Data Processing Addendum

Data Processing Addendum

Last Updated: August 15, 2026

This Data Processing Addendum ("DPA") is incorporated into the Terms of Service and applies where Syvon.ai (operated by Infty Global, "Processor" or "we") processes personal data contained in customer workspace content on behalf of a business customer ("Customer" or "Controller"). Its terms reflect Article 28 GDPR and equivalent requirements under Panama's Law 81 of 2019.

1. Roles and scope

The Customer is the controller of personal data in the content it stores, generates, or publishes through the Service. Syvon processes that data as a processor, only on the Customer's documented instructions (as given through the Service's interfaces and configuration) and to deliver the Service. For account, billing, and platform-usage data relating to the Customer itself, Syvon is the controller — see the Privacy Policy.

2. Processing details

  • Subject matter: hosting, generating, rendering, and publishing Customer's workspace content.
  • Duration: for the term of the Customer's subscription, plus deletion on request or account termination.
  • Nature and purpose: storage, AI generation and rendering as requested by the Customer, and publication to endpoints the Customer configures.
  • Categories of data subjects: individuals whose personal data the Customer includes in its content (for example, names, images, or copy in marketing material it creates).
  • Categories of data: whatever personal data the Customer places in its content. Syvon does not systematically review content.

3. Subprocessors

The current subprocessors are listed at Subprocessors. We will give at least 30 days' notice of new subprocessors (by email to billing contacts or an in-product notice); the Customer may object on reasonable data-protection grounds, which is its sole remedy for such changes.

4. International transfers

Where personal data is transferred outside the EEA, UK, or Switzerland, transfers rely on the subprocessor's Data Privacy Framework certification or on the EU/UK Standard Contractual Clauses. We maintain the applicable agreements with each subprocessor and make them available on request under confidentiality.

5. Security measures

We maintain technical and organisational measures including encryption in transit and at rest, least-privilege access control, audit logging of privileged operations, rate limiting and spend ceilings on anonymous endpoints, incident response procedures, and periodic backups with a rehearsed restore procedure. Details available on request under confidentiality.

6. Data incidents

We notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer content, with enough detail for the Customer to meet its own regulatory obligations.

7. Data subject requests

Where a data subject request concerns personal data in Customer content, we assist the Customer in responding. Requests that reach us directly are forwarded to the Customer where the Customer is the controller.

8. Deletion and return

On termination or the Customer's instruction, workspace content is deleted through the Service's deletion controls (databases and object storage). Backups age out per retention schedule. A structured export of Customer workspace content is available through the Service.

9. Audits

We make available, on reasonable notice and at most annually, the information necessary to demonstrate compliance (including independent assurance reports where available, such as SOC 2 once issued).

10. Contact

Data-protection matters: contact@syvon.ai