LegalLast updated: August 10, 2026

Data Processing Agreement

This Data Processing Agreement ("DPA") forms part of the agreement between Shah Shakil trading as ZyncoAI (ABN 38 138 129 187)("Processor") and the clinic or business ("Controller") using the ZyncoAI platform, and describes how personal information is processed on the Controller's behalf.

Scope & roles

The Controller determines the purposes and means of processing personal information collected through its use of ZyncoAI. ZyncoAI acts as Processor, handling that information solely to provide the AI voice receptionist service, in accordance with the Controller's instructions and this DPA.

Categories of data processed

  • Business profile data: name, address, phone number, hours, industry.
  • Staff/administrative data: names, titles, email addresses, calendar availability.
  • Caller/patient contact details necessary for scheduling: name, phone number, email.
  • Call audio and transcripts. Audio is automatically deleted 90 days after the call where recording is enabled; transcripts are retained indefinitely today — see Privacy Policy → Data retention for the full breakdown by data type.

What is never processed

Consistent with the My Health Records Act 2012 and Healthcare Identifiers Act 2010, ZyncoAI does not process clinical health records (diagnoses, medications, test results), Medicare numbers, HPI-I, or IHI numbers. Any such data returned by a connected system is rejected and not stored.

Processor obligations

  • Process personal information only as instructed by the Controller and as described in the Privacy Policy.
  • Maintain reasonable technical and organisational security measures.
  • Log consent and data-access events in an audit trail.
  • Notify the Controller without undue delay upon becoming aware of a data breach affecting personal information.

Support access

Authorised Processor personnel may access the Controller's account and the personal information it contains solely to provide support, diagnose and resolve technical issues, and operate the service on the Controller's behalf — never for any other purpose. This is processing carried out under the Controller's instructions per Scope & roles above, not an independent use of the data.

All such access is logged in the audit trail described under Processor obligations — who accessed the account, when, and why — including cases where call audio is reviewed to resolve a specific issue, which is separately flagged in that log. Any change made on the Controller's behalf during a support session requires additional authentication beyond a normal login and is recorded as performed by ZyncoAI support, distinguishable from the Controller's own account activity. The Controller may request a copy of this access history at any time by contacting support@zyncoai.com.

Controller obligations

The Controller is responsible for the accuracy of business registration details provided during onboarding, for obtaining any consents required from staff and patients prior to their information being entered into ZyncoAI, and for ensuring its use of the platform complies with applicable law, including AHPRA requirements relevant to its practitioners.

Subprocessors

The full named list — provider, what it receives, and where it processes — is published at Privacy Policy → Subprocessors and kept in sync with this DPA. In summary: Neon (database, Sydney), Twilio (telephony), Deepgram (speech-to-text), OpenAI (conversational AI), Cartesia (text-to-speech), Square (payments), Resend (transactional email), Upstash (Redis cache/queues), and Google/Microsoft (calendar sync, only if the Controller connects one). Each is bound by confidentiality and data-protection obligations no less protective than this DPA.

Data residency

The database and file storage underlying ZyncoAI — business records, contacts, appointments, invoices, and call recordings — are hosted in Sydney, Australia. Voice processing is not: to answer a call, audio and transcript text are sent in real time to the overseas subprocessors listed above (Twilio, Deepgram, OpenAI, Cartesia — all US-processed), which is necessary to provide the service and is disclosed here rather than covered by a blanket no-overseas-transfer promise that wouldn't be accurate. Current infrastructure region status is visible to the Controller in Settings → Security & Compliance.

Breach notification

In the event of a data breach likely to result in serious harm, ZyncoAI will notify the Controller promptly and assist as reasonably required to meet obligations under the Notifiable Data Breaches Scheme. Incident contact: support@zyncoai.com.

Data return & deletion

The Controller can export all personal information ZyncoAI holds on its behalf at any time — contacts, appointments, call history, revenue records, and staff data — as CSV/Excel/JSON directly from the dashboard, with no request required, including after cancellation.

Deletion on termination is not yet automated. Ending a subscription or suspending an account retains the Controller's data rather than deleting it — we're stating this plainly rather than promising an automatic purge that doesn't exist today. To request deletion, the Controller can email support@zyncoai.com and we will process it manually, except where retention is required by law (e.g. issued tax invoices).

Contact

Questions about this DPA can be sent to support@zyncoai.com.