Skip to main content

NotiSynk legal information

Data Processing Addendum

How NotiSynk handles the Client information a Professional records

Version:
2.0
Effective date:
2026-08-16

This Addendum forms part of the Terms of Service and applies whenever a Professional records information about their Clients in NotiSynk. It sets out what the operator of NotiSynk does with that information, what the Professional is responsible for, and what each party owes the other.

1. The roles of the two parties

The Professional decides which Clients to record, what to record about them, and why. NotiSynk provides the software and stores and processes what the Professional records, in order to run the Service on the Professional's instructions.

NotiSynk also processes information on its own account, and this Addendum does not cover that. Running the Workspace billing subscription, keeping the Service secure, investigating abuse, keeping legal acceptance evidence and meeting a legal obligation are NotiSynk's own responsibilities, described in the Privacy Policy.

This Addendum does not make either party the agent, partner or employee of the other, and neither party may hold itself out as such.

2. Scope, purpose and duration

ItemDetail
Subject matterProvision of the NotiSynk Service to the Professional's Workspace
DurationFor as long as the Workspace exists, and afterwards only for the retention described in section 10
PurposeTo run the Service: manage Clients, Plans, Client Subscriptions and sessions, send configured reminders, provide support, and on Max record revenue
Categories of personThe Professional's Clients, and the people the Professional gives access to the Workspace
Categories of informationClient name, email address, phone number, notes, Plan and Client Subscription records, session records, reminder and consent preferences, reminder delivery records, and on Max the revenue records the Professional enters
Information that must not be recordedInformation revealing health, genetic identity or sexual life; complete payment-card numbers and card security codes; government identification numbers; authentication secrets

3. Acting on the Professional's instructions

NotiSynk processes Client information to provide the Service and does not use it for its own purposes, does not sell it, and does not use it to advertise to anyone. The Professional's instructions are given through the Service itself: the records created, the settings chosen, the reminders configured and the support requests submitted.

NotiSynk will not process Client information outside those instructions except where the law requires it. Where the law requires it and it is lawful to say so, NotiSynk will tell the Professional first.

If NotiSynk considers that an instruction would breach the law, it will say so and may decline to act on it.

4. What the Professional is responsible for

The Professional is responsible for being entitled to record what they record, and for the relationship with the Client. Specifically, the Professional must:

  • Be entitled to collect and record each Client's name, email address, phone number, Client Subscription details, session records, consent evidence and, on Max, their payment records.
  • Tell each Client what is recorded in NotiSynk, why, who it is sent to, and that they may ask for access, correction or erasure and may object. Because the information reaches NotiSynk from the Professional and not from the Client, Lebanese law places that duty on the Professional.
  • Obtain WhatsApp consent before enabling WhatsApp reminders for a Client, and keep the record of it.
  • Keep Client records accurate and up to date, and act on a Client's request to correct or remove their details.
  • Not record information revealing a Client's health, genetic identity or sexual life. NotiSynk holds no licence for information of that kind and the Service must not be used for it.
  • Not use the Service to send unsolicited advertising, and not repurpose reminder templates as marketing.
  • Keep Workspace access limited to people who need it and remove access promptly when they no longer do.

5. What NotiSynk is responsible for

  • Taking measures appropriate to the nature of the information and the risks of processing it, to keep it accurate and secure and to protect it against alteration, damage and unauthorised access.
  • Keeping each Workspace separated from every other Workspace, with the boundary enforced on the server and derived from the authenticated session rather than from anything the browser sends.
  • Limiting internal access to the small number of people who need it to operate, support or secure the Service.
  • Binding the people with access to confidentiality.
  • Telling the Professional about a security incident affecting their Workspace, as described in section 8.
  • Helping the Professional answer a Client request, as described in section 9.

6. Confidentiality and personnel

Client information is confidential. The people who can reach it are bound by confidentiality obligations that continue after their engagement ends, and access is granted on the basis of what a role actually needs rather than by default.

Administrative access is limited and is used to operate, support and secure the Service. It is not used to browse Workspace records without a reason connected to one of those purposes.

7. Providers NotiSynk uses

NotiSynk uses the providers listed in the Subprocessors notice to deliver the Service. The Professional agrees to their use. Each is engaged for a stated purpose and receives only what that purpose needs.

  • Stripe: Processing of the Workspace billing subscription: checkout, recurring charges, payment-method updates, refunds and related fraud prevention.
  • Meta Platforms (WhatsApp Business Platform): Delivery of approved WhatsApp template messages to Clients and return of delivery-status callbacks.
  • Aiven: Managed PostgreSQL database hosting for the application database.
  • Namecheap Private Email: Delivery of transactional email, including email verification, password reset and account and billing notices.
  • Vercel: Website audience and page-performance measurement through Vercel Web Analytics and Speed Insights, loaded only after the visitor grants analytics consent.

NotiSynk remains responsible to the Professional for a provider's processing of Client information in the same way as for its own.

If NotiSynk adds or replaces a provider that processes Client information, the Subprocessors notice is updated before the change takes effect where that is practicable, and the change is announced in the Service. A Professional who objects to a new provider on reasonable grounds connected to the protection of Client information may tell us, and if the objection cannot be resolved the Professional may end the subscription without penalty for the remainder of the paid period.

8. Security incidents

If NotiSynk becomes aware of a security incident that has led to Client information in a Workspace being destroyed, altered, disclosed or reached without authorisation, NotiSynk will tell the affected Professional without undue delay once the incident is confirmed.

The notice will describe what is known: what happened, which categories of information and roughly how many records are affected, the likely consequences, what has been done, and what the Professional should consider doing. Where the full picture is not yet available, NotiSynk will say what is known and follow up rather than delay the first notice.

NotiSynk will provide the information the Professional reasonably needs to meet their own obligations to their Clients or to an authority. Sending a notice is not an admission of fault.

9. Helping with Client requests

A Professional can see, correct, complete, update and remove Client records directly in their Workspace, which answers most requests without needing NotiSynk.

Where a request cannot be answered from the Workspace, NotiSynk will help, taking into account the nature of the processing and the information available to us. Where Lebanese law sets a deadline for a correction, completion, update or erasure, NotiSynk will act within the time needed for the Professional to meet it, and in any event within 10 days of a clear request.

If a Client contacts NotiSynk directly, NotiSynk will not answer for the Professional. NotiSynk will tell the Client to contact the Professional, tell the Professional that the request was made, and act on anything the law requires NotiSynk to do itself. Requests reach us at info@notisynk.com.

10. Return and deletion

While the Workspace is open, the Professional can export the exportable parts of their data at any time using the tools in the Service.

After the agreement ends, NotiSynk keeps the Workspace data for a reasonable retrieval period so it can still be exported, then removes it. Backups are overwritten on their own cycle rather than edited, so a record can persist in a backup for a short period after it is removed from the live system; while it does, it is not used for anything.

Some records survive deletion because they have to. Legal acceptance evidence, revenue transactions and session events are append-only and are not rewritten or removed. Billing records are kept as business records for the period the applicable law requires. Security records are kept where they are needed to investigate an incident or to establish or defend a claim. The Data Retention Policy sets out each case.

11. Where processing happens

The Service is operated from Lebanon and the providers listed in the Subprocessors notice operate infrastructure outside Lebanon, so Client information is processed outside Lebanon. Each provider is bound by its own contract and data-protection commitments. NotiSynk does not claim to rely on European standard contractual clauses, on an adequacy decision, or on any other transfer mechanism it has not entered into.

A Professional who needs processing to remain within a particular territory should not assume the Service provides it. Ask before relying on it.

12. Information and cooperation

NotiSynk will provide the information a Professional reasonably needs to satisfy themselves that this Addendum is being met, including the descriptions in the Security Statement, the Subprocessors notice and the Data Retention Policy, and answers to reasonable written questions.

NotiSynk does not hold an independent security certification or audit report, and this Addendum does not promise one. Where a Professional is under a legal obligation that requires more, they should raise it before relying on the Service for that purpose.

13. Changes and conflicts

This Addendum carries its own version number and effective date. A material change is put to the Professional for acceptance in the Service, and previous acceptances are kept unchanged.

If this Addendum conflicts with the Terms of Service on the handling of Client information, this Addendum prevails. Nothing in it removes or limits a right that applicable law does not permit the parties to remove, and any clause that purported to do so would have no effect.

Change log

  • v2.02026-08-16First published version. Rewritten to describe the actual processing: Workspace isolation, the Professional's responsibility for the lawfulness of Client information and for informing Clients, assistance with Client requests, the verified provider list, incident handling, and what happens to information on termination.