Legal
Privacy notice
Last updated 20 August 2026
This notice explains how [Legal entity name], trading as Capra ('we'), handles personal data when you visit this website and when your business uses the Capra CRM.
Who we are
Controller: [Legal entity name], [registered address], company number [number]. Data protection contact: [privacy@yourdomain.com].
When your business uses Capra to hold records about its own customers, your business is the controller of that data and we act as its processor. Our processing commitments in that role are set out in the data processing addendum.
What we collect
- Account data: name, work email, orbit (account) name, role, and authentication metadata such as sign-in timestamps.
- Content you enter: companies, people, deals, documents, tickets, tasks, notes, inventory records, and any files you upload.
- Mailbox content: when you connect a mailbox over your own SMTP/IMAP credentials, message headers and bodies needed to thread replies onto tickets.
- Operational logs: request metadata, error traces, background job outcomes, API key usage, and webhook delivery results.
- Website enquiries: the name, email and message you submit through the contact form.
Why we process it and on what basis
- To provide the service you asked for — performance of a contract.
- To keep the service secure, detect abuse and investigate incidents — legitimate interests.
- To meter usage against plan limits and to bill — performance of a contract and legal obligation.
- To respond to enquiries you send us — legitimate interests, or consent where you opted in.
AI processing
Capra's AI features are designed so that reasoning happens on infrastructure the customer controls, using open-weight models. AI features can be switched off per orbit and per feature by an administrator. We do not train foundation models, and we do not use your records to train models for other customers.
Where a deployment is configured to call an external inference endpoint, that endpoint is listed in our sub-processor list and the administrator of the orbit can disable those features entirely.
Retention
Orbit administrators set their own retention windows for activity history, email messages and audit logs inside the product. Where no window is set, we keep records for the life of the account and delete them within 30 days of account closure, except where we must retain billing records to meet legal obligations.
Your rights
You may request access, correction, erasure, restriction, portability, or object to processing. Capra includes a built-in erasure workflow: an administrator can raise an erasure request against a person record, and the product removes or anonymises the associated records and logs the action in the audit trail.
To exercise a right against us as controller, write to [privacy@yourdomain.com]. If your data sits in a customer's orbit, contact that business — we will forward requests we receive to them.
You may also complain to your supervisory authority; in the UK that is the Information Commissioner's Office.
International transfers
Hosting region for this deployment: [region]. Where a sub-processor operates outside your region, transfers rely on the UK/EU standard contractual clauses or an adequacy decision.
Changes
We will post material changes on this page and, for changes that affect how we process customer data, notify orbit administrators by email at least 30 days before they take effect.
