LEGAL & COMPLIANCE

Data Processing Agreement

SyncNexa Limited• Effective Date: January 1, 2026

1. Purpose & Scope

This Data Processing Agreement (“DPA”) governs the cryptographic processing of personal data by SyncNexa Limited in connection with the decentralized verification and trust services provided to educational institutions and verifying organizations under our Terms of Service.

2. Cryptographic Privacy-by-Design

SyncNexa operates on a strict zero-knowledge, zero-persistence decentralized attestation model. Academic documents, transcripts, student ID card images, GPA records, and unhashed identifiers are neither requested nor stored on SyncNexa servers.

  • Pairwise Pseudonymity: Verifying organizations receive distinct pairwise identifiers that cannot be correlated across third-party commercial platforms.
  • Zero PII Retention:Verification queries confirm boolean status (“active” / “inactive”) directly from the accredited institution without database replication.
  • Mutual TLS (mTLS 1.3): All communications between the SyncNexa Trust Adapter and institutional SIS networks are encrypted with hardware-anchored mutual TLS.

3. Rights of Data Subjects

Data subjects maintain complete sovereignty over their credential disclosures. Explicit cryptographic consent is required for each verification event and may be revoked immediately at any time via the SyncID mobile application.

4. Compliance & Contact

For institutional DPA countersigning, compliance audits, or legal inquiries, contact our Data Protection Officer at:

Email: privacy@syncnexa.co
Entity:SyncNexa Limited • Legal & Compliance Division