Data processing agreement

Effective 8 September 2026. This DPA forms part of the terms of service and applies to the hosted Seean service at app.seean.io. No signature is needed; accepting the terms accepts this DPA. We will sign a copy for your records on request.

1. Parties and roles

This agreement is between you, the customer (“controller”), and NesDesign LLC, a Wyoming limited liability company (“processor”, “we”). For analytics data collected from your websites you determine the purposes and means of processing and we act only on your instructions. For our own account and billing records we act as controller; that processing is described in the privacy policy.

2. Subject matter

We process personal data only to provide, secure and support the Seean web analytics service as described in the terms and in your configuration of it.

3. Duration

Processing lasts for as long as your account is open, and afterwards only for the period needed for deletion under clause 12.

4. Categories of data subjects

Visitors to the websites on which you install the tracker, and the people you authorise to use your account.

5. Categories of personal data

Analytics data includes page paths, hostnames, referring hostnames, timezone, campaign tags, browser and device categories, Web Vitals measurements, and random visitor and session identifiers. The tracker sends the referrer URL available to the browser; only its hostname is retained in analytics records. The request’s user agent and language may be processed to derive browser categories and country estimates. The tracker does not send screen dimensions or use device fingerprinting.

Visitor and session identifiers are stored in localStorage and sessionStorage rather than cookies and sent with events. The visitor ID has no automatic expiry in the tracker and may persist across visits. These identifiers are pseudonymous and may constitute personal data. Analytics records do not include a visitor IP field; network and hosting services may nevertheless process IP addresses while handling requests.

Two optional features are under your control and may carry personal data if you choose to send it: custom event properties, and order data used for revenue attribution. You must not send special categories of personal data as defined in Article 9 of the GDPR.

For account users: email address, sign-in method, and authentication metadata.

6. Processing instructions

We process personal data only on your documented instructions, which are given by the terms, this DPA and your use of the service, unless law requires otherwise, in which case we will tell you before processing unless the law forbids it. We will tell you if, in our opinion, an instruction infringes data protection law.

7. Confidentiality

Access to personal data is limited to those who need it to operate or support the service. Everyone with access is bound by a written confidentiality obligation that survives the end of their engagement, and access is withdrawn when it is no longer needed.

8. Security measures

We maintain technical and organisational measures appropriate to the risk of the processing, and we review them as the service changes. They include:

  • personal data encrypted in transit with TLS, and encrypted at rest by the infrastructure providers named in clause 9;
  • access granted on a least-privilege basis and protected by multi-factor authentication;
  • production separated from development, with no production personal data used in development;
  • rate limiting and input validation on the endpoints that receive events;
  • analytics records that omit a visitor IP field, while network services may process IP addresses;
  • dependencies kept current and security updates applied without undue delay;
  • backups encrypted and restricted to service recovery.

We never receive or store payment card numbers. We do not describe the detail of our controls publicly; a customer with a legitimate need may request further information under clause 14.

9. Sub-processors

You give general authorisation for the sub-processors below. We remain responsible for their performance.

Sub-processor Purpose
Convex, Inc. Application database and backend
Hetzner Online GmbH Application hosting, database and backend
Cloudflare, Inc. DNS, web traffic delivery and encrypted recovery backup storage
Polar Software Inc. Payments and invoicing, merchant of record
Resend, Inc. Transactional email delivery
Google LLC Sign-in with Google, and Search Console data where you connect it
GitHub, Inc. Sign-in with GitHub

For current processing locations and data-residency enquiries, contact hello@seean.io. This provider list does not establish a particular hosting region or an EU-only processing guarantee.

Sign-in providers process data only for customers who choose them. We will announce a new or replacement sub-processor by email at least thirty days before it starts processing; if you object on reasonable data protection grounds within that period you may terminate the affected part of the service and receive a refund for the unused period.

10. International transfers

Where personal data of people in the European Economic Area, the United Kingdom or Switzerland is transferred to a country without an adequacy decision, the transfer is made under the European Commission’s standard contractual clauses (Decision 2021/914), module two where you are a controller and we are your processor, and module three where a sub-processor is engaged, with the United Kingdom International Data Transfer Addendum where the United Kingdom GDPR applies. The clauses are incorporated by reference; the annexes are populated by clauses 2, 4, 5, 8 and 9 of this DPA, and the parties’ contact point is the address in clause 17.

11. Assistance

Taking account of the nature of the processing, we will help you by appropriate technical and organisational measures to answer requests from data subjects, and we will help you with data protection impact assessments and prior consultation where the information is available to us. If a data subject contacts us directly about data we process for you, we will refer them to you and will not respond substantively ourselves.

12. Deletion and return

You can export event and order records as CSV from the dashboard. For other data return requests, contact us. On deletion of a website or closure of the account, we delete or irreversibly anonymise the personal data within thirty days, except where storage is required by law. Encrypted recovery backups follow a separate 30-day retention schedule. Deletion requests must be reapplied before restored data returns to service.

13. Personal data breach

We will notify you without undue delay, and in any case within seventy-two hours of becoming aware of a personal data breach affecting personal data processed for you, with the information we have about its nature, likely consequences and the measures taken, and we will update you as more becomes known.

14. Audits

We will make available the information needed to demonstrate compliance with this DPA and will contribute to audits carried out by you or an auditor you appoint. Audits take place no more than once a year unless a breach or a supervisory authority requires otherwise, on thirty days’ notice, during business hours, without disrupting the service, and subject to confidentiality. Answering a reasonable written questionnaire satisfies this clause where it addresses your concern.

15. Your responsibilities

You are responsible for having a legal basis for the processing you instruct, for telling your visitors about it, for keeping personal data out of custom event properties and order payloads unless you have a basis for sending it, and for the accounts you grant access to.

16. Liability and precedence

Liability under this DPA is subject to the limitations in the terms of service. If this DPA and the terms conflict on data protection, this DPA prevails; if this DPA and the standard contractual clauses conflict, the clauses prevail.

17. Contact

Data protection enquiries: NesDesign LLC, Wyoming, United States, hello@seean.io.

18. Acceptance

Accepting the terms of service, or using the service, constitutes acceptance of this DPA by both parties. The version published at this address is the operative one, unless we have signed a separate written agreement with you.