Data Processing Addendum
Last Updated: March 17, 2026.
This Data Processing Addendum (“DPA”) applies to the Processing of Personal Information by VSC Synapse, LLC, a Delaware limited liability company (“Synapse”), on behalf of customers that have entered into the SYO Master Subscription and Software License Agreement or another written agreement with Synapse that incorporates this DPA by reference (each, a “Customer”). This DPA governs Synapse’s Processing of Personal Information on behalf of Customer in connection with the Services.
1. Definitions.
Capitalized terms not defined in this DPA have the meanings set forth in the Agreement.
- “Applicable Data Protection Laws” means U.S. federal and state laws applicable to the Processing of Personal Information under the Agreement, including, where applicable, the California Consumer Privacy Act as amended by the California Privacy Rights Act, and similar comprehensive state privacy laws.
- “Personal Information” means information that is regulated as personal information, personal data, or a similar term under Applicable Data Protection Laws, that is provided by or on behalf of Customer to Synapse, or collected by Synapse on Customer’s behalf, in connection with the Services. Personal Information does not include Deidentified Data.
- “Deidentified Data” means data that has been deidentified or aggregated such that it is not reasonably capable of being associated with an identified or identifiable individual, as defined under Applicable Data Protection Laws.
- “Process” or “Processing” means to collect, use, store, transmit, disclose, delete, or otherwise handle Personal Information.
- “Security Incident” means a confirmed unauthorized access to, or acquisition of, Personal Information in Synapse’s systems that compromises the confidentiality, security, or integrity of such Personal Information. Security Incident does not include unsuccessful attempts that do not result in unauthorized access, including pings, port scans, denial of service attacks, and failed login attempts.
- “Subprocessor” means a third party engaged by Synapse to Process Personal Information on Synapse’s behalf for purposes of providing the Services.
- “Services” has the meaning in the Agreement.
2. Roles and Scope.
- Customer Responsibilities: Customer determines the purposes and means of Processing Personal Information using the Services and is responsible for providing required notices and obtaining required consents under Applicable Data Protection Laws.
- Synapse Role: Synapse will Process Personal Information only as described in the Agreement and this DPA. For purposes of Applicable Data Protection Laws, Synapse acts as a service provider or processor with respect to Personal Information Processed on behalf of Customer.
- Scope of Processing: This DPA applies solely to Personal Information Processed by Synapse on behalf of Customer in connection with the Services. It does not apply to information Synapse collects or Processes independently as a controller, such as information relating to its own employees, contractors, or general website visitors.
3. Processing Instructions and Permitted Uses.
- Permitted Processing: Synapse will Process Personal Information to:
- provide, operate, maintain, and support the Services
- monitor, secure, and improve the reliability and performance of the Services
- detect, prevent, and investigate security incidents, fraud, abuse, or misuse
- modify, copy, distribute, sublicense, lease, rent, sell, or otherwise transfer the Field App;
- Customer Instructions: Customer instructs Synapse to Process Personal Information as described in Schedule 1. Customer may provide reasonable written instructions consistent with the Agreement and this DPA. If an instruction requires material modification of the Services, the parties will discuss in good faith any associated changes or fees.
- Prohibited Data: Unless expressly agreed in writing, Customer will not provide Synapse with:
- protected health information regulated by HIPAA
- payment card data beyond tokenized or truncated billing information
- biometric identifiers used for identification
- precise geolocation of individuals
4. Synapse Restrictions.
- No Sale or Sharing: Synapse will not sell or share Personal Information, as those terms are defined under applicable California law.
- Limited Purpose Use: Synapse will not retain, use, or disclose Personal Information for any purpose other than those described in Section 3 or as otherwise permitted by Applicable Data Protection Laws.
- Combining Across Customers: Synapse will not combine Personal Information Processed on behalf of Customer with personal information received from or on behalf of another customer, except:
- as reasonably necessary to provide, maintain, secure, or improve the Services
- to detect, prevent, or investigate security incidents, fraud, or misuse
- where such data has been aggregated or deidentified in accordance with Applicable Data Protection Laws.
- Aggregated and Benchmarking Data: Nothing in this DPA restricts Synapse’s ability to create or use Deidentified Data, including aggregated traffic, infrastructure, telemetry, or system performance data derived from multiple customers, for lawful business purposes such as: (i) analytics, (ii) benchmarking system optimization, (iii) capacity planning, (iv) product development, (v) research and modeling, and (vi) commercialization of aggregated insights; provided that all such Deidentified Data does not identify Customer or any individual and is maintained in deidentified form.
5. Deidentified and Operational Data.
- Deidentified Data: Synapse may create and use Deidentified Data for lawful business purposes consistent with this DPA. Synapse will implement reasonable technical and organizational measures designed to ensure Deidentified Data cannot reasonably be reidentified and will not attempt to reidentify such data.
- Operational Telemetry: The Services may generate operational logs, system diagnostics, performance metrics, and security monitoring data. Synapse may use such data to operate, secure, and improve the Services consistent with this DPA.
- Infrastructure and Device Data Clarification: The Services support traffic management, roadway infrastructure, and device monitoring functions. Much of the data generated relates to traffic controllers, intersection timing plans, signal configurations, device telemetry, sensor outputs, and system event logs.
- Personal Information Status of Infrastructure Data: Such infrastructure or device data does not constitute Personal Information unless it is reasonably capable of being associated with an identified or identifiable individual under Applicable Data Protection Laws.
- Operational Data: For clarity, the following are operational data and not Personal Information unless linked to identifiable individuals: (i) intersection identifiers, (ii) controller serial numbers, (iii) signal timing plans, (iv) traffic flow metrics, (v) environmental sensor readings, (vi) event and fault logs, (vii) system performance data, and (vii) infrastructure configuration metadata
6. Security.
- Security Program: Synapse will maintain a written information security program that includes commercially reasonable administrative, technical, and physical safeguards designed to protect Personal Information.
- Updates to Security Measures: Synapse may update its security measures from time to time provided such updates do not materially reduce the overall level of protection.
- Personnel Confidentiality: Synapse will ensure personnel with access to Personal Information are subject to confidentiality obligations and receive appropriate training.
7. Subprocessors.
- Engagement: Synapse may engage Subprocessors to support delivery of the Services.
- Contractual Protections: Synapse will impose data protection obligations on Subprocessors that are appropriate to the services provided.
- Responsibility: Synapse remains responsible for Subprocessors’ Processing of Personal Information to the extent required under the Agreement.
- Notice: Synapse will make available a list of Subprocessors upon request or via a published list and will provide notice of material updates.
8. Security Incident Notification.
- Timing: Synapse will notify Customer without undue delay and no later than seventy-two (72) hours after confirming a Security Incident.
- Content: To the extent reasonably available, notice will include:
- a description of the incident
- categories of Personal Information involved
- remediation steps taken or planned
- information reasonably necessary for Customer to meet legal obligations
- No Admission: Notification does not constitute an admission of fault or liability.
9. Consumer Rights Requests.
- Customer Responsibility: Customer is responsible for responding to individual rights requests.
- Synapse Assistance: Synapse will provide commercially reasonable assistance where required by Applicable Data Protection Laws and where Customer cannot address the request using the Services.
- Requests Received by Synapse: If Synapse receives a request directly relating to Customer’s use of the Services, Synapse may refer the requester to Customer and notify Customer.
10. Return and Deletion.
- During Term: Synapse may retain and Process Personal Information to provide the Services.
- Upon Termination: Upon expiration or termination, Synapse will delete or return Personal Information in accordance with the Agreement and Synapse’s standard backup and retention practices.
- Retention Exceptions: Synapse may retain Personal Information as required by law or retained in backups, provided such data remains protected and is deleted in accordance with standard retention cycles.
- Deidentified Data: Synapse may retain Deidentified Data in accordance with Section 5.
11. Audit Materials.
- Security Reports: Upon written request no more than once annually, Synapse will provide its most recent third party security report, if available, subject to confidentiality obligations.
- No On-Site Audit: Except where required by Applicable Data Protection Laws, this DPA does not grant on site audit rights. The parties will cooperate in good faith to address legally required audit rights in a reasonable manner.
12. Liability.
The limitations of liability and exclusions of damages set forth in the Agreement apply to this DPA.
13. Order of Precedence.
If there is a conflict between this DPA and the Agreement solely regarding Processing of Personal Information, this DPA controls. In all other respects, the Agreement controls.
14. Updates to this DPA.
Synapse may update this DPA from time to time to reflect changes in applicable law, industry standards, or the Services. If Synapse makes material changes, Synapse will update the “Last Updated” date above and post the revised version at the applicable URL.