Data Processing Agreement
SyncNexa Limited• Effective Date: January 1, 2026
1. Purpose & Scope
This Data Processing Agreement (“DPA”) governs the processing of personal data by SyncNexa Limited in connection with the verification and trust services provided to educational institutions and verifying organizations under our Terms of Service.
2. Cryptographic Privacy-by-Design
SyncNexa operates on a zero-knowledge, decentralized attestation model. Academic documents, transcripts, student ID card images, grades, and unhashed identifiers are neither requested nor stored on SyncNexa servers.
- Pairwise Identifiers: Verifying organizations receive distinct pairwise identifiers that cannot be correlated across third-party platforms.
- Zero PII Retention: Verification queries confirm boolean status (“active” / “inactive”) directly from the accredited institution.
- Mutual TLS (mTLS): All communications between the SyncNexa Trust Adapter and institutional SIS networks are encrypted with mutual TLS.
3. Rights of Data Subjects
Data subjects maintain complete sovereignty over their credential disclosures. Consent is required for each verification event and may be revoked immediately via the SyncID mobile application.
4. Compliance & Contact
For institutional DPA execution or compliance inquiries, contact our Data Protection Officer at privacy@syncnexa.co.