Legal information
Data Processing Agreement
Effective date: 8 September 2026 · Version 2026-09-08
1. Parties and application
This Data Processing Agreement forms part of the Seysuite Projects Terms of Service and each applicable customer order. The customer is the organisation using the service. Zil Smart Solutions is the registered business name under which Rimond Arnold Pillay operates in the Republic of Seychelles, Business Registration Number B8441574. If this Agreement conflicts with general service terms on processing customer personal data, this Agreement controls for that subject.
2. Roles
The customer generally acts as controller for personal data it or its users place in project content and determines the purposes and essential means of that processing. ZSS acts as processor for that data. Each party remains independently responsible for personal data it controls for its own account administration, billing, security, compliance, and legal purposes.
3. Processing details
- Subject and purpose: hosting and operating project-management, collaboration, file, notification, audit, reporting, support, and security functions.
- Duration: the subscription period plus the export, deletion, backup, and legal-retention periods described below.
- Operations: collection, recording, organisation, storage, retrieval, consultation, transmission, restriction, backup, export, and deletion.
- Data subjects: customer personnel, contractors, users, contacts, suppliers, customers, and other people whose information the customer lawfully includes.
- Data types: identity and contact details, roles, assignments, project and work-item information, comments, uploaded files, activity, notifications, and audit information.
4. Customer instructions
ZSS will process customer personal data only on documented instructions contained in the order, Terms, this Agreement, the customer’s authorised use of the service, and written support requests, unless processing is required by law. If legally permitted, we will inform the customer before processing required by law. We will notify the customer if an instruction appears to infringe applicable data-protection law and may suspend that instruction while it is reviewed.
5. Confidentiality and personnel
Access to customer personal data is limited to personnel and providers who need it to perform the service, support customers, maintain security, or comply with law. Those persons are subject to appropriate confidentiality obligations and receive access only for the period and purpose required.
6. Security measures
Measures include secure transport; authenticated and invitation-controlled access; email verification; role, project, and edition controls; organisation tenant separation; database row-level security; restricted privileged functions; private file storage and expiring download links; password-recovery controls; audit and activity records; browser security headers; environment-secret separation; tested migrations; and access revocation. Measures may evolve as technology and risk change, provided overall protection is not materially reduced.
7. Subprocessors
The customer authorises the subprocessors below. ZSS remains responsible for requiring data-protection obligations appropriate to their services. We will provide reasonable advance notice of a material new subprocessor where practicable. A customer with reasonable data-protection grounds may object promptly; the parties will work in good faith on a practical solution.
| Provider | Purpose | Processing |
|---|---|---|
| Supabase | Database, authentication, file storage, realtime, and platform infrastructure | Provider infrastructure configured for the service, potentially outside Seychelles |
| Netlify | Application build, hosting, server rendering, and content delivery | Provider infrastructure and delivery network, potentially outside Seychelles |
8. International transfers
Customer personal data may be processed outside Seychelles. ZSS will use reasonable contractual, technical, and organisational safeguards appropriate to the transfer, including provider due diligence, confidentiality and security terms, access limitation, and encryption in transit, and will comply with applicable requirements of the Seychelles Data Protection Act, 2023.
9. Security incidents
ZSS will investigate a confirmed personal-data breach affecting customer personal data and notify the customer without undue delay after becoming aware of it. As information becomes available, the notice will describe the nature and likely consequences of the breach, affected information, mitigation taken or proposed, and a contact point. Notification is not an admission of fault. The customer remains responsible for its own regulatory and data-subject notifications unless otherwise required by law.
10. Assistance
Taking account of the processing and information available, ZSS will provide reasonable assistance with data-subject requests, security assessments, impact assessments, breach response, and regulator enquiries relating to customer personal data. The customer is responsible for responding to requests as controller. Work outside ordinary service operation may be subject to agreed reasonable charges.
11. Return, export, and deletion
During the subscription, customers may use available report and file-download tools and may request reasonable assistance with an available export. Unless otherwise agreed, an authorised administrator may request an export for 30 days after access ends. Customer data is then deleted or anonymised from active systems, ordinarily within 30 further days, unless retention is required for law, security, fraud prevention, or a dispute. Residual backups are isolated from ordinary use and removed or overwritten through the applicable backup-retention cycle.
12. Information and audits
ZSS will make available information reasonably necessary to demonstrate compliance with this Agreement. If that information is insufficient, a customer may request an audit no more than once in a 12-month period, unless a breach or regulator requires otherwise. Audits must be reasonably scoped, protect other customers and security, use an independent confidential reviewer where appropriate, and avoid disruption. The requesting customer bears its audit costs unless material non-compliance is found.
13. Customer responsibilities
The customer is responsible for lawful instructions, transparency notices, legal bases, permissions, data accuracy, user and role administration, device and export security, and avoiding unnecessary or prohibited sensitive information. The customer must notify ZSS promptly of suspected compromise or unlawful use and must not instruct ZSS to process data contrary to law.
14. Liability, law, and termination
Liability under this Agreement is subject to the lawful limitations in the Terms and applicable order. Nothing excludes rights or liability that cannot lawfully be excluded. This Agreement is governed by Seychelles law and ends when ZSS has completed the return, deletion, and lawful retention of customer personal data after the relevant service ends.
15. Contact
Data-processing questions may be sent to info@zilsmartsolutions.com. Zil Smart Solutions · BRN B8441574 · Anse Aux Pins, Mahé, Seychelles.