Last updated: July 2026
The data controller for personal data is SealTrust SAS, whose registration is in progress and whose registered office is in Lyon, France. Until that registration is complete the company has no legal personality: the processing is carried out by its founder, Nordine Bouchelia, acting in the name and on behalf of the company being formed, which will take it over once registered. As the data controller, SealTrust determines the purposes and means of personal data processing implemented in connection with the Service.
As part of providing the Service, SealTrust collects the following categories of personal data: identification data (last name, first name, email address, phone number); connection data (IP address, connection logs, browser type, operating system); transaction data (product verification history, ownership transfers, blockchain operations); location data (approximate location during NFC scans); professional data (company name, position, industry for partner accounts); newsletter data (the email address of prospects who subscribe to our newsletter without a SealTrust account); theft-declaration data, where the User reports a product as stolen (a police-report or complaint number and the supporting documents attached, i.e. data relating to criminal offences, processed solely to manage the theft report and prevent fraud). Data is collected directly from the User or generated through the use of the Service. We also record an approximate location of each scan: if you allow location access, the coordinates sent by your browser are rounded to about 1.1 km on receipt, before anything is stored, so no precise position is kept; otherwise, only an approximate city and country are derived from your IP address using a local database queried offline on our servers. Neither your coordinates nor your IP address are sent to any third-party geolocation service.
Personal data processing by SealTrust is based on the following legal grounds: performance of the contract (Article 6.1.b GDPR) for processing necessary for the provision of the Service, including account creation, product authentication, and ownership transfer; User consent (Article 6.1.a GDPR) for processing related to non-essential cookies and marketing communications; SealTrust's legitimate interest (Article 6.1.f GDPR) for processing related to Service security, anti-counterfeiting, fraud detection, the approximate location of scans, and Service improvement; compliance with a legal obligation (Article 6.1.c GDPR) for the retention of connection and billing data. The approximate location of scans rests on legitimate interest in fighting counterfeiting, not on consent: coordinates are rounded to about 1.1 km on receipt, city and country are derived from a local database queried offline without being sent to a third party, sharing the position remains optional, and the User has the right to object under Article 21 GDPR.
Personal data is retained only for as long as strictly necessary for the purposes for which it is processed. Account data is retained for the duration of the contractual relationship. Past three years with no activity at all, the account is listed in a report a person reviews, and that person decides what happens to it: nothing is anonymised automatically. Deleting the account immediately anonymises personal data, with no grace period: first name, last name, e-mail address, phone number and sign-in credentials are removed for good. The records that have to survive are kept with no link to your identity: the custodial wallet, held so the assets it carries are not orphaned, and the lifecycle events, which stay attached to the product. Newsletter email addresses (prospects without an account) are kept until the User unsubscribes, then anonymized within 90 days. Security and audit logs are retained for 24 months. Blockchain transaction data is retained indefinitely due to the immutable nature of the blockchain, but associated personal data (off-chain) is deleted according to the stated timeframes. Billing data is retained for 10 years in accordance with accounting obligations. Cookies have a maximum lifespan of 13 months. Scan coordinates are rounded to about 1.1 km on receipt, then to about 11 km after 90 days. Labeled features used to train fraud detection are deleted after 24 months.
In accordance with the GDPR and French data protection legislation, the User has the following rights: right of access (Article 15 GDPR): to obtain confirmation that their data is being processed and to receive a copy; right to rectification (Article 16 GDPR): to request the correction of inaccurate or incomplete data; right to erasure (Article 17 GDPR): to request the deletion of their data in cases provided by regulation; right to restriction of processing (Article 18 GDPR): to request the suspension of data processing; right to data portability (Article 20 GDPR): to receive their data in a structured, commonly used format; right to object (Article 21 GDPR): to object to the processing of their data on legitimate grounds; right to withdraw consent at any time when processing is based on consent. To exercise these rights, the User may write to contact@sealtrust.io. SealTrust undertakes to respond within one month. In case of difficulty, the User may file a complaint with the CNIL (www.cnil.fr).
SealTrust implements appropriate technical and organizational measures to ensure the security and confidentiality of personal data, and in particular to protect it against unauthorized access, loss, alteration, or disclosure. These measures include: encryption of data in transit (TLS 1.2 or higher) and encryption at rest of the most sensitive secrets and cryptographic keys (wallet keys, integration credentials, signing keys held in a key management service, daily database backups encrypted with AES-256 before upload); multi-factor authentication for administrator accounts; cryptographic key management via enterprise-grade key management services; regular automated security audits (dependency and container image scanning in continuous integration, secret detection); data access restriction based on the principle of least privilege; logging and monitoring of system access. SealTrust commits to notifying the CNIL and affected individuals in the event of a data breach within 72 hours of discovery, in accordance with Article 33 of the GDPR.<br/><br/>Recipients and subprocessors: personal data is accessible only to authorized SealTrust personnel and to the technical subprocessors strictly required to operate the Service: AWS KMS (cryptographic key management, EU); Hostinger (application hosting, EU); Scaleway (media and backups, France); Pinata (IPFS metadata, US); Firebase / Google (push notifications, US); Firebase Crashlytics / Google (mobile crash reporting, US); Sentry (API error monitoring); Stripe (billing and payments, US); Resend (transactional email, US); Alchemy and Infura (blockchain RPC, US); Amazon Web Services (Amazon Route 53, DNS resolution, US/EU); hCaptcha (anti-bot on forms, US). No geolocation subprocessor is involved: the city and country attached to a scan are determined on SealTrust's own servers from a local database queried offline, without sending the IP address or the coordinates to a third party. Some of these subprocessors are located outside the European Union (United States); such transfers are framed by the European Commission's Standard Contractual Clauses (Article 46 GDPR). SealTrust does not sell personal data to third parties.
The SealTrust website uses cookies and similar technologies. Strictly necessary cookies (authentication, language preferences, security) are placed without prior consent as they are essential for the Service to function. Audience measurement is cookieless and falls under the exemption provided by the CNIL for audience measurement limited to the publisher of the site alone: the consent banner does not govern it. No third-party audience measurement cookie is active to date; should SealTrust deploy one, it would be placed only with the User's prior consent via the consent banner. SealTrust does not use advertising cookies or trackers for commercial profiling purposes. The User may change their cookie preferences at any time through the website settings. Removing necessary cookies may affect the functioning of the Service.
For any questions regarding the protection of your personal data or to exercise your rights, you may write to us: by email at contact@sealtrust.io; by post to SealTrust SAS, Lyon, France. SealTrust has not designated a data protection officer, the conditions of Article 37 GDPR not being met at this time. We undertake to acknowledge receipt of your request within 48 hours and to respond within a maximum of one month. This period may be extended by two additional months for complex requests, in which case you will be informed.