Trust

Data Processing Agreement

The processing terms Seiton offers, and how to have one countersigned.

This page is not a signed contract

It sets out the terms on which Seiton processes data on your behalf, so your review can see them before you ask for anything. It is not executed by using the product. To have a DPA countersigned, email hello@seiton.online with your entity name and any form your organisation requires; until a document is signed by both sides, the Privacy Policy and Terms of Service are the live agreements.

Roles

You are the data controller for the data in your own SaaS. Seiton is a processor: it reads what you connect, computes metrics from it, and shows them back to you. Seiton does not sell data, does not share it with other customers, and does not use one customer's data to produce another customer's numbers.

What is processed

Metrics and metadata from the providers you connect — subscription, invoice and charge metadata from billing providers (including customer email addresses where the provider returns them), search performance from Search Console, error counts from Sentry, and first-party analytics events from sites carrying your Seiton tracking snippet. Card numbers are never exposed to this integration. Raw IP addresses are not stored: in cookieless mode the address is one input to a salted daily hash, and in cookie mode it is not used at all.

Purpose and instructions

Processing happens only to operate the product for you: compute health dimensions, raise signals, and deliver your briefing to the channels you configure. Seiton acts on your instructions, which are the settings in your account — connecting a provider is the instruction to read it, disconnecting it is the instruction to stop.

Subprocessors

Supabase (authentication and database), Vercel (hosting), Stripe (Seiton's own subscription billing, not your customers' charges) and Resend (transactional email). Providers you authorise — Stripe, Google Search Console, PostHog, Sentry and others — remain under your own contract with them, and Seiton reaches them with the credentials you supplied.

Security measures

Provider tokens are encrypted at rest with AES-256-GCM; transport is TLS. Access to a project's data is scoped per tenant in the database itself through row-level security, and API tokens carry explicit scopes and permissions. No SOC 2 report, ISO certification or third-party penetration test is claimed, because none has been completed.

Retention and deletion

Project data is kept while your trial or subscription is active. After a trial that ends without a subscription it is deleted 7 days later; after a paid cancellation it is kept 30 days from the end of the period you paid for and then deleted. Collection stops when access ends. A daily job performs the deletion, removes stored provider credentials and deletes the webhook endpoint Seiton created in your billing provider. Email hello@seiton.online to have it done sooner.

Your rights as controller

You can export or delete your data at any time from the dashboard or by emailing hello@seiton.online. Requests from your own end users (access, correction, erasure) are yours to answer as controller; Seiton will assist with anything that requires data only it holds.

Breach notification

Seiton will notify you without undue delay after becoming aware of a personal-data breach affecting your data, with what is known at the time and what is being done about it. Report a suspected issue to hello@seiton.online.

International transfers

Infrastructure is operated by the subprocessors named above and data may be processed in the regions they operate in. If your organisation requires specific transfer mechanisms, raise it at hello@seiton.online before signing — Seiton will not claim a mechanism it has not put in place.

Related

Security describes the same handling in operational terms. Privacy covers what is collected about you as a Seiton customer, as opposed to the data you connect.