and/or replaced after this Addendum has been entered into.
7. Hierarchy: In the event of a conflict or inconsistency between this Addendum and the provisions of the Clauses or other related agreements between the Parties, existing at the time this Addendum is agreed or entered into thereafter, the provisions which provide the most protection to data subjects shall prevail.
8. Incorporation of the Clauses: This Addendum incorporates the Clauses which are deemed to be amended to the extent necessary so they operate:

   a. for transfers made by the data exporter to the data importer, to the extent that UK Data Protection Laws apply to the data exporter’s processing when making that transfer; and

   b. to provide appropriate safeguards for the transfers in accordance with Articles 46 of the UK GDPR Laws.
9. The amendments required by Section 7 above, include (without limitation):

   a. References to the “Clauses” means this Addendum as it incorporates the Clauses.

   b. Clause 6 Description of the transfer(s) is replaced with:

   “The details of the transfers(s) and in particular the categories of personal data that are transferred and the purpose(s) for which they are transferred) are those specified in Annex I.B where UK Data Protection Laws apply to the data exporter’s processing when making that transfer”.

   c. References to “Regulation (EU) 2016/679” or “that Regulation” are replaced by “UK Data Protection Laws” and references to specific Article(s) of “Regulation (EU) 2016/679” are replaced with the equivalent Article or Section of UK Data Protection Laws.

   d. References to Regulation (EU) 2018/1725 are removed.

   e. References to the “Union”, “EU” and “EU Member State” are all replaced with the “UK”.

   f. Clause 13(a) and Part C of Annex II are not used; the “competent supervisory authority” is the Information Commissioner.

   g. Clause 17 is replaced to state “These Clauses are governed by the laws of England and Wales”.

   h. Clause 18 is replaced to state:

   “Any dispute arising from these Clauses shall be resolved by the courts of England and Wales. A data subject may also bring legal proceedings against the data exporter and/or data importer before the courts of any country in the UK. The Parties agree to submit themselves to the jurisdiction of such courts.”

   i. The footnotes to the Clauses do not form part of the Addendum.
10. Amendments to this Addendum

    b. The Parties may amend this Addendum provided it maintains the appropriate safeguards required by Art 46 UK GDPR for the relevant transfer by incorporating the Clauses and making changes to them in accordance with Section 7 above.
11. Executing this Addendum

    a. The Parties may enter into the Addendum (incorporating the Clauses) in any way that makes them legally binding on the Parties and allows data subjects to enforce their rights as set out in the Clauses. This includes (but is not limited to):

    i. By attaching this Addendum as Schedule 4 to the Synap DPA.

    ii. By adding this Addendum to the Clauses and including in the following above the signatures in Annex 1A:

    “By signing we agree to be bound by the UK Addendum to the EU Commission Standard Contractual Clauses dated:” and add the date (where all transfers are under the Addendum)

    “By signing we also agree to be bound by the UK Addendum to the EU Commission Standard Contractual Clauses dated” and add the date (where there are transfers both under the Clauses and under the Addendum)

    (or words to the same effect) and executing the Clauses; or

    iii. By amending the Clauses in accordance with this Addendum and executing those amended Clauses.


# Accessibility & Section 508

Learn about Synap's Accessibility and relevant attestations towards WCAG / Section 508 (U.S.) standards

We regularly review the Synap platform against the WCAG 2.1 criteria, which are an internationally recognised set of guidelines regarding the accessibility of web content for users with physical, sensory and/or cognitive impairments.&#x20;

Please find below a Voluntary Product Accessibility Template (VPAT) report attesting to Synap's conformity with the WCAG 2.1 guidelines.&#x20;

* Synap Web - [Student Exam Platform - WCAG 2.1 / Revised Section 508 Report ](https://drive.google.com/file/d/1XdB1gtNOXjvEM0KQwNPmdOe4snzi0Q_y/view?usp=sharing)(April 2024)

Based on the findings of this report, the Synap Web - Student Exam Platform is conformant with Level AAA of the WCAG 2.1 guidelines. It is worth pointing out that Level AAA includes several criteria that may be difficult for Synap Customers to achieve without significant consideration and/or changes to their assessment policies (e.g. the use of untimed exams, and requiring exam content to be easily understood). For this reason we generally suggest that Synap is compliant with Level AA, as when used in conjunction with most commonly accepted examination practices, or without significant and explicit consideration regarding how a set of online assessments should be adapted, it is likely that it would fail to meet Level AAA criteria.&#x20;

{% hint style="info" %}
To summarise the above, if you are delivering exams to students using Synap, you can expect WCAG 2.1 Level AA (and by extension, U.S. Section 508) compliance 'out of the box' as long as you use our authoring tools appropriately. \
\
If Level AAA compliance is important to you, then Synap does provide the foundational structure and tools for this, however you will need to take additional steps to ensure your content, and the configuration of your exam maintains that level of compliance.
{% endhint %}

Please note that this evaluation does not cover Administrator areas of the platform though this part of the site uses the same underlying methodologies and technologies as the Student platform. We aim to complete a formal evaluation in Q4 2024.&#x20;

### Notes on U.S. Section 508

The Revised 508 Standards incorporate by reference the WCAG 2.0 Level AA Success Criteria, and apply the WCAG 2.0 Level AA success criteria and conformance requirements to both web and non-web electronic content. Our understanding of this is that conformance with WCAG 2.0 (and by extension 2.1, which is a superset of 2.0) Level AA, meets the criteria set out by Section 508. Please seek independent legal advice about this if Section 508 is applicable to you.


# Candidate Privacy Policy

Candidate refers to Students, End users, using Synap through a Synap client or otherwise

If you have been registered to take an exam on Synap, this document outlines key information about what data is collected and why. Please read through it carefully. If you have any questions about these policies and how it relates to your data, then you should contact the institution that is responsible for organising your exam.&#x20;

**What is Synap?**

Synap is an online exam platform, based in the UK. We provide our platform as a web-based app which schools, universities employers can use to deliver their assessments online.&#x20;

**How do you use my data?**

**Overview**

It is your institution who are the primary 'controllers' of your data, and who decide on the overall policies around how personal data is used.&#x20;

Synap primarily uses your data for 'essential' purposes - for example, we store your name, email address and password so that you can log in to the website, and access the correct assessments.

Like most online platforms, we also collect some technical data as you are using the platform - for example, we store your IP address, and simple information about the browser and operating system that you are using. This data is used for cybersecurity purposes and to help us monitor the website to check for things that are not working.&#x20;

Sometimes, our customers (your instutition) may ask us to assist them with an issue that people are experiencing, in which case we may use the above data to help us identify and fix the issuse.&#x20;

**Proctored Exams**

If you have been registered to take a proctored exam, then additional data is gathered. Proctoring is the remote monitoring of an online exam, usually by recording a combination of your computer screen, webcam and microphone for the duration of your exam. These exams may also require an identity check which asks you to share a photo of an identification document (such as a passport or driver's license) and  to take a passport-style photo of your face via your webcam.&#x20;

During a proctored exam, additional information may also be gathered about what you are doing on your computer, such as what websites you visit during the exam and your internet connection speed.&#x20;

Synap's main role in this is to provide the software and to ensure that your data is collected securely and responsibly. This is something we take very seriously.&#x20;

**How is my data used in a proctored exam?**

The primary purpose of proctoring is to prevent and detect cheating in an online exam. This means that during or after your exam, someone will review the footage provided to look for any suspicious behaviour - such as having headphones in, or opening another website. If such behaviour is detected, then it will be flagged and timestamped.&#x20;

The final report is then reviewed and a decision is made as to whether the attempt can be accepted.&#x20;

If you are taking an exam that is proctored by Rosalyn - our proctoring partner - then they use a "human in the loop" approach to proctoring whereby an AI algorithm monitors the footage for suspicious behaviour, and alerts a human proctor who will then review the footage and intervene if necessary. No decisions are made by the AI itself.&#x20;

Final decisions on your proctoring session will most likely be made by your institution themselves, or by a trusted party they appoint to manage it on their behalf. Synap itself does not have any direct involvement with your proctoring footage, unless we have been asked by our customer to assist with the management of a particular exam, or to investigate a specific issue.&#x20;

**How long is my data stored for?**

The decision on how long to store your data - whether that is your general account data, or detailed proctoring data from your exams - lies with your institution. You should contact them if you have any questions about it.&#x20;

**Where is my data stored?**

Synap's primary data centers are located in Ireland (EU), on Amazon Web Services (AWS) infrastructure. Like most online platforms, we use a handful of 3rd party tools which also process data on our behalf - for example sending automated emails, and tracking errors on our website.&#x20;

Our proctoring partner, Roaslyn, is hosted in the US.&#x20;

**Is my data secure?**

Yes. We take data security very seriously. We adhere to industry best practices, and data protection laws such as the GDPR.&#x20;

* Data is encrypted in transit and at rest
* Only authorised Synap employees, who are directly managing your institution's exams, have the ability to access your data, and are only permitted to do so for specific purposes&#x20;
* We do not spam and would never sell your data

**What about cookies?**

Like most online platforms, we use cookies, and related technologies. Cookies are small data files that a website can store on your browser - this makes them very useful for a range of things, the most common being that it lets a webpage know that you are logged in. &#x20;

We use cookies for that reason, as well as to personalise and enhance your experience on the platform.&#x20;

We do not use 'advertising' cookies.&#x20;


# Website Terms of Use

Synap Learning Limited ("Synap", "Us", "We") welcome you to our Site! The **"Site"** means [synap.ac](https://www.intercom.com/),  and any successor URLs, mobile or localized versions and related sub-domains, in whatever format they may be offered now or in the future. Through the Site, we may provide you with general information regarding our company, products and services.

By using or accessing any part of the Site, you are agreeing to these Website Terms of Use (**"Terms"**), our [Privacy Policy](https://www.intercom.com/privacy) and all other policies or notices posted by us on our Site. We may change these Terms and Conditions at any time, and your continued use of the Websie following any changes shall be deemed to be your acceptance of such changed Terms and Conditions.

Synap also offers a suite of software-as-a-service solutions designed to enable customers to manage communications with, and data about, their end users (**"Synap Services"**). Use of the Synap Services is subject to our [Subscription Terms of Service](https://www.intercom.com/legal/website-terms-of-use#terms) , and these Terms do not apply to use of the Synap Services or receipt of related services, except where otherwise noted.

### 2. Use of the Website

You must not use the Website for any purpose that is unlawful or prohibited by these Terms and Conditions. You must not use the Website to copy, adopt, reproduce or redistribute the Website or any content on the Website in any similar way. Unauthorised attempts to upload information or change information on this Website is illegal and strictly prohibited.

You must not misuse the Website by knowingly introducing viruses, trojans, worms, logic bombs or other material which is malicious or technologically harmful. You must not attempt to gain unauthorised access to the Website, the server on which the website is hosted or any server, computer or database connected to the Website.

If you choose, or you are provided with, a user identification code, password or any other piece of information as part of our security procedures, you must treat such information as confidential, and you must not disclose it to any third party. We have the right to disable any user identification code or password, whether chosen by you or allocated by us, at any time, if in our opinion you have failed to comply with any of the provisions of these Terms and Conditions.

### 3. Changes to Website

Access to the Website is permitted on a temporary basis and we reserve the right to: (a) change or remove (temporarily or permanently) the Website or any part of it without notice and you confirm that we shall not be liable to you for any such change or removal; (b) Change these Terms and Conditions at any time, and your continued use of the Website following any changes shall be deemed to be your acceptance of such changed terms and conditions.

### 4. Links to Third Party Websites

The Website may include links to third party websites that are controlled and maintained by others. Any link to other websites is not an endorsement of such websites or of the owners of such websites or of the goods and/or services offered on such third party websites and we do not accept any responsibility in respect of such. We do not give any warranty as to the accuracy, reliability or content of any information or materials on such third party websites and shall not be liable for any loss or damage arising from their use. You acknowledge and agree that we are not responsible for the content or availability of any such sites.

### 5. Copyright and Intellectual Property

All copyright, database rights, trade marks and all other intellectual property rights in the Website and its content (including without limitation the Website design, text, graphics and all software and source codes connected with the Website) are owned by us or our licensors.

In accessing the Website you agree that you will access the content solely for your personal, non-commercial use. None of the content may be downloaded, copied, reproduced, transmitted, stored, sold or distributed without the prior written consent of the copyright holder, however you shall be entitled to download, copy and / or print pages of the Website for personal, non-commercial home use only.

No permission is given by us for use by any person of any intellectual property in the Website which may constitute an infringement of our intellectual property rights or the rights of any third party.

### 6. Disclaimers and Limitation of Liability

Although we have taken reasonable care to ensure that the information and material on the Website is accurate and up to date, we do not give any warranty or guarantee as to the accuracy or completeness of such information and material contained on the Website. The content of the Website does not constitute advice and you use the Website at your own risk.

We are not responsible for any loss or damage arising from the use of such material and information including, without limitation, for any inaccuracy, misleading statement or representation made by any third party information provided for publication on this Website.

The Website is provided strictly on an “as is” and “as available” basis without any representation or endorsement made and without warranty of any kind whether express or implied. Except as expressly set out in these terms and conditions any warranties, term and conditions implied by statute, common law or otherwise shall be excluded to the fullest extent permitted by law.

To the fullest extent permitted by law, we shall not be liable for any loss of profit; loss of business; loss of contract; loss of use; loss of or corruption to data or information; loss of anticipated savings; loss or depletion of goodwill or similar losses; or any special, indirect or consequential loss, costs or damage arising out of or in connection with these Terms and Conditions and/or the Website.

We give no warranty regarding the functionality of the Website including without limitation that the Website will be available on an uninterrupted or error free basis; that defects will be corrected; or that the Website or the server that makes it available are free of viruses or anything else which may be harmful or destructive and no liability can be accepted in respect of losses or damages arising out of such. We recommend that you take all appropriate safeguards before downloading information or images from the Website.

Nothing in these Terms and Conditions shall be construed so as to exclude or limit our liability for death or personal injury caused as a result of negligence or for fraud or fraudulent misrepresentation.

### 7. Indemnity

You agree to indemnify and keep us indemnified from and against all liabilities, legal fees, damages, losses, costs and other expenses incurred by us in relation to any claims or actions brought against us or the Website arising out of any breach by you of these Terms and Conditions or other liabilities arising out of your use of this Website.

### 8. General Terms

8.1. **Entire Agreement.** These Terms and Conditions represent the entire understanding relating to the use of the Website and supersede all other statements, representations or warranties (whether written, made by email or oral) made by us. Nothing in these Terms and Conditions shall affect the liability of either party in respect of any misrepresentation, warranty or condition that it makes fraudulently. Any rights not expressly granted in these Terms and Conditions are reserved by us.

8.2. **Jurisdiction & Governing Law.** These Terms and Conditions shall be governed by and construed in accordance with the law of England and you and us hereby submit to the exclusive jurisdiction of the English courts.

8.3. **No Waiver.** No failure or delay by us to exercise any right or remedy provided under these Terms and Conditions or by law shall constitute a waiver of that or any other right or remedy, nor shall it preclude or restrict the further exercise of that or any other right or remedy. No single or partial exercise of such right or remedy by us shall preclude or restrict the further exercise of that or any other right or remedy.

8.4.  **No Third Party.** These Terms and Conditions govern the contract between you and us in relation to your use of the website. These Terms and Conditions do not create any right for any third party who is not a party to the contract between us to enforce any term of these Terms and Conditions under the Contract (Rights of Third Parties) Act 1999.

8.5. **Severance.** If any provision contained in these Terms and Conditions should be determined to be invalid, illegal or unenforceable for any reason by any court of competent jurisdiction then such provision shall be severed and the remaining Terms and Conditions shall survive and remain in full force and effect and continue to be binding and enforceable.

### 9. Contact us

9.1 If you have any concerns about material which appears on the Website, please contact <legal@synap.ac> or write to us at the address given at the top of these Terms and Conditions.

‍


# Acceptable Use Policy

This Acceptable Use Policy applies to Synap's (a) websites (including without limitation synap.ac, any successor URLS, mobile or localized versions and related domains and subdomains) and (b) online learning products and services ((a) and (b) collectively, “Services”). To keep the Services running safely and smoothly, we need our users to agree not to misuse them. Specifically, you agree not to:

1. probe, scan, or test the vulnerability of any system or network used with the Services. If you require a penetration test or vulnerability report this must be arranged in advance and with the express permission of a Synap Authorised Representative;
2. tamper with, reverse engineer or hack the Services, circumvent any security or authentication measures of the Services or attempt to gain unauthorized access to the Services (or any portion thereof) or related systems, networks or data;
3. modify or disable the Services or use the Services in any manner that interferes with or disrupts the integrity or performance of the Services or related systems, network or data;
4. access or search the Services by any means other than our publicly supported interfaces, or copy, distribute, or disclose any part of the Service in any medium, including without limitation by any automated or non-automated “scraping”;
5. overwhelm or attempt to overwhelm our infrastructure by imposing an unreasonably large load on the Services that consume extraordinary resources, such as by: (i) using “robots,” “spiders,” “offline readers” or other automated systems to send more request messages to our servers than a human could reasonably send in the same period of time using a normal browser; or (ii) going far beyond the use parameters for any given Service as described in its corresponding documentation;
6. solicit any users of our Services for commercial purposes;
7. use the Services to generate or send unsolicited communications, advertising or spam, or otherwise cause Synap to become impaired in its ability to send communications on its own or on its customers’ behalf (e.g., by causing Synap to become registered on any Email DNS blocked list or otherwise be denied services by any other third party communications service provider);
8. misrepresent yourself or disguise the origin of any data, content or other information you submit (including by “spoofing”, “phishing”, manipulating headers or other identifiers, impersonating anyone else, or falsely implying any sponsorship or association with Synap or any third party) or access the Services via another user’s account without their permission;
9. use the Services for any illegal purpose or in violation of any laws (including without limitation data, privacy and export control laws);
10. use the Services to violate the privacy of others, or to collect or gather other users’ personal information (including account information) from our Services;
11. use the Services to stalk, harass, bully or post threats of violence against others;
12. submit (or post, upload, share or otherwise provide) data, content or other information that (i) infringes Synap or a third party’s intellectual property, privacy or other rights or that you don’t have the right to submit (including confidential or personal information you are not authorized to disclose); (ii) that is deceptive, fraudulent, illegal, obscene, defamatory, libelous, threatening, harmful to minors, pornographic, indecent, harassing, hateful, religiously, racially or ethnically offensive, that encourages illegal or tortious conduct or that is otherwise inappropriate in Synap's discretion; (iii) contains viruses, bots, worms, scripting exploits or other similar materials; or (iv) that could otherwise cause damage to Synap or any third party;
13. promote or advertise products or services other than your own without appropriate authorization;
14. use meta tags or any other “hidden text” including Synap's or our suppliers’ product names or trademarks; or
15. permit or encourage anyone else to commit any of the actions above.

Without affecting any other remedies available to us, Synap may permanently or temporarily terminate or suspend a user’s account or access to the Services without notice or liability if Synap (in its sole discretion) determines that a user has violated this Acceptable Use Policy.


# Billing & Payment Terms

An MAU refers to a Monthly Active User, someone who logs in and uses your Synap Services in a given calendar month.&#x20;

This document is intended to provide an overview of the key principles of our billing and payment terms. Specific references to Synap's prices or associated user numbers is provided as examples of how this works only. Please visit our website pricing page for the most up-to-date information

### Monthly billing cycle <a href="#billing-cycle" id="billing-cycle"></a>

You are billed monthly based on:

1. the Synap plan and user quota you select (i.e., Standard 100 MAUs, Pro 250 MAUs), and
2. the number of Monthly Active Users (MAUs) in your quota (i.e. 100, 250, 500)
3. the number of additional users of your account in the preceding month ('overages')
4. any fees due for Professional Services, including any agreed 3rd Party costs (e.g. proctoring seats) at the time your bill is calculated

These are the “Pricing Metrics” that are used to calculate your bill. We bill you each month in advance according to your agreed plan, with the exception of 'additional users' which are billed in arrears.&#x20;

### Annual plans <a href="#overages-and-credits" id="overages-and-credits"></a>

We offer substantial discounts (\~20%) for annual payments, paid upfront. Customers on an annual plan can request to pay by invoice with 30 day terms, as opposed to card.&#x20;

### In-plan and Out-of-plan users <a href="#overages-and-credits" id="overages-and-credits"></a>

We undersand that your usage will change over time, and for many of our clients, may vary substantially from month to month (e.g. a startup launching a new product, or a tutoring company with seasonal peaks around exams).&#x20;

Our plans are designed to accommodate these different scenarios. Our Standard and Pro plans come with a baseline of 25 and 100 MAUs respectively, with additional users over those amounts being charged at a flat rate of £2 per user.&#x20;

As you scale, or during seasonal peaks, you can upgrade your plan to include more MAUs (e.g. 250, 500 or 1,000). This upgrade could be temporary or permanent, depending on which option represents the best value for you. 'In plan' users offer a significant discount (upto 70%) over out-of-plan users, so if you are seeing or expecting to have more users, it is often advisable to move to a higher plan.&#x20;

Our customer success team can advise you on the right plan and associated MAU quotas as we learn about your project and expected usage.&#x20;

### Estimating your upcoming invoice <a href="#estimating-your-upcoming-invoice" id="estimating-your-upcoming-invoice"></a>

You can see your current plan and user quota by logging in to your Admin Account, clicking on Profile Icon and selecting 'Billing'. You can also see how many MAUs have been on your platform in the last rolling 30 days by going to your Dashboard.&#x20;

This information should give you an accurate estimate of your monthly bill. Please note that, at the moment, there is a slight discrepancy between how your MAUs are calculated in your bill (calendar month), and how they are calculated in your Dashboard (30 days). We are working to change this.&#x20;

From your Billing page, you can also access past invoices for your records. A copy of these will also be emailed to you each month.

**VAT Information for B2B Transactions**

Please note that Synap operates as a B2B (business-to-business) service company, catering exclusively to businesses. Consequently, all the prices listed in our pricing documentation are exclusive of VAT.

VAT will be calculated and added to your total upon portal creation, plan upgrades and changes, and will be explicitly itemised for overages. This ensures full transparency and compliance with tax regulations, allowing your organisation to handle or reclaim VAT in accordance with your local jurisdiction's policies.

### Billing, subscription management, and cancellation

**Automated billing**\
Unless otherwise agreed under a separate Business or Enterprise Agreement, all monthly subscription plans are billed automatically via the payment method on file. Clients are responsible for maintaining up-to-date billing details and ensuring sufficient funds are available on the billing date.

**Cancellations and downgrades**\
For monthly plans, cancellations must be requested at least five (5) working days prior to the next billing date to ensure the change can be processed in time. Requests made within five working days of the billing date may not be processed before the next charge, though Synap will make reasonable efforts to apply retrospective adjustments or refunds at its discretion.

**Non-payment and service suspension**\
Clients on monthly billing are subscribed on a rolling basis. Whilst we will make reasonable attempts to contact and notify clients who are in arrears to provide time to rectify, Synap reserves the right, at its discretion, to terminate, suspend or delete portals with invoices in arrears of 30 days or more.

<br>


# Proctoring Policy

Synoptic proctoring policy

### Synoptic Options

Synoptic assessments are configured using both an **Install Level** and a **Monitoring Level**. Install Levels determine how candidates access the assessment and the security controls available, while Monitoring Levels determine the evidence collected during the assessment.

Any Install Level can be combined with any Monitoring Level. Pricing is based on the selected Monitoring Level and is charged per started 4-hour assessment session. Where multiple monitoring methods are used, the assessment will be classified and billed according to the **highest monitoring level enabled**. For example, if webcam monitoring uses Video & Audio Recording and screen monitoring uses Recreation & Snapshots, the assessment will be charged at the Video & Audio Recording rate.

| **Install Level**    | <p>Determines how candidates access the assessment and the security controls available during the exam. Options are:<br><strong>- No install</strong><br><strong>- Browser Extension</strong><br><strong>- Desktop App</strong></p><p><br></p>                                                                       |
| -------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Monitoring Level** | <p>The Monitoring Level determines the type of evidence collected during the assessment and how the session is reviewed afterwards. Options are: <br><strong>- No Recording</strong> <br><strong>- Recreation & Snapshots</strong> <br><strong>- Video & Audio Recording (required for Live proctoring)</strong></p> |

See the Pricing & Credits section below for Synoptic Proctoring costs

{% content-ref url="/pages/1ZjL3rbYqHNcrDnlwtim" %}
[Pricing & Credits](/pricing-and-credits)
{% endcontent-ref %}

### Synoptic Data Retention Policy

Unless otherwise agreed as part of an Enterprise agreement, Synoptic proctoring data is retained in accordance with the following policy.

#### Video, Audio and Monitoring Data

Retention periods are calculated from the time an assessment attempt is submitted.

| Data State         | Retention Period     |
| ------------------ | -------------------- |
| Active Storage     | First 90 days        |
| Cold Storage       | 90 days to 12 months |
| Permanent Deletion | After 12 months      |

#### Cold Storage

After 90 days, proctoring footage and monitoring data is moved from active storage to cold storage. Data remains accessible but retrieval may take longer than data stored in active storage.

#### Permanent Deletion

Proctoring footage and monitoring data is permanently deleted 12 months after the assessment attempt is submitted.

#### Enterprise Agreements

Enterprise clients may agree alternative retention periods as part of their contract. Where an alternative retention period has been agreed, this will take precedence over the standard Synoptic retention policy.


# Pricing & Credits

## Introduction

Our customers use Synap in a number of different ways - we work with small and large organisations, some of whom are expecting to deliver a handful of exams at different points in the year, and others who will be running multiple exams and other kinds of assessments every day.&#x20;

For this reason, we have recently updated our pricing model to accomodate these different use cases. This document contains our up to date prices.&#x20;

## Assessment Credits & Associated Pricing

In 2023, we are introducing 'Assessment Credits' ("credits"). These can be purchased in bulk and used to pay for the different kinds of assessments available on Synap.&#x20;

As a general rule, higher-volume purchases are eligible for larger discounts. Once purchased a credit is valid for 12 months, and is non-refundable.&#x20;

The reason we have credits is to provide a flexible and transferrable system that our customers can use to pay for different types of assessment - for example, credits can be used to pay for usage of Exams, Assignments, Practice Tests, as well as the various kinds of proctoring we offer on the platform.&#x20;

The table below shows how many credits each type of assessment requires. As you'll notice most types of assessment use 1x credit - it is only the various kinds of proctored assessments that use more credits, this is due to the additional resources associated with running them.&#x20;

| **Assessment Type**                                           | **Cost - Credit-based plans** | **Cost - MAU-based plans (3)** |
| ------------------------------------------------------------- | ----------------------------- | ------------------------------ |
| Exam - Non proctored                                          | 1 credit                      | Included                       |
| Synoptic Exam: Any Install Level, **No recording**            | 2 credits                     | £1.00                          |
| Synoptic Exam: Any Install Level, **Recreation & Snapshots**  | 5 credits                     | £3.00                          |
| Synoptic Exam: Any Install Level, **Video & Audio Recording** | 10 credits                    | £8.00                          |
| Assignment                                                    | 1 credit                      | Included                       |
| Low-stakes MAUs (2)                                           | 1 credit per user per month   | Included                       |

1. Synoptic monitoring charges are applied per started 4-hour session. Attempts exceeding 4 hours will be charged again for each additional 4-hour period started. Billing is based on the highest monitoring level enabled; for example, an assessment using webcam Video & Audio Recording and screen Recreation & Snapshots will be charged at the Video & Audio Recording rate.&#x20;
2. "Low-stakes MAUs" refers to the use of Synap's various 'low-stakes' assessment tools such as Collections and Spaced Learning, to deliver tests and revision materials to users. These are essentially charged as Monthly Active Users - so, one user taking any number of practice tests on the platform in a given month, will only cost 1 credit.&#x20;
3. "MAU-based plans" - Customers who have purchased a monthly or annual subscription to Synap, with billing based on MAUs, have all of their non-proctored use of the platform included as a part of their MAU quota. Under these plans, a given user can take as many assessments on the platform as they like, and you will only be charged once for that user. Proctored assessments on the other hand, are charged separately.&#x20;

The baseline cost of a Credit is £1.50 - this is the amount that you will be charged by default if you use the above assessment features. However, you can also purchase credits in bulk, in which case various levels of discount will be applied. Once purchased a credit is valid for 12 months, and is non-refundable.&#x20;

Our current pricing for credit bundles is:

| **Number of Credits**       | **Price** | **Cost per credit** |
| --------------------------- | --------- | ------------------- |
| 500                         | £1,200    | £2.40               |
| 1,000                       | £1,800    | £1.80               |
| 2,500                       | £3,000    | £1.20               |
| 5,000                       | £4,500    | £0.90               |
| 10,000                      | £7,000    | £0.70               |
| 20,000                      | £10,000   | £0.50               |
| 1 (Not purchased upfront)\* | £1.50     | £1.50               |

## Estimating How Many Credits You Need

Our team would be more than happy to prepare a quote for you, with an estimate on the number of credits you need and the best-value package to purchase.&#x20;

Once you have made this initial purchase, your subsequent credits will be charged at £1.50 each, even if you do not make a larger purchase in the future.

Alternatively, if you are looking to get the best value for money, our higher-volume packages do offer significant discounts and you may wish to consider purchasing one of those.&#x20;

## MAU overages&#x20;

Synap pricing is based on **Monthly Active Users (MAU)** rather than total registered users.

A **Monthly Active User** is any learner who logs in and performs a meaningful action during a billing month — for example starting an exam, completing practice questions, or accessing learning content. Plans include an agreed **MAU allowance** each month.

f the number of Monthly Active Users (MAUs) in a billing month exceeds the amount included in your plan, Synap will treat the additional usage as **overage**.

Key points:

* **Additional active users above your plan allowance are billed as overage** at the agreed per-MAU rate.
* Overage is typically **calculated at the end of the billing month** based on the total number of unique active users.
* If higher usage becomes consistent, we may **recommend moving to a larger MAU plan** to provide better value and predictability.

| Plan         | Overage per MAU |
| ------------ | --------------- |
| Standard MAU | £2              |
| Pro MAU      | £2              |
| Business MAU | £2              |


# Sustainability Pledge

At Synap, we are committed to integrating sustainability into every aspect of our business operations. As a cloud-based SaaS provider based in Leeds, UK, we recognise the importance of environmental stewardship and are dedicated to contributing positively to the planet. Our sustainability pledge includes the following key initiatives:

1. **Energy Efficiency**: We strive to optimise energy usage in our operations, including utilising energy-efficient cloud services from AWS, known for their commitment to sustainability.
2. **Reducing Carbon Footprint**: We are working towards reducing our carbon footprint through a combination of remote working policies, digital-first strategies, and minimising non-essential travel.
3. **Sustainable Procurement**: Where physical resources are required, we prioritise purchasing from local suppliers who demonstrate a strong commitment to environmental sustainability.
4. **Waste Reduction and Recycling**: We implement waste reduction practices in our office and encourage recycling and responsible waste management among our team.
5. **Continuous Improvement**: We commit to regularly reviewing and improving our sustainability practices, setting measurable goals for reduction in resource usage and carbon emissions.

As we continue to grow and evolve, Synap pledges to remain vigilant and proactive in our sustainability efforts, ensuring that our business not only thrives but also positively impacts the environment.


# Vulnerability Disclosures

## Introduction

This vulnerability disclosure policy applies to any vulnerabilities you are considering reporting to a Synap (the “Organisation”).

We recommend reading this vulnerability disclosure policy fully before you report a vulnerability and always acting in compliance with it.

We value those who take the time and effort to report security vulnerabilities according to this policy. However, we do not offer monetary rewards for vulnerability disclosures.

## Reporting

If you believe you have found a security vulnerability relating to the Organisation’s system, please submit a vulnerability report to <security@synap.ac>

In your report please include details of:

* The website, IP or page where the vulnerability can be observed.
* A brief description of the type of vulnerability, for example; “XSS vulnerability”.
* Steps to reproduce. These should be a benign, non-destructive, proof of concept. This helps to ensure that the report can be triaged quickly and accurately. It also reduces the likelihood of duplicate reports, or malicious exploitation of some vulnerabilities, such as sub-domain takeovers.

## What to expect

After you have submitted your report, we will respond to your report within 5 working days and aim to triage your report within 10 working days. We’ll also aim to keep you informed of our progress.

Priority for remediation is assessed by looking at the impact, severity and exploit complexity. Vulnerability reports might take some time to triage or address. You are welcome to enquire on the status but should avoid doing so more than once every 14 days. This allows our teams to focus on the remediation.

We will notify you when the reported vulnerability is remediated, and you may be invited to confirm that the solution covers the vulnerability adequately.

Once your vulnerability has been resolved, we welcome requests to disclose your report. We’d like to unify our guidance, so please do continue to coordinate public release with us.

## Guidance

You must NOT:

* Break any applicable law or regulations.
* Access unnecessary, excessive or significant amounts of data.
* Modify data in the Organisation's systems or services.
* Use high-intensity invasive or destructive scanning tools to find vulnerabilities.
* Attempt or report any form of denial of service, e.g. overwhelming a service with a high volume of requests.
* Disrupt the Organisation's services or systems.
* Submit reports detailing non-exploitable vulnerabilities, or reports indicating that the services do not fully align with “best practice”, for example missing security headers.
* Submit reports detailing TLS configuration weaknesses, for example “weak” cipher suite support or the presence of TLS1.0 support.
* Communicate any vulnerabilities or associated details other than by means described in the published security.txt.
* Social engineer, ‘phish’ or physically attack the Organisation's staff or infrastructure.
* Demand financial compensation in order to disclose any vulnerabilities.

You must:

* Always comply with data protection rules and must not violate the privacy of any data the Organisation holds. You must not, for example, share, redistribute or fail to properly secure data retrieved from the systems or services.
* Securely delete all data retrieved during your research as soon as it is no longer required or within 1 month of the vulnerability being resolved, whichever occurs first (or as otherwise required by data protection law).

## Legalities

This policy is designed to be compatible with common vulnerability disclosure good practice. It does not give you permission to act in any manner that is inconsistent with the law, or which might cause the Organisation or partner organisations to be in breach of any legal obligations.


# Anti-Slavery Policy Statement

Modern slavery is a crime and a violation of fundamental human rights. It includes various forms such as slavery, servitude, forced and compulsory labor, and human trafficking. At Synap, we are committed to maintaining an ethical business environment and ensuring that modern slavery is not present in any part of our operations or supply chains.

**Our Commitment**

We voluntarily uphold a strong stance against modern slavery. We are committed to acting with integrity and transparency in all our business dealings. We expect the same high standards from all of our contractors, suppliers, and other business partners.

**Policy Application**

This policy applies to all individuals working for or on behalf of Synap, including employees at all levels, directors, contractors, external consultants, third-party representatives, and business partners.

**Employee Training and Responsibility**

Synap provides annual training to all employees on our Modern Slavery Policy to ensure they understand the importance of preventing modern slavery and human trafficking in our business and supply chains. This training reinforces our zero-tolerance approach and equips employees to recognise and report any concerns or suspicions.

All employees are responsible for reading, understanding, and complying with this policy. Any employee who has concerns or suspicions about modern slavery or human trafficking within Synap or its supply chains is encouraged to report these concerns as soon as possible to their line manager or a company Director.

**Raising Concerns**

Synap is committed to maintaining an open and supportive environment. We encourage all employees and business partners to raise any concerns related to modern slavery. Reports will be treated with seriousness and confidentiality, and we will support anyone who raises genuine concerns.

**Supplier Vetting Process**

We are committed to maintaining ethical standards across our supply chains. As part of our supplier vetting process, we evaluate potential suppliers to ensure they comply with laws and regulations related to modern slavery and human trafficking. We expect our suppliers to uphold high ethical standards and demonstrate a clear commitment to preventing modern slavery within their own operations and supply chains. This vetting process is part of our broader commitment to combatting modern slavery and ensuring transparency in all aspects of our business relationships.

**Continuous Improvement**

We are dedicated to continually reviewing and improving our practices to ensure they remain effective in combating modern slavery. This includes providing relevant training to employees and ensuring our zero-tolerance approach to modern slavery is communicated to all suppliers, contractors, and business partners at the outset of our business relationships.

**Conclusion**

Synap is committed to ethical business practices and human rights. We take a proactive stance in preventing modern slavery within our business and expect our partners to share this commitment. Our dedication to combating modern slavery is integral to maintaining the integrity and ethical standards of our operations.


