Data Processing Addendum

Version 1.0 · Effective Jan. 1, 2026

Draft — under review.

This Data Processing Addendum ("DPA") requires legal counsel review before use.

1. ROLES
For certain personal data processed on behalf of customers, Seema AI, a Delaware LLC acts as a
processor and the customer acts as controller. For its own operational data,
Seema acts as controller.

2. SUBPROCESSORS
Seema engages the following subprocessors: Stripe (payments and payouts),
Anthropic (managed-LLM compute), and DigitalOcean (hosting). We will maintain an
up-to-date list and provide notice of changes.

3. SECURITY
We implement appropriate technical and organizational measures to protect
personal data, including access controls, encryption in transit, and logging.

4. DATA-SUBJECT REQUESTS
We will assist the controller, to the extent reasonable, in responding to
data-subject access, deletion, correction, and portability requests.

5. BREACH NOTIFICATION
We will notify the controller without undue delay after becoming aware of a
personal-data breach affecting their data.

6. DELETION
Upon termination, we will delete or return personal data processed on the
controller's behalf, except as required by law.

7. COUNSEL REVIEW
This DPA is a draft and must be reviewed and finalized by legal counsel before
execution. Contact legal@seemaai.ai.