Trust at Dataseka
Dataseka helps businesses connect, analyse and share important data. Protecting that data is fundamental to how we design, operate and support the platform.
This page explains how Dataseka approaches security, privacy, AI processing and infrastructure across Dataseka Cloud and customer-managed deployments.
Security overview
Dataseka applies layered safeguards across the application, infrastructure and operational processes used to provide the platform.
These safeguards include:
- Encryption in transit
- Encryption at rest where supported by the underlying service
- Role-based access controls
- Workspace and customer-data separation
- Controlled administrative access
- Secure credential and secrets management
- Logging and monitoring
- Backup and recovery processes
- Software updates and vulnerability management
The safeguards that apply may differ depending on whether Dataseka is deployed on shared Dataseka Cloud, dedicated Dataseka-managed infrastructure or infrastructure controlled by the customer.
Dataseka only publishes security controls that are implemented and maintained. Additional security information may be made available to customers during procurement or due diligence.
Data protection
Customers retain ownership of the data they submit to Dataseka.
Dataseka processes Customer Data only to:
- Provide and support the platform
- Execute customer instructions
- Secure and maintain the service
- Diagnose technical problems
- Meet applicable legal obligations
Dataseka does not sell Customer Data.
Dataseka does not use identifiable Customer Data, prompts or AI outputs to train general-purpose AI models unless the customer has given separate, explicit permission.
Access by Dataseka personnel is limited to authorised individuals who require access for support, security, maintenance or legal purposes.
For more information, see the Privacy Notice.
Identity and access
Dataseka supports controls intended to help customers manage access to their information.
Depending on the subscription and deployment, these may include:
- Unique user accounts
- Role-based permissions
- Creator and viewer access levels
- Administrator-controlled access
- Multifactor authentication
- Single sign-on
- Audit and activity records
- Access revocation
Customers are responsible for managing their users, permissions, connected data sources and authentication credentials.
AI
Seeka uses AI to help customers query data, create charts, configure datasets and build dashboards.
When Seeka performs a task, relevant instructions, schema information, business context and limited data may be sent to the configured AI service. The information sent depends on the task and deployment configuration.
Dataseka applies controls around AI processing, including:
- Permission-aware access to customer information
- Limiting context to information relevant to the task
- Tool and query execution controls
- Logging of task activity
- Validation and retry processes
- Administrator-configured spending and usage controls
AI outputs may contain errors or require interpretation. Customers should review important outputs before relying on them for financial, legal, regulatory, employment, medical or other high-impact decisions.
Where supported, Enterprise customers may use an AI provider account controlled by their organisation. In those cases, the customer is responsible for its provider agreement, configuration, retention settings and usage charges.
Google Cloud’s treatment of prompts, outputs and retained data depends on the specific service and configuration selected. Dataseka configures its services according to its documented production requirements and does not claim zero retention unless the relevant configuration has been verified.
Deployment
Dataseka supports several deployment models.
Shared Dataseka Cloud
Starter and Premium workspaces may operate on shared Google Cloud infrastructure with logical separation between customer environments.
Dataseka manages the application, infrastructure configuration, updates and standard operational controls.
Dataseka-managed dedicated hosting
Eligible customers may purchase a dedicated environment operated by Dataseka on Google Cloud.
Dedicated hosting provides increased infrastructure isolation but may still rely on shared Google Cloud services and authorised Google service providers.
Customer-managed private cloud
Enterprise customers may deploy Dataseka into a cloud account controlled by their organisation.
The customer is responsible for its cloud account, infrastructure costs, networking, capacity, backups and provider configuration unless otherwise agreed.
Dataseka remains responsible for the Dataseka software and the support obligations stated in the applicable agreement.
Customer-managed on-premises
Dataseka may also be deployed on infrastructure controlled by the customer.
The customer is responsible for the security, availability and maintenance of its infrastructure, operating environment and network. Dataseka’s responsibilities are limited to the software and services defined in the applicable Order or statement of work.
Infrastructure and service provider
Dataseka uses Google Cloud Platform to provide cloud infrastructure and AI capabilities.
Google Cloud may provide:
- Compute
- Storage
- Databases
- Networking
- Authentication infrastructure
- Monitoring and logging
- Backup services
- Gemini and other AI services
Google Cloud operates under its own contractual, privacy and security commitments.
Google Cloud’s certifications, audit reports and compliance programmes apply to Google’s audited services. They do not mean that Dataseka itself holds the same certification or attestation.
Subprocessors
A subprocessor is a third party appointed by Dataseka to process Personal Information or Customer Data in connection with the service.
Dataseka currently uses the following principal subprocessor:
| Provider | Services and purpose | Processing locations |
|---|---|---|
| Google Cloud | Cloud hosting, storage, databases, networking, monitoring, authentication and AI processing through supported Google Cloud services | Google Cloud regions selected by Dataseka or the customer, together with authorised support and service locations |
The exact Google contracting entity depends on Dataseka’s applicable Google Cloud agreement.
Google Cloud maintains its own list of companies and affiliates that support Google Cloud services:
https://cloud.google.com/terms/subprocessors
Google’s list may include:
- Google affiliates
- Data-centre operators
- Technical support providers
- Service and infrastructure providers
Dataseka will update this section before appointing another material subprocessor to process Customer Data.
Where required by an applicable agreement or Data Processing Addendum, Dataseka will provide customers with notice of material subprocessor changes and an opportunity to raise legitimate data-protection objections.
International data transfers
Google Cloud and its authorised providers may process data in countries outside the customer’s country or selected hosting region.
Where required, Dataseka uses appropriate legal safeguards for international transfers, which may include:
- Contractual protections
- The European Commission’s Standard Contractual Clauses
- The UK International Data Transfer Addendum
- Safeguards required by section 72 of POPIA
- Other recognised transfer mechanisms
A customer’s selected deployment region does not necessarily mean that all support, security or maintenance processing occurs only within that region.
Further details are provided in Dataseka’s Privacy Notice and Data Processing Addendum.
Security incidents
Dataseka maintains procedures for identifying, investigating and responding to suspected security incidents.
Where Dataseka confirms an incident affecting Customer Data, it will notify affected customers in accordance with applicable law, Dataseka’s processing role, the customer’s agreement and the applicable Data Processing Addendum.
Notification timing and content may depend on the nature of the incident and the information available during the investigation.
Business continuity
Dataseka uses backup, recovery and service-monitoring processes appropriate to the selected deployment.
Recovery commitments, service levels and customer responsibilities may differ across shared cloud, dedicated hosting, private cloud and on-premises deployments.
Contractual recovery objectives or availability commitments apply only where expressly included in an Order, Service Level Agreement or other written agreement.
Report security
Security researchers and customers may report suspected vulnerabilities to:
Reports should include:
- A description of the suspected vulnerability
- The affected page, endpoint or service
- Steps required to reproduce it
- Potential impact
- Relevant screenshots or technical evidence
- The reporter’s contact details
Do not:
- Access or modify information belonging to another customer
- Exfiltrate Personal Information or Customer Data
- Perform denial-of-service testing
- Use automated testing that materially affects the service
- Attempt social engineering
- Publicly disclose an issue before Dataseka has had a reasonable opportunity to investigate
Dataseka will review good-faith reports and may contact the reporter for further information.
Legal and privacy documents
- Terms of Service
- Privacy Notice
- PAIA Manual
- Data Processing Addendum — available on request
- Cookie information
For privacy or data-protection enquiries, contact: