Governs how CAMTECH AI processes personal data on behalf of clients acting as data controllers.
This agreement governs processing of personal data by CAMTECH AI on behalf of clients (data controllers) for services including SynapMess, SynapInsight, SynapMarket, SynapChain, SynapSpark, SynapID, and Custom AI engagements. Managed Infrastructure services are excluded — clients deploy on their own AWS accounts and CAMTECH AI does not act as processor for those workloads.
CAMTECH AI processes personal data strictly on documented instructions from the data controller and only for the purposes specified in the applicable service agreement. CAMTECH AI will not process personal data for any other purpose without prior written authorization from the data controller.
| Service | Purposes | Data subjects | Data categories |
|---|---|---|---|
| SynapMess | Automated conversation delivery, lead qualification, order processing, channel routing | End customers of the data controller | Message content, channel identifiers, conversation history, order data, opt-in records |
| SynapInsight | Panel management, survey distribution and collection, response analysis | Survey participants recruited by the data controller | Survey responses, demographic segments, panel participation records |
| SynapMarket | Marketplace operations, vendor management, order processing | Vendors and buyers on the controller's marketplace | Account data, product catalog, order and transaction records, vendor identity |
| SynapChain | Inventory and supply chain operations, demand forecasting, operational alert delivery | Internal operational users of the data controller | Stock levels, order records, supplier contact data, operational logs |
| SynapSpark | Content generation, campaign scheduling, performance analytics | Internal users; end audiences of published campaigns (indirect) | Brand assets, content drafts, campaign schedules, performance metrics |
| SynapID | Central authentication, SSO, passkeys, and identity management | End users of controller applications | User identity, email addresses, authentication credentials, session tokens |
| Custom AI engagements | As specified in the individual Statement of Work | As specified in the Statement of Work | As specified in the Statement of Work |
CAMTECH AI shall inform the data controller promptly if, in its opinion, any instruction from the data controller infringes applicable data protection law.
CAMTECH AI engages the following sub-processors in connection with data processing under this agreement. CAMTECH AI ensures each sub-processor is bound by data protection obligations at least equivalent to those applicable under this agreement.
| Sub-processor | Category | Data processed | Primary region | Status |
|---|---|---|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure | Application data, logs, contact data, operational metadata | US (primary), configurable | Operational at launch |
| Supabase | Database, auth, realtime | User records, service data, conversation metadata | Vendor-dependent | Operational at launch |
| Meta Platforms (WhatsApp, Instagram, Messenger) | Messaging channel infrastructure | Conversation content, channel metadata, opt-in records | Global | Operational for SynapMess |
| Cloudflare | Edge network, DNS, WAF, anti-abuse (Turnstile) | IP data, request metadata, challenge telemetry | Global edge | Operational (Turnstile on contact forms) |
| Stripe | Payment processing | Billing identity, transaction metadata, payment tokens | US, global | Planned — active when SaaS subscriptions launch |
| Google Analytics (GA4) | Web analytics | Pseudonymous device/browser usage events | Global | Operational (consent-gated) |
CAMTECH AI will notify the data controller at least 14 days before adding or replacing a sub-processor. The data controller may object in writing within that period.
CAMTECH AI applies technical and organisational measures consistent with those described in the Security & Trust page.
CAMTECH AI assists clients in responding to data subject requests as technically feasible within service scope.
CAMTECH AI notifies the data controller within 72 hours of becoming aware of a personal data breach affecting controller data.
Upon contract termination, CAMTECH AI deletes or returns controller data as agreed and within applicable regulatory timeframes.
If your question is not addressed by this policy, our legal team will respond within one business day.