Data Processing Addendum
Version 1.1 · Effective July 1, 2026
This is an AI-drafted starting template, not legal advice. It must be reviewed by a licensed attorney before reliance. Sections marked FOUNDER_ require completion by the operator.
This Data Processing Addendum ("DPA") is a draft that requires legal counsel
review AND execution before use.
1. ROLES
For certain personal data processed on behalf of customers, FOUNDER_LEGAL_NAME
acts as a processor and the customer acts as controller. For its own operational
data, Seema acts as controller.
2. SUBPROCESSORS
Seema engages the following subprocessors: Stripe (payments and payouts),
Anthropic (AI processing, United States), DigitalOcean (hosting), and an
email/SMTP provider. We will maintain an up-to-date list and provide notice of
changes.
3. SECURITY
We implement appropriate technical and organizational measures to protect
personal data, including access controls, encryption in transit, and logging.
4. DATA-SUBJECT REQUESTS
We will assist the controller, to the extent reasonable, in responding to
data-subject access, deletion, correction, and portability requests.
5. BREACH NOTIFICATION
We will notify the controller without undue delay after becoming aware of a
personal-data breach affecting their data.
6. INTERNATIONAL TRANSFERS
Where personal data is transferred out of the EEA or UK, the parties will rely
on a valid transfer mechanism under GDPR Chapter V (transfer mechanism:
FOUNDER_TRANSFER_MECHANISM). This must be completed and executed with counsel.
7. DELETION
Upon termination, we will delete or return personal data processed on the
controller's behalf, except as required by law.
8. COUNSEL REVIEW
This DPA is a draft and must be reviewed, completed, and executed by legal
counsel before use. Contact legal@seemaai.ai.