legal
Data Processing Addendum
Version and effective date: 31 August 2026
This Data Processing Addendum (DPA) forms part of the agreement (Agreement) between Focused Productivity Pte. Ltd. (UEN 202311385N), trading as Sync 365, with its registered office at 77 High Street, #10-12B, High Street Plaza, Singapore 179433 (Sync 365, Processor, we, us or our), and the customer identified in an Order, account or signature block (Customer, Controller or you).
This DPA applies when Sync 365 processes Customer Personal Data on Customer’s behalf. It is incorporated into the Sync 365 Terms and Conditions and any Order that refers to those Terms. It becomes effective on the later of the date Customer accepts the Agreement and the date Sync 365 first processes Customer Personal Data. The parties may also execute the signature block in Schedule 4 without changing the effect of an existing electronic acceptance.
This DPA is intended to address processor-contract requirements under the Singapore Personal Data Protection Act 2012, the EU GDPR, the UK GDPR and other Applicable Data Protection Law. Compliance also depends on the parties’ actual practices, configurations and instructions.
1. Definitions
Applicable Data Protection Law means each privacy or data-protection law that applies to the processing of Customer Personal Data under the Agreement, including where applicable:
- Singapore’s Personal Data Protection Act 2012 and its regulations (PDPA);
- Regulation (EU) 2016/679 (EU GDPR);
- the EU GDPR as incorporated into United Kingdom law, the UK Data Protection Act 2018 and applicable UK privacy legislation (UK GDPR); and
- US state privacy laws that use the concepts of processor, service provider or contractor.
Controller, Data Subject, Personal Data, Personal Data Breach, Processing, Processor and Supervisory Authority have the meanings given by Applicable Data Protection Law. Under the PDPA, references to a Processor include a data intermediary processing personal data on behalf of another organisation under a written contract.
Customer Personal Data means Personal Data contained in Customer Data that Sync 365 processes on Customer’s behalf under the Agreement.
EU SCCs means the unmodified standard contractual clauses in the Annex to European Commission Implementing Decision (EU) 2021/914, available from the European Commission.
Restricted Transfer means a transfer of Customer Personal Data that requires an approved transfer safeguard under the EU GDPR, UK GDPR or other Applicable Data Protection Law.
Security Incident means a confirmed Personal Data Breach affecting Customer Personal Data. Unsuccessful attempts that do not compromise Customer Personal Data, such as blocked scans, failed sign-ins or denial-of-service attempts, are not Security Incidents.
Subprocessor means a third party appointed by Sync 365 to process Customer Personal Data on Customer’s behalf. It does not include Customer’s staff or a Customer-Selected Integration.
Customer-Selected Integration means Microsoft, a PSA or another service that Customer separately selects, controls or contracts with and instructs Sync 365 to exchange Customer Data with.
UK Addendum means the then-current International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner’s Office under section 119A of the Data Protection Act 2018.
2. Scope, roles and compliance
2.1 Roles. Customer is a Controller and Sync 365 is its Processor where Customer determines the purposes and essential means of processing. If Customer processes personal data for another Controller, Customer is a Processor and Sync 365 is Customer’s Subprocessor. Under the PDPA, Sync 365 is a data intermediary for the same processing.
2.2 Customer-controlled purposes. Customer determines which tenants, users, contacts, subscriptions, licences, Azure data, PSA records, portal functions, mappings, filters and integrations are enabled. Schedule 1 describes the processing covered by this DPA.
2.3 Independent processing. Each party acts independently for personal data it processes for its own purposes. Sync 365 is an independent Controller or organisation for its business-contact, account, billing, website, fraud-prevention, legal and service-security processing described in the Privacy Policy.
2.4 Compliance. Each party will comply with Applicable Data Protection Law for its role. Customer is responsible for the lawfulness, fairness and transparency of its processing, its instructions, and the accuracy and quality of Customer Personal Data.
3. Documented instructions
3.1 Sync 365 will process Customer Personal Data only:
- on Customer’s documented instructions;
- to provide, secure and support the Services and Customer-Selected Integrations;
- as described in the Agreement and Schedule 1; or
- where applicable law requires processing.
3.2 Customer’s documented instructions include the Agreement, Orders, configuration and use of the Services, authorised support requests, and additional written instructions consistent with the Services and this DPA.
3.3 If law requires processing outside Customer’s instructions, Sync 365 will inform Customer of the legal requirement before processing unless the law prohibits notice on important grounds of public interest.
3.4 Sync 365 will promptly inform Customer if, in our reasonable opinion, an instruction infringes Applicable Data Protection Law. We may suspend the affected processing while the parties resolve the issue. This does not require Sync 365 to provide legal advice or conduct Customer’s compliance assessment.
3.5 Customer will not instruct Sync 365 to process data that the Services are not designed to handle, including special-category data, criminal-offence data, government identity numbers, health records or consumer payment-card data, unless the parties first document the necessity and additional safeguards in an Order.
4. Authorised personnel and confidentiality
4.1 Sync 365 will limit access to Customer Personal Data to personnel who need it to provide, secure or support the Services.
4.2 Personnel authorised to process Customer Personal Data are bound by contractual or statutory confidentiality obligations and receive appropriate privacy and security guidance for their responsibilities.
4.3 Confidentiality obligations continue after access or employment ends.
5. Security measures
5.1 Taking into account the state of the art, implementation costs, the nature, scope, context and purposes of processing, and risks to individuals, Sync 365 will maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
5.2 The measures in place at the effective date are described in Schedule 2. Sync 365 may update them as technology and risk change, provided the overall protection of Customer Personal Data is not materially reduced.
5.3 Customer is responsible for secure endpoints, Authorised Users, least-privilege permissions, Customer-Selected Integrations, credentials under its control, and reviewing the outputs and access granted through its configuration.
6. Security Incidents
6.1 Sync 365 will notify Customer without undue delay after becoming aware of a Security Incident and will provide available information reasonably needed for Customer to meet its notification obligations.
6.2 As information becomes available, notice will describe, to the extent known:
- the nature of the Security Incident;
- affected categories and approximate numbers of Data Subjects and records;
- likely consequences;
- measures taken or proposed to contain, investigate and remediate it; and
- a contact for follow-up.
6.3 Sync 365 will take reasonable steps to contain, investigate and mitigate the Security Incident and will provide material updates. Notification is not an admission of fault or liability.
6.4 Customer is responsible for determining whether to notify a Supervisory Authority, affected person, customer or other party. Sync 365 will reasonably assist, taking into account the nature of processing and information available to us.
7. Data Subject requests
7.1 Taking into account the nature of processing, Sync 365 will provide reasonable technical and organisational assistance for Customer to respond to requests to access, correct, delete, restrict, object to or port Customer Personal Data and to address other rights under Applicable Data Protection Law.
7.2 If Sync 365 receives a request directly relating to Customer Personal Data, we will not respond substantively unless Customer instructs us or law requires it. We will redirect the requester to Customer or notify Customer, where permitted.
7.3 If assistance requires material work beyond standard Service functionality, the parties will agree scope and reasonable charges in advance, except where the work is required because Sync 365 breached this DPA.
8. Risk assessments and regulatory assistance
Taking into account the nature of processing and information available to us, Sync 365 will reasonably assist Customer with:
- security-of-processing obligations;
- Personal Data Breach assessments and notices;
- data protection impact assessments;
- prior consultation with a Supervisory Authority; and
- information reasonably needed for a transfer impact or transfer risk assessment.
Customer remains responsible for deciding whether an assessment, consultation or notification is required and for completing its legal analysis.
9. Government and legal requests
9.1 Unless prohibited by law, Sync 365 will notify Customer before disclosing Customer Personal Data in response to a binding government, law-enforcement or court request.
9.2 We will review the legal validity of a request, challenge overbroad or unlawful demands where reasonable, disclose only the minimum data legally required, and document requests as required by law.
10. Subprocessors
10.1 Customer gives general written authorisation for Sync 365 to use the Subprocessors in Schedule 3.
10.2 We will provide at least 30 days’ advance notice before appointing a new Subprocessor that will process Customer Personal Data or making a material replacement. Notice may be sent to Customer’s account administrator or designated privacy contact and may also be published with the current DPA.
10.3 Customer may object within 14 days after notice on reasonable, documented data-protection grounds. The parties will work in good faith to address the objection. If no reasonable alternative is available, either party may terminate only the affected Service on written notice, and Sync 365 will refund prepaid fees for the unused portion of that affected Service.
10.4 Sync 365 will enter into a written agreement requiring each Subprocessor to protect Customer Personal Data to a standard no less protective than the obligations applicable to Sync 365 under this DPA. Sync 365 remains responsible for its Subprocessors’ performance to the extent required by Applicable Data Protection Law.
10.5 If Customer asks for a copy of a relevant Subprocessor agreement, we may provide a redacted copy or a summary sufficient to demonstrate the applicable data-protection terms, subject to confidentiality and security restrictions.
10.6 A Customer-Selected Integration is not a Sync 365 Subprocessor merely because the Services retrieve data from it or send data to it at Customer’s instruction. Customer is responsible for its contract, permissions, transfer mechanism and lawful use of that service. For example, an Autotask account separately licensed and controlled by Customer is normally a Customer-Selected Integration for Contact Sync.
11. International transfers
11.1 Sync 365’s primary application hosting region is Microsoft Azure North Europe in Ireland. Customer authorises access and processing in Ireland and Singapore and the limited onward processing by approved Subprocessors described in Schedule 3.
11.2 Sync 365 will not make a Restricted Transfer unless a lawful transfer mechanism applies. Where necessary, the parties will implement supplementary technical or organisational measures informed by the relevant transfer assessment.
11.3 EU and EEA transfers
For a Restricted Transfer subject to the EU GDPR, the EU SCCs are incorporated into this DPA by reference and deemed executed by the parties. The unmodified EU SCC text forms part of the Agreement as if set out in full. The following selections and completed appendices apply:
- Module Two (controller to processor) applies when Customer is a Controller.
- Module Three (processor to processor) applies when Customer is a Processor for another Controller.
- Clause 7, the optional docking clause, applies.
- For Clause 9, Option 2 (general written authorisation) applies and the notice period is 30 days.
- The optional language in Clause 11(a) does not apply.
- For Clause 17, Option 1 applies and the governing law is the law of Ireland.
- For Clause 18(b), disputes will be resolved by the courts of Ireland.
- Annex I is completed by Schedule 1 and the party details at the beginning of this DPA and in the applicable Order or account.
- Annex II is completed by Schedule 2.
- Annex III is completed by Schedule 3.
- The competent Supervisory Authority under Annex I.C is the authority determined by Clause 13. Where Clause 13 does not identify another authority, it is the Irish Data Protection Commission.
Customer is the data exporter and Focused Productivity Pte. Ltd. is the data importer, except where the transfer direction or applicable module requires otherwise. If Customer acts as a Processor, it confirms that its Controller has authorised Sync 365 as a Subprocessor and the transfer.
11.4 United Kingdom transfers
For a Restricted Transfer subject to the UK GDPR, the UK Addendum is incorporated and deemed executed. Its tables are completed as follows:
- Table 1: the parties and contacts are those in Schedule 1, the applicable Order or account, and the beginning of this DPA.
- Table 2: the approved EU SCC version is Decision (EU) 2021/914; Module Two or Module Three and the clause selections in section 11.3 apply.
- Table 3: the Appendix Information is in Schedules 1, 2 and 3.
- Table 4: both the Importer and Exporter may end the UK Addendum as permitted by its mandatory clauses if the ICO issues a revised approved addendum.
The mandatory clauses of the UK Addendum prevail over inconsistent Agreement terms. The UK Information Commissioner’s Office is the competent Supervisory Authority for UK Restricted Transfers.
If the EU SCCs and UK Addendum cannot lawfully be used for a particular UK transfer, the parties will use the then-current UK International Data Transfer Agreement or another valid safeguard.
11.5 Singapore overseas transfers
Where the PDPA applies, Sync 365 will ensure that an overseas recipient processing Customer Personal Data on our behalf is bound by legally enforceable obligations providing a standard of protection comparable to the PDPA. The contemplated countries and territories and applicable safeguards are identified in Schedule 3.
11.6 Transfer cooperation and priority
Each party will provide information reasonably needed to assess a Restricted Transfer and will cooperate in good faith to replace an invalid or superseded transfer mechanism. The applicable EU SCCs or UK Addendum prevail over this DPA and the rest of the Agreement for a Restricted Transfer. Nothing in the Agreement limits rights or liability that may not be limited under those transfer clauses.
12. Return, deletion and retention
12.1 During the Services and for 60 days after termination, Customer may request an available export of Customer Personal Data. Customer may also instruct earlier deletion, subject to technical feasibility, security, legal retention and payment of undisputed amounts.
12.2 At Customer’s choice, Sync 365 will return or delete Customer Personal Data after the Services end and will delete existing copies unless applicable law requires storage. If Customer gives no contrary instruction, Customer instructs Sync 365 to delete active copies after the 60-day retrieval period in the Agreement.
12.3 Customer Personal Data remaining in protected backups will be isolated from ordinary use, kept subject to this DPA and overwritten or deleted according to the applicable backup lifecycle. If law requires retention, we will keep the data isolated, process it only for that legal requirement and delete it when the requirement ends.
12.4 On reasonable request, Sync 365 will confirm completion of deletion in writing.
13. Information and audits
13.1 Sync 365 will make available information reasonably necessary to demonstrate compliance with this DPA, which may include current security documentation, relevant policies, completed questionnaires and independent assurance reports when available.
13.2 Customer may audit compliance with this DPA once in any 12-month period and additionally after a Security Incident, a reasonable indication of material non-compliance, or a request from a Supervisory Authority.
13.3 Unless urgent or prohibited by a Supervisory Authority, Customer will give at least 30 days’ notice. Audits must:
- be scoped to Customer Personal Data and the relevant Services;
- occur during normal business hours without unreasonable disruption;
- protect other customers, security information and confidential information;
- use an independent auditor who is not a competitor and is bound by confidentiality; and
- use existing reports and remote review first where they provide reasonable assurance.
13.4 Customer bears its audit costs and reimburses reasonable Sync 365 costs for an on-site or unusually burdensome audit, unless it identifies a material breach by Sync 365. These safeguards do not restrict a Supervisory Authority’s lawful powers or an audit right that Applicable Data Protection Law does not permit the parties to limit.
13.5 Sync 365 will cooperate with a competent Supervisory Authority as required by Applicable Data Protection Law.
14. US state privacy terms
Where a US state privacy law applies to Customer Personal Data and treats Sync 365 as a processor, service provider or contractor, Sync 365 will:
- process the data only for the limited and specified business purposes in the Agreement and Customer’s instructions;
- provide the same level of privacy protection required of a processor, service provider or contractor under that law;
- not sell or share Customer Personal Data, retain, use or disclose it outside the Agreement’s business purposes, or use it outside the direct business relationship with Customer;
- not combine it with personal data received from another person or collected from our own interaction with an individual, except where the law permits;
- notify Customer if we determine that we can no longer meet an applicable obligation; and
- allow Customer to take reasonable steps to verify, stop and remediate unauthorised use.
15. Records and DPO cooperation
Each party will maintain records of processing and designate a data-protection contact or officer where required by Applicable Data Protection Law. On reasonable request, each party will provide the other with current contact information needed for this DPA, regulator cooperation and Data Subject rights.
Sync 365’s data-protection contact is info@sync365license.com.
16. Liability and order of precedence
16.1 The liability provisions of the Agreement apply to this DPA to the maximum extent permitted by law.
16.2 Nothing in the Agreement limits a Data Subject’s rights, a Supervisory Authority’s powers, or liability that may not lawfully be limited. The liability and third-party-beneficiary provisions of the EU SCCs and UK Addendum remain effective for transfers governed by them.
16.3 If there is a conflict about Customer Personal Data, the order of precedence is: applicable EU SCCs or UK transfer terms; this DPA; a signed Order that expressly identifies the provision it changes; and the remaining Agreement.
17. Term and changes
17.1 This DPA continues while Sync 365 processes Customer Personal Data, regardless of termination of other Agreement provisions.
17.2 We may update this DPA to reflect a change in law, regulator guidance, the Services, security measures or Subprocessors. We will not materially reduce Customer’s protection during a current paid term without notice and, where required, consent.
17.3 A change to a transfer mechanism or Subprocessor will follow sections 10 and 11. Earlier versions will be retained in our records for contract-evidence purposes and may be requested from our data-protection contact.
Schedule 1 — Processing details and EU SCC Annex I
A. Parties
Data exporter / Customer: the customer legal entity identified in the Order, Sync 365 account or signature block. Address and contact details are those maintained in the Order or account. Customer’s role is Controller or Processor as described in section 2.
Data importer / Processor: Focused Productivity Pte. Ltd. (UEN 202311385N), 77 High Street, #10-12B, High Street Plaza, Singapore 179433. Data-protection contact: info@sync365license.com. Role: Processor, Subprocessor or data intermediary.
Activities relevant to the transfer are the activities described below. Electronic acceptance of the Agreement constitutes each party’s signature and agreement to be bound by the incorporated EU SCCs and UK Addendum. A separate signature block is in Schedule 4.
B. Subject matter
Provision, security and support of the Sync 365 SaaS platform, including configured Microsoft licence and subscription reconciliation, Azure billing workflows, user and managed-user calculations, custom recurring billing, Contact Sync, End User Portal functionality, reporting, alerts and supported PSA synchronisation.
C. Duration
For the subscription term and the post-termination retrieval, deletion and backup periods described in section 12, unless law requires longer retention.
D. Nature and processing operations
Collection, access, retrieval, recording, organisation, structuring, storage, consultation, comparison, matching, filtering, calculation, mapping, display, transmission, synchronisation, support, security monitoring, backup, export, restriction and deletion.
Processing may occur continuously when users access the Services and on configured, event-driven or scheduled refresh and synchronisation cycles.
E. Purposes
- provide and administer Customer’s configured Services;
- authenticate and support Authorised Users;
- retrieve supported data from Customer-authorised Microsoft and related systems;
- reconcile licences, subscriptions, users, Azure data and recurring-service quantities;
- map and synchronise data with Customer-Selected Integrations;
- perform Contact Sync and End User Portal workflows selected by Customer;
- maintain security, availability, auditability, backup and recovery;
- respond to authorised support requests; and
- comply with documented instructions and applicable law.
F. Categories of Data Subjects
- Customer’s employees, contractors, administrators and Authorised Users;
- Customer’s end customers and their staff, contractors, users and business contacts;
- Microsoft tenant users, contacts, group members and mailbox users;
- individuals recorded in Customer-controlled PSA company, site, contact, agreement, contract or billing records;
- End User Portal users and order contacts; and
- people whose Personal Data Customer or an Authorised User lawfully includes in a configured field or support request.
G. Categories of Personal Data
- name, business email, business telephone, job title, office, department, city, state, country, company and domain;
- account, customer, partner, tenant, user, contact, group, subscription, licence, product and related identifiers;
- enabled status, assigned licences, group membership, extension attributes and supported mailbox metadata;
- Microsoft subscription, licence, commitment, quantity and Azure subscription or consumption information where linked to a person;
- PSA company, site, contact, agreement, contract, product, billing, mapping and sync information;
- portal account, catalogue, order, subscription, pricing and branding information;
- authentication, authorisation, integration, device, IP, audit, diagnostic and security records; and
- content supplied in an authorised support request.
H. Sensitive data and safeguards
The Services are not designed to require special-category data, criminal-offence data, government identity numbers, health records or consumer payment-card data in Customer Personal Data. Customer must not intentionally submit that data unless the parties document the need and safeguards in an Order.
If sensitive data appears incidentally in a customer-controlled free-text or custom field, the security and confidentiality measures in Schedule 2 apply, access remains limited to authorised personnel and Customer should remove or restrict the field promptly.
I. Frequency and retention
Transfers and processing occur as Customer configures and uses the Services, including scheduled refreshes and syncs. Active Customer Personal Data is retained for the Service term and normally up to 60 days after termination for retrieval, then deleted or rendered inaccessible, subject to protected backup cycles and legal retention.
J. Customer rights and obligations
Customer retains the rights and obligations of a Controller or Processor under Applicable Data Protection Law, including determining lawful purpose and instructions, providing notices, responding to Data Subjects, managing Customer-Selected Integrations and ensuring its Controller authorises any Subprocessor where Customer acts as a Processor.
K. Competent Supervisory Authority
For the EU SCCs, the competent authority is determined under Clause 13 and section 11.3. For UK transfers, it is the UK Information Commissioner’s Office. For Singapore PDPA matters, it is the Personal Data Protection Commission Singapore.
Schedule 2 — Technical and organisational measures / EU SCC Annex II
Sync 365 maintains measures appropriate to the Services and risks, including:
1. Infrastructure and architecture
- Primary application hosting in Microsoft Azure North Europe, located in Ireland.
- Serverless-first application components, including Azure Functions, and managed Azure database services.
- Segmentation and network restrictions appropriate to managed production services.
- Data minimisation so the Services retrieve and retain information needed for configured functions.
2. Identity and access management
- Unique administrative identities and role-based access restricted to authorised personnel with a business need.
- Least-privilege access and periodic review of privileged access.
- Multi-factor authentication for privileged cloud and administrative access where supported.
- Customer-controlled roles, permissions and connected-service authorisations.
- Prompt removal or adjustment of access when responsibilities change.
3. Credential and secret protection
- Account passwords salted and hashed where password authentication is used.
- Integration credentials, tokens and secrets protected in managed storage and not intentionally exposed in ordinary logs or user interfaces.
- Procedures for rotating or revoking credentials where compromise is suspected.
4. Encryption and transmission
- Encryption of Customer Personal Data in transit over public networks using current transport security protocols.
- Encryption at rest for managed production storage and backups where supported by the Azure service.
- Secure API authentication and authorisation for supported integrations.
5. Secure development and change control
- Controlled source and deployment workflows.
- Review and approval controls for production changes through the deployment process.
- Separation of development and production activities appropriate to the size and risk of the service.
- Risk-based testing, dependency maintenance and remediation of identified vulnerabilities.
6. Logging, monitoring and incident response
- Application, infrastructure and security logging appropriate to troubleshooting, audit and incident investigation.
- Restricted access to logs and avoidance of unnecessary secrets in logs.
- Procedures to assess, contain, investigate, document and remediate suspected incidents.
- Escalation and customer-notification procedures for confirmed Security Incidents.
7. Availability, backup and recovery
- Managed cloud resilience appropriate to the selected Azure services.
- Protected backups and recovery procedures for applicable production data.
- Operational monitoring, maintenance and restoration procedures.
- Periodic review of continuity and recovery arrangements in proportion to risk.
8. Organisational security
- Confidentiality obligations for authorised personnel.
- Privacy and security guidance appropriate to personnel responsibilities.
- Restricted production infrastructure access and controlled administrative approval.
- Supplier due diligence and written data-protection obligations for Subprocessors.
9. Data lifecycle
- Purpose limitation and minimisation.
- Customer export and deletion procedures.
- Isolation of retained backups from ordinary use until overwrite or deletion.
- Legal-retention controls and secure disposal when retention is no longer required.
10. Assistance and assurance
- Processes for handling Data Subject requests, regulatory enquiries, customer questionnaires, risk assessments and audits under this DPA.
- Review of measures as the Services, threats and Applicable Data Protection Law change.
No certification is incorporated into this DPA unless Sync 365 confirms it in a signed Order or current assurance document.
Schedule 3 — Approved Subprocessors / EU SCC Annex III
Customer generally authorises the following Subprocessors at the effective date:
Microsoft group companies
Service: Microsoft Azure cloud infrastructure, managed compute, Azure Functions, database, storage, backup, logging, security and related support.
Data: Customer Personal Data needed to host, secure, operate, back up and support the Services.
Locations: Primary hosting in North Europe (Ireland). Limited support, resilience and onward processing may occur in countries identified for the relevant Microsoft online service in Microsoft’s current Products and Services Data Protection Addendum and Online Services Subprocessor List.
Safeguards: Microsoft’s data-protection terms; EU SCCs and the UK Addendum or another lawful mechanism where required; contractual PDPA-comparable protection.
Zoho group companies
Service: customer relationship management and support-case handling when Customer asks Sync 365 to process Customer Personal Data through a support request.
Data: account contact details, support communications and only the Customer Personal Data needed to investigate the authorised request. Customers should not place production credentials, bulk contact lists or unnecessary Customer Personal Data in support tickets.
Locations: United States and other locations identified for the configured Zoho service and its disclosed subprocessors.
Safeguards: Zoho data-processing terms; EU SCCs and the UK Addendum or another lawful mechanism where required; contractual PDPA-comparable protection.
Customer-Selected Integrations
Microsoft as a Customer’s source or destination system, and ConnectWise Manage, Autotask PSA, HaloPSA or another Customer-controlled destination, are Customer-Selected Integrations rather than Sync 365 Subprocessors for that exchange. Customer authorises transfers to and from those systems through its configuration and is responsible for its own agreement and lawful transfer mechanism with each provider.
For PDPA purposes, the contemplated overseas processing locations are Ireland, Singapore, the United States for limited support processing, and the additional countries specifically identified in the incorporated Microsoft or Zoho subprocessor disclosures for the relevant service. Sync 365 will provide notice under section 10 before adding a different Subprocessor for Customer Personal Data.
Schedule 4 — Optional execution block
The DPA is binding through the Agreement without this block. A Customer that requires a countersigned copy may complete its details and send the DPA to info@sync365license.com.
Customer legal name: ______________________________________
Registered address: ______________________________________
Registration number (if applicable): ______________________
Privacy contact and email: _________________________________
Customer role: Controller / Processor (delete as appropriate)
For Customer
Name: ______________________________________
Title: _____________________________________
Signature: __________________________________
Date: _______________________________________
For Focused Productivity Pte. Ltd.
Name: ______________________________________
Title: _____________________________________
Signature: __________________________________
Date: _______________________________________
