Back to Seamix Legal centre
Data Protection // Article 28 Terms

Data Processing
Addendum.

Processor terms for business customers whose briefs, uploads or team records contain personal data. Incorporated automatically into the Terms of Service where the customer acts as controller.

Last updated: 14 August 2026 // Version 1.0 // Governing law: the laws of England and Wales

1. Roles and Scope

  • For that customer content you are the controller and Seamix AI is the processor.
  • For your own account, billing, security and product analytics data we are the controller, and the Privacy Policy applies.
  • This Addendum forms part of the Terms of Service and applies automatically, with no signature needed. A countersigned copy is available on request from privacy@seamix.ai.
  • It is governed by the UK GDPR and the Data Protection Act 2018, and by the EU GDPR where that applies to you.

2. Details of Processing

ItemDetail
Subject matterProvision of the Seamix AI technical documentation platform
DurationFor the term of your subscription, plus the retention periods in the Privacy Policy
Nature and purposeHosting, storage, transmission to AI model providers for inference, generation and version control of technical documents, metering, support and security
Types of personal dataNames, email addresses, job titles, account identifiers, body or block measurements where supplied, images that may contain a person's likeness where supplied, billing metadata, IP addresses and usage logs
Categories of data subjectsYour personnel and authorised users, and any individual whose measurements or likeness you choose to upload
Special category dataNot permitted. You must not upload special category data to the Service

3. Our Obligations as Processor

  • We process customer content only on your documented instructions, which include your use of the features of the Service, and for no other purpose.
  • We will tell you if in our opinion an instruction infringes data protection law, and may suspend that instruction.
  • We keep customer content confidential and ensure that personnel authorised to access it are bound by confidentiality and are trained appropriately.
  • We implement the technical and organisational measures described in the Privacy Policy and the Security Policy, and will not materially reduce them during your subscription.
  • We assist you, at your cost where the work is substantial, in responding to data subject requests, and will forward to you without undue delay any request we receive that relates to your customer content.
  • We provide the information reasonably necessary for you to carry out a data protection impact assessment or to consult a supervisory authority.
  • We notify you without undue delay, and in any event within 48 hours of becoming aware, of any personal data breach affecting your customer content, with the information available to us at that point and updates as the investigation progresses.

4. Sub-processors

5. International Transfers

6. Audit, Return and Deletion

  • We will make available the information reasonably necessary to demonstrate compliance with this Addendum. Because we are a small provider without a SOC 2 report, we satisfy audit rights by written response to a reasonable questionnaire, no more than once in any 12 months unless a breach or a regulator requires more.
  • You may export your documents and content from the dashboard at any time.
  • On termination we delete customer content from live systems in accordance with the Privacy Policy, and it is removed from routine backups on our providers' standard cycle, unless retention is required by law.