top of page

Data Processing Agreement

This agreement is between ABS Synergy Ltd (CRO No. IE491109, VAT No. IE9773454J), operating through its divisions Synergy Up, Synergy Bookkeeping, and Synergy Stocktaking, as Data Processor, and the client organisation as Data Controller. It is entered into under Article 28 of the EU General Data Protection Regulation (2016/679) and the UK GDPR.

Version 1.6  ·  August 2026  ·  

1. Parties

3. Our Obligations

5. Sub - Processors

7. Retention & Deletion

9. Contact & Complaints

2. Personal Data Processed

4. Your Obligations

6. Data Location

8. Data Subject Rights

10. Governing Law

Section 1

Parties

Data Processor: 

ABS Synergy Ltd (trading as Synergy Up, Synergy Bookkeeping, and Synergy Stocktaking), CRO No. IE491109, VAT No. IE9773454J, with registered offices at 8–10 Coke Lane, Smithfield, Dublin, Ireland, D07 EN2Y.

 

Contact:

privacy@synergyup.com

 

Data Controller: 

The client organisation completing and accepting this agreement.

 

This agreement is entered into under Article 28 of the EU General Data Protection Regulation (2016/679) and the UK GDPR.

Section 2

Personal Data Processed on Your Behalf

Depending on which ABS Synergy Ltd services you use, we may process some or all of the following personal data on your behalf. Only the personal data relevant to the services you use will be processed.

Synergy Up platform

  • Employee Up: Employee names, contact details, dates of birth, PPS numbers, bank details, passport copies, work permit details, emergency contacts, employment contracts, and HR documents

  • Cash Up: Names and login details of staff who perform cash reconciliations

  • Order Up: Names of staff who perform stock counts and place orders; supplier email addresses

  • Report Up: Any personal data contained within reports uploaded to the platform

  • General platform access: Names and email addresses of managers and administrators with platform access

Synergy Bookkeeping services

  • Business owner and director details: Names, contact details, PPS numbers, and signatures where required for filings

  • Employee payroll and financial data: Names, PPS numbers, salary information, bank details, and tax records

  • Supplier and client contact details: Names, email addresses, phone numbers, and business addresses contained in invoices, statements, and correspondence

  • Financial records: Bank statements, invoices, receipts, and VAT records which may contain personal data relating to individuals

  • Any other personal data contained within financial documents or records provided to us for processing

Synergy Stocktaking services

  • Client site contact details: Names, email addresses, and phone numbers of managers and staff responsible for stock on site

  • Staff identity for audit purposes: Names of staff present during stock counts, where recorded for audit trail purposes

  • Report data: Any personal data contained within stocktaking reports, summaries, or documentation produced or uploaded as part of the service

This ​agreement covers all services provided by ABS Synergy Ltd regardless of which division delivers them.

Section 3

Our Obligations as Data Processor

 

  • Instructions only: We will only process your data on your documented instructions. We will inform you if we believe an instruction breaches GDPR.

  • Confidentiality: All staff and contractors with access to your data are bound by written confidentiality obligations.

  • Security: We implement appropriate technical and organisational measures in accordance with Article 32 GDPR to ensure a level of security appropriate to the risk. These measures include: encryption of personal data at rest and in transit; role-based access controls and the principle of least privilege; multi-factor authentication for platform access; ongoing confidentiality, integrity, availability, and resilience of processing systems; regular testing and evaluation of the effectiveness of technical and organisational measures; and the ability to restore access to personal data in a timely manner in the event of a physical or technical incident.

  • Sub-processors: We will notify you at least 30 days before engaging a new sub-processor. Our current sub-processors are listed in Schedule A. You may object to the addition of a new sub-processor within the notice period by contacting privacy@synergyup.com.

  • Data subject rights: We will assist you in responding to requests from individuals exercising their GDPR rights within required timeframes.

  • Breach notification: We will notify you without undue delay and in any event within 72 hours of becoming aware of a personal data breach affecting your data. Our notification will include, to the extent available at the time: a description of the nature of the breach; the categories and approximate number of individuals and personal data records affected; the likely consequences of the breach; and the measures taken or proposed to address it, including steps to mitigate its effects. Where full information is not available within 72 hours, we will provide an initial notification and follow up with further detail as the investigation progresses.

  • DPIAs: We will assist you with Data Protection Impact Assessments where our processing is relevant.

  • Deletion or return: At the end of your contract we will securely delete all your personal data within 30 days. Where you request it before deletion takes place, we will return your data to you in a portable format, in accordance with Section 7.

  • Audit rights: You have the right to request evidence of our compliance with this agreement once per year on at least 30 days' written notice. We will respond in the first instance by providing available compliance documentation, third-party audit reports, or certifications. Where that does not satisfy your reasonable requirements, we will facilitate an on-site or third-party audit at your cost, subject to agreed scope and confidentiality terms.

  • Compliance evidence: We will make available all information necessary to demonstrate compliance with Article 28 GDPR on request.

Section 4

Your Obligations as Data Controller

 

  • Ensure you have a lawful basis for each category of personal data you ask us to process on your behalf

  • Provide your employees, clients, and other data subjects with a privacy notice explaining how their data is used

  • Ensure that data provided to us is accurate, relevant, and limited to what is necessary

  • Inform us promptly of any data subject request or data breach affecting data we hold on your behalf

Section 5

Sub Processors

We engage third-party sub-processors to deliver our services. A current list of sub-processors is available at synergyup.com/sub-processors. Each sub-processor is bound by data protection obligations no less protective than those in this agreement. Where a sub-processor is located outside the EEA, transfers are made under an appropriate safeguard mechanism, details of which are included in the sub-processor list. We will update the list as changes occur. If you have questions about our sub-processors or the safeguards in place, contact privacy@synergyup.com.

Sub Processor
Location
Purpose
Amazon Web Services (AWS) eu-west-1
Ireland (EEA)
Cloud infrastructure and data storage for the Synergy Up platform
Bizimply
Ireland (EEA)
Workforce management integration (Synergy Up clients only, where applicable)
Cloudflare
EU nodes (EEA)
Security
Microsoft 365
EEA (EU data boundary)
Email and document handling used by Synergy Bookkeeping. May incidentally process client contact details.
OpenAI
United States
Invoice data extraction feature (Synergy Up). Incidental personal data: client names and addresses in invoice documents. No employee personal data processed.
QuickBooks Online (Intuit)
EEA (AWS EU region)
Cloud accounting software used by Synergy Bookkeeping. May include employee names, payroll figures, supplier contacts, and director details.
Spiceworks
United States
Customer support helpdesk. May process names, email addresses, and support query content.

An up-to-date sub-processor list is available on request at privacy@synergyup.com.

Section 6

Data Location

All production personal data on the Synergy Up platform is stored in AWS eu-west-1 (Ireland) and does not leave the European Economic Area at the infrastructure level.

A limited category of data may be processed by sub-processors located outside the EEA in the course of delivering the services. Details and the current status of safeguard mechanisms in place for each such transfer are set out in the sub-processor list at synergyup.com/sub-processors.

Our development and testing environments use only fully synthetic (non-personal) data. No production personal data is used in any non-production environment.

Section 7

Data Retention and Deletion

We retain your personal data only for the duration of your active contract with us.

Your responsibility: As Data Controller, you are responsible for retaining records for the periods required by law (including, where applicable, the Taxes Consolidation Act 1997 and the Organisation of Working Time Act 1997). You must download and retain any records you are legally required to keep before ending your contract with us.

On termination: We will permanently and securely delete all of your organisation's personal data within 30 days of contract termination. This deletion is irreversible. You are responsible for requesting the return of any data you need before the 30-day window closes. We do not send deletion reminders.

Data return: You may request the return of your data in a portable format at any time up to the point of deletion by contacting privacy@synergyup.com. Requests will be fulfilled within 5 working days. Once deleted, data cannot be recovered.

Our own records: We retain records of this agreement and its acceptance for 7 years for our own legal compliance purposes.

Section 8

Data Subject Rights

Responsibility for responding to data subject rights requests (access, rectification, erasure, portability, restriction, objection) lies with you as the Data Controller. We will assist you by providing the technical means to extract, correct, or delete personal data held on our systems within required GDPR timeframes. Requests for assistance should be directed to privacy@synergyup.com.

Where a data subject contacts us directly with a rights request relating to data for which you are the Controller, we will acknowledge the request and redirect the individual to you as the relevant Controller within 5 working days.

Section 9

Contact and Complaints

For all data protection queries, contact: privacy@synergyup.com

If you believe we have not handled your data in accordance with this agreement or applicable law, you have the right to lodge a complaint with the supervisory authority in your country of establishment.

 

Our lead supervisory authority is:

  • Irish Data Protection Commission (DPC): dataprotection.ie · +353 57 8684800

UK clients may also contact:

  • UK Information Commissioner's Office (ICO): ico.org.uk · 0303 123 1113

Section 10

Governing Law

This agreement is governed by the laws of Ireland and subject to the exclusive jurisdiction of the Irish courts. For UK clients, disputes arising specifically from obligations under the UK GDPR shall be subject to the laws of the United Kingdom and the relevant UK courts. All other disputes remain subject to Irish law and jurisdiction.

Questions?

bottom of page