Skip to content

Data Processing Addendum

Last updated: 15 July 2026 - Version 5.0

1. Scope

This Data Processing Addendum ("DPA") forms part of the Terms of Service between SYNDICATES TRADING LTD and the customer or user using the Services. It explains our data processing commitments under the UK GDPR and Data Protection Act 2018.

For ordinary individual users, we generally act as controller of account, payment, security, usage, support, and community data, as described in our Privacy Policy. This DPA applies where we process personal data on behalf of a business customer as processor, or where these processor-style terms are required by a separate written agreement.

2. Definitions

"Controller", "processor", "personal data", "processing", "data subject", "personal data breach", and "supervisory authority" have the meanings given in the UK GDPR.

3. Roles

  • Controller: for ordinary platform use, SYNDICATES TRADING LTD is controller of the personal data needed to operate the Services.
  • Processor: where a business customer provides personal data for us to process strictly on its documented instructions, we act as processor for that processing.
  • Subprocessors: our service providers process personal data to help us host, secure, bill for, and deliver the Services.

4. Processing Details

Subject matterProvision, security, billing, support, and administration of the Syndicates trading education platform.
DurationFor the term of the Services and any retention period required for legal, accounting, security, dispute, or fraud-prevention purposes.
Nature and purposeCollection, storage, retrieval, use, disclosure, restriction, deletion, and security monitoring for account access, membership delivery, content access, payments, support, community access, and legal compliance.
Types of dataIdentity, contact, authentication, payment, usage, analytics (where consented), support, technical, security, affiliate, journal/backtesting, Discord, avatar, and TradingView username data.
Data subjectsUsers, subscribers, affiliates, support contacts, and business-customer authorised users.

5. Processor Obligations

Where we act as processor, we will:

  • process personal data only on documented instructions unless required by UK law;
  • ensure people authorised to process personal data are subject to confidentiality obligations;
  • implement appropriate technical and organisational security measures;
  • assist the controller with data subject requests where reasonably possible;
  • assist with UK GDPR Articles 32 to 36 obligations where relevant to our processing;
  • notify the controller without undue delay after becoming aware of a personal data breach;
  • make available information reasonably necessary to demonstrate compliance;
  • delete or return personal data after processing ends, unless retention is required by law.

6. Subprocessors

You give general authorisation for us to use subprocessors needed to provide the Services. We remain responsible for subprocessors to the extent required by UK GDPR Article 28.

SubprocessorPurposeLocationTransfer safeguard
StripePayments, billing, invoices, fraud preventionUK, EU, United StatesUK-approved transfer safeguards where required
DiscordOAuth identity and community accessUnited States and other regionsUK-approved transfer safeguards where required
Google (Google Analytics)Optional website analytics after end-user cookie consentUnited States and other regionsUK-approved transfer safeguards / Google terms where required
CloudflareDNS, security, CDN/proxy, TLSGlobalUK-approved transfer safeguards where required
Proton Mail / SMTP providerTransactional email delivery and support email handlingSwitzerland / EUAdequacy or equivalent safeguards where required
Server hosting providerApplication hosting, database, file storageAs configured for productionContractual and technical safeguards

We will notify affected customers of material subprocessor changes where required by law or contract. Objections must be based on reasonable data protection grounds.

7. International Transfers

Where personal data is transferred outside the United Kingdom, we will use UK GDPR-compliant safeguards such as UK adequacy regulations, the International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, supplementary measures, or the UK Extension to the EU-US Data Privacy Framework where applicable.

8. Security Measures

Our measures include password hashing, encryption of sensitive tokens and 2FA secrets, HTTPS, secure cookies, rate limiting, account lockout, refresh-token expiry, role-based access controls, admin access controls, audit logs, content access logging, and backup and recovery controls appropriate to the Services.

9. Audit and Information Rights

Where UK GDPR Article 28 audit rights apply, audits must be reasonable, limited to relevant processing, conducted no more than once per calendar year unless required by a regulator or breach event, and subject to confidentiality and security requirements. We may satisfy audit obligations by providing policies, summaries, security information, or third-party reports where appropriate.

10. Deletion or Return

At the end of processing, we will delete or return personal data where technically feasible, unless we are required or permitted to retain it for legal, tax, accounting, fraud, chargeback, dispute, security, or backup purposes.

11. Contact

SYNDICATES TRADING LTD
Company number: 17252162
Registered office: 128 City Road, London, United Kingdom, EC1V 2NX
Data protection contact: [email protected]