Private betaZynth Auth is currently in private beta testing.New organizations are created by invitation only, and no plan can be purchased yet.Request early access

Zynth Media Technology

Legal

Data Processing Addendum

Effective date: 6 September 2026

How we process your end-users' personal data as your processor — our obligations, sub-processors, transfer safeguards, and breach and deletion commitments.

Private beta. Zynth Auth is currently in private beta testing. These terms govern that private, invitation-only beta and may change; we will give advance notice of material changes before they take effect. The Service is offered for business use and is not intended for consumers.

This DPA governs our processing of personal data on your behalf. It complements our Terms of Service and Privacy Policy.

1. Roles and scope

This Data Processing Addendum ("DPA") forms part of the agreement between you (the "Controller") and Zynth Media Technology (the "Processor") for Zynth Auth. It applies where we process personal data of your end-users on your behalf — the identities, credentials, and access records your organization manages in the platform.

You determine the purposes and means of that processing; we process it only to provide the Service and on your documented instructions, including as configured through the product.

2. Nature of processing

  • Subject matter: identity and access management for your end-users and agents.
  • Nature: substantially automated. Access and authentication events are evaluated continuously by automated detection, and autonomous agent identities act within the platform. Automated protective measures may contain an agent identity, revoke sessions or tokens, or throttle requests; automated decision-making is described in our Privacy Policy.
  • Duration: for the term of your use of the Service.
  • Categories of data subject: your workforce, customers, and machine/agent identities.
  • Categories of personal data: identifiers (email, name), authentication data (hashed credentials, MFA/passkey material), and access/security event logs.

3. Our obligations as processor

  • Process personal data only on your documented instructions, including for international transfers.
  • Ensure personnel authorized to process the data are bound by confidentiality.
  • Implement appropriate technical and organizational security measures (see below).
  • Assist you, taking into account the nature of processing, in responding to data-subject requests and in meeting your security, breach-notification, and impact-assessment obligations.
  • Delete or return personal data at the end of the engagement, as described below.
  • Make available information necessary to demonstrate compliance and allow for reasonable audits.

4. Security measures

We maintain a defense-in-depth security program: encryption in transit and at rest; tenant isolation enforced at the database with row-level security; Argon2id password hashing; least-privilege database roles; a tamper-evident, hash-chained audit log; egress network controls; and a signed, digest-pinned software supply chain. The Service is designed to fail closed. These measures are described further in our Privacy Policy and Trust Centre.

5. Sub-processors

You provide a general authorization for us to engage the sub-processors below to help deliver the Service. Each is bound by data-protection terms consistent with this DPA. We will give notice of any intended addition or replacement so you may object on reasonable data-protection grounds.

Sub-processorPurposeLocation
DigitalOceanCloud hosting & infrastructure for the managed offering, including off-box encrypted backupsSingapore (APAC region)
ResendTransactional email (verification, password reset, invitations)United States
PayPalPayment processing for paid plans (card data never touches our systems)United States
Google (used only if enabled)Social sign-in — only when an end-user chooses to authenticate with GoogleUnited States
GitHub (used only if enabled)Social sign-in — only when an end-user chooses to authenticate with GitHubUnited States
Fireworks AI (used only if enabled)AI-generated text — the documentation site's Ask AI assistant (the question typed and the documentation excerpts retrieved for it), the security console's detection analyst (detection summaries, which can include a source IP address), and the website-analytics narrative (aggregate counts only). Not part of the authentication data path.United States

6. International transfers

The managed offering is hosted in Singapore (APAC). Where a sub-processor processes personal data outside your region, we rely on appropriate transfer safeguards, such as standard contractual clauses. If you self-host, personal data remains within your own infrastructure and no transfer to us occurs.

7. Data-subject requests

The platform provides built-in tools — the Privacy & Data centre — for access, export, rectification, and erasure of end-user data, so you can respond to data-subject requests directly. Where you need additional assistance, we will provide it taking into account the nature of the processing.

8. Personal data breaches

We will notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information reasonably available to help you meet your own notification obligations. The platform's detection and audit spine is designed to surface such events quickly.

9. Deletion and return

On termination, and at your choice, we will delete or return the personal data we process on your behalf, and delete existing copies unless retention is required by law. For self-hosted deployments, deletion is under your control.

10. Contact

For any question about this DPA, and for notices under it, contact legal@zynthmedia.com. Security matters may also be raised at security@zynthmedia.com.

Questions about this document, or a legal notice? Contact legal@zynthmedia.com. See all legal documents.