Legal
Data Processing Agreement
Last updated: 30 June 2026
1. Introduction
This Data Processing Agreement (“DPA”) forms part of the SyftOS Terms of Service, any applicable order form, statement of work, pilot agreement or other written agreement between Techshift Digital Ltd and the customer for use of SyftOS.
This DPA applies where Techshift Digital Ltd processes personal data on behalf of a customer in connection with SyftOS. It is intended to support the parties in meeting their obligations under applicable data protection law, including the UK GDPR and the Data Protection Act 2018.
This DPA should be read together with the SyftOS Terms of Service, Privacy Notice, Sub-processor List, AI Data Use Statement and any applicable order form or pilot terms. This DPA is incorporated into and accepted as part of the SyftOS Terms of Service; where a Customer requires a signed counterpart, Techshift Digital Ltd will provide one on request.
2. Parties
| Party | Role and details |
|---|---|
| Customer | The organisation or person that enters into the SyftOS Terms of Service, order form, pilot arrangement or other agreement for use of SyftOS. |
| Processor | Techshift Digital Ltd, company number 15218025, registered office: 1 The Briars, Waterberry Drive, Waterlooville, England, PO7 7YH. |
| Product | SyftOS, a governed digital workforce platform operated by Techshift Digital Ltd. |
| Data protection contact | privacy@syftos.com (interim fallback: mathew@techshift.digital). |
3. Definitions
In this DPA, the following terms have the meanings below. Terms not defined here have the meaning given in the SyftOS Terms of Service or applicable data protection law.
| Term | Meaning |
|---|---|
| Applicable Data Protection Law | All data protection and privacy laws that apply to the processing of personal data under this DPA, including the UK GDPR and Data Protection Act 2018 where applicable. |
| Customer Data | Data, documents, prompts, files, records, messages, integration data, workflow inputs, workflow outputs, run history and related content submitted to or processed through SyftOS by or on behalf of Customer. |
| Personal Data | Any information relating to an identified or identifiable living individual. |
| Processing | Any operation performed on personal data, including collection, access, use, storage, transmission, analysis, deletion or return. |
| Controller | The party that determines the purposes and means of processing personal data. |
| Processor | The party that processes personal data on behalf of a controller. |
| Sub-processor | A third party engaged by Techshift Digital Ltd to process personal data on behalf of Customer in connection with SyftOS. |
| AI Provider | A third-party provider of artificial intelligence, large language model, embedding, transcription or related model services used by SyftOS. |
4. Scope and order of precedence
This DPA applies only to personal data processed by Techshift Digital Ltd as processor on behalf of Customer.
Where Techshift Digital Ltd processes personal data as an independent controller, such as for account administration, billing, support, sales, legal compliance or product communications, that processing is covered by the SyftOS Privacy Notice and not by this DPA.
If there is a conflict between this DPA and the SyftOS Terms of Service in relation to the processing of personal data, this DPA takes priority for that conflict only. Commercial terms, payment terms, liability limits and service terms remain governed by the SyftOS Terms of Service unless expressly varied in writing.
5. Roles of the parties
Customer is the controller of Customer Data containing personal data, unless otherwise agreed in writing.
Techshift Digital Ltd acts as processor when it processes Customer Data on behalf of Customer through SyftOS.
Customer is responsible for deciding what data is submitted to SyftOS, which integrations are connected, which workflows are configured, which users are authorised, and whether proposed actions or outputs are approved, rejected or used.
Techshift Digital Ltd will process Customer Data only to provide, maintain, secure, support and improve SyftOS in accordance with Customer instructions and this DPA.
6. Customer instructions
Customer instructs Techshift Digital Ltd to process Customer Data as necessary to provide SyftOS and related services, including hosting, storage, retrieval, workflow execution, agent operation, integration processing, approval handling, audit logging, support, troubleshooting, security, monitoring and service improvement.
Customer instructions include this DPA, the SyftOS Terms of Service, the Customer workspace configuration, connected integrations, workflow settings, approved actions, order forms, pilot terms and any written instructions accepted by Techshift Digital Ltd.
Techshift Digital Ltd will process Customer Data only on Customer’s documented instructions, including in relation to international transfers, unless required to do so by law to which Techshift Digital Ltd is subject. In that case, Techshift Digital Ltd will inform Customer of the legal requirement before processing, unless that law prohibits such notice on important grounds of public interest.
Techshift Digital Ltd may refuse or suspend an instruction if it reasonably believes the instruction breaches applicable law, creates a security risk, infringes rights, exceeds agreed service scope, involves prohibited use, or would require processing that Techshift Digital Ltd is not able to perform safely or lawfully. Techshift Digital Ltd will inform Customer if, in its opinion, an instruction infringes applicable data protection law.
7. Details of processing
The details of the processing are set out in Schedule 1. Customer is responsible for ensuring that the processing described in Schedule 1 accurately reflects its intended use of SyftOS.
8. Confidentiality
Techshift Digital Ltd will ensure that personnel authorised to process Customer Data are subject to appropriate confidentiality obligations, whether contractual, statutory or professional.
Techshift Digital Ltd will limit access to Customer Data to personnel and authorised service providers who need access for the purposes of providing, maintaining, securing or supporting SyftOS.
9. Security measures
Techshift Digital Ltd will implement and maintain appropriate technical and organisational measures designed to protect Customer Data against unauthorised or unlawful processing, accidental loss, destruction, damage, alteration or disclosure.
The security measures are summarised in Schedule 2. Security measures may evolve over time, provided that the overall level of protection is not materially reduced.
10. Sub-processors
Customer authorises Techshift Digital Ltd to use sub-processors where necessary to provide SyftOS, including cloud infrastructure, hosting, database, storage, monitoring, email, billing, analytics, support, AI model and integration-related service providers.
Techshift Digital Ltd maintains a SyftOS Sub-processor List identifying relevant sub-processors, their purpose and, where practical, their processing location or relevant transfer mechanism.
Techshift Digital Ltd will impose written data protection obligations on its sub-processors that are appropriate to the nature of the processing and no less protective in substance than the obligations imposed on Techshift Digital Ltd under this DPA. Techshift Digital Ltd remains responsible for the performance of its sub-processors’ data protection obligations.
Where Customer enables an integration with a third-party service, such as a communication, CRM, project management, finance, repository or storage platform, that third-party service may be acting as Customer’s own provider rather than as a sub-processor of Techshift Digital Ltd. Customer is responsible for ensuring it has appropriate rights and terms in place with those connected services.
Techshift Digital Ltd will give Customer at least 30 days’ advance notice before adding or replacing a sub-processor that processes Customer Data, by updating the Sub-processor List and by a reasonable means of notification (such as email or an in-product or website notice). Customer may object on reasonable data protection grounds within 30 days of the notice. The parties will work in good faith to resolve the objection; if it cannot be resolved, Customer may terminate the affected service in accordance with the SyftOS Terms of Service. Where a change to a sub-processor is required urgently for security, legal or service-continuity reasons, Techshift Digital Ltd may make the change immediately and will notify Customer promptly afterwards.
11. AI providers and model processing
SyftOS may use third-party AI providers to process prompts, workflow inputs, documents, integration data, agent instructions, memory, embeddings, summaries, outputs and related content where necessary to provide the service.
Customer authorises such processing where AI functionality is enabled or used in its workspace.
Techshift Digital Ltd does not use Customer workspace content to train Techshift-owned models.
Processing by third-party AI providers may depend on the provider selected, configured region, account settings, provider terms and technical implementation. The specific AI providers are identified in the SyftOS Sub-processor List and AI Data Use Statement.
Customer should not submit special category data, criminal offence data, highly sensitive data, confidential regulated information, children’s data, or data subject to special restrictions unless Customer has confirmed that SyftOS is suitable for that processing and has obtained any required permissions, notices, assessments and safeguards.
12. International transfers
Customer Data may be processed in the United Kingdom, European Economic Area, United States or other locations where Techshift Digital Ltd, its sub-processors or enabled service providers operate.
Where applicable data protection law requires a transfer mechanism for international transfers, Techshift Digital Ltd will use appropriate safeguards such as adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to EU Standard Contractual Clauses, EU Standard Contractual Clauses, or another lawful transfer mechanism as applicable.
Further details are set out in the SyftOS Sub-processor List, Privacy Notice and AI Data Use Statement.
13. Data subject rights
Taking into account the nature of the processing, Techshift Digital Ltd will provide reasonable assistance to Customer to respond to requests from individuals exercising their data protection rights, where the request relates to Customer Data processed by Techshift Digital Ltd as processor.
If Techshift Digital Ltd receives a request directly from an individual relating to Customer Data, it may direct the individual to Customer unless legally required to respond otherwise.
Customer is responsible for determining whether and how to respond to the request.
14. Personal data breaches
Techshift Digital Ltd will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Data processed by Techshift Digital Ltd as processor.
The notification will include available information reasonably required by Customer to meet its obligations, taking into account the nature of the breach and the information available to Techshift Digital Ltd at the time.
Techshift Digital Ltd may provide information in stages as it investigates and remediates the incident.
Customer is responsible for determining whether notification to a regulator or affected individuals is required, unless Techshift Digital Ltd is legally required to notify in its own capacity. Customer remains responsible for its own obligation (where it applies) to notify the Information Commissioner’s Office without undue delay and, where feasible, within 72 hours.
15. Assistance with compliance
Taking into account the nature of the processing and the information available to Techshift Digital Ltd, Techshift Digital Ltd will provide reasonable assistance to Customer with data protection impact assessments, prior consultations, security obligations, breach response and other compliance obligations relating to Customer Data processed under this DPA.
Additional assistance may be subject to reasonable fees where the request is complex, excessive, outside standard support scope, or requires substantial technical, legal or operational work.
16. Audit and information rights
Techshift Digital Ltd will make available reasonable information necessary to demonstrate compliance with this DPA, including relevant policies, security summaries, sub-processor information, audit summaries, evidence packs or responses to reasonable security and privacy questionnaires.
Any audit or inspection must be reasonable, proportionate, subject to confidentiality, scheduled in advance, limited to systems and records relevant to Customer, and conducted in a way that does not compromise security, confidentiality, other customers, service availability or Techshift Digital Ltd’s intellectual property. Unless required more frequently by applicable data protection law or following a personal data breach affecting Customer Data, audits are limited to once in any 12-month period.
Techshift Digital Ltd may satisfy audit requests by providing existing security materials, policy summaries, written responses to security and privacy questionnaires, and any independent reports or certifications it actually holds at the relevant time, where appropriate.
17. Return and deletion of Customer Data
On termination or expiry of the service, Customer may export Customer Data using available product functionality during the subscription and for a short period afterwards.
At Customer’s choice, Techshift Digital Ltd will return or delete Customer Data, and delete existing copies, within 30 days of termination or expiry (or of Customer’s written request, if later), except to the extent retention is required as set out below.
Techshift Digital Ltd may retain limited copies of Customer Data where required for legal, regulatory, security, backup, dispute resolution, audit or fraud prevention purposes, subject to applicable data protection law. Backup copies will be deleted or overwritten in the ordinary course of our backup cycles, within a further limited period (typically up to 90 days).
Audit logs may be retained where necessary to preserve integrity, security, accountability, dispute records or legal compliance. Where audit logs contain personal data, they will remain subject to applicable data protection obligations.
18. Customer responsibilities
Customer is responsible for:
- having a lawful basis for personal data submitted to or processed through SyftOS;
- providing any required privacy notices to its users, employees, contractors, customers and other individuals;
- ensuring it has rights to connect third-party systems and process data from those systems;
- configuring users, roles, integrations, workflows, approvals and automation safely;
- reviewing and approving outputs and proposed actions before relying on them where appropriate;
- not submitting data that SyftOS is not designed or agreed to process;
- keeping login credentials and connected accounts secure;
- responding to data subject requests and regulator enquiries where Customer is controller;
- using SyftOS in accordance with the Terms of Service, Acceptable Use Policy and applicable law.
19. High-risk and sensitive processing
SyftOS is not designed to make final legal, medical, financial, employment, regulatory, credit, insurance, housing, criminal justice, immigration or other high-risk decisions without appropriate human review and separate written approval.
Customer must not use SyftOS for prohibited or high-risk processing unless that use has been expressly agreed in writing and appropriate safeguards have been implemented.
20. Liability
Liability under or in connection with this DPA is governed by the SyftOS Terms of Service, unless applicable data protection law requires otherwise.
Nothing in this DPA limits liability where such limitation is not permitted by applicable law.
21. Changes to this DPA
Techshift Digital Ltd may update this DPA from time to time, including to reflect changes in SyftOS, applicable law, sub-processors, security practices or operational requirements.
Material changes will be notified by reasonable means, such as email, in-product notice, website update, documentation update, or another method appropriate to the nature of the change.
Continued use of SyftOS after an update takes effect will be handled in accordance with the SyftOS Terms of Service.
22. Governing law
This DPA is governed by the laws of England and Wales, unless applicable data protection law requires a different position for a specific issue.
Schedule 1 — Details of processing
| Item | Details |
|---|---|
| Subject matter | The provision, operation, support, security and improvement of SyftOS as a governed digital workforce platform. |
| Duration | For the duration of Customer’s use of SyftOS and any additional retention period described in the Terms of Service, Privacy Notice, this DPA, backup processes, audit retention requirements, or written agreement. |
| Nature of processing | Collection, receipt, hosting, storage, retrieval, organisation, transmission, analysis, summarisation, generation, enrichment, transformation, logging, deletion, export and other processing required to provide SyftOS. |
| Purpose of processing | To provide AI-assisted digital workers, workflows, departments, integrations, approvals, audit logs, reporting, support, security, troubleshooting, usage tracking and related product functionality. |
| Types of personal data | Names, email addresses, phone numbers, job titles, company details, account identifiers, user IDs, messages, documents, tasks, tickets, CRM data, financial/admin data, repository metadata, support content, prompts, outputs, integration content and other personal data submitted by or on behalf of Customer. |
| Categories of data subjects | Customer personnel, users, administrators, contractors, suppliers, prospects, customers, support contacts, communication participants, project stakeholders and other individuals whose personal data is included in Customer Data. |
| Special category data | Not intentionally required for standard SyftOS use. Customer should not submit special category data unless it has confirmed suitability, lawful basis and safeguards. |
| Criminal offence data | Not intentionally required for standard SyftOS use. Customer should not submit criminal offence data unless expressly agreed and lawful. |
| Frequency | Continuous, recurring, scheduled, event-driven or user-initiated processing depending on workspace configuration. |
Schedule 2 — Technical and organisational measures
| Measure | Summary |
|---|---|
| Tenant isolation | Customer workspaces are logically separated using a tenant identifier enforced at the application layer to reduce the risk of cross-customer access. |
| Access control | Access is restricted to authorised users, roles and personnel with a business need, on a least-privilege basis. |
| Authentication | User authentication with role-based permissions. Two-factor authentication (TOTP) and passkeys are available and are mandatory for owner and administrator roles; SSO (SAML/OIDC) and SCIM provisioning are available. |
| Approvals | External or side-effecting actions are approval-gated unless Customer has explicitly configured permitted automation; high-risk actions cannot be auto-approved. |
| Audit logging | SyftOS maintains append-only, tamper-evident (hash-chained) audit logs recording run, approval and action information to support accountability and traceability. |
| Secrets management | Connected integration credentials and secrets are encrypted at rest using authenticated encryption and are accessed only through a controlled, audited path. |
| Encryption | Data is encrypted in transit using TLS. Integration credentials and secrets are encrypted at rest using authenticated (AES-256) encryption. Customer Data stored in our database and object storage is protected using encryption at rest provided by our infrastructure providers. |
| Monitoring | Operational and security monitoring is used to detect errors, misuse, incidents and service issues. |
| Backups | Backups and recovery processes are used to support service continuity and data recovery. |
| Personnel confidentiality | Personnel with access to Customer Data are subject to confidentiality obligations. |
| Sub-processor controls | Relevant sub-processors are assessed and subject to written obligations where required. |
| Incident response | Techshift Digital Ltd maintains processes to investigate, contain and respond to security incidents. |
Schedule 3 — Sub-processors and connected services
The current SyftOS Sub-processor List is maintained separately and published on the SyftOS website. It identifies sub-processors in the following categories:
- cloud hosting and infrastructure;
- database, storage and backup services;
- AI model providers and embedding/model services;
- email and notification services;
- billing and payment services;
- monitoring, analytics and logging services;
- support and customer communication tools;
- security and authentication services.
Connected third-party services chosen by Customer, such as Slack, Google, Microsoft, GitHub, Jira, HubSpot, Stripe, Xero, Teamwork or similar systems, may process data under Customer’s own relationship with those providers. They are not automatically sub-processors of Techshift Digital Ltd merely because Customer connects them to SyftOS.
Schedule 4 — AI processing notes
SyftOS uses AI functionality to support digital workers, workflows, summaries, drafts, recommendations, retrieval, analysis and proposed actions.
Customer remains responsible for reviewing outputs and approving actions. SyftOS outputs should not be treated as professional advice, legal advice, financial advice, medical advice, employment advice or a substitute for human judgement.
Customer workspace content is not used by Techshift Digital Ltd to train Techshift-owned models. Third-party AI provider handling is described in the SyftOS AI Data Use Statement and Sub-processor List.