Seshat shield seshatsecure file vault
Features How it works Security Pricing Help Sign in Get started

Data Processing Addendum

Last updated: July 16, 2026 · Effective: upon publication

This Data Processing Addendum ("DPA") forms part of the Terms of Service between Seshat ("Processor") and the customer ("Controller") and applies where Seshat processes personal data contained in Customer Data on the Controller's behalf. If there's a conflict, this DPA controls for data-protection matters.

1. Roles2. Scope & instructions3. Processing details4. Confidentiality5. Security6. Subprocessors7. Data-subject rights8. Breach notice9. Transfers10. Deletion & return11. Audits12. CCPA13. Liability

1. Roles of the parties

For Customer Data, the Controller determines the purposes and means of processing and Seshat (operated by FTSC Consulting LLC, a Wyoming limited liability company) acts as Processor. Each party will comply with applicable data-protection laws (including the GDPR, UK GDPR, and CCPA/CPRA) in its role.

2. Scope & the Controller's instructions

Seshat processes Customer Data only to provide the service and on the Controller's documented instructions (these Terms, the DPA, and the Controller's use of the service), unless required by law—in which case Seshat will inform the Controller first where permitted. Seshat will tell the Controller if, in its view, an instruction violates data-protection law.

3. Subject matter & details (Annex)

Subject matter: provision of secure email vaulting, indexing, search, retrieval, and deletion. Duration: the term of the agreement plus the retention/deletion windows. Nature & purpose: storing, organizing, encrypting, transmitting, displaying, and deleting email at the Controller's direction. Data subjects: the Controller's users and any individuals referenced in the vaulted email. Categories: email content, attachments, metadata, and any personal data they contain (which may include sensitive data the Controller chooses to vault).

4. Confidentiality

Seshat ensures personnel authorized to process Customer Data are bound by confidentiality and trained appropriately, and limits access on a need-to-know basis.

5. Security measures

Seshat maintains technical and organizational measures appropriate to the risk (GDPR Art. 32), including encryption in transit and at rest, isolation of Customer Data, identity-gated access, least-privilege controls, logging and monitoring, and resilience and recovery practices. See our Security page. Seshat may update measures provided protection is not materially reduced.

6. Subprocessors

The Controller gives general authorization for Seshat to engage the subprocessors listed at our Subprocessors page. Seshat imposes data-protection obligations on each subprocessor no less protective than this DPA and remains responsible for their performance. Seshat will give at least 30 days' advance notice before a new or replacement subprocessor begins processing Customer Data. If the Controller raises a reasonable data-protection objection within that period and Seshat cannot address it, the Controller may terminate the affected service and receive a pro-rata refund of prepaid, unused fees as its sole remedy.

7. Assisting with data-subject rights

Taking into account the nature of processing, Seshat will assist the Controller—through appropriate technical and organizational measures and the service's self-service tools (export, search, deletion, disconnect)—in responding to data-subject requests (access, rectification, erasure, restriction, portability, objection). If Seshat receives such a request directly, it will refer the individual to the Controller.

8. Personal-data breach notification

Seshat will notify the Controller without undue delay—and within 72 hours where feasible—after becoming aware of a personal-data breach affecting Customer Data, with the information the Controller reasonably needs to meet its own notification duties, and will take reasonable steps to mitigate and remediate.

9. International transfers

Seshat operates from the United States and is designed for US customers; it does not target the EEA, UK, or Switzerland. Where a customer nonetheless requires a transfer mechanism for personal data leaving the EEA/UK/Switzerland to a country without an adequacy decision, the parties will enter into the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum), which Seshat makes available on request and which are incorporated by reference once executed, together with supplementary measures including encryption.

10. Deletion & return

On termination or the Controller's request, Seshat will delete or return Customer Data per the Controller's choice and the service's retention settings, and delete existing copies within the retention/backup windows described in our Privacy Policy, except where law requires retention.

11. Audits

Seshat will make available information reasonably necessary to demonstrate compliance with this DPA and respond to reasonable audit requests, including via security documentation and completed security questionnaires; where Seshat holds third-party reports or certifications, it will make them available under confidentiality. On-site audits may be arranged on reasonable notice, during business hours, subject to confidentiality and not more than once in any 12-month period absent a regulator's requirement or a breach.

12. CCPA/CPRA

Where the CCPA applies, Seshat acts as a "service provider," processes personal information only to provide the service, and will not sell or "share" it, retain, use, or disclose it for any purpose other than the service or as permitted by law, or combine it with other data except as permitted. Seshat certifies it understands and will comply with these restrictions.

13. Liability

Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service.

This DPA is incorporated into and forms part of the Terms of Service and applies automatically to business customers who process personal data through Seshat — no separate signature is required. A countersigned copy is available on request at [email protected].

seshat · seshatvault.com Help · Security · SLA · Terms · Acceptable Use · Privacy · Cookies · DPA · Subprocessors · Law Enforcement