This GDPR Compliance Statement explains how SYCONX LLC ("SYCONX", "we", "us", or "our") approaches its obligations under the European Union General Data Protection Regulation (Regulation (EU) 2016/679, the "EU GDPR") and the United Kingdom GDPR as incorporated into UK law by the Data Protection Act 2018 (together with the EU GDPR, the "GDPR") in connection with ChargeCrafter (https://chargecrafter.com), our software-as-a-service platform for accounting, invoicing, quotes and estimates, subscription and recurring billing, expense and vendor-bill management, bank-feed reconciliation, inventory and stock tracking, and tax reporting. ChargeCrafter is owned and operated by SYCONX LLC, a limited liability company organized under the laws of the State of New York, United States, with its principal address at 2 West Montauk Highway, Westhampton, NY 11977, USA.
Effective date: July 31, 2026.
This statement should be read together with the ChargeCrafter Privacy Policy, Cookie Policy, and Terms & Conditions. Capitalized terms used but not defined here have the meanings given to them in those documents.
1. Introduction & Commitment
SYCONX LLC is committed to protecting the privacy and security of personal data and to processing personal data lawfully, fairly, and transparently. Although SYCONX is established in the United States, we recognize that ChargeCrafter is used by businesses and individuals located in the European Economic Area (EEA) and the United Kingdom, and that personal data relating to individuals in those regions may be processed through the platform.
Where the GDPR applies to our processing activities, we are committed to complying with its requirements, including the principles set out in Article 5 of the GDPR: lawfulness, fairness, and transparency; purpose limitation; data minimization; accuracy; storage limitation; integrity and confidentiality (security); and accountability. This statement describes the roles we and our customers play, the legal bases on which personal data is processed, the rights available to data subjects, and the measures we take to safeguard personal data across ChargeCrafter's accounting, invoicing, billing, expense-management, bank-reconciliation, inventory, and tax-reporting features.
We remind all users that ChargeCrafter is a software tool and not an accountant, bookkeeper, tax advisor, or law firm. ChargeCrafter does not provide professional accounting, tax, financial, or legal advice, and each Customer remains responsible for the accuracy of its records and for its own tax and legal compliance, including its own compliance with the GDPR in respect of the personal data it chooses to process through the platform.
2. Controller & Processor Roles
The GDPR distinguishes between a "controller" (the party that determines the purposes and means of processing personal data) and a "processor" (the party that processes personal data on behalf of, and on the documented instructions of, a controller). SYCONX plays different roles depending on the category of personal data involved.
2.1 SYCONX as controller
For personal data relating to the ChargeCrafter account, identity, and use of the service — such as the name, email address, login credentials, billing details, support communications, device and log information, and usage and analytics data of the Customer and its authorized users — SYCONX LLC acts as the controller. We determine the purposes and means of processing this data in order to create and administer accounts, authenticate users, provide and improve the service, process subscription payments through Stripe, provide support, ensure security, and meet our own legal obligations. Our processing of this data as controller is described in the Privacy Policy.
2.2 SYCONX as processor / subprocessor
For the personal data that a Customer enters, uploads, or otherwise processes about its own clients, customers, contacts, vendors, employees, and other third parties through ChargeCrafter — for example the names, addresses, and contact details on invoices, quotes, and estimates; vendor and bill records; expense entries; bank-feed transactions and reconciliation data; inventory and stock records; and any documents that make up the Customer Data — the Customer is the controller and SYCONX acts as a processor (or subprocessor where the Customer is itself acting as a processor for a further controller). In this capacity, and consistent with Article 28 of the GDPR, SYCONX processes such Customer Data only to provide the ChargeCrafter service and on the Customer's documented instructions, which are given through the Customer's use and configuration of the platform, the Terms & Conditions, and any applicable Data Processing Addendum (see Section 5).
As controller of the personal data it processes through ChargeCrafter, the Customer is responsible for establishing a valid legal basis for that processing, for providing appropriate privacy notices to its own data subjects, and for responding to those data subjects' requests. SYCONX will provide reasonable assistance to the Customer in meeting these obligations as described in this statement and in any applicable Data Processing Addendum.
2.3 Point of contact for data-protection matters
SYCONX has appointed a point of contact for data-protection matters relating to ChargeCrafter. You may contact us in relation to any data-protection question or request at:
SYCONX LLC
2 West Montauk Highway
Westhampton, NY 11977
USAEmail: support@chargecrafter.com
3. Legal Bases for Processing
Where SYCONX processes personal data as a controller, we rely on one or more of the legal bases set out in Article 6(1) of the GDPR, depending on the purpose of the processing:
- Performance of a contract (Art. 6(1)(b)). We process account, identity, and billing data as necessary to enter into and perform our contract with the Customer — for example to create and maintain the account, provide the ChargeCrafter service, process subscription payments, and provide support.
- Legitimate interests (Art. 6(1)(f)). We process certain data where necessary for our legitimate interests or those of a third party, provided those interests are not overridden by the data subject's interests or fundamental rights — for example to secure the platform and prevent fraud and abuse (including through bot- and abuse-protection services such as Cloudflare Turnstile), to maintain and improve the service, to understand how the service is used, and to communicate with users about the service.
- Consent (Art. 6(1)(a)). We rely on consent where required, for example for certain non-essential cookies and similar technologies (see the Cookie Policy) and for optional communications. Where processing is based on consent, the data subject may withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal.
- Legal obligation (Art. 6(1)(c)). We process personal data where necessary to comply with our legal obligations, such as tax, accounting, and record-keeping requirements and responding to lawful requests from public authorities.
Where SYCONX acts as a processor in respect of Customer Data, the Customer, as controller, is responsible for identifying and documenting the appropriate legal basis under Article 6 (and, where applicable, the conditions for processing special categories of data under Article 9) for the personal data it processes through ChargeCrafter.
4. Data Subject Rights
Subject to the conditions and exceptions set out in the GDPR, data subjects have the following rights in relation to their personal data:
- Right of access. To obtain confirmation of whether we process personal data about them and to receive a copy of that data along with certain information about the processing.
- Right to rectification. To have inaccurate personal data corrected and incomplete personal data completed.
- Right to erasure ("right to be forgotten"). To have personal data deleted in certain circumstances, for example where it is no longer necessary for the purposes for which it was collected.
- Right to restriction of processing. To have the processing of personal data restricted in certain circumstances, for example while the accuracy of the data is being verified.
- Right to data portability. To receive certain personal data in a structured, commonly used, and machine-readable format and to have it transmitted to another controller where technically feasible.
- Right to object. To object to processing based on legitimate interests, and to object at any time to processing for direct-marketing purposes.
- Right not to be subject to solely automated decisions. Not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects, except as permitted by the GDPR. SYCONX does not use ChargeCrafter to make such decisions about data subjects.
- Right to withdraw consent. Where processing is based on consent, to withdraw that consent at any time.
- Right to lodge a complaint. To lodge a complaint with a supervisory authority, in particular in the EEA or UK Member State of the data subject's habitual residence, place of work, or place of the alleged infringement.
4.1 How to exercise your rights
Where SYCONX is the controller, you may exercise your rights by contacting us at support@chargecrafter.com. We will respond to requests without undue delay and, in any event, within one month (approximately 30 days) of receipt. That period may be extended by up to two further months where necessary, taking into account the complexity and number of requests, in which case we will inform you of the extension and the reasons for it. We may need to verify your identity before acting on a request.
Where the personal data relates to a Customer's own clients or contacts and SYCONX acts as a processor, the data subject should direct the request to the relevant Customer as controller. If a data subject contacts SYCONX directly about such data, we will, where appropriate and permitted, forward the request to the relevant Customer and assist that Customer in responding, as described in Section 5.
5. Data Processing Addendum (DPA)
For business customers acting as controllers (or as processors for a further controller) who require a data processing agreement to satisfy Article 28 of the GDPR, SYCONX makes a Data Processing Addendum ("DPA") available. The DPA sets out the subject matter, duration, nature, and purpose of the processing, the types of personal data and categories of data subjects, and the parties' respective obligations, including SYCONX's commitments to process Customer Data only on documented instructions, to ensure confidentiality, to implement appropriate security measures, to assist the Customer with data subject requests and with its own compliance obligations, to engage subprocessors only under equivalent terms, and to delete or return Customer Data at the end of the service.
To request the DPA, please contact support@chargecrafter.com. Where a DPA is executed between SYCONX and a Customer, it forms part of and supplements the Terms & Conditions and, in the event of a conflict regarding the processing of personal data, the DPA prevails.
6. Subprocessors
To provide ChargeCrafter, SYCONX engages certain third-party service providers that may process personal data on our behalf as subprocessors. Each subprocessor is engaged under terms that require it to implement appropriate technical and organizational measures and to process personal data only as necessary to provide its services. The current subprocessors and third-party services used by ChargeCrafter are:
- Amazon Web Services, Inc. (AWS) — cloud hosting, file storage (Amazon S3), and transactional email (Amazon SES). Region: United States.
- Stripe, Inc. — subscription billing and payment processing for ChargeCrafter plans, and optionally the Customer's own invoice payments.
- OpenAI, L.L.C. — AI features (AI invoice/receipt scanning and the in-app AI assistant); processes only the content the Customer submits to those features.
- Google LLC — optional "Sign in with Google" (OAuth) authentication.
- Cloudflare, Inc. — bot and abuse protection (Turnstile) and network security.
- Tax-rate data providers (such as TaxJar) — sales-tax rate lookup and assistance.
In addition, the Customer may choose to enable optional connectors, which process personal data only when and to the extent the Customer connects and uses them: PayPal, Square, Adyen, Mollie, Klarna, Authorize.Net, Wise, Mercury, and Brex. When a Customer enables one of these connectors, the relevant provider processes the associated data in accordance with its own terms and privacy notice, and typically acts as an independent controller (or the Customer's own processor) with respect to that data rather than as SYCONX's subprocessor.
We keep the list of subprocessors under review and will notify Customers of any material changes to our subprocessors — for example the addition of a new subprocessor — so that Customers have an opportunity to review the change, in accordance with any applicable DPA. Notification may be provided by email, through the platform, or by updating this statement.
7. International Data Transfers
ChargeCrafter is operated from, and Customer Data and other personal data are hosted in, the United States. As a result, when personal data is transmitted from the EEA or the United Kingdom to SYCONX or to our US-based infrastructure and subprocessors, that personal data is transferred outside the EEA and the UK.
Where such transfers take place, we rely on appropriate safeguards recognized under the GDPR to protect the personal data, including the European Commission's Standard Contractual Clauses (SCCs) for transfers from the EEA and, for transfers from the United Kingdom, the UK International Data Transfer Addendum to the SCCs (the "UK Addendum") or the UK International Data Transfer Agreement, as applicable. Where required, these safeguards are supplemented by additional technical, organizational, and contractual measures. Our agreements with subprocessors that receive personal data from the EEA or UK likewise incorporate appropriate transfer mechanisms. Business customers may obtain the applicable transfer terms as part of the DPA described in Section 5 by contacting support@chargecrafter.com.
8. Security Measures
SYCONX implements appropriate technical and organizational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as required by Article 32 of the GDPR. These measures include:
- Encryption in transit. Data transmitted between users and ChargeCrafter is encrypted using industry-standard protocols (such as TLS/HTTPS).
- Protection of credentials. Account passwords are stored using salted one-way cryptographic hashing rather than in plain text.
- Access controls and least privilege. Access to personal data is restricted to authorized personnel and systems on a need-to-know basis, following least-privilege principles, with authentication and authorization controls in place.
- Reputable cloud infrastructure. ChargeCrafter is hosted on established United States cloud infrastructure (AWS) that maintains its own robust physical, network, and operational security controls.
- Network and abuse protection. We use bot- and abuse-protection and network-security services (such as Cloudflare) to help protect the platform against malicious activity.
- Operational safeguards. We maintain logging, monitoring, and other operational measures designed to detect and respond to security events, and we periodically review our security practices.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Customers are responsible for maintaining the confidentiality of their login credentials, for configuring the platform appropriately, and for managing access by their own authorized users.
9. Data Retention & Deletion
We retain personal data for as long as it is necessary to fulfill the purposes for which it was collected. In general, personal data associated with a ChargeCrafter account — including Customer Data — is retained for as long as the account remains active and for so long thereafter as is necessary to comply with our legal, accounting, tax, and record-keeping obligations, to resolve disputes, and to enforce our agreements.
Customers may request deletion of personal data, and personal data associated with an account is deleted, or returned, following account deletion, subject to any retention we are required or permitted to apply by law or for legitimate business purposes such as maintaining transaction and billing records. Where SYCONX acts as a processor, we will delete or return Customer Data at the end of the provision of the service in accordance with the Customer's instructions and any applicable DPA. To make a deletion request, contact support@chargecrafter.com. Further detail about retention is set out in the Privacy Policy.
10. Personal Data Breach Notification
SYCONX maintains procedures to detect, investigate, and respond to personal data breaches. Where SYCONX acts as a controller and a personal data breach occurs that is likely to result in a risk to the rights and freedoms of individuals, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, as required by Article 33 of the GDPR, and we will notify affected data subjects where the breach is likely to result in a high risk to their rights and freedoms as required by Article 34.
Where SYCONX acts as a processor, we will notify the affected Customer (as controller) without undue delay after becoming aware of a personal data breach affecting that Customer's Customer Data, and we will provide reasonable information and assistance to help the Customer meet its own notification obligations to supervisory authorities and data subjects.
11. Data Protection Officer / Contact
While SYCONX is not required to appoint a statutory Data Protection Officer, we have designated a point of contact responsible for overseeing questions relating to this statement and our data-protection practices for ChargeCrafter. You may contact us regarding any data-protection matter, including to exercise your rights, request the DPA, or raise a concern, at:
SYCONX LLC
2 West Montauk Highway
Westhampton, NY 11977
USAData-protection and privacy requests: support@chargecrafter.com
General company inquiries: info@syconx.com
If you are located in the EEA or the UK and believe our processing of your personal data infringes the GDPR, you also have the right to lodge a complaint with a supervisory authority, as noted in Section 4.
12. Changes to This Statement
We may update this GDPR Compliance Statement from time to time to reflect changes in our practices, our subprocessors, applicable law, or the ChargeCrafter service. When we make material changes, we will update the "Effective date" above and, where appropriate, provide additional notice by email or through the platform. We encourage you to review this statement periodically, together with the Privacy Policy and Cookie Policy. Your continued use of ChargeCrafter after an updated statement takes effect constitutes acceptance of the updated statement to the extent permitted by applicable law.