Sealio Data Processing Addendum

Version 06.10.2026

This Data Processing Addendum ("DPA") is part of the contract between Sealio SA ("Sealio") and the Customer under the Sealio Terms of Service ("Terms"). It applies without separate signature when the Customer places an Order. Capitalised words not defined here have the meaning given in the Terms.

Contact: privacy@mysealio.com

1. Scope and roles

1.1 This DPA applies to personal data contained in Customer Data ("Customer Personal Data"). The Customer is the controller, or a processor acting for its own clients. Sealio is the Customer's processor.

1.2 "Data Protection Law" means the Swiss Federal Act on Data Protection (FADP) and, where applicable, the EU General Data Protection Regulation (GDPR).

1.3 Annex 1 describes the processing. Sealio's own processing of billing and business contact data as controller is covered by its Privacy Policy, not by this DPA.

2. Instructions

2.1 Sealio processes Customer Personal Data only on the Customer's instructions. The contract and the Customer's use and settings of the Service are the Customer's instructions. The Customer instructs Sealio to anonymise Customer Personal Data for the purposes in Section 6.3 of the Terms. Further instructions must be in writing.

2.2 Sealio informs the Customer if it believes an instruction breaches Data Protection Law. If the law requires Sealio to process data otherwise, Sealio informs the Customer first unless the law prohibits it.

2.3 Persons who process Customer Personal Data at Sealio are bound by confidentiality.

3. Security

Sealio implements the technical and organisational measures listed in the "Technical and organisational measures" section of Sealio's Trust Center at https://trust.mysealio.com. Sealio may update them, provided the overall level of protection is not reduced.

4. Subprocessors

4.1 The Customer authorises Sealio to use the subprocessors listed in Sealio's Trust Center at https://trust.mysealio.com (the "Subprocessor List"). Sealio uses subprocessors only under written data protection terms appropriate to the processing.

4.2 Sealio keeps the Subprocessor List up to date. At least 14 days before adding or replacing a subprocessor, Sealio updates the list and informs the Customer by email or through a Trust Center notification. The Customer may object on reasonable data protection grounds within that period. If the parties find no solution, the Customer may terminate the affected Order, and Sealio refunds prepaid fees for the period after termination.

5. Transfers abroad

Sealio transfers Customer Personal Data outside Switzerland and the European Economic Area only where Data Protection Law allows it, for example under an adequacy decision or the EU Standard Contractual Clauses. The Subprocessor List states the basis for each subprocessor.

6. Assistance

6.1 Sealio forwards to the Customer any request from a data subject it receives about Customer Personal Data and helps the Customer answer it, as far as the Service allows.

6.2 Sealio provides reasonable help with data protection impact assessments and with consultations of the Federal Data Protection and Information Commissioner (FDPIC) or another supervisory authority, as far as they concern the Service.

7. Data breaches

7.1 Sealio notifies the Customer without undue delay, and at the latest within 72 hours, after becoming aware of a breach of security affecting Customer Personal Data.

7.2 The notice contains the information available to Sealio, in particular the nature of the breach, the data and persons likely affected, the likely consequences and the measures taken. Sealio provides further information as it becomes available and takes reasonable steps to limit the consequences.

8. Audits

8.1 On request, Sealio provides the information needed to show compliance with this DPA, in particular its security documentation and answers to a reasonable security questionnaire once per year.

8.2 If this information is not sufficient, or if an authority requires it, the Customer may have an audit carried out once per year, with at least 30 days' notice, during business hours, by an auditor bound by confidentiality. The Customer bears its own costs and the auditor's costs.

9. Return and deletion

At the end of the Subscription Term, the Customer can export its data and Sealio deletes Customer Personal Data as set out in Section 10.4 of the Terms, unless the law requires Sealio to keep it.

10. Other terms

10.1 Liability under this DPA is governed by Section 11 of the Terms.

10.2 For the processing of personal data, this DPA prevails over the Terms. Changes to this DPA follow Section 12.1 of the Terms.

Annex 1: Description of the processing

ItemDetail
Subject matterProvision of the Service under the Terms
DurationThe Subscription Term, plus the deletion period in Section 10.4 of the Terms
Nature and purposeStoring, parsing, indexing and searching Customer Data; analysing tenders and generating Outputs with AI models; user authentication; support
Data subjectsThe Customer's Users and employees; persons named in Customer Data, such as team members in CVs, contacts for project references, buyer contacts, partners and subcontractors
Categories of dataIdentification and contact data; professional data such as qualifications, experience, roles and project references; Users' account data and activity logs
Sensitive personal dataNot intended. The Customer avoids uploading sensitive personal data, such as health data, unless a tender requires it
LocationsSee the Subprocessor List

essai gratuit

Prêt à remporter plus d'appels d'offres ?

Apportez votre appel d'offres. Nous vous montrons comment Sealio le traite en moins de 10 secondes.