1. Data Controller
The data controller is:
Eyelo SA Rue du Simplon 37 1006 Lausanne Switzerland UID: CHE-108.174.302 Email: support@sealarca.ch
Eyelo SA operates the Sealarca service available at sealarca.ch.
2. Service Scope
Eyelo SA operates Sealarca, a confidential artificial intelligence service. It may be used primarily through Sealarca Desk, Sealarca Bridge or the Sealarca API. The local, versioned behavior of Desk and Bridge is described on the Application data handling page. Vault routes are service routes that use the protected Vault execution environment. Sealarca does not present its models as specialized in legal, medical, financial, or any other professional field.
3. Data Processed
Eyelo SA processes only the data required to operate, secure, support, and bill for the service. This may include:
- account and identification data;
- payment, billing, and credit data;
- technical and security data, such as IP addresses, timestamps, authentication logs, and technical errors;
- usage data, such as the model called, token count, cost, request status, and duration;
- information voluntarily submitted to support or through the public pre-contractual and compliance request form.
4. Content Submitted to the Service
Content submitted to the service, directly through the API or by means of Desk or Bridge depending on the mode used, is processed inside the protected Vault execution environment to produce the requested response. Sealarca does not log prompt or response content. Vault routes do not use a response cache for that content. Sealarca does not use it for advertising or profiling.
Common safeguards are described in the common Vault standard. Processing countries, any subprocessors, and specific conditions are communicated in the contract and, where applicable, the DPA.
5. Service Infrastructure
Eyelo SA operates the Sealarca service, including accounts, access to the service, billing, support, security, and request orchestration. The resources required for execution are allocated dynamically within a decentralized compute infrastructure, within the scope of the common Vault standard and applicable contractual conditions. Data used for each function is limited to what is necessary to operate the service.
6. Purposes of Processing
Data is processed to:
- create and administer accounts;
- provide, operate, and secure the Sealarca service;
- orchestrate requests and return responses;
- measure usage and debit credits;
- process payments, invoices, support requests, and pre-contractual or compliance requests;
- prevent abuse and maintain service stability;
- comply with applicable legal, accounting, and regulatory obligations.
7. Legal Bases
Depending on the circumstances, processing is based on performance of the contract, Eyelo SA’s legitimate interests in securing and operating the service, consent where required, or compliance with a legal obligation.
8. Cookies
The site uses only cookies required for navigation, authentication, security, and payments. Eyelo SA does not use advertising cookies for commercial targeting.
9. Location and Processing
Eyelo SA is established in Switzerland. Processing countries and applicable specific conditions are communicated in the contract and, where applicable, the DPA.
10. Retention Period
Account, billing, security, support, and pre-contractual or compliance request data is retained for as long as required for its purpose and applicable legal obligations. Accounting records may notably be retained for up to ten years where required by Swiss law.
Sealarca does not log prompt or response content. Vault routes do not use a response cache for that content. Any specific retention condition is communicated in the contract and, where applicable, the DPA.
11. Security
Eyelo SA applies reasonable technical and organizational measures, including access controls, encrypted communications, environment separation, and data minimization. The common Vault standard describes the common safeguards of the protected execution environment. No Internet-connected system can, however, be guaranteed as absolutely secure.
12. Individual Rights
Under the Swiss Federal Act on Data Protection (FADP) and, where applicable, the General Data Protection Regulation (GDPR), individuals may notably request access, rectification, or deletion of their data, as well as restriction of or objection to processing where those rights apply.
Requests may be sent to support@sealarca.ch. Eyelo SA may request proof of identity before processing them.
13. User Responsibility
Users are solely responsible for the data they submit to the Sealarca service, regardless of the access mode used. They must ensure they hold the rights, authorizations, and legal bases required to transmit this data — including any third-party, confidential, or regulated data — and that they comply with their professional, contractual, and regulatory obligations. Users must also verify that the common Vault standard and contractual conditions are appropriate for their use case.
14. Updates, Applicable Law, and Jurisdiction
Eyelo SA may update this policy to reflect changes to the service or applicable law. This policy is governed by Swiss law. In the event of a dispute, the registered office of Eyelo SA is the reference location, subject to any applicable mandatory jurisdiction.
© 2026 Eyelo SA