Data Processing Addendum
(DPA)
Effective Date: February 10, 2026
|Last Updated: February 10, 2026
This Data Processing Addendum (“DPA”) forms part of the Terms of Service (“Agreement”) between:
Customer (“Controller”)
and
Digital Nexus Inc., a Delaware corporation, operating the Seamline platform (“Processor,” “Seamline,” “Digital Nexus,” “we,” “us,” or “our”).
1. Definitions
For purposes of this DPA:
Personal Data means any information relating to an identified or identifiable natural person.
Processing means any operation performed on Personal Data, including collection, storage, use, disclosure, or deletion.
Controller means the entity that determines the purposes and means of processing Personal Data.
Processor means the entity that processes Personal Data on behalf of the Controller.
Subprocessor means any third party engaged by Processor to process Personal Data.
Data Protection Laws means applicable privacy laws, including GDPR where applicable.
2. Roles of the Parties
Customer is the Controller of Personal Data.
Digital Nexus Inc. is the Processor of Personal Data.
Seamline processes Personal Data solely on behalf of Customer.
Seamline does not determine the purposes of Customer Data processing.
3. Scope and Purpose of Processing
Seamline processes Personal Data solely to provide the Service, including:
- hosting customer workspaces
- storing customer records
- managing production workflows
- storing design files
- enabling team store functionality
- providing technical support
- maintaining platform security
Seamline does not sell Personal Data.
Seamline does not use Personal Data for advertising.
4. Categories of Personal Data
Personal Data processed may include:
- names
- email addresses
- customer identifiers
- business contact information
- order information
- team roster information (if provided by Customer)
Seamline does not intentionally collect sensitive personal data.
Customer is responsible for ensuring lawful collection of Personal Data.
5. Categories of Data Subjects
Personal Data may relate to:
- Customer employees
- Customer customers
- Customer vendors
- Customer contractors
- Customer end users
6. Processor Obligations
Seamline agrees to:
- process Personal Data only on documented instructions from Customer
- ensure personnel are bound by confidentiality obligations
- implement appropriate technical and organizational security measures
- assist Customer with data subject requests where reasonably possible
- notify Customer of confirmed Personal Data breaches without undue delay
- delete or return Personal Data upon termination of the Agreement upon request
7. Security Measures
Seamline implements industry-standard security measures, including:
- encryption in transit using TLS
- secure cloud infrastructure
- access controls and authentication
- role-based access restrictions
- audit logging
- infrastructure security monitoring
Seamline regularly reviews and improves security measures.
8. Subprocessors
Customer authorizes Seamline to use Subprocessors to provide the Service.
Subprocessors may include:
- Stripe (payment infrastructure)
- Supabase (database infrastructure)
- cloud hosting providers
- email service providers
Seamline ensures Subprocessors are subject to appropriate data protection obligations.
Seamline remains responsible for Subprocessor compliance.
9. International Data Transfers
Personal Data may be transferred to and processed in the United States.
Customer consents to such transfers.
Seamline ensures appropriate safeguards are in place where required.
10. Data Subject Rights Assistance
Seamline will provide reasonable assistance to Customer in responding to:
- access requests
- correction requests
- deletion requests
- restriction requests
Customer remains responsible for responding to data subject requests.
11. Data Breach Notification
Seamline will notify Customer without undue delay after confirming a Personal Data breach affecting Customer Data.
Notification will include:
- description of the breach
- likely consequences
- remediation steps taken
12. Data Retention and Deletion
Seamline retains Personal Data only as necessary to provide the Service.
Upon termination of the Agreement, Customer may request deletion of Personal Data.
Backup systems may retain data temporarily consistent with disaster recovery practices.
13. Audit Rights
Customer may request reasonable information regarding Seamline's security practices.
Seamline may provide documentation sufficient to demonstrate compliance.
Seamline is not required to disclose confidential security architecture details.
14. Limitation of Liability
This DPA is subject to the liability limitations set forth in the Terms of Service.
15. Governing Law
This DPA is governed by the laws of the State of Delaware.
Digital Nexus Inc.
Legal Department
[Address Placeholder]
Website
seamline.pro