Legal

Data Processing Addendum

Last updated: June 6, 2026

This Data Processing Addendum forms part of the Terms & Conditions between the customer and G. Brown IT & Photography for the use of Synchronator.

1. Parties

This Data Processing Addendum applies where G. Brown IT & Photography processes personal data on behalf of a customer as a processor in connection with Synchronator.

The customer is the controller or processor of Customer Personal Data, depending on the customer's own relationship with the relevant data subjects.

G. Brown IT & Photography is the processor or subprocessor of Customer Personal Data, depending on the context.

2. Definitions

"Customer Personal Data" means personal data processed by Synchronator on behalf of the customer through the Service.

"Data Protection Laws" means applicable data protection laws, including the Swiss Federal Act on Data Protection and, where applicable, the GDPR.

"GDPR" means Regulation (EU) 2016/679.

"Subprocessor" means a third party engaged by Synchronator to process Customer Personal Data on behalf of the customer.

Capitalised terms not defined in this Data Processing Addendum have the meaning given in the Terms & Conditions.

3. Scope and Instructions

Synchronator will process Customer Personal Data only:

The customer's instructions include use of the Service, configuration of Workspace settings, connection of LinkedIn accounts, use of AI features, scheduling or publishing content, user management and support requests.

If Synchronator believes an instruction violates applicable Data Protection Laws, Synchronator may notify the customer and may suspend the relevant processing where legally required or reasonably necessary.

4. Customer Responsibilities

The customer is responsible for:

5. Confidentiality

Synchronator will ensure that persons authorized to process Customer Personal Data are subject to appropriate confidentiality obligations.

6. Security Measures

Synchronator will implement reasonable technical and organizational measures designed to protect Customer Personal Data against unauthorized access, loss, misuse, alteration and disclosure.

These measures may include, as appropriate:

No system can be guaranteed to be completely secure.

7. Subprocessors

The customer gives Synchronator general authorization to use subprocessors to provide the Service.

Synchronator maintains a Subprocessor list.

Synchronator will impose data protection obligations on subprocessors that are appropriate for the nature of the services they provide.

Synchronator remains responsible for subprocessors to the extent required by applicable Data Protection Laws.

Where required by applicable law or this Data Processing Addendum, Synchronator will provide notice of material subprocessor changes.

8. International Transfers

Customer Personal Data may be processed in Switzerland, the EEA, the United Kingdom, the United States or other countries.

Where required, Synchronator will use appropriate transfer safeguards, such as adequacy decisions, standard contractual clauses or equivalent safeguards.

9. Assistance

Taking into account the nature of the processing and information available to Synchronator, Synchronator will provide reasonable assistance to the customer with:

The customer remains responsible for determining whether such obligations apply.

10. Data Subject Requests

If Synchronator receives a request from a data subject relating to Customer Personal Data, Synchronator may direct the data subject to the customer unless legally required to respond directly.

The customer can also use available Service features to access, export, correct or delete certain Customer Personal Data.

11. Personal Data Breaches

Synchronator will notify the customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data.

The notice will include available information reasonably needed by the customer to meet its own breach notification obligations.

12. Deletion and Return

After termination or expiry of the Service, Synchronator will delete or return Customer Personal Data according to the Terms, Privacy Policy, product functionality and applicable law.

Customer Personal Data may remain in backups for a limited period until overwritten or deleted through normal backup cycles.

Synchronator may retain data where required for legal, accounting, security, dispute handling or legitimate business record purposes.

13. Audits and Information

Synchronator will make available information reasonably necessary to demonstrate compliance with this Data Processing Addendum.

Audits must be reasonable, proportionate, limited to relevant processing, subject to confidentiality and scheduled in advance.

The customer must not conduct audits in a way that compromises the security, confidentiality or availability of the Service or data of other customers.

14. Liability

Liability under this Data Processing Addendum is subject to the liability limits in the Terms & Conditions unless applicable law requires otherwise.

15. Conflict

If there is a conflict between this Data Processing Addendum and the Terms & Conditions regarding processing of Customer Personal Data, this Data Processing Addendum controls.

Annex 1: Details of Processing

Subject matter: Provision of Synchronator, a B2B LinkedIn publishing workspace with AI-assisted content features.

Duration: For the term of the customer's use of the Service and any retention period described in the Terms or Privacy Policy.

Nature and purpose of processing:

Categories of data subjects:

Categories of personal data:

Additional processing for Voice Profiles where enabled

Nature and purpose:

Categories of personal data:

Retention:

Voice Profiles are used to personalise AI-assisted drafting, rewriting, scoring or repurposing. They are style and workflow aids only. They do not guarantee that Output will match your style, be accurate, be original, comply with LinkedIn policies or achieve any particular business result.

You are responsible for reviewing, editing and approving all Output before use or publication.

You may pause, edit, rebuild or delete your Voice Profile where the feature is available.

Special categories of data:

The Service is not intended for processing special categories of personal data. Customers must not upload special categories of personal data unless they have all required legal bases, permissions and safeguards.

Annex 2: Technical and Organizational Measures

Synchronator applies reasonable technical and organizational measures appropriate for a B2B SaaS service, including as applicable:

Annex 3: Authorized Subprocessors

The current authorized subprocessor list is available on the Subprocessors page.

At launch, the listed AI subprocessor is OpenAI for AI-assisted content features.