Controller and processor roles, how the DPA works, and what is not a sub-processor.
Synthelio holds personal data about your employees: names, work email addresses, roles, hours worked, absence records, and in many configurations cost rates. Under the GDPR that makes the relationship a controller and processor arrangement, and it requires a written agreement.
That agreement is the Data Processing Addendum, drafted to Article 28 and accepted alongside the Terms of Service.
You are the controller. It is your data about your people, and you decide what goes into the system and why.
Synthelio is the processor. It processes that data on your instructions in order to provide the service, and does not decide the purposes for itself.
The distinction is not paperwork. It determines who answers to a data subject, who is accountable to a regulator, and who has to act when someone asks what is held about them. Those obligations sit with you as controller, and Synthelio's job is to make it possible for you to meet them.
Acceptance is a clickwrap, and the acceptance itself is recorded: who accepted, which version, and when.
There is a practical reason for logging it rather than just showing it. Two years into a relationship, the question is not whether a DPA exists but whether it was agreed to, by whom, and against which version of the text. A recorded acceptance answers that. A PDF in an inbox does not.
The sub-processor list is written into Annex III of the DPA itself rather than published at an external URL.
That is a deliberate choice with a real consequence. A sub-processor list at a URL can change without anyone telling you, and your agreement points at whatever is there today. A list inside the document means the set you agreed to is the set in the version you accepted.
The most common error in a vendor assessment of a system like this.
Your CRM, your Jira, your QuickBooks company, your Slack workspace, and your identity provider are yours. When you connect them, you are instructing Synthelio to exchange data with systems you already control under agreements you already hold. They do not become Synthelio sub-processors, and Synthelio does not assume responsibility for them.
Getting this right when you fill in an assessment saves an argument later.
Requests come to you as controller. If someone asks what is held about them, or asks for it to be corrected or erased, you are the one who has to answer.
Practically, most of what is held about a person is visible and editable in the app, so the request can usually be answered directly. Where it cannot, Synthelio's obligation as processor is to assist you.
One thing worth thinking through before it arises: an erasure request from a former employee interacts with records you may be legally required to keep. Hours worked underpin invoices already issued and tax records already filed. Erasure rights are not absolute, and this is a question for your own counsel rather than for a help article.
If you are being asked to complete a vendor assessment, the documents that answer most of it are the DPA, the Privacy Policy, and the Terms of Service, all published. Where a reviewer wants something not covered in them, ask rather than infer, and get the answer in writing so it is worth something.
Tell us what you need. We will point you to the answer or write the article.