Version 1.0, 14 July 2026
Document prepared in good faith in accordance with the GDPR (Regulation (EU) 2016/679) and the French Data Protection Act, aligned with the actual behaviour of the product. It will be reviewed by legal counsel upon incorporation of the company.
The data controller is SealTrust SAS, represented by its President, Nordine Bouchelia, registered office in Lyon, France (company in the process of incorporation).
For certain processing carried out on behalf of Brand clients (for example a Brand's end-customer data), SealTrust acts as a processor within the meaning of Article 28 GDPR, governed by a Data Processing Agreement (DPA).
For any question or to exercise your rights: contact@sealtrust.io, or by post to SealTrust SAS, Lyon, France. We acknowledge receipt within 48 hours and respond within a maximum of one month, extendable by two months for complex requests (Article 12 GDPR).
SealTrust has not designated a data protection officer: the conditions of Article 37 GDPR are not met at this time. This analysis is reviewed at least once a year.
Theft report data (Article 10 GDPR) is processed on the basis of the legitimate interest in preventing fraud, with access restricted to authorised staff and retention limited to handling the report.
Data is accessible only to authorised SealTrust staff and to the strictly necessary technical sub-processors:
SealTrust does not sell any personal data to third parties.
Some sub-processors are located in the United States. These transfers are governed by the European Commission's standard contractual clauses (Article 46 GDPR), supplemented where appropriate by additional safeguards (encryption, minimisation).
Public blockchain: SealTrust uses Base (Layer 2 on Ethereum). Token identifiers, ownership and transfers are public by design and non-erasable. A wallet address may, in some contexts, constitute personal data. SealTrust documents a data protection impact assessment (DPIA) covering the on-chain data and minimisation measures.
Technical and organisational measures: TLS 1.2 or higher, Argon2id hashing, signing via AWS KMS, NFC Secure Dynamic Messaging AES-128 (anti-replay, anti-clone), encryption at rest of sensitive credentials (including custodial wallet keys), multi-factor authentication for administration, least-privilege access, logging. In the event of a data breach, SealTrust notifies the CNIL and, where applicable, the data subjects (Articles 33 and 34 GDPR).
In accordance with the GDPR (Articles 15 to 22) and the Data Protection Act, you have the rights of access, rectification, erasure, restriction, portability and objection, the right to withdraw consent, and the right to give post-mortem directives.
You may lodge a complaint with the CNIL (www.cnil.fr).
The Service uses cookies strictly necessary (CSRF token, language preference, session), placed without consent. Non-essential cookies are placed only with your consent via the banner, reopenable via "Manage cookies" in the footer. No advertising cookies or cross-site tracking. Details in the Cookie Policy.
The Service offers a conversational assistant on the public website and in the administration workspace. Its answers are generated by an artificial intelligence, from documentation written and reviewed in house, and may contain errors.
The assistant has no access to any database, any account and any brand data. It therefore cannot look up information about you, whatever the question. It never asks you for personal data and you are advised not to enter any.
The model runs on Amazon Web Services (Bedrock) in the Paris region (eu-west-3). Questions are not passed to any model vendor and are not used for training. No transfer outside the European Union takes place for this call.
Legal basis: legitimate interest (Article 6(1)(f)) for the public website assistant, performance of the contract (Article 6(1)(b)) for the assistant and support channel in the administration workspace.
Public website conversations being anonymous, SealTrust cannot identify a person from a conversation. Access and erasure rights therefore cannot be exercised on that scope, a situation provided for by Article 11 GDPR; short retention and automatic purges address it in practice.
SealTrust may amend this policy. In the event of a substantial change, data subjects are informed and, where applicable, consent is collected anew (version in force: 2026-07).