Data Processing Agreement
Reference DPA-2026-v2.0 · Last updated: July 30, 2026 · Versión en español (the Spanish version is authoritative; this English version is provided for convenience)
This Data Processing Agreement is entered into between the Client (the “Controller”), identified per its account registration details, and Sealmetrics S.L. (the “Processor” or “Sealmetrics”), Spanish tax ID ESB70933239, Carrer de Tirso de Molina 36, 08940 Cornellà de Llobregat, Barcelona, Spain. It takes effect upon acceptance of the Sealmetrics Terms of Service, which incorporate it by reference, and prevails over any conflicting provision regarding data protection.
The service is built on data protection by design and by default (Art. 25 GDPR): no cookies or terminal-equipment storage, no persisted IP addresses, and no identifiers capable of cross-site tracking. The parties formalise this arrangement under Art. 28 GDPR, the Spanish LOPDGDD and the criteria of the AEPD Guide on cookies for audience-measurement tools (January 2024).
1. Definitions
GDPR terms have their Art. 4 meaning. “Service” is the Sealmetrics analytics platform; “Service Data” is the data processed on the Client’s behalf (Annex 1); “Sub-processor” is a third party engaged by Sealmetrics processing Service Data; “Data Subjects” are visitors of the Client’s websites; “BYOK” is the optional use of the Client’s own external AI provider key; “SCCs” are the clauses of Decision (EU) 2021/914.
2. Subject matter and documented instructions
Sealmetrics processes Service Data solely on behalf of and under the documented instructions of the Client, namely: this DPA and Annex 1, the Terms of Service, and the configuration the Client applies in the platform (conversion events, properties, integrations, exports). Sealmetrics will not process Service Data for any other purpose, and will promptly inform the Client if it considers an instruction infringes applicable data protection law, suspending its execution until clarified.
3. Audience-measurement guarantees (AEPD criteria)
In compliance with section III.C of the AEPD audience-measurement guide, Sealmetrics undertakes:
- No reuse. Service Data is never reused for Sealmetrics’ own or third parties’ purposes: no model training, no algorithm improvement with identifiable data, no cross-client benchmarking, no disclosure or sale.
- Purpose restriction. Processing is limited to (a) the strictly necessary audience measurements listed by the AEPD, and (b) the marketing attribution features (conversions, amounts, click identifiers, conversion properties) expressly instructed by the Client through its configuration, whose legal basis the Client documents as controller.
- Multi-publisher independence. Service Data is collected, processed and stored independently per client, with per-account isolation across all storage layers and per-client technical identifiers unfit for cross-referencing or unified reach measurement across sites of different controllers.
- EU location (clause 7) and a documented assessment of the Service’s configuration against the guide (section III.C.2), updated at least annually and available to the Client on request.
4. Processor obligations
4.1 Confidentiality
Persons authorised to process Service Data are bound by confidentiality undertakings surviving the end of their engagement; access follows least privilege and is logged.
4.2 Security (Art. 32)
Sealmetrics maintains the measures of Annex 2 — encryption in transit and at rest, structural minimisation (no persisted IPs, no terminal storage), automatic retention enforcement, per-account isolation, incident management — and may update them provided protection is not reduced.
4.3 Sub-processors
The Client grants general authorisation for the sub-processors in Annex 3. Additions or replacements are notified reasonably in advance so the Client can object on reasonable data protection grounds; failing agreement, the Client may terminate the affected Service without penalty. Sealmetrics imposes equivalent obligations on each sub-processor by contract and remains liable for their compliance. Providers connected by the Client (BYOK AI providers, export destinations) are not Sealmetrics sub-processors.
4.4 Data subjects’ rights (Arts. 11, 12-22)
Sealmetrics cannot identify Data Subjects within Service Data (no direct identifiers, no persisted IPs, short-lived pseudonymous or aggregated data), so Art. 11 GDPR applies: Sealmetrics assists the Client by documenting the processing and confirming the impossibility of identification, unless the data subject provides information enabling it. Requests received directly are forwarded to the Client without undue delay and not answered without its instruction.
4.5 Personal data breaches (Arts. 33-34)
Sealmetrics notifies the Client without undue delay after becoming aware of a breach affecting Service Data — mindful of the Client’s 72-hour window towards the supervisory authority — including, as available, the Art. 33(3) particulars, possibly in phases; cooperates with the Client’s notification duties; and documents every breach per Art. 33(5).
4.6 DPIAs and prior consultation
Sealmetrics assists with impact assessments and prior consultations and keeps technical documentation of the processing (architecture, data inventory, retention, the AEPD assessment) at the Client’s disposal.
4.7 Information and audits
Sealmetrics provides the information necessary to demonstrate compliance. The Client (or an independent, non-competitor auditor under confidentiality) may audit with 30 days’ notice, at most once per 12-month period save after a breach or on a supervisory authority’s requirement, during business hours and without disproportionate interference; each party bears its costs, unless a material breach is found.
4.8 End of processing
Upon termination the Client has 30 days to export its data (API and/or BigQuery). At the Client’s choice, Sealmetrics then deletes or returns Service Data and deletes copies within a reasonable period, save legal retention duties (data blocked).
5. Controller obligations
The Client ensures the lawfulness of the processing and its information duties (Arts. 13-14, with suggested wording provided by Sealmetrics); does not send direct personal data through free-configuration fields (conversion properties, URL parameters, campaign names — e.g. emails, phone numbers, ID numbers), Sealmetrics being entitled to apply detection and redaction filters as an additional safeguard; configures the Service per its own obligations; documents the legal basis of the attribution layer when enabled; and handles data subjects’ requests.
6. Client-directed services (BYOK, exports, webhooks)
Under BYOK, prompts are sent to the Client’s chosen AI provider on the Client’s behalf and responsibility, under that provider’s terms; Sealmetrics acts as a mere conduit. The default provider (“Seal AI”) runs entirely in the EU. Data exported to the Client’s infrastructure (API, BigQuery, webhooks, reports) is, from receipt, the Client’s own processing, including any international transfer it entails.
7. Location and international transfers
Visitor data is processed and stored exclusively within the European Union, including default AI inference (Scaleway, Paris, zero data retention), with no dependence on the EU-US Data Privacy Framework or SCCs. Sole exception in Annex 3: service emails to the Client’s account users via Resend, Inc. (USA), covered by SCCs/DPF — with no effect on visitor data. Any future non-EEA sub-processor would require prior notice, a valid Chapter V instrument and a documented transfer impact assessment. Transfers arising from Client-directed services are the Client’s responsibility.
8. Liability
Each party is liable per Art. 82 GDPR: Sealmetrics only where it breaches processor-specific GDPR obligations or acts outside the Client’s lawful instructions; the Client in all other cases. Neither party assumes indemnities beyond mandatory law; indirect and consequential damages are excluded to the maximum extent permitted. The Client’s sole remedy consists of credits against or waiver of future Service fees, up to the fees of the preceding 12 months; amounts already paid are not refunded and Sealmetrics makes no monetary payment. These limits do not apply where the law forbids them (wilful misconduct or gross negligence, data subjects’ Art. 82 claims, supervisory fines for a party’s own non-compliance).
9. Term, law and jurisdiction
This DPA applies from acceptance of the Terms and while Sealmetrics processes Service Data; clauses 4.1 and 4.8 survive. Amendments are notified reasonably in advance. Spanish law governs; the parties submit to the courts of Barcelona; the Processor’s reference supervisory authority is the AEPD. Notices: privacy@sealmetrics.com.
Annex 1 — Description of processing
Subject matter: consentless web analytics. Purpose A: aggregated audience measurement (the AEPD strictly necessary measurements). Purpose B (optional): marketing attribution per the Client’s configuration. Data subjects: visitors of the Client’s websites.
Data processed: browsing data (URLs, referrer, landing page, events, engagement); technical data (device, browser, OS derived from the user agent; browser time zone); country derived from the browser time zone, not the IP (on accounts with agent detection, an additional IP-derived country is used transiently as an anti-fraud signal, without persisting the IP); an ephemeral session identifier computed in the browser with no device storage, independent per client; UTM data and, under Purpose B, click identifiers, conversion types, amounts and Client-defined properties. Not processed: persisted IPs, cookies or device storage, names or emails of visitors, special categories, cross-site identifiers.
| Data | Retention (automatic TTL) |
| Event-level technical log (user agent, full URLs) | 14 days |
| Hourly aggregates | 90 days |
| Daily aggregates, conversions and properties | 24 months |
| Session state (operational memory) | 2 hours |
| After contract termination | 30-day export window + deletion |
Annex 2 — Security measures
TLS 1.2+ in transit (including AI inference); AES-256 at rest; structural minimisation (no IP persistence, no terminal storage, URL parameters not parsed on the device); per-client logical isolation; database-level TTL retention; RBAC, MFA and least privilege with logged access; platform keys only in secret managers and content logging prohibited across the AI chain; dependency install-script hardening; encrypted backups (30 days); security monitoring. Organisational: privacy training, confidentiality undertakings, documented breach and rights procedures, Art. 28 contracts with all sub-processors, periodic internal compliance audits.
Annex 3 — Authorised sub-processors
| Sub-processor | Location | Service |
| Noraina Limited | Ireland (EU) | Infrastructure and database hosting — all Service Data |
| Scaleway SAS (Iliad group) | Paris, France (EU) | Managed LLM inference for the default AI provider “Seal AI” (open model, zero data retention; token counters only) |
| Resend (Plus Five Five, Inc.) | USA — SCCs + EU-US DPF certified | Service emails to the Client’s account users (verifications, alerts, reports); no visitor data |
AI providers connected by the Client under BYOK are not Sealmetrics sub-processors. Billing-side and anti-abuse providers (payment gateway, registration anti-bot) process data for which Sealmetrics is controller and are documented in the Privacy Policy. Change notifications: subscribe via privacy@sealmetrics.com.
Annex 4 — Transfer framework (conditional)
In the standard flow there are no transfers of visitor data outside the EEA. Should a non-EEA sub-processor ever be engaged: SCCs under Decision 2021/914 (applicable module), general authorisation with list, Spanish governing law, AEPD as reference authority, SCC Annexes I/II completed by reference to Annexes 1 and 2, and a prior documented transfer impact assessment.
This Agreement is deemed accepted upon acceptance of the Terms of Service. For individually executed copies, contact privacy@sealmetrics.com.
