Skip to main content
Sealens logo Sealens
Privacy Terms DPA Homepage Request Early Access

Legal

Data Processing Agreement

Effective date: July 8, 2026. This Data Processing Agreement (DPA) describes how Sealens processes personal data on behalf of business customers ("Customer") using the Sealens early access service, and forms part of the Terms of Service.

On this page

  • 1. Parties and Definitions
  • 2. Subject Matter and Duration
  • 3. Nature and Purpose of Processing
  • 4. Data and Data Subjects
  • 5. Processor Obligations
  • 6. Security Measures
  • 7. Sub-processors
  • 8. International Transfers
  • 9. Data Subject Rights
  • 10. Breach Notification
  • 11. Audit and Documentation
  • 12. Deletion or Return of Data
  • 13. How This DPA Applies
  • 14. Liability
  • 15. Contact

1. Parties and Definitions

This DPA is entered into between Customer, acting as controller (or processor on behalf of a further controller) of the personal data described below, and Sealens, acting as processor. Sealens is currently operated by Mathurin Bourgouin, a web developer based in France, pending formal incorporation of a company — consistent with the Privacy Policy and the Terms of Service.

"Personal Data", "Processing", "Controller", "Processor", "Data Subject", "Sub-processor" and "Personal Data Breach" have the meaning given to them under applicable data protection law, including the EU General Data Protection Regulation (GDPR) where it applies.

2. Subject Matter and Duration

The subject matter of this DPA is the processing of personal data by Sealens in order to provide the Sealens Service described in the Terms of Service. This DPA remains in effect for as long as Sealens processes personal data on Customer's behalf, and terminates automatically upon completion of the deletion or return of Customer Data described in Section 12.

3. Nature and Purpose of Processing

Sealens processes personal data to: ingest and analyze the Git repositories connected by Customer; correlate deployments, incidents, and code changes; compute risk scores and generate natural-language summaries of that analysis; and operate workspace, account, and notification features for Customer's authorized users. Sealens does not process personal data for any purpose other than providing, securing, and improving the Service for Customer, as further described in Section 5 of the Terms of Service.

4. Data and Data Subjects

Categories of data subjects:

  • Customer's employees, contractors, and other individuals who appear as authors, committers, or contributors in the Git history of repositories connected to the Service.
  • Individuals who create or are invited to a Sealens workspace on Customer's behalf (workspace admins and members).

Categories of personal data:

  • Name and email address as recorded in Git commit metadata (author and committer identity).
  • Commit messages, code comments, and file content, which may incidentally include personal data if included by Customer's own contributors.
  • Account data for workspace users: name, work email, role.
  • Technical and usage data: authentication events, IP address, timestamps, and other operational logs needed to run and secure the Service.
Special categories of data: Sealens does not intentionally process special categories of personal data (health, biometric, political, or similar data under Article 9 GDPR). Customer must not include such data in repository content, commit messages, or configuration processed through the Service.

5. Processor Obligations

Sealens will:

  • Process personal data only on Customer's documented instructions, including with regard to international transfers, unless required otherwise by law — in which case Sealens will inform Customer beforehand, unless legally prohibited from doing so.
  • Ensure that personnel authorized to process personal data are bound by confidentiality obligations.
  • Implement the technical and organizational security measures described in Section 6.
  • Engage Sub-processors only as permitted under Section 7.
  • Provide assistance to Customer as described in Sections 9 and 10.

6. Security Measures

Sealens applies the following measures:

  • Access to Customer's Git repositories is strictly read-only (repository content and metadata scopes). Sealens cannot create commits, pull requests, or branches.
  • Customer data is logically isolated by workspace; no cross-workspace access is possible by design.
  • Data is encrypted at rest (AES-256) and in transit (TLS 1.3).
  • Access credentials and secrets are stored in a dedicated secrets manager, never in plain text.
  • Administrative and security-relevant actions are logged.

A more detailed description of these measures is available on request — see Section 11.

7. Sub-processors

Customer authorizes Sealens to engage the Sub-processors listed below to provide the Service. Sealens will give Customer notice, by email or on this page, of any intended addition or replacement of a Sub-processor, and Customer may object on reasonable data protection grounds within 15 days of that notice.

Sealens is offered exclusively as a hosted SaaS service — no self-hosted or on-premises deployment option exists — so the Sub-processors below apply uniformly to every customer.

Annex 1 — Current Sub-processors

  • Scaleway — France (Paris) — cloud infrastructure, hosting, and storage. Sealens deliberately hosts on a European provider rather than a US-headquartered cloud, so that infrastructure data is not subject to US extraterritorial access regimes (e.g. the US CLOUD Act). Sealens' primary data store (the graph database) runs as self-managed software on this infrastructure, not as a separate managed service — it is not a distinct Sub-processor.
  • Anthropic (Claude API) — United States — generates natural-language summaries from structured data already computed by Sealens; the underlying commits, diffs, and raw code are not sent to this provider. Anthropic does not use data submitted through its commercial API to train its models.
  • Slack Technologies / Microsoft (Teams) — used only to deliver notification content to a channel or workflow that Customer explicitly configures. Applies only if Customer enables this integration.
  • Scaleway Transactional Email (TEM) — France — used to deliver account and workspace notifications (invitations, password resets) once those features exist. Same provider as our infrastructure host — no additional Sub-processor is introduced for this purpose. Not currently used to process closed beta applications — see Brevo below.
  • Brevo (Sendinblue SA) — France — used for two distinct purposes on two separate contact lists, never merged: (1) every closed beta applicant is recorded as a contact (name, company, team size, deploy frequency) to process the application and send related communications (confirmation, acceptance, decision) — this does not depend on any marketing consent, it follows directly from the applicant's own request; (2) the optional product newsletter, added only for visitors who explicitly opt into that separate consent checkbox on the same form. A visitor who applies without opting in is recorded under (1) only, never added to the newsletter list, and never receives marketing email.

8. International Transfers

Sealens hosts Customer Data in the EU (see Section 7). Where a Sub-processor is located outside the EU/EEA — currently, the AI language model provider described in Section 7 — Sealens relies on Standard Contractual Clauses or an equivalent recognized transfer mechanism, limited to the structured, already-computed analysis payload necessary to generate a natural-language summary.

9. Assistance with Data Subject Rights

Taking into account the nature of the processing, Sealens will provide reasonable assistance to Customer in responding to requests from data subjects seeking to exercise their rights (access, rectification, erasure, restriction, portability, or objection) under applicable data protection law. Requests received directly by Sealens from a data subject concerning Customer's data will be redirected to Customer, unless Sealens is legally required to respond directly.

10. Personal Data Breach Notification

Sealens will notify Customer without undue delay, and in any event within 72 hours of becoming aware, of any confirmed Personal Data Breach affecting Customer Data, along with information reasonably available to Sealens that Customer may need to meet its own notification obligations under applicable law.

11. Audit and Compliance Documentation

Upon reasonable written request, and no more than once every 12 months absent a security incident, Sealens will provide Customer with documentation describing its technical and organizational security measures — including the exact scope of Git access tokens and workspace isolation — sufficient to support Customer's vendor security review.

Sealens does not currently hold third-party security certifications such as SOC 2 or ISO 27001; Customer will be notified if and when such certifications are obtained. On-site or third-party audits may be arranged by mutual written agreement, at Customer's expense, with reasonable advance notice.

12. Deletion or Return of Data

Upon termination of the Agreement, or upon Customer's written request, Sealens will delete or, where technically feasible, return Customer Data — including data derived from repository content — within 30 days, except to the extent applicable law requires longer retention. Backups containing Customer Data are purged in the ordinary course of Sealens' backup rotation cycle.

13. How This DPA Applies

This DPA is incorporated by reference into the Terms of Service. It applies automatically from the moment Customer connects a repository, invites a workspace member, or otherwise causes personal data to be processed through the Service — without requiring a separate signature, in the same way the Terms of Service themselves apply upon use of the Service.

Customers who require a countersigned copy for internal procurement or security review, or negotiated terms (for example, extended audit rights or Sub-processor approval rights), can request one at hello@sealens.io — available as part of the Enterprise plan described on the pricing page.

14. Liability

Each party's liability arising out of or in connection with this DPA, including in relation to the processing of personal data, is subject to the limitations of liability set out in Section 9 of the Terms of Service, to the extent permitted by applicable law.

15. Contact

Questions about this DPA, requests for a countersigned copy, or requests for the security documentation described in Section 11 can be sent to hello@sealens.io.

Read Privacy Policy Read Terms of Service Back to Homepage
Sealens logo Sealens

Incident Investigation Workspace

Product

  • How It Works
  • Features
  • Pricing
  • Early Access

Legal

  • Privacy Policy
  • Terms of Service
  • Data Processing Agreement

Connect

  • Email

© Sealens. All rights reserved.