Skip to main content
Back to Home
GDPR Compliance

GDPR Compliance

Protecting the privacy and rights of individuals in the EEA

Processor Role

We process message data strictly on your behalf

SCCs Included

Standard Contractual Clauses covered in our DPA

Subject Rights

Full support for access, rectification, and erasure

Download our DPA

Our Data Processing Addendum (DPA) includes the latest EU SCCs. You can review and sign it electronically.

1. Our Commitment to GDPR

SyncRivo is fully committed to compliance with the General Data Protection Regulation (GDPR), which protects the personal data of individuals in the European Economic Area (EEA).

We have integrated GDPR principles into our entire platform lifecycle—from 'Privacy by Design' in our engineering architecture to our legal contracts and vendor management.

2. Controller vs. Processor

It is important to understand our role in handling your data:

• Processor: For the content of messages and files transmitted through our service, SyncRivo acts as a Data Processor. We process this data solely on your behalf and according to your instructions.

• Controller: For account administration data (e.g., billing contacts, admin user logins), SyncRivo acts as a Data Controller.

3. Data Subject Rights

We support all fundamental rights granted to data subjects under GDPR:

Right to Access & Rectification

  • You can view and update your settings directly in the SyncRivo Dashboard.
  • Admins can conduct widespread updates to integration configurations.

Right to Erasure ('Right to be Forgotten')

  • We support the deletion of workspace data upon account termination.
  • Since message data is transient (processed in RAM and cleared), it is inherently 'erased' immediately after delivery.

Right to Data Portability

  • Admins can export configuration logs and usage history.
  • We do not hold long-term message archives, so message portability is managed within your primary platforms (e.g., Slack/Teams exports).

4. International Data Transfers

SyncRivo ensures that data transferred outside the EEA is protected by appropriate safeguards.

• Standard Contractual Clauses (SCCs): We include the EU's modernized SCCs in our Data Processing Addendum (DPA).

• Data Privacy Framework: We participate in the EU-U.S. Data Privacy Framework (DPF) for transfers to the United States.

5. Sub-Processors

We engage third-party sub-processors to assist in providing our services (e.g., AWS for hosting).

• Due Diligence: All sub-processors undergo rigorous security and privacy reviews.

• List: We maintain a transparent list of all sub-processors.

• Notification: We notify customers before adding new sub-processors, providing an opportunity to object.

6. Security of Processing

In accordance with Article 32 of GDPR, we implement technical and organizational measures to ensure a level of security appropriate to the risk, including:

• Pseudonymization and encryption of personal data.

• Ability to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems.

• Regular testing, assessing, and evaluating the effectiveness of technical and organizational measures.

Three-Platform Bridges

Connect three enterprise messaging platforms simultaneously with SyncRivo's cross-platform bridges.

cookie_consent.banner.aria_announcement
Cookie consent banner is now visible. This site uses cookies to create a better experience for you.