Legal
Data processing addendum
Last updated 20 August 2026
This addendum applies whenever [Legal entity name] processes personal data on behalf of a customer using Capra. It forms part of the terms of service.
Roles
The customer is the controller. We are the processor and act only on the customer's documented instructions, which include the customer's use of product features.
Subject matter and duration
- Subject matter: provision of the Capra CRM, including AI features the customer chooses to enable.
- Duration: for the term of the subscription plus the deletion window described below.
- Categories of data subjects: the customer's operators, its business contacts, and senders of email into connected mailboxes.
- Types of personal data: names, business contact details, job roles, correspondence content, activity history, and any data the customer chooses to store in custom fields.
Security measures
- Encryption in transit for all service traffic, and encryption at rest for stored data.
- Mailbox credentials are encrypted with a dedicated key that is separate from the application database.
- Row-level access rules isolate each orbit; operators only reach data in orbits they are an active member of.
- Role-based permissions, per-key API scopes with rate limits, and an append-only audit trail of privileged actions.
- Least-privilege internal access; staff access to customer orbits is limited to named internal roles and is logged.
- Optional multi-factor authentication enforcement and session controls per orbit.
These are the technical controls the product implements today. We make no certification claim in this document; any certification or audit report we hold will be named explicitly on request.
Sub-processors
We use the sub-processors listed on the sub-processor page. We will give at least 30 days' notice before adding one, and the customer may object on reasonable data-protection grounds.
Personnel and confidentiality
Everyone with access is bound by confidentiality obligations and receives access only where needed for their role.
Assisting the controller
The product includes self-service tooling for data subject requests: export, correction, and an erasure workflow that removes or anonymises a person's records and writes the outcome to the audit trail. Where a request cannot be met with product tooling, we will assist within [10] working days.
Breach notification
We will notify affected customers without undue delay and in any event within 72 hours of becoming aware of a personal data breach, with the facts known at the time, the likely consequences, and the measures taken.
Audit
On reasonable written notice and no more than once a year, we will provide the information needed to demonstrate compliance with this addendum, subject to confidentiality.
Deletion and return
On termination the customer may export its data from the product for 30 days. After that we delete customer data from active systems, and from backups within [35] days, unless retention is required by law.
International transfers
Where personal data is transferred outside the customer's region, the transfer relies on the UK/EU standard contractual clauses or an adequacy decision, together with the measures described above.
