Tutti i documenti legali

Privacy Policy

How Seait processes personal data, and the rights data subjects have.

Ultimo aggiornamento 18 agosto 2026

1. Controller and roles

Seait is provided by Seait AS (org. no. 930 847 763), Bergliveien 3, 3427 Gullaug, Norway. For data about the harbour's customer relationship, contact persons and use of the service, Seait is the controller.

For personal data about a harbour's members, boats, berths, guests and similar, the individual harbour (marina, boat association or similar) is the controller, and Seait is a processor on the harbour's behalf under the written data processing agreement between the harbour and Seait.

Privacy questions can be directed to post@seait.no.

2. Personal data we process

Depending on the individual's role and the modules the harbour has enabled, we may process the following categories:

  • Identification and contact: name, member number, email address, phone number and address.
  • Boat and berth data: boat name, registration number, dimensions, and berth/storage assignment.
  • Finance: orders, invoice references, subscriptions and payment references (not full card numbers).
  • Use of the service: login data, roles, language preference and activity logs.
  • Communication: logs of email and SMS, and messages in the meeting chat.
  • Meetings and voting: participation and votes. In a secret ballot, individual votes are not available to the harbour's administration; only the individual can see their own vote.
  • Optional modules: access control (key fob/card), power metering and boat images.
  • AI assistant (optional module): the questions harbour staff write, and the data from the harbour's own records used to answer them.

3. Purposes and legal basis

We process personal data to deliver, operate and improve the service, administer the customer relationship, send notifications and invoices, ensure security and comply with legal obligations.

The legal basis is generally performance of a contract (GDPR Art. 6(1)(b)), our legitimate interest in operating and securing the service (Art. 6(1)(f)), legal obligations such as accounting and bookkeeping duties (Art. 6(1)(c)), and, for certain additional services, consent (Art. 6(1)(a)). We do not process special categories of personal data.

4. Sub-processors and sharing

We use selected sub-processors to deliver the service. Core operations — database, authentication, file storage and server functions — run in EEA regions at Supabase and Vercel, and where a provider offers a choice of region we have chosen the EEA. Email and SMS are sent through providers in the EEA. Several providers are nonetheless established outside the EEA, so some data may be processed in third countries — for example logs, metadata and support access, and for harbours using the AI assistant also the questions and the data that answers them. Such transfers take place only on a valid transfer basis, such as the EU Standard Contractual Clauses (SCCs) or the EU–US Data Privacy Framework. The table below shows this per provider. We do not sell personal data.

Only the first three providers in the table are always in use. The others engage only when the harbour takes up the feature they belong to — email, SMS, the AI assistant, eID signing, video meetings, guest-harbour payments or an accounting integration — as the "When it applies" column shows. Providers listed as alternatives we do not use today have received no personal data and will not be adopted without prior notice to the harbour.

The AI assistant is the only feature that sends the harbour's data to a language-model provider. It is available to harbour staff, not to members, and it only reads data the signed-in user can already access. The question, and the data used to answer it, are sent to the provider named in the table and are not used to train models. The harbour can switch the assistant off, and then nothing is sent.

Sub-processorPurposeLocationTransfer basisWhen it applies
SupabaseDatabase, authentication and file storageStored in the EEA (Ireland). The company is registered in Singapore, and support may take place outside the EEASCCsAlways — core infrastructure
VercelHosting and server functionsEU region selected for server functions. The company is AmericanEU–US Data Privacy Framework + SCCsAlways — core infrastructure
Amazon Web Services (AWS)Immutable backup copy of signed agreements and signatures, and rotating backup copies of the database and snapshots, see section 6 of the DPAEEA (Sweden), in the processor's own account. The company is AmericanSCCs + EU–US Data Privacy FrameworkAlways — backup of signed agreements
LettermintEmail deliveryEU. A Dutch company on European infrastructure; email, metadata and logs are processed in the EUWithin the EEAWhen email is sent
ResendEmail delivery (alternative provider)Sent from the EEA (Ireland), but Resend states that customer data is stored in the USA — including recipient addresses, email metadata and logsSCCs + EU–US Data Privacy FrameworkNot in use. An alternative that may only be adopted after notice
SinchSMS deliveryEEA (Sweden), EU region selectedWithin the EEAWhen SMS is sent
GatewayAPISMS delivery (alternative provider)EEA (Denmark)Within the EEANot in use. An alternative that may only be adopted after notice
OpenAIThe AI assistant: the language model that answers harbour staff's questions, and the indexing of the harbour's content that makes them searchableUSA. The company is American, and requests are processed in the USASCCs + EU–US Data Privacy Framework. The data is not used to train modelsOptional — the AI assistant module. Off means nothing is sent
Anthropic (Claude)The AI assistant (alternative language model)USA. The company is American, and requests are processed in the USASCCs + EU–US Data Privacy Framework. The data is not used to train modelsNot in use. An alternative that may only be adopted after notice, and only for harbours with the module on
SignicatElectronic signing with eID (BankID and equivalents), and confirmation of name and date of birth on signingEEA (Norway)Within the EEAOptional — only harbours that have chosen eID signing
LiveKitReal-time video for board meetingsEU region for video. The company is AmericanEU–US Data Privacy FrameworkOptional — the board meetings module, when video is used
StripeGuest-harbour paymentsEEA (Ireland), with transfers to the USASCCs + EU–US Data Privacy Framework. Separate controller for payment dataOptional — guest harbour with Stripe as the payment provider
Vipps MobilePayGuest-harbour paymentsNorwayWithin the EEA. Separate controller for payment dataOptional — guest harbour with Vipps MobilePay as the payment provider
TripletexAccounting and invoicing integrationEEA (Norway)Within the EEA. Separate controllerOptional — only if the harbour chooses Tripletex as its accounting integration
Fatture in CloudAccounting and invoicing integration (Italy)EEA (Italy)Within the EEA. Separate controllerOptional — only if the harbour chooses Fatture in Cloud as its accounting integration

5. Storage, location and retention

Personal data is stored in EEA regions. Transfers to third countries take place only on a valid transfer basis, see section 4 and the table there.

We retain data for as long as necessary for the purpose and the customer relationship, and thereafter for as long as required by law (for example the Bookkeeping Act for accounting data). It is then deleted or anonymised. Signed agreements and signatures are contracts and are kept for as long as the harbour, as controller, needs them — at least as long as the Bookkeeping Act and limitation rules require; they are not deleted automatically.

6. Rights of data subjects

The data subject has the right to access, rectification and erasure of their own personal data, as well as the right to restriction, data portability and to object to processing. Where processing is based on consent, the consent may be withdrawn at any time.

Where the request concerns data for which the harbour is the controller, it is addressed to the harbour; Seait assists the harbour in fulfilling these rights. Otherwise the request may be addressed to us at post@seait.no.

7. Information security

We protect the data with technical and organisational measures, including encryption in transit (TLS) and at rest, role-based access control enforced at the database level, secure authentication, backups and logging. Security is followed up in a standing programme of security audits, risk assessments, vulnerability assessments, gap analyses and penetration tests, see section 5 of the DPA. In the event of a personal data breach, we notify in accordance with the applicable rules.

8. Cookies

The service uses only strictly necessary cookies and local storage for login and settings. See the separate cookies page.

9. Complaints to the Data Protection Authority

Anyone who considers that our processing of personal data breaches the rules may lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet), P.O. Box 458 Sentrum, 0105 Oslo (www.datatilsynet.no). We appreciate being contacted first, so that we can correct any errors.

10. Changes

We may update this privacy policy. The current version is always available here, and material changes are communicated appropriately.

Questo documento è un modello e può essere aggiornato. Verifica i dati aziendali, i responsabili del trattamento e le basi per il trasferimento prima di farne uso.