Charming Seal

Charming Seal·DPA

A data processing agreement with almost nothing to process.

Charming Seal is software you download and run on your own infrastructure, and it never receives your shop data, your buyers' data, card data or your Stripe keys. This page sets out the position that follows from that, and the terms that would apply if it ever changed.

In effect 26 July 2026Version 1.0

1. Definitions

These carry the meaning they have in the UK and EU General Data Protection Regulation. They are repeated because section 2 depends on the difference between the first two.

ControllerWhoever decides why and how personal data is processed. The one who answers to the data subject and to the regulator.
ProcessorWhoever processes personal data on a controller's behalf, on that controller's instructions, and for no purpose of their own.
Personal dataAny information relating to an identified or identifiable living person.
Sub-processorA processor engaged by a processor to carry out part of the work.
Data subjectThe person the personal data is about. In a shop, usually the buyer.

2. For a self-hosted deployment, this project is not your processor

Charming Seal is not a processor of your data, because your data never reaches it. The software runs on infrastructure you chose, against a database you own, with your own payment keys inside it. There is no telemetry, no phone-home and no console on this side. Nothing about a buyer, an order, a card or a shop travels to this project, so there is nothing here to instruct, secure, disclose, export or delete.

You are the controller of everything inside your deployment. Your own vendors are your processors: your host, your database provider, Stripe, PayPal, your email sender, and anyone else you connect. Each of them publishes a DPA, and you need your own agreement with each. Those documents, not this one, are what a privacy assessment of your shop actually turns on.

A DPA with this project would not cover any of that data, and signing one would not make your buyers safer. It would only record an obligation nobody is in a position to perform.

3. The processing that does occur

One flow of personal data exists, and it belongs to this website rather than to any deployment: the request logs produced by serving these pages, the font requests your browser makes to Google, and email sent to the contact address. For that data Charming Seal is the controller and nobody's processor. It is not processed on your behalf, on your instructions, or for your purposes, so no controller-to-processor relationship arises from reading this site.

What is collected, why, for how long and by which vendors is set out in the privacy notice and the sub-processor list.

4. Terms that would apply if the project ever processed data for you

Should that ever happen, whether through a service the project comes to operate or an arrangement agreed in writing, the following terms apply to that processing from the day it starts, without a separate signature. They are written down now so the document is usable rather than merely correct.

Instructions

Personal data is processed only on the controller's documented instructions, including on transfers, unless a law requires otherwise, in which case the controller is told before processing unless that law forbids it. The processor takes no purpose of its own, and never sells the data.

Confidentiality

Access is limited to people who need it to do the work, each bound by a duty of confidentiality that survives the engagement.

Security

Measures appropriate to the risk: encryption in transit and at rest, access control with least privilege, separation of environments, logging, backups that are tested, and prompt patching. Any specific measures agreed with a controller are recorded with that agreement.

Sub-processors

General authorisation to appoint sub-processors, each bound by terms no weaker than these, with the current list published and notice of an addition given in advance so the controller has a chance to object. The processor stays liable for its sub-processors' acts.

Assistance

Reasonable help with data subject requests, and with data protection impact assessments and prior consultations, taking into account the nature of the processing and the information available.

Breach notification

Notice to the controller without undue delay after becoming aware of a personal data breach, with what is known at the time and updates as more is learned, so the controller can meet its own deadlines.

Deletion or return

On termination, and at the controller's choice, personal data is deleted or returned, together with existing copies, unless a law requires it to be kept.

Audit

Information made available to demonstrate compliance, and audits or inspections by the controller or an auditor it appoints, on reasonable notice and without disturbing other controllers' data.

5. Transfers and the standard contractual clauses

This project and the vendors that run this website are in the United States. Where personal data of people in the United Kingdom or the European Economic Area is transferred there by the website, it is done under the safeguards those vendors provide, which include the standard contractual clauses and the UK addendum to them. The vendors are named on the sub-processor page. Any processing under section 4 would rely on the same clauses and addendum, and where they apply they take precedence over anything inconsistent on this page.

6. Duration and precedence

Section 2 and section 3 describe the position today and last for as long as it holds. Section 4 applies for as long as any processing on a controller's behalf continues, and its confidentiality, deletion and audit terms outlast it. Where this document and the terms of use disagree about personal data, this one governs. Nothing here changes the MIT licence, which contains no data protection terms and grants no rights over anyone's data.

7. If your procurement process wants a countersigned DPA

Write to hello@charmingseal.com and say what your assessment actually needs. Three honest things first.

For a self-hosted deployment there is usually nothing for a DPA between us to cover, and a reviewer who understands that will accept a link to this page. The vendors that do process your buyers' data all publish DPAs, and those are the ones your file is missing. And a free project maintained by one person may not be able to review, negotiate, sign and stand behind a bespoke agreement, or accept the liabilities drafted into it. Where a countersignature is genuinely required, the answer may be no, and it is better to hear that early than after a procurement cycle.

8. Questions

Write to hello@charmingseal.com, the single address for every enquiry. The companion documents are the privacy notice, the sub-processor list, the terms of use and the acceptable use policy.