SealTrustSealTrustSealTrust
Home
How it worksVerifyDemo
Sign inSign up
SealTrust
HomeHow it worksVerifyDemo

Product

Digital Product PassportFeaturesPricingSolutionsRegulation radarUse casesIntegrations

Company

AboutCareersPressContact

Resources

BlogDocumentationAPI DocsDevelopersSecurityTrust CenterAll resources
Sign inCreate an account

© 2026 SealTrust

SealTrust

Product authentication through NFC and blockchain. Protect your brand against counterfeiting.

Product

  • How it works
  • Features
  • Pricing
  • Solutions
  • Regulation radar
  • Use cases
  • Integrations
  • Documentation

Company

  • About
  • Contact
  • Careers
  • Press

Legal

  • Terms of Use
  • Terms of Sale
  • Privacy Policy
  • Legal notices
  • GDPR
  • Cookie Policy
  • Return & warranty

Resources

  • All resources
  • Technical documentation
  • Blog
  • Digital Product Passport
  • DPP 2027 Guide
  • Developers
  • Verification badge
  • Security
  • Trust Center
  • API Docs
  • Help
  • Support

EN 18219 · EN 18220 · ESPR-ready · GDPR

© 2026 SealTrust. All rights reserved.

Follow us on LinkedInMade with trust in France
Legal

Privacy Policy

Version 1.1, 7 August 2026

Document prepared in good faith in accordance with the GDPR (Regulation (EU) 2016/679) and the French Data Protection Act, aligned with the actual behaviour of the product. It will be reviewed by legal counsel upon incorporation of the company.

01

Data controller

The data controller is Nordine Bouchelia, a natural person acting on behalf of SealTrust SAS, a simplified joint-stock company being formed, not yet registered and therefore without legal personality to date. Based in Lyon, France. The company will take over the controller role once it is registered.

For certain processing carried out on behalf of Brand clients (for example a Brand's end-customer data), SealTrust acts as a processor within the meaning of Article 28 GDPR, governed by a Data Processing Agreement (DPA).

02

Data protection contact

For any question or to exercise your rights: contact@sealtrust.io, or by post to SealTrust SAS, Lyon, France. We acknowledge receipt within 48 hours and respond within a maximum of one month, extendable by two months for complex requests (Article 12 GDPR).

SealTrust has not designated a data protection officer: the conditions of Article 37 GDPR are not met at this time. This analysis is reviewed at least once a year.

03

Data collected

  • Account data: email, password (Argon2id hashed), first name, last name, phone (optional), country, language.
  • Custodial wallet: blockchain wallet address (custodial); private keys are encrypted and stored server-side.
  • NFC / QR verification: chip fingerprint (uid_hash), step and status, anti-replay counter (ctr), approximate scan coordinates, city, country, IP address, User-Agent.
  • Scan location: if you allow geolocation, the coordinates sent by your browser are rounded to 2 decimal places (about 1.1 km) as soon as they are received, before anything is stored: no precise position is kept. Otherwise, only an approximate city and country are derived from the IP address using a local database queried offline on our servers. Neither your coordinates nor your IP address are sent to any third-party geolocation service.
  • Push notification token (FCM): only if you enable notifications.
  • Crash reports (Firebase Crashlytics): optional, disabled by default; anonymous per-install identifier, no email.
  • Billing (Brands): via Stripe; card data is not stored by SealTrust.
  • Newsletter: email with double opt-in, timestamp, source, version and consent IP.
  • Theft report: complaint number and supporting documents (data relating to offences, Article 10 GDPR), processed to handle the report and prevent fraud.
  • Biometric data (Face ID / Touch ID): processed locally on the device, never transmitted to our servers.
  • Audit and security logs: administration events, IP address, User-Agent.
04

Purposes

  • Creation and management of the account.
  • NFC / QR authentication service and Digital Product Passport (DPP).
  • Fraud and clone detection (trust scoring, anti-replay, geo-consistency).
  • Customer support.
  • Billing and payments (Brands).
  • Improvement and security of the Service.
  • Marketing communication, only with your explicit consent.
05

Legal bases (Article 6 GDPR)

  • Performance of the contract (Art. 6.1.b): account, authentication, ownership transfer, billing.
  • Consent (Art. 6.1.a): marketing, non-essential cookies, crash reports.
  • Legitimate interest (Art. 6.1.f): security, anti-counterfeiting, fraud detection, approximate scan location, improvement of the Service.
  • Legal obligation (Art. 6.1.c): accounting and tax retention of billing data.

Scan location: why legitimate interest. The location of a scan is used to spot the inconsistencies that reveal a cloned chip, for example the same product verified in two distant places within an impossibly short time. This processing rests on the legitimate interest of SealTrust and of the Brands in fighting counterfeiting, not on your consent. It is proportionate because the data is reduced before it is stored.

  • Coordinates are rounded to about 1.1 km as soon as they are received: no precise position exists in our systems.
  • City and country are derived locally, without sending your IP address or your coordinates to any third party.
  • Sharing your position through the browser remains optional: declining does not prevent you from verifying a product, it only removes one of the authenticity signals.
  • You retain the right to object under Article 21 GDPR, exercisable at contact@sealtrust.io.

Theft report data (Article 10 GDPR) is processed on the basis of the legitimate interest in preventing fraud, with access restricted to authorised staff and retention limited to handling the report.

06

Retention periods

  • Account data: duration of the contractual relationship. On account deletion, anonymised without delay. If you do not delete your account, nothing is erased automatically: after 3 years without activity it appears in a report reviewed by a person, except for specific periods below.
  • IP addresses: pseudonymised as soon as they are stored on the public verification routes; scheduled anonymisation after 30 days in NFC and audit logs.
  • User-Agent: erased after 30 days.
  • Scan coordinates: rounded to about 1.1 km (2 decimal places) on receipt, therefore never stored precisely; then rounded to about 11 km (1 decimal place) after 90 days.
  • NFC verification logs: deleted after 365 days.
  • Unlabelled ML features: deleted after 365 days.
  • Labelled ML features (fraud-detection training data): deleted after 24 months.
  • Audit and security logs: 730 days (24 months).
  • Partner API key usage logs: deleted after 365 days.
  • Newsletter, unsubscribed: email anonymised within 90 days.
  • Billing: 10 years (accounting obligations, Article L.123-22 of the Commercial Code; Article 17.3.b GDPR).
  • Cookies: 13 months maximum; your choice is kept for 6 months, after which the banner asks again.
  • Public on-chain data: permanent and non-erasable by design.
07

Recipients and sub-processors

Data is accessible only to authorised SealTrust staff and to the strictly necessary technical sub-processors:

  • AWS KMS (cryptographic keys, eu-west-3, EU)
  • Hostinger (application hosting, EU)
  • Scaleway (media and backups, France)
  • Pinata (IPFS metadata, US)
  • Firebase / Google (push notifications and crash reports, US)
  • Sentry (API error monitoring)
  • Stripe (billing and payments, US)
  • Resend (transactional email, US)
  • Alchemy and Infura (blockchain RPC, US)
  • Amazon Web Services (Amazon Route 53, DNS resolution, US/EU)
  • hCaptcha (anti-bot, US)

No geolocation sub-processor. The city and country attached to a scan are determined on our own servers, from a local geolocation database queried offline. Neither your IP address nor your coordinates are sent to any third-party geolocation or geocoding service.

SealTrust does not sell any personal data to third parties.

08

Transfers outside the European Union

Some sub-processors are located in the United States. These transfers are governed by the European Commission's standard contractual clauses (Article 46 GDPR), supplemented where appropriate by additional safeguards (encryption, minimisation).

Public blockchain: SealTrust uses Base (Layer 2 on Ethereum). Token identifiers, product and metadata fingerprints, ownership and transfers, and batch Merkle roots are public by design and non-erasable. Verification data from a scan is not recorded on-chain. A wallet address may, in some contexts, constitute personal data. SealTrust documents a data protection impact assessment (DPIA) covering the on-chain data and minimisation measures.

09

Security

Technical and organisational measures: TLS 1.2 or higher, Argon2id hashing, signing via AWS KMS, NFC Secure Dynamic Messaging AES-128 (anti-replay, anti-clone), encryption at rest of sensitive credentials (including custodial wallet keys), multi-factor authentication for administration, least-privilege access, logging. In the event of a data breach, SealTrust notifies the CNIL and, where applicable, the data subjects (Articles 33 and 34 GDPR).

10

Your rights

In accordance with the GDPR (Articles 15 to 22) and the Data Protection Act, you have the rights of access, rectification, erasure, restriction, portability and objection, the right to withdraw consent, and the right to give post-mortem directives.

  • Access and portability: export your data via the app (endpoint GET /me/data-export): profile, wallet, products, NFC scan logs, transfers, messages and, for Brands, billing.
  • Erasure: permanently delete your account from the app (Settings, Edit profile, Delete account), with cascading anonymisation. Retained by legal obligation: immutable on-chain data and billing (10 years).
  • Withdrawal of marketing consent: at any time via settings or the unsubscribe link.
  • Other requests: contact@sealtrust.io. Response within 30 days.

You may lodge a complaint with the CNIL (www.cnil.fr).

11

Cookies

The Service uses cookies strictly necessary (CSRF token, language preference, session), placed without consent. Non-essential cookies are placed only with your consent via the banner, reopenable via "Manage cookies" in the footer. No advertising cookies or cross-site tracking. Site audience measurement is carried out without cookies, on our own infrastructure: it is exempt from consent and is therefore not governed by the banner. Details in the Cookie Policy.

12

Conversational assistant

The Service offers a conversational assistant on the public website and in the administration workspace. Its answers are generated by an artificial intelligence, from documentation written and reviewed in house, and may contain errors.

The assistant has no access to any database, any account and any brand data. It therefore cannot look up information about you, whatever the question. It never asks you for personal data and you are advised not to enter any.

The model runs on Amazon Web Services (Bedrock) in the Paris region (eu-west-3). Questions are not passed to any model vendor and are not used for training. No transfer outside the European Union takes place for this call.

  • Conversation content: never retained. Neither your question nor the answer is written to a database or to a log. This is a design property, not a setting.
  • Current conversation thread: kept in your browser tab so it survives a page reload, and cleared when that tab closes. The last six exchanges are sent back with your next question so the assistant can follow up; they are not retained on receipt.
  • Usage counters: volume, tokens, cost, the identifiers of our own documentation pages retrieved, and your rating if you give one. No content, no identifier relating to you.
  • Abuse protection: a truncated cryptographic digest of your IP address, not reversible and deleted within 26 hours.

Legal basis: legitimate interest (Article 6(1)(f)) for the public website assistant, performance of the contract (Article 6(1)(b)) for the assistant and support channel in the administration workspace.

Public website conversations being anonymous and not retained, SealTrust cannot identify a person from a conversation, nor retrieve a past exchange. Access and erasure rights therefore cannot be exercised on that scope, a situation provided for by Article 11 GDPR; the absence of retention addresses it in practice.

13

Amendments to this policy

SealTrust may amend this policy. In the event of a substantial change, data subjects are informed and, where applicable, consent is collected anew (version in force: 2026-07).

Back to home