Legal
Data Processing Addendum
Last updated June 1, 2026.
This Data Processing Addendum ("DPA") forms part of the agreement between Sema and customers ("Controller"/"Data Fiduciary") who use Sema to process personal data, and reflects the parties' obligations under the DPDP Act, 2023 and, where applicable, the GDPR.
1. Roles
- For personal data processed on the Controller's behalf, the Controller is the data controller / Data Fiduciary and Sema is the data processor / Data Processor.
- Sema processes personal data only on documented instructions from the Controller, including with regard to international transfers.
2. Processing scope
- Subject matter: provision of the Sema semantic-layer service. Duration: the term of the agreement.
- Nature and purpose: hosting, querying, glossary generation, and governance over Controller data sources.
- Categories of data subjects and data are determined by the Controller's connected sources.
3. Sema's obligations
- Process personal data only on documented instructions; ensure personnel are bound by confidentiality; implement appropriate technical and organisational security measures.
- Assist the Controller, taking into account the nature of processing, in responding to data-subject / Data Principal requests and in meeting security, breach-notification, and impact-assessment obligations.
4. Subprocessors
- The Controller authorises Sema to engage the subprocessors listed on our Subprocessors page. Sema imposes data-protection obligations on each and remains responsible for their performance, and will give notice of intended changes.
5. Breach notification
- Sema notifies the Controller without undue delay after becoming aware of a personal-data breach affecting Controller personal data, with information reasonably available to assist the Controller's own notification obligations.
6. International transfers
- Where personal data is transferred across borders, the parties rely on lawful transfer mechanisms, including standard contractual clauses where required.
7. Audits
- Sema makes available information necessary to demonstrate compliance and allows for and contributes to reasonable audits, subject to confidentiality and security constraints.
8. Return & deletion
- On termination, Sema deletes or returns personal data in accordance with the agreement, except where retention is required by law.
9. Contact
- To execute a signed DPA, email privacy@semalayer.com.

