Legal
Data Processing Addendum
Effective date: 6 September 2026
How we process your end-users' personal data as your processor — our obligations, sub-processors, transfer safeguards, and breach and deletion commitments.
Private beta. Zynth Auth is currently in private beta testing. These terms govern that private, invitation-only beta and may change; we will give advance notice of material changes before they take effect. The Service is offered for business use and is not intended for consumers.
This DPA governs our processing of personal data on your behalf. It complements our Terms of Service and Privacy Policy.
1. Roles and scope
This Data Processing Addendum ("DPA") forms part of the agreement between you (the "Controller") and Zynth Media Technology (the "Processor") for Zynth Auth. It applies where we process personal data of your end-users on your behalf — the identities, credentials, and access records your organization manages in the platform.
You determine the purposes and means of that processing; we process it only to provide the Service and on your documented instructions, including as configured through the product.
2. Nature of processing
- Subject matter: identity and access management for your end-users and agents.
- Nature: substantially automated. Access and authentication events are evaluated continuously by automated detection, and autonomous agent identities act within the platform. Automated protective measures may contain an agent identity, revoke sessions or tokens, or throttle requests; automated decision-making is described in our Privacy Policy.
- Duration: for the term of your use of the Service.
- Categories of data subject: your workforce, customers, and machine/agent identities.
- Categories of personal data: identifiers (email, name), authentication data (hashed credentials, MFA/passkey material), and access/security event logs.
3. Our obligations as processor
- Process personal data only on your documented instructions, including for international transfers.
- Ensure personnel authorized to process the data are bound by confidentiality.
- Implement appropriate technical and organizational security measures (see below).
- Assist you, taking into account the nature of processing, in responding to data-subject requests and in meeting your security, breach-notification, and impact-assessment obligations.
- Delete or return personal data at the end of the engagement, as described below.
- Make available information necessary to demonstrate compliance and allow for reasonable audits.
4. Security measures
We maintain a defense-in-depth security program: encryption in transit and at rest; tenant isolation enforced at the database with row-level security; Argon2id password hashing; least-privilege database roles; a tamper-evident, hash-chained audit log; egress network controls; and a signed, digest-pinned software supply chain. The Service is designed to fail closed. These measures are described further in our Privacy Policy and Trust Centre.
5. Sub-processors
You provide a general authorization for us to engage the sub-processors below to help deliver the Service. Each is bound by data-protection terms consistent with this DPA. We will give notice of any intended addition or replacement so you may object on reasonable data-protection grounds.
| Sub-processor | Purpose | Location |
|---|---|---|
| DigitalOcean | Cloud hosting & infrastructure for the managed offering, including off-box encrypted backups | Singapore (APAC region) |
| Resend | Transactional email (verification, password reset, invitations) | United States |
| PayPal | Payment processing for paid plans (card data never touches our systems) | United States |
| Google (used only if enabled) | Social sign-in — only when an end-user chooses to authenticate with Google | United States |
| GitHub (used only if enabled) | Social sign-in — only when an end-user chooses to authenticate with GitHub | United States |
| Fireworks AI (used only if enabled) | AI-generated text — the documentation site's Ask AI assistant (the question typed and the documentation excerpts retrieved for it), the security console's detection analyst (detection summaries, which can include a source IP address), and the website-analytics narrative (aggregate counts only). Not part of the authentication data path. | United States |
6. International transfers
The managed offering is hosted in Singapore (APAC). Where a sub-processor processes personal data outside your region, we rely on appropriate transfer safeguards, such as standard contractual clauses. If you self-host, personal data remains within your own infrastructure and no transfer to us occurs.
7. Data-subject requests
The platform provides built-in tools — the Privacy & Data centre — for access, export, rectification, and erasure of end-user data, so you can respond to data-subject requests directly. Where you need additional assistance, we will provide it taking into account the nature of the processing.
8. Personal data breaches
We will notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information reasonably available to help you meet your own notification obligations. The platform's detection and audit spine is designed to surface such events quickly.
9. Deletion and return
On termination, and at your choice, we will delete or return the personal data we process on your behalf, and delete existing copies unless retention is required by law. For self-hosted deployments, deletion is under your control.
10. Contact
For any question about this DPA, and for notices under it, contact legal@zynthmedia.com. Security matters may also be raised at security@zynthmedia.com.