Data Processing Agreement
Last updated: 6 October 2026
This Data Processing Agreement (DPA) forms part of the agreement between Syndicbase and its customers ("you"). It applies when you use the Syndicbase application to process personal data about your owners, tenants, suppliers and other parties. For that data you are the controller and Syndicbase acts as your processor, in accordance with Article 28 of the GDPR. For personal data we determine ourselves (your account and this website), our privacy policy applies instead.
1. Roles of the parties
You are the controller of the personal data you enter into the application and you determine the purposes and means of its processing. Syndicbase is the processor and processes that personal data only to provide the service to you.
2. Subject matter, nature and purpose
The subject matter is the provision of software for the management of co-ownerships. We process personal data to deliver the features you use, such as keeping your registers of owners, tenants and suppliers, maintaining the accounts, sending communications, recording meter readings, managing documents and meetings, and providing a client portal through which co-owners can consult the documents of their own co-ownership, including contracts, invoices and accounts.
This processing lasts for as long as you use the service, unless a longer period is agreed or required by law.
To maintain and improve the service, we also record usage statistics and error reports about how the application is used. These may contain the internal identifier of a record you create, such as an owner, a supplier or an invoice, but never the name, contact details or other content of that record. This processing forms part of your instructions under this agreement.
3. Data subjects and categories of data
The data subjects are the persons you record, such as owners, tenants, suppliers, board members, notaries and other contacts, including co-owners to whom you grant access to the client portal.
The personal data includes identification and contact details, ownership shares, financial and accounting data, consumption (meter) readings, and the correspondence and documents you upload. You decide what you enter and must not enter special categories of data unless this is necessary and lawful.
4. Our obligations
We process personal data only on your documented instructions, including for transfers, unless we are required to act otherwise by law; in that case we inform you first, unless the law prohibits it.
Persons authorised to process personal data are bound by confidentiality. We take the technical and organisational measures set out in section 6.
5. Sub-processors
You give us general authorisation to engage sub-processors to provide the service. We currently use Vercel (hosting), Supabase (database), Amazon SES / Resend (email), PostHog (usage statistics and error reports), Upstash (temporary cache and protection against misuse), Cloudflare (bot protection on forms and the login), EasyPost (postal letters and Peppol e-invoices), Anthropic (AI reading of invoices) and OpenAI / Cerebras (automatic translation of texts).
When you connect a Google or Microsoft mailbox or calendar, we exchange data with that account on your instructions. Google and Microsoft then act as your own service providers, not as our sub-processors.
We impose the same data-protection obligations on each sub-processor by contract and remain responsible for their performance. We inform you of any intended change of sub-processor so that you can object.
6. Security
We implement appropriate technical and organisational measures in accordance with Article 32 GDPR, taking account of the state of the art and the risks of the processing. These include encryption of data in transit, access controls, separation between customer workspaces and regular backups.
7. Assistance to you
Taking the nature of the processing into account, we help you respond to requests from data subjects and to meet your obligations regarding security, breach notification, data protection impact assessments and prior consultation, insofar as you cannot do so yourself within the application.
8. Personal data breaches
We notify you without undue delay after becoming aware of a personal data breach affecting your data, and provide the information you need to meet your own notification obligations.
9. Return and deletion
On the end of the service, we delete or return all personal data at your choice and delete existing copies, unless the law requires us to keep them.
10. Audits
We make available the information needed to demonstrate compliance with this agreement and allow for and contribute to audits, on reasonable prior notice and subject to confidentiality.
11. International transfers
We process personal data within the European Union where possible. Any transfer outside the EU takes place with appropriate safeguards such as the European Commission's standard contractual clauses.
12. Governing law
This agreement is governed by Belgian law and forms part of your agreement with us. Where it conflicts with other terms on the protection of personal data, this agreement prevails.