LIFAIO
Seal LIFAIO
verified by LIFAIO

Data processing agreement

This agreement applies when an organisation entrusts Seal LIFAIO with the processing of personal data. The organisation is the controller; Technologies Marco Prive is its processor, within the meaning of Article 28 of Regulation (EU) 2016/679.

It is accepted when the account is opened, box by box, and that acceptance is recorded with the document version, the date and the IP address. Article 28(9) expressly provides that the contract may be in electronic form.

What Seal processes, and what it does not

Seal processes: an actor's public identifier (E-XXXXXX), the label the organisation gives it, attested presence moments, and the account's business contact details. Seal processes NO location data, NO biometric data, NO images, and opens NO account in an employee's name.

An actor's label is a free-text field filled in by the organisation. If it enters a name there, that name is personal data and falls under this agreement. Seal never requires one.

Seal's commitments — Article 28(3)

a) Process the data only on the organisation's documented instructions, including for transfers outside the Union, unless required by law.
b) Grant access only to persons bound by confidentiality.
c) Implement the Article 32 security measures: encryption in transit, account isolation, mandatory two-factor authentication, access logging.
d) Engage a sub-processor only on the conditions below, and inform the organisation of any addition or replacement before it takes effect, allowing it to object.
e) Assist the organisation in responding to data subject requests: the account is exportable and erasable from the portal, without any action on our part.
f) Assist the organisation with security, breach notifications and impact assessments, and report any breach without undue delay after becoming aware of it.
g) Erase the data at the end of the service. Erasure is triggered by the organisation itself from its portal, and is immediate.
h) Provide all information necessary to demonstrate compliance with these obligations and allow audits by the organisation or an auditor it mandates.

Authorised sub-processors

The organisation authorises the sub-processors below. Any addition or replacement is published on this page and notified before it takes effect.

Sub-processor Role Location Since
Cloudflare, Inc. Service hosting, database, administrator access protection USA / UE 2026-08-18
Stripe, Inc. Payments, subscriptions and merchant of record; Connect for promoters' payment accounts USA / Irlande 2026-08-18
Resend, Inc. Sending service emails USA 2026-08-18
Didit Company legal-existence verification (KYB) and identity verification of individuals (KYC: ID document, liveness, face comparison) — processed at Didit, never received or stored by Seal, which only gets a verdict UE 2026-08-25
Prighter (Maetzler Rechtsanwalts GmbH & Co KG) Article 27 representative — receives data subject requests Autriche 2026-09-05

Registry lookups

The organisation's name and country are sent to these services to verify its legal existence. No data relating to a natural person is sent to them.

Sub-processor Role Location Since
Google Places (Google Ireland Ltd.) Anchoring the phone number to the company's public listing Irlande / USA 2026-08-25
OpenCorporates Ltd. Company registry lookup Royaume-Uni 2026-08-25
GLEIF Global Legal Entity Identifier registry Suisse / UE 2026-08-25

Technical calls carrying no personal data

Declared for transparency. A domain name or a hash is sent, never a person or an organisation.

Sub-processor Role Location Since
Transparence des certificats (crt.sh, Cert Spotter) Detecting certificates issued for a monitored DOMAIN USA 2026-08-30
Résolution DNS (Google Public DNS) Checking a DOMAIN's records USA 2026-08-30
OpenTimestamps Timestamping a HASH — the document never leaves the device monde 2026-08-28
Aucun appel — texte seulement Platform names declared by a creator as publication places. Seal sends nothing there and embeds no player: an embedded player would send every visitor's IP address to the platform. 2026-08-18

Transfers outside the European Union

Some sub-processors are established outside the Union. These transfers rely on the standard contractual clauses adopted by the European Commission, included in the contracts concluded with each of them. The GDPR expressly permits such transfers under its Chapter V; it does not require data to be hosted in the Union.

Representative in the Union

In accordance with Article 27, Technologies Marco Prive has designated a representative in the European Union. Its details appear on the privacy page.

Technologies Marco Prive · 2200-1250 Rene-Levesque Ouest, Montreal, Quebec, Canada H3B 4W8 · 1415 Louisiana St Ste 1800, Houston, TX 77002, USA · +1-263-999-2751 · info@lifaio.com · privacy@lifaio.com
Document version : 2026-09-12 · Privacy policy

🌐 Available in 18 languages
© Technologies Marco Prive — UK patents pending — GB2619490.2 · GB2619948.9 · GB2620153.3 · GB2620211.9 · GB2620220.0 · GB2620253.1 · GB2620315.8 · GB2620629.2 · GB2621074.0 · GB2621382.7
Terms · Privacy · Méthode · ⏱️ Séquentiel · Refunds · Site protection · Cookies · Data processing · Nothing to steal · Measurement · Tickets: how it works
Seal LIFAIO v3.51.0