Privacy Policy
Template — review with a lawyer before you rely on it, and fill in the bracketed values. Set COMPANY_LEGAL_NAME and the contact emails in the environment.
Sealio (“we”) operates Sealio, a service that lets a professional practice (the “practice”) request, collect and verify documents from its own clients. This policy explains what we do with personal information.
Two kinds of user
Practice administrators hold an account with us. Clients of the practice receive a private link and upload documents; they do not hold an account and we act as a processor on the practice’s behalf for that data.
What we collect
- Account data: the administrator’s name, email and hashed password.
- Case data entered by the practice: client names, contact email, case type, and the checklist of requested documents.
- Uploaded documents: the files a client submits (e.g. identification, financial statements). These are encrypted before storage.
- Activity and technical data: a timestamped log of uploads, verification results and reminders; IP address and request metadata for security and rate limiting.
How we use it
- To run the service: route each upload to the right slot, run the automated document check, and send reminders the practice triggers.
- To keep the service secure: authentication, rate limiting, abuse detection, and the audit log.
- We do not sell personal information or use uploaded documents to train models.
Automated document check
When a document is uploaded, its contents are sent once to our AI provider to classify it against the requested list and, for statements, to read the statement month. The result and a confidence score are logged. A practice administrator can override any automated decision.
Subprocessors
We share data with these providers only as needed to run the service:
| Provider | Purpose | Data |
|---|---|---|
| Vercel | Application hosting | Request metadata, logs |
| AWS (RDS + S3) | Database & encrypted file storage | All case data (documents stored as ciphertext) |
| Anthropic | Automated document check | Document contents, at upload time only |
| Resend | Reminder email delivery | Client name, email, list of pending documents |
| Upstash | Rate limiting | Hashed keys derived from IP / link id |
Retention
Case data and documents are kept for the life of the case and then per the practice’s instructions. A practice administrator can permanently delete a case — every client, the checklist, all files and the activity log — from the case’s settings. Backups roll off within [30] days. Self-service demo workspaces and their data are purged automatically after the demo window closes.
Security
Files are encrypted at the application layer (AES-256-GCM per file, key wrapped with RSA-OAEP) before they reach storage, so the storage provider only ever holds ciphertext. Transport is HTTPS only. Access to a client’s files requires an authenticated administrator account that owns that case; the client upload link is upload-only and time limited.
Your rights
Depending on where you live you may have rights to access, correct, export or delete personal information. Clients of a practice should contact that practice first; we will help the practice respond. For account data or unresolved requests, contact us at office@sealio.ca.
Changes
We’ll post material changes here and, for account holders, notify by email.
Contact
Sealio — office@sealio.ca. [Add a postal address if required in your jurisdiction.]