Privacy Policy
How Seait processes personal data, and the rights data subjects have.
Ultimo aggiornamento 18 agosto 2026
1. Controller and roles
Seait is provided by Seait AS (org. no. 930 847 763), Bergliveien 3, 3427 Gullaug, Norway. For data about the harbour's customer relationship, contact persons and use of the service, Seait is the controller.
For personal data about a harbour's members, boats, berths, guests and similar, the individual harbour (marina, boat association or similar) is the controller, and Seait is a processor on the harbour's behalf under the written data processing agreement between the harbour and Seait.
Privacy questions can be directed to post@seait.no.
2. Personal data we process
Depending on the individual's role and the modules the harbour has enabled, we may process the following categories:
- Identification and contact: name, member number, email address, phone number and address.
- Boat and berth data: boat name, registration number, dimensions, and berth/storage assignment.
- Finance: orders, invoice references, subscriptions and payment references (not full card numbers).
- Use of the service: login data, roles, language preference and activity logs.
- Communication: logs of email and SMS, and messages in the meeting chat.
- Meetings and voting: participation and votes. In a secret ballot, individual votes are not available to the harbour's administration; only the individual can see their own vote.
- Optional modules: access control (key fob/card), power metering and boat images.
- AI assistant (optional module): the questions harbour staff write, and the data from the harbour's own records used to answer them.
3. Purposes and legal basis
We process personal data to deliver, operate and improve the service, administer the customer relationship, send notifications and invoices, ensure security and comply with legal obligations.
The legal basis is generally performance of a contract (GDPR Art. 6(1)(b)), our legitimate interest in operating and securing the service (Art. 6(1)(f)), legal obligations such as accounting and bookkeeping duties (Art. 6(1)(c)), and, for certain additional services, consent (Art. 6(1)(a)). We do not process special categories of personal data.
4. Sub-processors and sharing
We use selected sub-processors to deliver the service. Core operations — database, authentication, file storage and server functions — run in EEA regions at Supabase and Vercel, and where a provider offers a choice of region we have chosen the EEA. Email and SMS are sent through providers in the EEA. Several providers are nonetheless established outside the EEA, so some data may be processed in third countries — for example logs, metadata and support access, and for harbours using the AI assistant also the questions and the data that answers them. Such transfers take place only on a valid transfer basis, such as the EU Standard Contractual Clauses (SCCs) or the EU–US Data Privacy Framework. The table below shows this per provider. We do not sell personal data.
Only the first three providers in the table are always in use. The others engage only when the harbour takes up the feature they belong to — email, SMS, the AI assistant, eID signing, video meetings, guest-harbour payments or an accounting integration — as the "When it applies" column shows. Providers listed as alternatives we do not use today have received no personal data and will not be adopted without prior notice to the harbour.
The AI assistant is the only feature that sends the harbour's data to a language-model provider. It is available to harbour staff, not to members, and it only reads data the signed-in user can already access. The question, and the data used to answer it, are sent to the provider named in the table and are not used to train models. The harbour can switch the assistant off, and then nothing is sent.
| Sub-processor | Purpose | Location | Transfer basis | When it applies |
|---|---|---|---|---|
| Supabase | Database, authentication and file storage | Stored in the EEA (Ireland). The company is registered in Singapore, and support may take place outside the EEA | SCCs | Always — core infrastructure |
| Vercel | Hosting and server functions | EU region selected for server functions. The company is American | EU–US Data Privacy Framework + SCCs | Always — core infrastructure |
| Amazon Web Services (AWS) | Immutable backup copy of signed agreements and signatures, and rotating backup copies of the database and snapshots, see section 6 of the DPA | EEA (Sweden), in the processor's own account. The company is American | SCCs + EU–US Data Privacy Framework | Always — backup of signed agreements |
| Lettermint | Email delivery | EU. A Dutch company on European infrastructure; email, metadata and logs are processed in the EU | Within the EEA | When email is sent |
| Resend | Email delivery (alternative provider) | Sent from the EEA (Ireland), but Resend states that customer data is stored in the USA — including recipient addresses, email metadata and logs | SCCs + EU–US Data Privacy Framework | Not in use. An alternative that may only be adopted after notice |
| Sinch | SMS delivery | EEA (Sweden), EU region selected | Within the EEA | When SMS is sent |
| GatewayAPI | SMS delivery (alternative provider) | EEA (Denmark) | Within the EEA | Not in use. An alternative that may only be adopted after notice |
| OpenAI | The AI assistant: the language model that answers harbour staff's questions, and the indexing of the harbour's content that makes them searchable | USA. The company is American, and requests are processed in the USA | SCCs + EU–US Data Privacy Framework. The data is not used to train models | Optional — the AI assistant module. Off means nothing is sent |
| Anthropic (Claude) | The AI assistant (alternative language model) | USA. The company is American, and requests are processed in the USA | SCCs + EU–US Data Privacy Framework. The data is not used to train models | Not in use. An alternative that may only be adopted after notice, and only for harbours with the module on |
| Signicat | Electronic signing with eID (BankID and equivalents), and confirmation of name and date of birth on signing | EEA (Norway) | Within the EEA | Optional — only harbours that have chosen eID signing |
| LiveKit | Real-time video for board meetings | EU region for video. The company is American | EU–US Data Privacy Framework | Optional — the board meetings module, when video is used |
| Stripe | Guest-harbour payments | EEA (Ireland), with transfers to the USA | SCCs + EU–US Data Privacy Framework. Separate controller for payment data | Optional — guest harbour with Stripe as the payment provider |
| Vipps MobilePay | Guest-harbour payments | Norway | Within the EEA. Separate controller for payment data | Optional — guest harbour with Vipps MobilePay as the payment provider |
| Tripletex | Accounting and invoicing integration | EEA (Norway) | Within the EEA. Separate controller | Optional — only if the harbour chooses Tripletex as its accounting integration |
| Fatture in Cloud | Accounting and invoicing integration (Italy) | EEA (Italy) | Within the EEA. Separate controller | Optional — only if the harbour chooses Fatture in Cloud as its accounting integration |
5. Storage, location and retention
Personal data is stored in EEA regions. Transfers to third countries take place only on a valid transfer basis, see section 4 and the table there.
We retain data for as long as necessary for the purpose and the customer relationship, and thereafter for as long as required by law (for example the Bookkeeping Act for accounting data). It is then deleted or anonymised. Signed agreements and signatures are contracts and are kept for as long as the harbour, as controller, needs them — at least as long as the Bookkeeping Act and limitation rules require; they are not deleted automatically.
6. Rights of data subjects
The data subject has the right to access, rectification and erasure of their own personal data, as well as the right to restriction, data portability and to object to processing. Where processing is based on consent, the consent may be withdrawn at any time.
Where the request concerns data for which the harbour is the controller, it is addressed to the harbour; Seait assists the harbour in fulfilling these rights. Otherwise the request may be addressed to us at post@seait.no.
7. Information security
We protect the data with technical and organisational measures, including encryption in transit (TLS) and at rest, role-based access control enforced at the database level, secure authentication, backups and logging. Security is followed up in a standing programme of security audits, risk assessments, vulnerability assessments, gap analyses and penetration tests, see section 5 of the DPA. In the event of a personal data breach, we notify in accordance with the applicable rules.
8. Cookies
The service uses only strictly necessary cookies and local storage for login and settings. See the separate cookies page.
9. Complaints to the Data Protection Authority
Anyone who considers that our processing of personal data breaches the rules may lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet), P.O. Box 458 Sentrum, 0105 Oslo (www.datatilsynet.no). We appreciate being contacted first, so that we can correct any errors.
10. Changes
We may update this privacy policy. The current version is always available here, and material changes are communicated appropriately.
Questo documento è un modello e può essere aggiornato. Verifica i dati aziendali, i responsabili del trattamento e le basi per il trasferimento prima di farne uso.