Echo-Synch

Legal

Data Processing Agreement

The Article 28 GDPR contract between Echo-Synch (Processor) and you (Controller). Auto-applies to every paid plan.

Effective date: 25 April 2026

This Data Processing Addendum ("DPA") forms part of the Terms of Service ("Agreement") between Echo-Synch ("we", "us", "Processor") and the customer organisation ("you", "Customer", "Controller") that has installed Echo-Synch into its Slack workspace. Where this DPA conflicts with the Agreement on matters of personal data processing, this DPA controls.

1. Context & architecture

Echo-Synch operates as a minimal-footprint processor inside your Slack environment. We do not ingest your full Slack history; we process only the messages posted in channels that you explicitly add Echo-Synch to.

2. Definitions

3. Scope and details of processing

4. Processor obligations

  1. Instructions. Echo-Synch processes Personal Data only on documented instructions from the Controller, including the instructions inherent in the Agreement and this DPA.
  2. Confidentiality. Echo-Synch ensures that all personnel with access to Personal Data are bound by appropriate confidentiality obligations.
  3. Security. Echo-Synch maintains the technical and organisational measures set out in Annex 2.
  4. Sub-processors. Echo-Synch uses the sub-processors listed in Annex 1. We will provide reasonable prior notice (via email and update of this page) of any addition or replacement of sub-processors. The Controller may object to such changes within 14 days; if the objection cannot be reasonably resolved, the Controller may terminate the Agreement without penalty.
  5. Data subject rights. Echo-Synch will assist the Controller, by appropriate technical and organisational measures and to the extent possible, in fulfilling its obligation to respond to requests from data subjects.
  6. Breach notification. Echo-Synch will notify the Controller without undue delay (and in any event within 72 hours) after becoming aware of a Personal Data Breach affecting the Controller's data.
  7. Audit. Echo-Synch will, at the Controller's reasonable written request and on no less than 30 days' notice, provide information necessary to demonstrate compliance with this DPA.

5. International data transfers

Primary processing happens in the EU. Where transfers to non-adequate third countries occur (currently: LemonSqueezy and Sentry, both US-based; and any BYOM provider the Controller chooses outside the EEA), such transfers are governed by the EU Standard Contractual Clauses 2021/914 incorporated into the relevant subprocessor agreements. Both LemonSqueezy and Sentry self-certify under the EU–US Data Privacy Framework.

6. Deletion or return of data

On uninstall of the Slack bot, or on termination of the Agreement, Echo-Synch will delete all Personal Data within one hour, with the following exceptions retained only for the period and on the legal basis stated:

Within the one-hour purge window, Personal Data may persist briefly in caches and replicated database snapshots that age out within 7 days. The Controller may request expedited deletion in writing; we will execute it on a best-effort basis but cannot guarantee sub-minute removal from cloud-provider backup systems.


Annex 1 — Authorised sub-processors

The following sub-processors are authorised under this DPA. The list is current as of the Effective date above.

Sub-processorPurposeLocation
Amazon Web Services (AWS)Cloud infrastructure: Lambda, Aurora Postgres, SQS, KMS, Secrets Manager, EventBridgeIreland (eu-west-1)
Google (Vertex AI / Gemini)Default AI provider for triage and summariesBelgium (EU)
Google (Vertex AI / Gemini) under BYOMAI provider when Enterprise customer configures Bring Your Own Model — runs in the Customer's own GCP projectCustomer-selected region
LemonSqueezy (Lemon Squeezy LLC)Merchant of record — payments, invoicing, subscription managementUSA (DPF-certified)
CloudflareDNS, CDN, and email routing for echo-synch.comGlobal edge; primary EU data centres
ResendTransactional email (e.g. billing notifications, security alerts)USA (DPF-certified)
SentryApplication error monitoring; PII attachment is disabled by configurationUSA (DPF-certified)

Note. When an Enterprise customer configures Bring Your Own Model with their own Google Gemini API key, message content is processed via the Customer's own GCP project and is not routed through Echo-Synch's default Vertex AI infrastructure.

Annex 2 — Security measures

Contact

For DPA-related matters, including audit requests and breach notifications: legal@echo-synch.com.