Legal

Data Processing Addendum

Last updated June 1, 2026.

This Data Processing Addendum ("DPA") forms part of the agreement between Sema and customers ("Controller"/"Data Fiduciary") who use Sema to process personal data, and reflects the parties' obligations under the DPDP Act, 2023 and, where applicable, the GDPR.

1. Roles

  • For personal data processed on the Controller's behalf, the Controller is the data controller / Data Fiduciary and Sema is the data processor / Data Processor.
  • Sema processes personal data only on documented instructions from the Controller, including with regard to international transfers.

2. Processing scope

  • Subject matter: provision of the Sema semantic-layer service. Duration: the term of the agreement.
  • Nature and purpose: hosting, querying, glossary generation, and governance over Controller data sources.
  • Categories of data subjects and data are determined by the Controller's connected sources.

3. Sema's obligations

  • Process personal data only on documented instructions; ensure personnel are bound by confidentiality; implement appropriate technical and organisational security measures.
  • Assist the Controller, taking into account the nature of processing, in responding to data-subject / Data Principal requests and in meeting security, breach-notification, and impact-assessment obligations.

4. Subprocessors

  • The Controller authorises Sema to engage the subprocessors listed on our Subprocessors page. Sema imposes data-protection obligations on each and remains responsible for their performance, and will give notice of intended changes.

5. Breach notification

  • Sema notifies the Controller without undue delay after becoming aware of a personal-data breach affecting Controller personal data, with information reasonably available to assist the Controller's own notification obligations.

6. International transfers

  • Where personal data is transferred across borders, the parties rely on lawful transfer mechanisms, including standard contractual clauses where required.

7. Audits

  • Sema makes available information necessary to demonstrate compliance and allows for and contributes to reasonable audits, subject to confidentiality and security constraints.

8. Return & deletion

  • On termination, Sema deletes or returns personal data in accordance with the agreement, except where retention is required by law.

9. Contact

  • To execute a signed DPA, email privacy@semalayer.com.