Client Data Processing Terms
Last updated: June 19, 2026
1. Controller–Processor Relationship
The Client confirms and acknowledges that, with respect to all Personal Data processed in connection with the Client’s use of the Synnect Platform, the Client acts as the Data Controller, while Synexly acts solely as a Data Processor, within the meaning of Regulation (EU) 2016/679 (GDPR).
Synexly does not determine the purposes or means of the processing of Personal Data and processes such data exclusively on behalf of and in accordance with the documented instructions of the Client.
2. Client Instructions and Applicability of the Privacy Policy
By using the Synnect Platform, the Client expressly confirms and instructs Synexly to process Personal Data in accordance with this Client Data Processing Terms and the Privacy Policy, as applicable to the processing activities performed via the Synnect Platform.
Synexly may collect Personal Data about the Client’s employees, contractors, representatives, or any other persons engaged by the Client on any work-related basis who access or use the Synnect Platform in the course of their work. Moreover, Synexly may also process Personal Data about customers or end-users of the Client that are interacting with the Client through the Synnect Platform.
In all cases, the Client, as the Data Controller, represents and warrants that it is authorized to provide Synexly with such Personal Data. The Client hereby authorizes Synexly to collect, access, use, disclose, and otherwise process such Personal Data strictly in accordance with the purposes and conditions set out in this Client Data Processing Terms and the Privacy Policy. This consent and instruction cover all types of Personal Data collected and processed, the sources of such data, the purposes for which the data is processed, the legal bases under GDPR, the methods of collection, and the retention periods.
For the avoidance of doubt, the Client’s reference to and acceptance of the Privacy Policy constitutes documented instructions.
3. Client Responsibilities
The Client must ensure that:
- Any Personal Data provided to Synexly is accurate, complete, and up to date;
- All Data Subjects whose Personal Data is provided are properly informed of the processing activities, including the purposes, categories of data collected, recipients, and retention periods;
- Any required consents, notices, or authorizations under applicable data protection laws are obtained prior to transferring Personal Data to Synexly;
- It promptly notifies Synexly of any errors, changes, or updates regarding the Personal Data provided;
- It reasonably cooperates with Synexly in responding to Data Subject requests, to the extent required under applicable law.
4. Compensation Claims and Jurisdiction
Without prejudice to the mandatory rights of Data Subjects under applicable data protection laws, including Regulation (EU) 2016/679 (GDPR), any claims, disputes, or proceedings arising out of or in connection with this Client Data Processing Terms and the Privacy Policy, including claims for material or non-material damages, shall be governed by the jurisdiction provisions set out below.
Any claims, actions, or proceedings between Synexly and the Client, including those relating to alleged breaches of data protection obligations or claims for compensation, shall be subject to the exclusive jurisdiction of the competent courts of the Republic of Serbia.
Where a Data Subject brings a claim against Synexly in connection with the processing of Personal Data, such claim shall be governed by applicable data protection laws. To the extent permitted by law, the competent courts of the Republic of Serbia shall have jurisdiction over such proceedings.
Nothing in this clause shall limit the mandatory rights of Data Subjects to lodge a complaint with a competent supervisory authority or to seek judicial remedies as provided by applicable law.