This is SYSOI's standard Data Processing Addendum (DPA) under GDPR Article 28 and analogous laws. It is offered to customers who process personal data through the platform. It is not a substitute for counsel review of your own obligations. To execute a counter-signed copy for your organization, contact brian@sysoi.ai. The current sub-processor list (Annex III) is maintained on our Privacy page and kept in lockstep with this DPA.
This Data Processing Addendum ("DPA") forms part of the agreement between the customer ("Customer") and Sandbox Group LLC ("SYSOI," "we," or "us") for use of the SYSOI platform at sysoi.ai (the "Service") and reflects the parties' agreement on the processing of personal data under the EU General Data Protection Regulation (GDPR), UK GDPR, and applicable US state privacy laws.
1. Definitions
"Controller", "Processor", "Data Subject", "Personal Data", "Processing", and "Personal Data Breach" have the meanings given in the GDPR. "Sub-processor" means any processor engaged by SYSOI to process Customer Personal Data. "Customer Personal Data" means personal data SYSOI processes on Customer's behalf under the Service.
2. Roles of the Parties
For Customer Personal Data processed through the Service, Customer is the Controller and SYSOI is the Processor. SYSOI processes Customer Personal Data only to provide the Service and only on Customer's documented instructions, including as set out in this DPA and the agreement.
Separately, SYSOI acts as a Controller for its own business operations described on the Privacy page (for example, visitors to sysoi.ai and direct business contacts about SYSOI itself). That controller processing is outside the scope of this DPA.
3. Scope and Details of Processing
The subject matter, duration, nature, and purpose of processing, the types of personal data, and categories of data subjects are described in Annex I.
4. Processor Obligations
SYSOI will:
- Process Customer Personal Data only on Customer's documented instructions, unless required by law (in which case SYSOI will inform Customer unless legally prohibited).
- Ensure persons authorized to process Customer Personal Data are bound by confidentiality.
- Implement the technical and organizational measures set out in Annex II (Art. 32).
- Respect the sub-processor conditions in Section 6.
- Assist Customer, taking into account the nature of processing, in responding to data-subject-rights requests (Section 7) and in meeting its obligations under Arts. 32–36 (security, breach notification, DPIA).
- At Customer's election, delete or return Customer Personal Data at the end of the Service (Section 10).
- Make available information necessary to demonstrate compliance and allow for audits (Section 9).
5. Security
SYSOI maintains the technical and organizational measures described in Annex II, including encryption in transit, application-layer encryption of connector secrets, tenant isolation enforced at every domain query, role-based access control, consent and suppression enforcement on outbound marketing email, data-subject tooling (access, export, erasure with re-ingest suppression), and an access/audit log of privileged actions and AI runs.
6. Sub-processors
Customer provides a general authorization for SYSOI to engage the sub-processors listed on the Privacy page (incorporated as Annex III). SYSOI imposes data-protection obligations on each sub-processor no less protective than those in this DPA and remains responsible for their performance. SYSOI will update the public list before engaging a new sub-processor and will give active customers advance notice (at least 30 days, by email or in the product) so Customer may object on reasonable data-protection grounds.
Customer-directed integrations are not SYSOI sub-processors. Registration platforms, CRMs, marketing tools, and similar systems Customer connects to the Service (for example Cvent, RainFocus, HubSpot, Salesforce, Mailchimp, Google Sheets) are Customer's own systems, accessed with Customer's credentials on Customer's behalf. OAuth tokens for those connections are held by Nango (a listed sub-processor); API keys are sealed at rest by SYSOI.
7. Data Subject Rights
Taking into account the nature of the processing, SYSOI assists Customer by appropriate technical and organizational measures, insofar as possible, in fulfilling Customer's obligation to respond to requests to exercise data-subject rights (access, rectification, erasure, restriction, portability, objection). The Service provides operator tooling to view, export, and erase a data subject's personal data within a Customer workspace, and records a suppression entry so a later re-sync from an original source does not recreate an erased person. Two honest limits: data already handed off to Customer's own CRM is Customer's copy to erase, and free-text content that mentioned a name before erasure cannot be un-generated.
8. Personal Data Breach
SYSOI notifies Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and provides information reasonably available to assist Customer in meeting its breach-notification obligations.
9. Audit
SYSOI makes available information necessary to demonstrate compliance with this DPA and allows for and contributes to audits, including inspections, conducted by Customer or an auditor mandated by Customer, subject to reasonable confidentiality, security, and frequency limits. Where available, third-party attestations (for example SOC 2 reports of SYSOI or its subservice organizations under NDA) may satisfy audit requests in whole or in part.
10. Deletion or Return
Upon termination of the Service, SYSOI will, at Customer's election, delete or return Customer Personal Data, and delete existing copies unless retention is required by law. Suppression and opt-out records may be retained as necessary to continue honoring prior erasure and marketing objections.
11. International Transfers
Where SYSOI processes Customer Personal Data originating in the EEA, UK, or Switzerland outside those territories, the parties rely on an appropriate transfer mechanism, including the Standard Contractual Clauses, which are incorporated by reference where applicable. SYSOI and most sub-processors process data in the United States.
12. Customer Instructions and Responsibilities
Customer's use of the Service, configuration of connectors, import of lists, enrollment of audiences, activation of campaigns or sequences, and recorded attestations constitute documented instructions to process the related Customer Personal Data for the purposes of the Service.
Customer is responsible for the lawfulness of its instructions and of the personal data it supplies or causes to be supplied to the Service, including having a valid legal basis to process and, where applicable, to market to those contacts. Where the Service asks Customer to confirm that contacts are marketing contacts or opted-in (an at-ingest or activation attestation), that confirmation is Customer's representation. Customer will indemnify and hold harmless Sandbox Group LLC and its personnel from and against third-party claims, damages, losses, and reasonable costs arising from Customer's unauthorized use of the Service or Customer's breach of this DPA or the agreement, including misclassification of contacts as marketing-ready. Those indemnification obligations are not subject to any standard liability cap in the agreement. This allocation does not relax SYSOI's own processor duties under this DPA: unsubscribe handling, complaint auto-denial, and hard blocks on contacts marked denied remain fully enforced by the Service regardless of any attestation.
Customer will not use the Service to process special-category data under GDPR Article 9, or data relating to children, except where Customer has a lawful basis, has configured the Service accordingly, and has given SYSOI any additional documented instructions required. Dietary, accessibility, or similar fields that Customer chooses to store remain Customer's responsibility as Controller.
13. Annexes
- Annex I — Details of Processing. Subject matter: provision of the SYSOI event-lifecycle system of intelligence. Duration: the term of the agreement and any post-termination retention required by this DPA or law. Nature and purpose: ingesting and unifying event and CRM contact data Customer connects or uploads; building a per-contact golden record across events; optional enrichment from publicly available professional sources at Customer's direction; AI-assisted scoring, summarization, and content drafting for Customer review; readiness/handoff to Customer's CRM; campaign and sequence drafting and human-activated sending; analytics and program reporting for Customer. Categories of data subjects: Customer's personnel and authorized users of the Service; event registrants, attendees, leads, nominees, and other business contacts Customer supplies or syncs; individuals referenced in Customer-connected systems. Types of personal data: names, work email addresses, phone numbers, titles, companies/accounts, registration and attendance history, session and meeting activity, email engagement, consent and suppression status, optional logistics fields Customer chooses to store, public professional-profile enrichment Customer enables, AI-generated scores and rationales, and related metadata necessary to operate the Service.
- Annex II — Technical and Organizational Measures. Encryption in transit (TLS) enforced by the application host; database encryption at rest via the database provider; application-layer AES-256-GCM sealing of connector API keys and webhook secrets; third-party OAuth tokens held in a dedicated vault (Nango), not in SYSOI's primary database; tenant isolation by organization on every domain query; server-enforced role-based access (owner/admin/member/viewer) plus a separate platform-admin axis; Clerk-backed per-user identity with multi-factor authentication available/enforced for the application; audit logging of privileged and data-changing actions and AI runs (model/tokens/status; prompt content not retained as a privacy measure); consent capture with hard opt-out / complaint / suppression enforcement on SYSOI-sent marketing email; DSAR access, export, and erasure tooling with re-ingest suppression; change management via pull request with required automated checks; vulnerability and secret-scanning controls as described in SYSOI's security program; backups and point-in-time recovery via the database provider; network controls including production database access restricted to dedicated application egress where configured.
- Annex III — Sub-processors. The current list on the Privacy page (sysoi.ai/privacy), kept in lockstep with SYSOI's internal vendor register and this DPA.
14. Order of Precedence; Changes
If there is a conflict between this DPA and the agreement regarding the processing of Customer Personal Data, this DPA controls. SYSOI may update this standard DPA to reflect changes in law, sub-processors, or the Service; the version and effective date above identify the current public terms. Material changes will be reflected on this page. An executed counter-signed copy controls between the parties to that copy.
15. Contact
Sandbox Group LLC (operator of SYSOI) · Oregon, USA · Privacy and DPA contact: brian@sysoi.ai
Related: Privacy (roles, rights summary, and live sub-processor list).