top of page
Square Transparant Up Logo.png

Data Processing Agreement (DPA)

ABS SYNERGY LTD T/A SYNERGY UP
Version 1.7  ·  September 2026  ·  Active​

This agreement is between ABS Synergy Ltd (CRO No. IE491109, VAT No. IE9773454J), operating through its divisions Synergy Up, Synergy Bookkeeping, and Synergy Stocktaking, as Data Processor, and the client organisation as Data Controller. It is entered into under Article 28 of the EU General Data Protection Regulation (2016/679) and the UK GDPR.

​​1. Parties

ABS Synergy Ltd (trading as Synergy Up, Synergy Bookkeeping, and Synergy Stocktaking), CRO No. IE491109, VAT No. IE9773454J, with registered offices at 8–10 Coke Lane, Smithfield, Dublin, Ireland, D07 EN2Y. 

 

Contact: 

privacy@synergyup.com

 

Data Controller: 

The client organisation completing and accepting this agreement.

 

This agreement is entered into under Article 28 of the EU General Data Protection Regulation (2016/679) and the UK GDPR.

2. Personal Data Processed on Your Behalf

Depending on which ABS Synergy Ltd services you use, we may process some or all of the following personal data on your behalf. Only the personal data relevant to the services you use will be processed.

​

Synergy Up platform

  • Employee Up: Employee names, contact details, dates of birth, PPS numbers, bank details, passport copies, work permit details, emergency contacts, employment contracts, and HR documents

  • Cash Up: Names and login details of staff who perform cash reconciliations

  • Order Up: Names of staff who perform stock counts and place orders; supplier email addresses

  • Report Up: Any personal data contained within reports uploaded to the platform

  • General platform access: Names and email addresses of managers and administrators with platform access

  • DocUp: Email account access credentials (via Google or Microsoft OAuth, or IMAP credentials for other providers), email metadata (sender, subject, date), and attachment content from email accounts you choose to connect. This feature retrieves invoice attachments automatically and also organises your mailbox by labelling and moving processed emails.

​

Synergy Bookkeeping services

  • Business owner and director details: Names, contact details, PPS numbers, and signatures where required for filings

  • Employee payroll and financial data: Names, PPS numbers, salary information, bank details, and tax records

  • Supplier and client contact details: Names, email addresses, phone numbers, and business addresses contained in invoices, statements, and correspondence

  • Financial records: Bank statements, invoices, receipts, and VAT records which may contain personal data relating to individuals

  • Any other personal data contained within financial documents or records provided to us for processing

​

Synergy Stocktaking services

  • Client site contact details: Names, email addresses, and phone numbers of managers and staff responsible for stock on site

  • Staff identity for audit purposes: Names of staff present during stock counts, where recorded for audit trail purposes

  • Report data: Any personal data contained within stocktaking reports, summaries, or documentation produced or uploaded as part of the service

​

This ​agreement covers all services provided by ABS Synergy Ltd regardless of which division delivers them.

3. Our Obligations as Data Processor

  • Instructions only: We will only process your data on your documented instructions. We will inform you if we believe an instruction breaches GDPR.

  • Confidentiality: All staff and contractors with access to your data are bound by written confidentiality obligations.

  • Security: We implement appropriate technical and organisational measures in accordance with Article 32 GDPR to ensure a level of security appropriate to the risk. These measures include: encryption of personal data at rest and in transit; role-based access controls and the principle of least privilege; multi-factor authentication for platform access; ongoing confidentiality, integrity, availability, and resilience of processing systems; regular testing and evaluation of the effectiveness of technical and organisational measures; and the ability to restore access to personal data in a timely manner in the event of a physical or technical incident.

  • Sub-processors: We will notify you at least 30 days before engaging a new sub-processor. Our current sub-processors are listed in Schedule A. You may object to the addition of a new sub-processor within the notice period by contacting privacy@synergyup.com.

  • Data subject rights: We will assist you in responding to requests from individuals exercising their GDPR rights within required timeframes.

  • Breach notification: We will notify you without undue delay and in any event within 72 hours of becoming aware of a personal data breach affecting your data. Our notification will include, to the extent available at the time: a description of the nature of the breach; the categories and approximate number of individuals and personal data records affected; the likely consequences of the breach; and the measures taken or proposed to address it, including steps to mitigate its effects. Where full information is not available within 72 hours, we will provide an initial notification and follow up with further detail as the investigation progresses.

  • DPIAs: We will assist you with Data Protection Impact Assessments where our processing is relevant.

  • Deletion or return: At the end of your contract we will securely delete all your personal data within 30 days. Where you request it before deletion takes place, we will return your data to you in a portable format, in accordance with Section 7.

  • Audit rights: You have the right to request evidence of our compliance with this agreement once per year on at least 30 days' written notice. We will respond in the first instance by providing available compliance documentation, third-party audit reports, or certifications. Where that does not satisfy your reasonable requirements, we will facilitate an on-site or third-party audit at your cost, subject to agreed scope and confidentiality terms.

  • Compliance evidence: We will make available all information necessary to demonstrate compliance with Article 28 GDPR on request.

4. Your Obligations as Data Controller

  • Ensure you have a lawful basis for each category of personal data you ask us to process on your behalf

  • Provide your employees, clients, and other data subjects with a privacy notice explaining how their data is used

  • Ensure that data provided to us is accurate, relevant, and limited to what is necessary

  • Inform us promptly of any data subject request or data breach affecting data we hold on your behalf

5. Sub Processors

We engage third-party sub-processors to deliver our services. A current list of sub-processors is available at synergyup.com/sub-processors. Each sub-processor is bound by data protection obligations no less protective than those in this agreement. Where a sub-processor is located outside the EEA, transfers are made under an appropriate safeguard mechanism, details of which are included in the sub-processor list. We will update the list as changes occur. If you have questions about our sub-processors or the safeguards in place, contact privacy@synergyup.com

6. Data Retention and Deletion

All production personal data on the Synergy Up platform is stored in AWS eu-west-1 (Ireland) and does not leave the European Economic Area at the infrastructure level.

​

A limited category of data may be processed by sub-processors located outside the EEA in the course of delivering the services. Details and the current status of safeguard mechanisms in place for each such transfer are set out in the sub-processor list at synergyup.com/sub-processors.

​

Our development and testing environments use only fully synthetic (non-personal) data. No production personal data is used in any non-production environment.

7. Data Retention and Deletion

We retain your personal data only for the duration of your active contract with us.

​

Your responsibility: As Data Controller, you are responsible for retaining records for the periods required by law (including, where applicable, the Taxes Consolidation Act 1997 and the Organisation of Working Time Act 1997). You must download and retain any records you are legally required to keep before ending your contract with us.

​

On termination: We will permanently and securely delete all of your organisation's personal data within 30 days of contract termination. This deletion is irreversible. You are responsible for requesting the return of any data you need before the 30-day window closes. We do not send deletion reminders.

​

Data return: You may request the return of your data in a portable format at any time up to the point of deletion by contacting privacy@synergyup.com. Requests will be fulfilled within 5 working days. Once deleted, data cannot be recovered.

​

Our own records: We retain records of this agreement and its acceptance for 7 years for our own legal compliance purposes.

8. Data Subject Rights

Responsibility for responding to data subject rights requests (access, rectification, erasure, portability, restriction, objection) lies with you as the Data Controller. We will assist you by providing the technical means to extract, correct, or delete personal data held on our systems within required GDPR timeframes. Requests for assistance should be directed to privacy@synergyup.com.

​

Where a data subject contacts us directly with a rights request relating to data for which you are the Controller, we will acknowledge the request and redirect the individual to you as the relevant Controller within 5 working days.

9. Contact and Complaints

For all data protection queries, contact: privacy@synergyup.com

​

If you believe we have not handled your data in accordance with this agreement or applicable law, you have the right to lodge a complaint with the supervisory authority in your country of establishment.

 

Our lead supervisory authority is:

  • Irish Data Protection Commission (DPC): dataprotection.ie · +353 57 8684800

​

UK clients may also contact:

  • UK Information Commissioner's Office (ICO): ico.org.uk · 0303 123 1113

10. Governing Law

This agreement is governed by the laws of Ireland and subject to the exclusive jurisdiction of the Irish courts. For UK clients, disputes arising specifically from obligations under the UK GDPR shall be subject to the laws of the United Kingdom and the relevant UK courts. All other disputes remain subject to Irish law and jurisdiction.

11. Acceptance

This agreement is accepted electronically through the Synergy Up platform. New clients must accept this agreement, together with the Terms of Service, before they are able to access the Platform. The individual completing this process confirms they are authorised to enter into this agreement on behalf of their organisation.

​

Existing clients will be notified of this agreement and given 30 days to accept it. Access to the Platform may be restricted for any account that has not accepted within that period.

​

Where Synergy Up notifies the Client of an update to this agreement, continued use of the Platform after the effective date of that update constitutes acceptance of the updated agreement, in accordance with Section 13 of the Terms of Service.

Questions?

bottom of page