Legal
9 documents, grouped by what they are for. Each one says what it actually answers, so you can find the right one without reading all of them. Nothing on this page is binding on its own — it points at the documents that are.
Terms version 2026-08-30 · last updated August 30, 2026
What you are agreeing to
One agreement, with two parts that sit inside it. There is nothing separate to sign.
- Terms of Service
The agreement itself — what the service does and deliberately does not decide, who owns what you put in, how billing works, and what happens when you leave.
Anyone signing up. This is the one you accept at signup, and the version you accepted is recorded against your account.
- Data Processing Addendum
The processor terms for your subcontractors' personal data: scope, security measures, subprocessors, breach notice, deletion, and the Article 32 measures annex.
Procurement and privacy reviewers. It applies automatically as part of the terms — you do not have to ask for it.
- Acceptable Use Policy
The four things you agree not to do, what happens if a rule is broken, and how to report abuse.
Security reviewers who ask for one by name, and anyone reporting misuse.
- Messaging program
How subcontractors opt in for a specific number, when scheduled and staff-triggered texts are sent, their frequency and sample wording, and how STOP blocks further texts.
A subcontractor who got a text and wants it to stop, and the carrier vetting the messaging campaign.
How we handle data
Most of the personal data in Sealinn is not about our customers — it is about their subcontractors, who never signed up for anything. The pages in this group are the ones that matter to those people as much as to you.
- Privacy Policy
What we collect, why, how long we keep each thing, what earlier AI processing transmitted and a future activation would transmit, and the rights you and your subcontractors can exercise.
Anyone. Sealinn-controlled retention periods are tied to software constants; provider defaults and unverified project settings are identified separately.
- Security
How one workspace is kept away from another, what stops the compliance record being changed, and what you walk away with if you leave.
The technical half of a buyer's diligence. Written to be checked rather than skimmed.
- Subprocessors
The 10 active companies that receive data, 2 inactive providers retained for historical context, plus 1 provider disclosed in advance, with what each does, what each gets, and a dated log of every change to that list.
Anyone who needs the list before signing. Credential-backed entries are checked against the production template; dashboard- and source-control-configured services still require manual review.
- Cookie Policy
The authentication and guest-workspace cookies used on this site, the first-party browser preferences we store, how to clear them, and the current cookieless analytics configuration.
Anyone. Short, because there is genuinely not much here.
Commitments
- Accessibility Statement
The standard we build to, which checks run on every change, what is not covered yet, and how to tell us something is unusable.
Public-sector buyers, and anyone who has hit a barrier and wants to know whether it is being worked on.
Contact channels
Use the address for the kind of request you are making. We do not publish a response-time commitment; mark urgent security, privacy, and legal messages clearly in the subject line.
- privacy@sealinn.com
- Anything about the data itself — what is held, a deletion or access request, a question about a subprocessor.
- legal@sealinn.com
- Contractual matters, including a request for a counter-signed data processing addendum or a review of the terms before you buy.
- security@sealinn.com
- Vulnerability reports and anything that looks like an incident. The coordinated disclosure practice is on the security page, and the machine-readable version is at
/.well-known/security.txt.
