Data Processing Addendum
1. Scope and roles
This Data Processing Addendum (the “DPA”) forms part of the Terms of Service between you (“Customer”) and Seiraiyu LLC (“Seiraiyu”) and applies where Seiraiyu processes personal data on Customer’s behalf through the Kisenon service (the “Service”). For that data, Customer is the controller (or a processor acting for a third-party controller) and Seiraiyu is the processor. Seiraiyu processes such personal data only on Customer’s documented instructions, which include Customer’s use of the Service and this DPA.
2. Subject matter, duration, and categories
Subject matter and duration: the provision of the Service for the duration of Customer’s account. Nature and purpose: hosting, storing, replicating, backing up, and transmitting Customer’s database contents to deliver a Postgres-compatible database. Categories of data subjects: whoever Customer chooses to store data about in its databases. Categories of personal data: any personal data Customer places into the Service; Seiraiyu does not require or control which categories Customer stores. Customer must not store special- category data unless it has a lawful basis and appropriate safeguards.
3. Sub-processors
Customer authorizes Seiraiyu to engage the sub-processors below to provide the Service. Seiraiyu remains responsible for its sub-processors’ performance and imposes data-protection obligations on them consistent with this DPA. We will give reasonable prior notice of any new sub-processor and give Customer an opportunity to object on reasonable data-protection grounds.
| Sub-processor | Purpose | Location | Status |
|---|---|---|---|
| Google Cloud (Google LLC) | Data-plane compute and object storage — hosts your database compute, pages, and archived write-ahead log. | United States (us-central1) | Live |
| Amazon Web Services (Amazon.com, Inc.) | Global control plane, secrets management, and transactional email — hosts the metadata describing your projects. | United States (us-east-2) | Live |
| Google LLC (Sign-in with Google) | OAuth authentication when you sign in with Google. | United States | Live |
| GitHub, Inc. | OAuth authentication when you sign in with GitHub. | United States | Live |
| Stripe, Inc. | Payment processing and subscription management for paid plans. | United States | Live for paid plans |
This list is current as of the date at the top of this page and may be updated as the Service evolves.
4. Security measures
Seiraiyu maintains technical and organizational measures appropriate to the risk, including:
- Encryption in transit — the console, control-plane API, and Postgres connections are secured with TLS using publicly trusted certificates.
- Encryption at rest — object storage and persistent disks are encrypted at rest by the cloud provider; API keys and service tokens are stored only as one-way hashes.
- Durability — write-ahead log is replicated to a majority quorum of safekeeper nodes and continuously archived to versioned object storage, with nightly backups of control-plane metadata.
- Access control — production access is limited to named operators; the Service offers per-database IP allow-lists and dynamic data masking.
- Auditability — security-relevant actions are recorded in a customer-visible audit log retained for 2 years, with legal-hold support.
5. Personal data breach
Seiraiyu will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer’s personal data, and will provide the information Customer reasonably needs to meet its own notification obligations. Notification is a process commitment carried out by Seiraiyu’s operators; it is not an admission of fault.
6. Assistance to Customer
Taking into account the nature of the processing, Seiraiyu will provide reasonable assistance to Customer in responding to data-subject requests and in meeting Customer’s obligations regarding security, breach notification, and data-protection impact assessments. Customer can action most requests itself using the Service’s export, audit, and deletion features.
7. Deletion and return
On termination, or on Customer’s request, Seiraiyu deletes Customer’s personal data, subject to the mechanics below. Customer may export its data before deletion.
When Customer deletes an account, organization, project, or other resource, Seiraiyu marks it deleted so it is no longer served, and the underlying database contents — compute, data pages, and archived write-ahead log — are decommissioned and age out on the object-storage retention cycle. Backups and archived logs likewise age out on their normal retention cycle rather than being erased instantaneously.
Audit records are treated differently by design: so that the record that a deletion occurred survives the deletion itself, audit entries are retained until their retention period expires (currently two years) and any entry placed under a legal hold is retained until that hold is released. Audit entries carry no link back to the deleted account, so they cannot be used to reconstitute it. Seiraiyu does not warrant a fixed post-termination purge deadline beyond these retention cycles and any period required by law.
8. International transfers
Seiraiyu stores and processes Customer’s personal data in the United States. Where Customer transfers personal data subject to European or UK data-protection law to Seiraiyu, the parties will rely on an appropriate transfer mechanism (such as the Standard Contractual Clauses), which are incorporated by reference and completed with the details in this DPA.
9. Audits
On reasonable written request, and no more than once per year (unless required by a supervisory authority), Seiraiyu will make available information reasonably necessary to demonstrate compliance with this DPA, including its then-current self-audit materials. Seiraiyu is not currently SOC 2, ISO 27001, GDPR-certified, or CCPA-certified.
10. Liability and precedence
Each party’s liability under this DPA is subject to the limitations of liability in the Terms of Service. If there is a conflict between this DPA and the Terms of Service regarding the processing of personal data, this DPA controls. This DPA is governed by the law and venue stated in the Terms of Service.
11. Contact
Seiraiyu LLC · Georgia, USA · legal@seiraiyu.com