Last updated: 24 August 2026
This agreement is between the customer named at signature ("Customer") and synthetic cfo, the operator of app.syntheticcfo.com ("Provider"). For the personal data described in section 3, Customer is the controller and Provider is the processor. "Data Protection Law" means the data protection law applying to that data, including, where relevant, the GDPR, the UK GDPR and South Africa's POPIA. This agreement forms part of the service agreement between the parties (the Terms of Service or a separately negotiated agreement, the "Agreement"); if the two conflict on data protection, this agreement prevails.
Provider processes Customer personal data only on Customer's documented instructions, including on transfers, unless required otherwise by law that applies to Provider; in that case Provider informs Customer before processing, unless that law forbids it on important grounds of public interest. The Agreement, this agreement, and the configurations and settings Customer's users choose in the product are the complete instructions at signature. Provider will tell Customer if, in its view, an instruction breaches Data Protection Law.
Access to Customer personal data is limited to persons who need it to provide the service, who are bound by confidentiality obligations. The platform is operated by its founder; administrative surfaces are locked to the owner account, and each account's data is isolated to that account.
Provider applies the technical and organisational measures published on the Security page, which include: TLS for all traffic; passwords stored only as salted PBKDF2-SHA256 hashes at 200,000 iterations; API keys stored only as hashes; httponly, same-site session cookies with idle expiry; rate limiting on authentication and generation endpoints; daily database snapshots with session tokens removed, encrypted with AES-256 under a key held only by the owner, with the restore procedure documented and rehearsed; and self-serve deletion. Provider holds no SOC 2 or ISO 27001 certification and does not claim otherwise. Provider may improve these measures over time and will not reduce the overall level of protection during the term.
Customer gives general authorisation for these sub-processors, which are the same ones the Privacy Policy discloses:
If a user chooses to sign in with Google, Microsoft or GitHub, that provider authenticates the user as a service the user selects, and shares the user's name and email address with Provider. Provider will give at least 30 days' notice before adding or replacing a sub-processor, by updating this page and emailing the account contact; Customer may object on reasonable data-protection grounds, and if the objection cannot be resolved Customer may terminate the affected service and delete its data under section 11.
The sub-processors above may process data in countries other than Customer's. Where Data Protection Law requires safeguards for such transfers, the parties rely on the appropriate mechanism for the jurisdiction, such as adequacy decisions or the applicable standard contractual clauses with those providers, and Provider will cooperate to put any additionally required terms in place.
The product answers most requests directly: a user can delete individual conversations and datasets, and can delete the whole account from the account page, which permanently erases the account and all personal data tied to that email. For access, correction or a portable copy, Customer or the user can email info@syntheticcfo.com. Taking into account the nature of the processing, Provider will assist Customer with data subject requests and, where a request reaches Provider directly, will pass it to Customer without undue delay rather than answering on Customer's behalf.
Provider will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer personal data, with the information Data Protection Law requires so far as it is available: the nature of the breach, the categories and approximate numbers affected, the likely consequences, and the measures taken. Provider will cooperate with Customer's own notification duties and document the breach and response.
On termination of the Agreement, or earlier on request, Customer's users delete their accounts in the product, or Customer asks Provider in writing to do it; either way the account and all personal data tied to it are permanently erased at that point. Copies inside the encrypted daily backups age out automatically on a 7 day rotation. Records that never belonged to an account, such as demo and access requests, are deleted automatically 24 months after the last interaction, as the Privacy Policy states. Generated packages are not archived separately: they are regenerable byte for byte from their seed and configuration, which is the product's core guarantee. On request Provider will confirm deletion in writing.
Provider will make available the information reasonably necessary to demonstrate compliance with this agreement: this page set, the Security page, and written answers to Customer's reasonable questions. Customer may audit once in any 12 month period on at least 30 days' written notice, in the first instance through written responses and remote review, and on site by agreement where Data Protection Law requires it, during business hours, without access to other customers' data. The platform is run by a single founder and audit logistics are scaled to that reality, honestly and cooperatively.
Each party's liability under this agreement is subject to the limitations and exclusions of the Agreement, except where Data Protection Law does not allow that. This agreement replaces any earlier data processing terms between the parties.
This agreement is governed by the same law as the Agreement; unless the parties agree otherwise at signature, that is the law of South Africa.
Executed as a document by the parties' authorised signatories, with the details below completed at signature.
For the Customer
Legal entity:
Registered address:
Name and title:
Signature:
Date:
For the Provider (registered legal details entered here at signature)
Legal entity:
Registered address:
Name and title:
Signature:
Date: