Legal information
Data Processing Agreement
Product draft for review. This DPA is adapted for Seysuite Projects from the broader Seysuite data-processing materials. It must be reviewed by qualified legal counsel and completed for the final service providers, locations, and customer jurisdictions.
Last updated: 8 September 2026
1. Roles
For personal data that an organisation places in Seysuite Projects, the organisation generally determines the purposes and means of processing and acts as the controller. Zil Smart Solutions processes that data to provide the service and acts as the processor where the law and the parties’ arrangement require that role.
2. Scope and purpose
Processing is limited to providing, securing, supporting, and improving Seysuite Projects according to the organisation’s instructions and the applicable service agreement. The service may contain account, membership, project, work-item, comment, file, notification, activity, and audit information.
3. Processor commitments
Zil Smart Solutions will apply appropriate confidentiality, access, security, and organisational measures; process customer content only for the agreed purposes; restrict access to authorised personnel and providers; and provide reasonable cooperation for documented compliance requests, subject to security and confidentiality limits.
4. Security measures
The product security design includes authenticated access, organisation tenant boundaries, database row-level security, role and capability checks, controlled invitations, and audit history. The final DPA will contain the confirmed technical and organisational measures, backup arrangements, incident process, and assurance information.
5. Subprocessors and transfers
We may use carefully selected infrastructure and service providers to host, secure, deliver, and support the service. The final DPA will list confirmed subprocessors, processing locations, change-notification arrangements, and the safeguards used for international transfers.
6. Breach and rights assistance
We will maintain an appropriate process for investigating and reporting confirmed security incidents affecting customer personal data. We will reasonably assist the organisation with data-subject requests, security assessments, impact assessments, and regulator cooperation where required by applicable law and the final DPA.
7. Return and deletion
At the end of the service relationship, customer data should be returned, exported, or deleted according to the organisation’s instruction, applicable law, backup-cycle constraints, and the final retention schedule. The production DPA will define the applicable timelines and exceptions.
8. Controller responsibilities
The organisation is responsible for its lawful basis, notices, permissions, instructions, user roles, uploaded content, data quality, and responses to people whose data it controls. The organisation should avoid placing unnecessary sensitive information in project content.
9. Contact and governing law
Privacy and data-processing questions may be sent to privacy@zilsmartsolutions.com. Zil Smart Solutions is based at Anse Aux Pins, Mahé, Seychelles, and has Business Registration Number B8441574. The final DPA will confirm the governing law and dispute provisions.