This Data Processing Addendum (the “DPA”) forms part of the Terms of Service or other agreement under which Seyuna Inc. provides the Services to Customer (the “Agreement”). It applies automatically to the extent Seyuna processes Customer Personal Data on Customer’s behalf.
Capitalized terms not defined in this DPA have the meanings given in the Agreement. “Applicable Data Protection Law” means privacy, data-protection, and data-security law applicable to the processing of Customer Personal Data. “Customer Personal Data” means personal data contained in Customer Data that Seyuna processes on Customer’s behalf. “Personal Data Breach” means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data. “Data Subject,” “controller,” “processor,” and “processing” have the meanings given by Applicable Data Protection Law.
1. Roles and instructions
Customer is the controller of Customer Personal Data or a processor acting on a controller’s behalf. Seyuna is Customer’s processor or subprocessor. For United States personal information, Customer is the business and Seyuna is its service provider or contractor where those terms apply.
Customer instructs Seyuna to process Customer Personal Data only to provide, secure, maintain, and support the Services; perform actions initiated by Customer and Authorized Users; and comply with the Agreement and documented instructions consistent with it. Seyuna will process Customer Personal Data only on Customer’s documented instructions, including with respect to transfers to a third country or international organization, unless Applicable Data Protection Law requires otherwise. If so, Seyuna will inform Customer before processing unless that law prohibits notice. Seyuna will not use Customer Personal Data to train general-purpose artificial-intelligence models.
If, in Seyuna’s opinion, an instruction infringes Applicable Data Protection Law, Seyuna will immediately inform Customer and may suspend the affected processing. Seyuna may also suspend processing that materially compromises security and will inform Customer.
Customer is responsible for the lawfulness, accuracy, and quality of Customer Personal Data; for providing all required notices and obtaining all required consents; and for configuring and using the Services consistently with Applicable Data Protection Law. Customer will not instruct Seyuna to process specially regulated data unless Seyuna has expressly authorized and documented that processing.
2. Processing details
The subject matter, nature, purpose, duration, data categories, and Data Subject categories are described in Annex 1. The processing continues for the term of the Agreement and any limited period during which Seyuna lawfully retains Customer Personal Data.
3. Confidentiality and personnel
Seyuna will ensure that personnel authorized to process Customer Personal Data are bound by contractual or statutory confidentiality obligations and receive access only as necessary for their responsibilities.
4. Security
Seyuna will maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Those measures include, as appropriate to the risk:
- identity, authentication, and role-based access controls;
- secure transport and managed storage protections;
- separation of customer resources and production privileges;
- credential and secret handling controls;
- logging, monitoring, abuse prevention, and vulnerability reporting;
- availability, recovery, deletion, and incident-response procedures; and
- periodic review of access, providers, risks, and material system changes.
Customer acknowledges that security depends in part on its configuration, access permissions, integrations, and protection of credentials and endpoints under its control.
5. Subprocessors
Customer gives Seyuna general written authorization to engage the subprocessors listed on the Service Providers page to process Customer Personal Data. Seyuna will impose on each subprocessor the same data-protection obligations set out in this DPA, insofar as they apply to that subprocessor’s services. Seyuna remains fully liable to Customer for the subprocessor’s performance of those obligations.
Seyuna will provide reasonable advance notice of a new or replacement subprocessor that will process Customer Personal Data. Customer may object before the stated effective date on reasonable, documented data-protection grounds by contacting privacy@seyuna.com. The parties will work in good faith toward a reasonable solution. If none is reasonably available, Customer may discontinue the affected feature or terminate the affected Services, and Seyuna will provide any refund required by the Agreement or applicable law.
An independent payment, identity, integration, or other provider that determines its own processing purposes is not a subprocessor merely because it appears on the Service Providers page.
6. Data Subject requests
Taking into account the nature of the processing, Seyuna will provide reasonable assistance through appropriate technical and organizational measures to help Customer respond to a Data Subject request. If Seyuna receives a request that relates principally to Customer’s processing, Seyuna will direct the requester to Customer or notify Customer where reasonably identifiable and lawful. Customer remains responsible for responding to the request.
7. Compliance assistance
Taking into account the nature of the processing and information available to Seyuna, Seyuna will provide reasonable assistance with Customer’s obligations concerning security, personal-data breach notifications, data-protection impact assessments, and prior consultation with a regulator.
Seyuna will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification will include information reasonably available to Seyuna concerning the nature of the breach, affected data and people, likely consequences, and measures taken or proposed. Seyuna may provide information in phases as the investigation develops. Notification is not an admission of fault or liability.
8. Return and deletion
During the term, Customer may use available features to access or export Customer Personal Data. Upon termination of the affected Services or Customer’s documented instruction, Seyuna will, at Customer’s choice, return Customer Personal Data and delete existing copies, or delete existing copies without return, unless applicable law requires retention.
Deleted data may remain temporarily in backups or restricted records until overwritten under applicable schedules. While retained, it remains protected under this DPA and is not used for another purpose. Security, billing, abuse, and legal records that Seyuna processes as an independent controller are governed by the Privacy Policy rather than this Section.
9. Information and audits
Seyuna will make available all information necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer. Where practicable, Customer will first use available questionnaires, certifications, or independent reports and will provide reasonable notice. An audit must be limited to relevant systems and records, protect other customers and Confidential Information, avoid unreasonable disruption, and comply with appropriate security requirements. Customer bears its audit costs unless applicable law requires otherwise or the audit identifies a material breach of this DPA by Seyuna.
10. International transfers
Seyuna is established in Canada and processes Customer Personal Data in the course of commercial activities subject to Canada’s Personal Information Protection and Electronic Documents Act. To the extent a transfer falls within the European Economic Area or United Kingdom adequacy treatment for Canadian commercial organizations subject to that Act, the parties may rely on that adequacy mechanism.
Seyuna will ensure that an onward transfer of Customer Personal Data uses an adequacy framework, contractual safeguard, or other transfer mechanism required by Applicable Data Protection Law. If an adequacy framework ceases to apply to a transfer to Seyuna, Seyuna will implement an appropriate safeguard before continuing the affected transfer. Customer will reasonably cooperate with information and documentation required for that purpose.
11. United States privacy terms
Where United States privacy law treats Seyuna as Customer’s service provider or contractor, Seyuna will:
- process Customer Personal Data only for the business purposes specified in the Agreement and Customer’s documented instructions;
- provide the same level of privacy protection required of a service provider or contractor under applicable law;
- not sell or share Customer Personal Data for cross-context behavioural advertising;
- not retain, use, or disclose Customer Personal Data outside the direct business relationship or for an unrelated commercial purpose, except as permitted by law;
- not combine Customer Personal Data with personal information received from another person or collected from Seyuna’s independent interaction with an individual, except as permitted by law; and
- notify Customer if Seyuna determines that it can no longer meet an applicable obligation and cooperate in reasonable steps to stop and remediate unauthorized processing.
Customer may take reasonable and proportionate steps to verify and require remediation of Seyuna’s use of Customer Personal Data consistent with Section 9.
12. Government requests
Unless legally prohibited, Seyuna will notify Customer of a binding government demand for Customer Personal Data and will direct the requester to Customer where reasonably appropriate. Seyuna will review demands for validity and scope and disclose only the information legally required.
13. Priority, liability, and term
If this DPA conflicts with the Agreement concerning the processing of Customer Personal Data, this DPA controls. The liability provisions of the Agreement apply to this DPA to the maximum extent permitted by Applicable Data Protection Law. Nothing in this DPA limits a Data Subject’s rights or either party’s obligations or liabilities that cannot lawfully be limited.
This DPA takes effect with the Agreement and remains effective while Seyuna processes Customer Personal Data.
Annex 1 — Description of processing
| Item | Description |
|---|---|
| Subject matter | Provision of the Services selected and configured by Customer, including application building, project storage, database functions, authentication, preview, hosting, publication, AI-assisted generation, support, security, and deletion. |
| Duration | The term of the Agreement and any limited backup, legal-retention, or deletion period described in this DPA. |
| Nature and purpose | Collection, transmission, organization, storage, retrieval, hosting, display, generation, support, security, deletion, and other processing initiated by Customer or reasonably necessary to provide the Services. |
| Data Subjects | Customer’s Authorized Users; end users, customers, prospects, personnel, contractors, and other individuals whose data Customer submits to the Services or configures a Customer Application to collect. |
| Personal-data categories | Identifiers, contact details, Account and role data, IP and device data, authentication data, Customer Application content, support data, and other personal data selected by Customer, excluding categories prohibited by the Agreement. |
| Frequency | Continuous or event-driven according to Customer’s use and configuration of the Services. |
| Controller rights and obligations | Customer determines the lawful purposes and instructions, configures the Services, responds to Data Subjects, and may access, export, correct, or delete data using available features or a verified request. |
Annex 2 — Security measures
The measures in Section 4 apply to the processing described in Annex 1. Seyuna may update them as technology and risk evolve, provided that the overall protection of Customer Personal Data is not materially reduced.
Contact
Questions and notices under this DPA may be sent to privacy@seyuna.com.