Data Processing Agreement
LAST UPDATED · 29 SEPTEMBER 2026
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between SeatLayer (Paiteq Private Limited, “Processor”) and the customer using SeatLayer (“Customer”, the controller). It applies automatically whenever we process Customer Personal Data. No signature is required. A countersigned copy is available on request at hello@seatlayer.io.
1. Definitions
“Customer Personal Data” means personal data that Customer or its buyers submit to the service and that we process on Customer's behalf. “Data Protection Law” means the GDPR, the UK GDPR and other applicable data protection laws. Other terms have the meanings given in the GDPR.
2. Scope and roles
Customer is the controller and SeatLayer is the processor of Customer Personal Data. The subject matter, nature, purpose and duration of the processing, and the types of data and data subjects, are set out in Annex 1.
3. Instructions
We process Customer Personal Data only on Customer's documented instructions, which are the Terms, this DPA and Customer's use and configuration of the service. We will inform Customer if we believe an instruction infringes Data Protection Law.
4. Confidentiality
We ensure that personnel authorised to process Customer Personal Data are bound by obligations of confidentiality and access it only as needed to provide or support the service.
5. Security
We implement and maintain the technical and organisational measures described in Annex 2.
6. Subprocessors
Customer authorises SeatLayer to use subprocessors. Our current subprocessors are listed in your dashboard under Settings → Data protection, and are available on request. We email account owners at least 30 days before adding or replacing one. Customer may object on reasonable data protection grounds. If we cannot resolve the objection, Customer may stop using the affected service and we will refund any unused prepaid credit. We impose data protection obligations on each subprocessor that are at least as protective as this DPA, and remain responsible for their performance.
7. Data subject requests
Taking into account the nature of the processing, we will assist Customer in responding to requests from data subjects to exercise their rights under Data Protection Law.
8. Personal data breaches
We will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data, and provide the information Customer reasonably needs to meet its obligations.
9. Assistance
We will provide reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities where required by Data Protection Law.
10. International transfers
SeatLayer is based in India and some subprocessors are located in the United States. Transfers of Customer Personal Data from the European Economic Area are governed by the Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914, which are incorporated into this DPA: Module 2 (controller to processor) for transfers from Customer to SeatLayer, and Module 3 (processor to processor) or the EU–US Data Privacy Framework for onward transfers to subprocessors. For those Clauses: clause 7 applies; under clause 9, option 2 applies with 30 days' notice; the optional wording in clause 11 does not apply; and for clauses 17 and 18 the governing law and courts are those of Ireland. Annexes 1 and 2 of this DPA complete the appendix to the Clauses. For transfers from the United Kingdom, the UK International Data Transfer Addendum applies, and for Switzerland the Clauses apply with the amendments required by Swiss law.
11. Audits
We will make available the information reasonably necessary to demonstrate compliance with this DPA. We will first answer written questions. Where that is not sufficient, Customer may conduct one audit per year on 30 days’ written notice.
12. Return and deletion
When Customer asks us to close its workspace, we will give Customer the opportunity to export its data and then delete Customer Personal Data within 30 days, except where the law requires us to retain it. Backup copies are deleted within a further 7 days.
13. Liability and precedence
Each party's liability under this DPA is subject to the limitations in the Terms, except where Data Protection Law does not allow a limitation. In case of conflict regarding personal data, this DPA prevails over the Terms, and the Standard Contractual Clauses prevail over both.
14. Contact
hello@seatlayer.io · Paiteq Private Limited, HD-101(A), WeWork Salarpuria Symbiosis Park, Bengaluru, Karnataka 560077, India.
Annex 1: Details of processing
| Data exporter | Customer (controller) |
| Data importer | Paiteq Private Limited (SeatLayer), processor |
| Data subjects | Customer's ticket buyers, attendees and season-ticket holders, and Customer's staff who use the service |
| Categories of data | Name, email address, phone number, answers to booking questions, order and ticket details, payment references, check-in status, and IP address and device information |
| Special categories | None intended |
| Nature and purpose | Seat selection, ticket sales, ticket delivery, check-in, reporting and support |
| Frequency | Continuous, for as long as Customer uses the service |
| Duration and retention | For the term of the Terms, then as set out in section 12 |
| Location | Customer data is stored in Germany; uploaded files in the Asia-Pacific region |
Annex 2: Technical and organisational measures
- Encryption of data in transit and at rest
- Passwordless sign-in; authentication credentials are never stored in readable form
- Logical separation of each customer's data
- Access restricted to authorised personnel on a need-to-know basis
- Confidentiality obligations for all personnel
- Daily backups, retained for 7 days
- Personal data minimised in system logs
Annex 3: Subprocessors
Listed in your dashboard under Settings → Data protection. A copy is available on request at hello@seatlayer.io.