Legal
Sub-processors
Last updated 20 August 2026
These are the categories of third party that may process customer data when you use Capra. Complete the bracketed fields with the specific provider and region for your deployment before launch.
Current list
| Purpose | What it does | Data | Region |
|---|---|---|---|
| Application and database hosting | Runs the application, stores orbit records, files and audit logs. | All customer content and operational logs | [region] |
| Transactional email delivery | Sends invites, password resets, notification digests and document links. | Recipient name and email address, message content | [region] |
| Customer's own mail servers | Inbox sync and replies use the customer's own SMTP/IMAP credentials — mail never routes through a third-party mailbox provider we choose. | Message headers and bodies for connected mailboxes | Controlled by the customer |
| Inference endpoint (optional) | Only when an orbit is configured to use a hosted endpoint instead of on-premise models. Every AI feature can be switched off per orbit. | The record excerpts included in the prompt for the requested feature | [region] |
Notice of change
We give orbit administrators at least 30 days' notice by email before a new sub-processor starts processing customer data, and customers may object on reasonable data-protection grounds.
Questions about this document? Contact us and we will respond within five working days.
