# Data Processing Addendum | Sealgate

Sealgate Data Processing Addendum (DPA): how Sealgate processes personal data as a data processor, covering UK and EU GDPR, CCPA, sub-processors, 120-day retention, international transfers, and technical and organisational measures.

Source: https://sealgate.ai/dpa

---

// Safety net only. Both entry points preload the chunk they are about to // render, so in practice nothing here suspends. It exists so a route // added without a matching SPLIT_ROUTES entry degrades to a blank frame // instead of throwing. [Back to home](https://sealgate.ai/)

# Data Processing Addendum

Last updated: 18th August 2026

This Data Processing Addendum ("DPA") supplements and forms part of the Sealgate Terms of Service (the "Agreement") between you and GPU-EVM LTD, whose common trading name is Sealgate. It describes how Sealgate processes Personal Data on your behalf and applies to Sealgate's SaaS (self-serve cloud) deployments. All capitalized terms not defined here have the meanings given in the Agreement.

Roles: For the SaaS Service, the Customer is the Data Controller and Sealgate acts as the Data Processor. For Self-Hosted deployments, Sealgate generally does not process, store, or access Personal Data, and this DPA applies only to the limited extent that Sealgate processes telemetry or support data.

## Definitions

"Data Protection Laws" means all data protection laws and regulations applicable to Sealgate's processing of Personal Data, including:

- The UK General Data Protection Regulation ("UK GDPR")
- The EU General Data Protection Regulation (Regulation (EU) 2016/679) ("EU GDPR")
- The California Consumer Privacy Act ("CCPA") "Personal Data" means any information relating to an identified or identifiable natural person processed by Sealgate as a data processor under the Agreement.

"Restricted Transfer" means any cross-border transfer of Personal Data that would be restricted by Data Protection Laws without appropriate safeguards.

## Details of Processing

The following table summarizes the processing carried out by Sealgate as a Data Processor for the SaaS Service.

Aspect | Details
Role of the parties | The Customer is the Data Controller; Sealgate (GPU-EVM LTD) acts as the Data Processor. For Self-Hosted deployments, Sealgate generally does not process, store, or access Personal Data.
Subject matter | Processing of Personal Data necessary to provide the Sealgate SaaS platform: runtime monitoring, policy enforcement, and audit logging of AI agent tool-call activity.
Categories of data subjects | Platform users; enterprise administrators and security teams; individuals whose data appears in proxied MCP tool-call payloads.
Categories of personal data | Name and email; credentials and authentication data; MCP tool-call metadata and associated request and response data; usage and interaction data.
Retention | Personal Data is retained for 120 days by default, unless a longer period is required by law. The retention window is configurable per organization from 1 up to 365 days; logs associated with deleted users are purged within 7 days.
Sub-processors | A current list is maintained at sealgate.ai/subprocessors. Sealgate provides 30 days' notice before adding or replacing a sub-processor, and the Customer may object.

You may view the current sub-processor list at [sealgate.ai/subprocessors](https://sealgate.ai/subprocessors) .

## Technical and Organizational Measures

Sealgate implements appropriate technical and organizational measures to protect Personal Data. For SaaS deployments these include:

- Encryption of Personal Data in transit and at rest
- Access controls and authentication
- Regular updates and patching
- Audit trails for platform activity For Self-Hosted deployments, the security of the environment hosting the Software is the responsibility of the Customer. Sealgate ensures the security of the software artifacts (such as containers and binaries) delivered to the Customer.

## Sub-processor Management

Sealgate maintains an up-to-date list of sub-processors at [sealgate.ai/subprocessors](https://sealgate.ai/subprocessors) . We will provide 30 days' notice before adding or replacing a sub-processor by updating that list. If you reasonably object to a new sub-processor, notify us in writing with the grounds for your objection, and we will work to find a commercially reasonable solution or allow you to terminate the affected services.

## Data Subject Rights

We will assist you in responding to data subject requests as required by Data Protection Laws. We will promptly notify you of any direct requests we receive from data subjects and provide reasonable assistance in responding to them.

## Personal Data Breach

We will notify you without undue delay upon becoming aware of any Personal Data breach involving your data processed by us, provide reasonable assistance in investigating the incident, and take appropriate measures to address the breach.

## International Transfers

For transfers of Personal Data outside the UK and EEA, we rely on appropriate safeguards including:

- The UK International Data Transfer Agreement (IDTA)
- EU Standard Contractual Clauses (SCCs)
- Adequate security measures and contractual commitments with sub-processors

## Governing Law

This DPA is governed by the laws of England and Wales, and disputes will be resolved in the courts of England and Wales.

## Contact

This DPA is entered into with GPU-EVM LTD, trading as Sealgate, 3rd Floor, 86-90 Paul Street, London EC2A 4NE, United Kingdom. For any data protection questions or to exercise your rights under this DPA, contact us at [hello@sealgate.ai](mailto:hello@sealgate.ai) .
