Version Date: July 10, 2026
This Data Processing Addendum (“DPA”) is a legal agreement between you (“You”, “Your”, or “Customer”) and Syncfusion, Inc., a Delaware corporation with its principal place of business located at 2501 Aerial Center Parkway, Suite 111, Morrisville, NC 27560 (“Syncfusion”).
This DPA is incorporated into and made part of the specific Terms of Use or Software License Agreement for the applicable Licensed Product (herein referred to as the “Agreement”). The Parties agree that the terms and conditions set forth below in this DPA govern the processing of Customer Personal Data. Except for the changes made by this DPA, the Agreement remains unchanged and in full force and effect. If there is any conflict between this DPA and the Agreement, this DPA will prevail only to the extent that conflict is in connection with the processing of Customer Personal Data.
Essential Studio, Bold BI Embedded, and Bold Reports Embedded (“Excluded Products”) are specifically excluded from this DPA. In connection with Your use of Excluded Products, this software is downloaded for use on Your own systems and doesn’t have data collection points or phone home functionality.
WHEREAS
Customer is Data Controller or equivalent as defined under Applicable Data Privacy Laws
Syncfusion is Data Processor or equivalent as defined under Applicable Data Privacy Laws.
Customer and Syncfusion seek to implement a DPA that complies with the requirements of Applicable Data Privacy Laws in relation to Data Processing. Syncfusion will act as a Processor for Customer soley to fulfill its obligations to Customer under the Agreement, including this DPA.
1. Definitions and Interpretation
1.1 “Applicable Data Protection Laws” means all applicable laws, regulations, and other legally binding requirements in any jurisdiction relating to privacy, data protection, data security, breach notification, that apply to Syncfusion’s Processing of Personal Data, including, without limitation, to the extent applicable, the General Data Protection Regulation (“EU GDPR”); the United Kingdom Data Protection Act of 2018 (“UK GDPR”); the Swiss Federal Act on Data Protection (“FADP”); and all laws and regulations, including laws and regulations of the European Union, the EEA and their member states, applicable to the Processing of Personal Data under this DPA and the Agreement.
1.2 “Customer Personal Data”, “Customer Data” or “Processed Data” means any Personal Data Processed by the Processor on behalf of Customer pursuant to or in connection with this DPA;
1.3 The terms, “Commission”, “Controller”, “Data Subject”, “Member State”, “Personal Data”, “Personal Data Breach”, “Processing” and “Supervisory Authority” (or equivalent terms) have the meanings set forth under Applicable Data Protection Laws.
1.4 “Contracted Processor” means a Subprocessor;”
1.5 “DPA” means this Data Processing Addendum;
1.6 “Data Transfer” means:
1.6.1 A transfer of Customer Personal Data from Customer to Syncfusion; or
1.6.2 A transfer of Customer Personal Data from the Customer to a Contracted Processor; or
1.6.3 An onward transfer of Customer Personal Data from a Contracted Processor to a Subcontracted Processor, or between two establishments of a Contracted Processor, in each case, where such transfer would be prohibited by Applicable Data Protection Laws
1.7 “EEA” means the European Economic Area;
1.8 “EU Data Protection Laws” means EU Directive 95/46/EC, as transposed into domestic legislation of each Member State and as amended, replaced or superseded from time to time, including by the GDPR and laws implementing or supplementing the GDPR;
1.9 “EU GDPR” means EU General Data Protection Regulation 2016/679 of the European Parliament and of the Council of 27 April 2016 (as applicable and in force across the European Union) on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (General Data Protection Regulation) as amended, replaced or superseded.
1.10 “EU Standard Contractual Clauses” or “EU SCCs” means (i) where the EU GDPR applies, the Standard Contractual Clauses for the Transfer of Customer Personal Data to Third Countries approved by the European Commission Decision of 4 June 2021 (Controller to Processor, Module 2), as attached to this DPA as Schedule 1; or (ii) where the UK GDPR applies, the EU Standard Contractual Clauses (controller to processor, Module 2), as supplemented by the UK Addendum.
1.11 “Licensed Product” has the same meaning as in the Agreement.
1.12 “UK Addendum” means the United Kingdom’s Data Transfer Addendum to the EU Standard Contractual Clauses available at https://ico.org.uk/for-organisations/guide-to-dataprotection/guide-to-the-general-data- protection-regulationgdpr/international-data-transfer-agreement-and-guidance/.
1.13 “UK GDPR” has the meaning given to it in section 3(10) (as supplemented by section 205(4)) of the DPA 2018 (defined below).
1.14 “UK Data Protection Legislation” means all applicable data protection and privacy legislation in force from time to time in the United Kingdom including without limitation the UK GDPR; the Data Protection Act 2018 (and regulations made thereunder) (DPA 2018); the Privacy and Electronic Communications Regulations 2003 (SI 2003/2426) as amended; and all other legislation and regulatory requirements in force from time to time which apply to a party relating to the use of Personal Data (including, without limitation, the privacy of electronic communications); and the guidance and codes of practice issued by the Commissioner or other relevant regulatory authority and which are applicable to a party.
1.15 “Subprocessor” means any person appointed by or on behalf of Processor to process Customer Personal Data on behalf of the Customer in connection with this DPA.
2. Scope and Purposes of Processing
2.1 Depending on Applicable Data Protection Laws, Customer is a Controller or Business and Syncfusion is a Processor or Service Provider with respect to Syncfusion’s Processing to provide services under the Agreement. This DPA applies to Syncfusion’s Processing of Personal Data on Customer’s behalf for the provision of Syncfusion Services as specified under the Agreement.
2.2 The term of this DPA will follow the subscription license term of the Agreement. Terms not otherwise defined in this DPA will have the meaning as set forth in the Agreement or Applicable Data Protection Laws, as applicable. Furthermore, such Agreement terms related to liability, arising out of or relating to this DPA, will be subject to the relevant limitations of liability set out in the Agreement.
2.3 The scope, nature, purposes, and duration of processing, the types of Personal Data Processed, and the Data Subjects concerned are set forth in this DPA.
2.4 Customer’s contact details and signature are as provided in the Agreement, Annex A of this DPA or as published publicly on their official website. Syncfusion’s contact details are as provided in our Privacy Policy or Annex A of this DPA.
2.4.1 The details provided in Annex A are deemed to satisfy any requirement to provide such details under Applicable Data Protection Laws.
3. Processing of Customer Personal Data
3.1 Processor shall:
3.1.1 Use best efforts to comply with all Applicable Data Protection Laws in the Processing of Customer Personal Data; and
3.1.2 Process Customer Personal Data in accordance with the Controller’s instructions below in Section 3.2.
3.2 Controller Instructions:
3.2.1 The Parties agree that Processor will process Customer Data for the purposes of performing a contract, compliance with legal obligations, and/or legitimate business interests.
3.2.2 The Parties agree that this DPA, together with Customer’s use of the Licensed Products in accordance with the terms and conditions of their respective Agreements, constitute your complete instructions to Processor in relation to the Processing of Customer Data.
3.2.3 Processor is not responsible for compliance with any Applicable Data Protection Laws solely applicable to Customer or Customer’s industry or jurisdiction that are not generally applicable to Processor.
4. Processor Personnel
Processor shall take reasonable steps to ensure the reliability of any employee, agent or contractor of any Contracted Processor who may have access to Customer Personal Data, ensuring in each case that access is strictly limited to those individuals who need to know / access the relevant Customer Personal Data, as strictly necessary for the purposes of this DPA, and to comply with applicable laws in the context of that individual’s duties to the Contracted Processor, ensuring that all such individuals are subject to confidentiality undertakings or professional or statutory obligations of confidentiality.
5. Security
5.1 Customer is responsible for independently determining whether the data security provided in relation to Customer’s use of the Licensed Products adequately meets Customer’s obligations under Applicable Data Protection Laws. Customer is also responsible for its secure use of the Licensed Products, including protecting the security of Personal Data in transit in connection with such use (including to securely backup or encrypt any such Personal Data).
5.2 Processor will implement and maintain appropriate technical and organizational measures to protect Customer Personal Data from Data Breaches.
6. Subprocessing
6.1 Processor will only appoint (or disclose any Customer Personal Data to) any Subprocessor for the purposes stated in Section 3.2.1.
6.2 Customer agrees that any Subprocessors listed on the applicable Licensed Product’s websites under “Subprocessors” are authorized; such lists may be updated from time to time.
6.3 Processor is responsible to ensure that sub-processors maintain sufficient guarantees to implement appropriate technical and organizational measures and that these are contractually imposed on the sub processor; Syncfusion is fully responsible to the Controller for the performance of the sub processor’s obligations.
7. Data Subject Rights
7.1 Processor shall assist Customer by implementing appropriate technical and organizational measures, insofar as this is possible, as described below.
7.2 Processor shall:
7.2.1 Promptly notify Customer if it receives a request from a Data Subject under any Data Protection Law in respect of Customer Personal Data; and
7.2.2 Ensure that it does not respond to that request except on the documented instructions of Customer or as required by applicable laws to which the Processor is subject, in which case Processor shall to the extent permitted by applicable laws.
8. Personal Data Breach
8.1 Processor shall notify Customer without undue delay upon Processor becoming aware of a Personal Data Breach affecting Customer Personal Data. Such notification will include information a Processor must provide to a Controller under Article 33(3) of EU GDPR and UK GDPR to the extent such information is reasonably available to Syncfusion.
8.2 Processor shall cooperate with Customer and take reasonable commercial steps as directed by Customer to assist in the investigation, mitigation and remediation of each such Personal Data Breach.
9. Data Protection Impact Assessment and Prior Consultation
Processor shall provide reasonable assistance to Customer with any data protection impact assessments, and prior consultations with Supervising Authorities or other competent data privacy authorities, which are reasonably considered to be required by article 35 or 36 of the EU GDPR and UK GDPR or equivalent provisions of any Applicable Data Protection Law, in each case solely in relation to Processing of Customer Personal Data by, and taking into account the nature of the Processing and information available to, the Contracted Processors.
10. Termination
10.1 Upon Termination of the subscription license term, Syncfusion will delete Customer Personal Data at the end of provision of processing services and delete all copies in line with the retention period specified in the Agreement of the Licensed Product, unless otherwise required by Applicable Data Protection Laws or other Legal Requirements for Retention or storage of such data is required.
10.2 Retention Period for Data will be as agreed to in the Agreement of the Licensed Product.
10.3 This DPA will terminate automatically upon termination of the subscription license.
11. Audit rights
11.1 Subject to this Section 11, Processor shall make available to the Customer on request all information necessary to demonstrate compliance with this DPA, and shall allow for and contribute to audits, including inspections, by the Customer or an auditor mandated by the Customer in relation to the Processing of the Customer Personal Data by the Contracted Processors.
11.2 Information and audit rights of the Customer only arise under section 11.1 to the extent that the DPA does not otherwise give them information and audit rights meeting the relevant requirements of Data Protection Law.
11.3 If Customer chooses to conduct an independent audit, Customer will be responsible for any fees charged by any auditor appointed by Customer to execute any such audit. Syncfusion will provide Customer with further details of any applicable costs or fees, and the basis of its calculation, in advance of any such review or audit.
11.4 Before the commencement of any such on-site audit, Customer and Syncfusion shall mutually agree upon the scope, timing, and duration of the audit.
11.5 Customer shall make (and ensure that each of its mandated auditors makes) reasonable endeavors to avoid causing (or, if it cannot avoid, to minimize) any damage, injury or disruption to Syncfusion’s premises, equipment, personnel and business while Customer’s personnel are on those premises in the course of such an audit.
12. Data Transfer
12.1 Customer acknowledges and agrees that Processor may access and Process Customer Personal Data on a global basis as described in Section 3.2.1. Wherever Customer Personal Data is transferred outside its country of origin, each party will ensure such transfers are made in compliance with the requirements of Applicable Data Protection Laws, as detailed in Section 12.2.
12.2 Cross-Border Transfer Mechanisms for International Data Transfers:
a. To the extent that Customer’s use of the Licensed Product requires a transfer of Personal Information outside the EEA or the United Kingdom (the “UK”), Syncfusion and Customer will take such measures as are necessary to ensure the transfer is in compliance with Applicable Data Protection Laws.
b. Syncfusion and Customer will only transfer Personal Information from the EEA or the UK to countries outside the EEA or the UK (i) that are recognized by the European Commission as providing an adequate level of protection for Personal Information; (ii) that are covered by a suitable framework recognized by the European Commission as providing an adequate level of protection for Personal Information; or (iii) through the use of other legally recognized validation methods such as Standard Contractual Clauses, as supplemented by the UK Addendum.
c. Syncfusion currently transfers personal data from the EEA or the UK to countries outside the EEA or the UK as follows: Syncfusion has adopted and hereby incorporates by reference the EU Standard Contractual Clauses. The parties further agree that the EU Standard Contractual Clauses will apply to Customer Personal Data that is transferred from the EEA or the UK, either directly or via onward transfer, to any country or recipient not recognized by the European Commission as providing an adequate level of protection for personal data.
d. The parties hereby agree that as new EU Standard Contractual Clauses are approved by the European Commission or other competent authority and become available for data controller to data processor transfers, this DPA will be updated (as necessary) to replace the existing EU Standard Contractual Clauses with the updated and approved EU Standard Contractual Clauses and updated UK Addendum, if any.
e. Each party agrees that, where Customer acts of the “Controller”, the EU Standard Contractual Clauses as supplemented by the UK Addendum (the terms of which are incorporated by reference) apply when Syncfusion acts as the “Processor”.
13. Governing Law and Jurisdiction
13.1 Except to the extent otherwise required by Applicable Data Protection Laws, this DPA will be governed by and construed in accordance with governing law and jurisdiction provisions in the Agreement.