Data Processing Addendum
Last updated: 15 July 2026 - Version 5.0
1. Scope
This Data Processing Addendum ("DPA") forms part of the Terms of Service between SYNDICATES TRADING LTD and the customer or user using the Services. It explains our data processing commitments under the UK GDPR and Data Protection Act 2018.
For ordinary individual users, we generally act as controller of account, payment, security, usage, support, and community data, as described in our Privacy Policy. This DPA applies where we process personal data on behalf of a business customer as processor, or where these processor-style terms are required by a separate written agreement.
2. Definitions
"Controller", "processor", "personal data", "processing", "data subject", "personal data breach", and "supervisory authority" have the meanings given in the UK GDPR.
3. Roles
- Controller: for ordinary platform use, SYNDICATES TRADING LTD is controller of the personal data needed to operate the Services.
- Processor: where a business customer provides personal data for us to process strictly on its documented instructions, we act as processor for that processing.
- Subprocessors: our service providers process personal data to help us host, secure, bill for, and deliver the Services.
4. Processing Details
| Subject matter | Provision, security, billing, support, and administration of the Syndicates trading education platform. |
| Duration | For the term of the Services and any retention period required for legal, accounting, security, dispute, or fraud-prevention purposes. |
| Nature and purpose | Collection, storage, retrieval, use, disclosure, restriction, deletion, and security monitoring for account access, membership delivery, content access, payments, support, community access, and legal compliance. |
| Types of data | Identity, contact, authentication, payment, usage, analytics (where consented), support, technical, security, affiliate, journal/backtesting, Discord, avatar, and TradingView username data. |
| Data subjects | Users, subscribers, affiliates, support contacts, and business-customer authorised users. |
5. Processor Obligations
Where we act as processor, we will:
- process personal data only on documented instructions unless required by UK law;
- ensure people authorised to process personal data are subject to confidentiality obligations;
- implement appropriate technical and organisational security measures;
- assist the controller with data subject requests where reasonably possible;
- assist with UK GDPR Articles 32 to 36 obligations where relevant to our processing;
- notify the controller without undue delay after becoming aware of a personal data breach;
- make available information reasonably necessary to demonstrate compliance;
- delete or return personal data after processing ends, unless retention is required by law.
6. Subprocessors
You give general authorisation for us to use subprocessors needed to provide the Services. We remain responsible for subprocessors to the extent required by UK GDPR Article 28.
| Subprocessor | Purpose | Location | Transfer safeguard |
|---|---|---|---|
| Stripe | Payments, billing, invoices, fraud prevention | UK, EU, United States | UK-approved transfer safeguards where required |
| Discord | OAuth identity and community access | United States and other regions | UK-approved transfer safeguards where required |
| Google (Google Analytics) | Optional website analytics after end-user cookie consent | United States and other regions | UK-approved transfer safeguards / Google terms where required |
| Cloudflare | DNS, security, CDN/proxy, TLS | Global | UK-approved transfer safeguards where required |
| Proton Mail / SMTP provider | Transactional email delivery and support email handling | Switzerland / EU | Adequacy or equivalent safeguards where required |
| Server hosting provider | Application hosting, database, file storage | As configured for production | Contractual and technical safeguards |
We will notify affected customers of material subprocessor changes where required by law or contract. Objections must be based on reasonable data protection grounds.
7. International Transfers
Where personal data is transferred outside the United Kingdom, we will use UK GDPR-compliant safeguards such as UK adequacy regulations, the International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, supplementary measures, or the UK Extension to the EU-US Data Privacy Framework where applicable.
8. Security Measures
Our measures include password hashing, encryption of sensitive tokens and 2FA secrets, HTTPS, secure cookies, rate limiting, account lockout, refresh-token expiry, role-based access controls, admin access controls, audit logs, content access logging, and backup and recovery controls appropriate to the Services.
9. Audit and Information Rights
Where UK GDPR Article 28 audit rights apply, audits must be reasonable, limited to relevant processing, conducted no more than once per calendar year unless required by a regulator or breach event, and subject to confidentiality and security requirements. We may satisfy audit obligations by providing policies, summaries, security information, or third-party reports where appropriate.
10. Deletion or Return
At the end of processing, we will delete or return personal data where technically feasible, unless we are required or permitted to retain it for legal, tax, accounting, fraud, chargeback, dispute, security, or backup purposes.
11. Contact
SYNDICATES TRADING LTD
Company number: 17252162
Registered office: 128 City Road, London, United Kingdom, EC1V 2NX
Data protection contact: [email protected]