Skip to main content

Legal information

Data Processing Agreement

Product draft for review. This DPA is adapted for Seysuite Projects from the broader Seysuite data-processing materials. It must be reviewed by qualified legal counsel and completed for the final service providers, locations, and customer jurisdictions.

Last updated: 8 September 2026

1. Roles

For personal data that an organisation places in Seysuite Projects, the organisation generally determines the purposes and means of processing and acts as the controller. Zil Smart Solutions processes that data to provide the service and acts as the processor where the law and the parties’ arrangement require that role.

2. Scope and purpose

Processing is limited to providing, securing, supporting, and improving Seysuite Projects according to the organisation’s instructions and the applicable service agreement. The service may contain account, membership, project, work-item, comment, file, notification, activity, and audit information.

3. Processor commitments

Zil Smart Solutions will apply appropriate confidentiality, access, security, and organisational measures; process customer content only for the agreed purposes; restrict access to authorised personnel and providers; and provide reasonable cooperation for documented compliance requests, subject to security and confidentiality limits.

4. Security measures

The product security design includes authenticated access, organisation tenant boundaries, database row-level security, role and capability checks, controlled invitations, and audit history. The final DPA will contain the confirmed technical and organisational measures, backup arrangements, incident process, and assurance information.

5. Subprocessors and transfers

We may use carefully selected infrastructure and service providers to host, secure, deliver, and support the service. The final DPA will list confirmed subprocessors, processing locations, change-notification arrangements, and the safeguards used for international transfers.

6. Breach and rights assistance

We will maintain an appropriate process for investigating and reporting confirmed security incidents affecting customer personal data. We will reasonably assist the organisation with data-subject requests, security assessments, impact assessments, and regulator cooperation where required by applicable law and the final DPA.

7. Return and deletion

At the end of the service relationship, customer data should be returned, exported, or deleted according to the organisation’s instruction, applicable law, backup-cycle constraints, and the final retention schedule. The production DPA will define the applicable timelines and exceptions.

8. Controller responsibilities

The organisation is responsible for its lawful basis, notices, permissions, instructions, user roles, uploaded content, data quality, and responses to people whose data it controls. The organisation should avoid placing unnecessary sensitive information in project content.

9. Contact and governing law

Privacy and data-processing questions may be sent to privacy@zilsmartsolutions.com. Zil Smart Solutions is based at Anse Aux Pins, Mahé, Seychelles, and has Business Registration Number B8441574. The final DPA will confirm the governing law and dispute provisions.