Capacity
Platform How it works
TicketingSell under your own name For nightclubsBuilt around how the week runs
Integrations Book a demo
Sign in Book a demo

Acceptable Use Policy

Version 1.0 Effective 25 August 2026

This policy governs all messages sent through Capacity. It forms part of the Terms of Service, and breach of it is a breach of that agreement.

1. Roles

The Customer is the sender and instigator of every message sent from its account, and the controller of its contact data. Capacity provides the platform and delivery route as processor, under the Data Processing Agreement.

Responsibility for lawful basis, message content and recipient selection rests with the Customer. Nothing in this policy or in the use of the platform transfers that responsibility to Capacity or constitutes a representation that the Customer's marketing is compliant.

2. Warranties

By adding a contact or including one in a send, the Customer warrants that:

  • it has a lawful basis under the UK GDPR for the processing, and a valid basis under the Privacy and Electronic Communications Regulations 2003 for marketing to that person on the channel used;
  • it holds evidence of that basis for each contact individually, recording the date, the source, the information given at the time and the permission granted;
  • the contact has not opted out and does not appear on a suppression list held by the Customer;
  • it has provided the privacy information required by Article 13 or 14 of the UK GDPR.

Capacity may require production of that evidence, and the Customer must provide it promptly.

3. Consent and the soft opt-in

Consent must be specific, informed, unambiguous and given by affirmative action. Pre-ticked boxes, consent bundled with acceptance of other terms, and consent to contact by unidentified third parties are not valid. Consent to one channel does not extend to another.

The soft opt-in under regulation 22(3) applies only where all of the following are satisfied:

  • the contact details were obtained from the recipient in the course of a sale or negotiations for a sale of the Customer's own product or service;
  • the marketing relates to the Customer's own similar products or services;
  • a simple means of refusing the marketing, free of charge, was given at the time the details were collected;
  • that means of refusal is given in every subsequent message.

Where any condition is not satisfied, consent is required.

4. Prohibited sources

The Customer must not upload or send to contacts that were:

  • purchased, rented, leased or exchanged;
  • scraped or harvested from any source;
  • obtained by co-registration or lead generation where permission was given to a class of third parties rather than to the Customer by name;
  • appended or enriched from a third-party source;
  • acquired with a business or venue, unless the Customer has verified and can evidence a valid basis for its own marketing to those contacts;
  • generated by pattern or sequence.

5. Message requirements

Every marketing message must identify the sender, must not disguise or conceal the sender's identity, must not use misleading headers or subject lines, and must contain a valid, free and simple means of opting out. Opt-outs must be actioned promptly and must not be reset by subsequent imports.

6. Prohibited content

The Customer must not send content that is unlawful, fraudulent, defamatory, harassing, obscene or that incites violence or hatred; that infringes third-party rights; that constitutes phishing or contains or links to malware; or that markets age-restricted products, including alcohol, to recipients whose age has not been established.

The platform must not be used to evade filtering, to relay another party's sending, or to send on behalf of any business other than those on the Customer's account.

7. Channel rules

Email must be sent from a domain controlled by the Customer with SPF, DKIM and DMARC records in place. Capacity may refuse to send from an unauthenticated domain.

SMS must use a sender identity registered to the Customer. Opt-out keywords must function without charge to the recipient beyond a standard message rate. Rotating sender identities or numbers to distribute volume or avoid filtering is prohibited.

WhatsApp requires channel-specific opt-in identifying the Customer by name. Marketing outside an open conversation must use approved templates. Opt-outs and blocks must be actioned immediately.

8. Provider policies

Messages are delivered through third-party providers listed on the sub-processor page. The Customer must comply with those providers' policies, which are incorporated by reference, in particular the Twilio Acceptable Use Policy and Messaging Policy and the WhatsApp Business Messaging Policy. Where a provider or network requires suspension of a send or disclosure of information, Capacity will comply and will notify the Customer unless prohibited from doing so.

The Customer is liable for any fine, charge or penalty passed through to Capacity by a provider, network or aggregator as a result of the Customer's sending.

9. Suspension

Capacity may pause or stop a send, and may suspend sending on an account, immediately and without prior notice, where:

  • bounce, complaint or unsubscribe rates exceed the thresholds set by the relevant provider or network, or otherwise threaten delivery for other customers;
  • Capacity reasonably believes a list was obtained in breach of section 4;
  • evidence of lawful basis is not produced on request;
  • content breaches section 6;
  • a provider, network, mailbox operator or regulator requires it;
  • this policy or the Terms of Service is otherwise breached.

Notice is not given in advance because the resulting damage to delivery is immediate and affects all customers on the platform. Capacity will notify the Customer as soon as reasonably practicable, state the cause, and specify what is required to lift the suspension. Repeated or deliberate breach, and any breach involving purchased or scraped data, may result in termination under the Terms of Service.

10. Reporting

Suspected breaches may be reported to legal@getcapacity.co, with the message and, where available, its headers or sender number.

Recipients enquiring about their personal data should contact the venue that sent the message, which is the controller of that data. Where the venue cannot be reached, Capacity will assist in identifying it.

11. Amendment

This policy may be amended, including to reflect changes in provider requirements or in law. Where an amendment materially increases the Customer's obligations, reasonable notice will be given before it takes effect, except where immediate effect is required by law or by a provider. Superseded versions remain published.

Capacity

Ticketing, bookings and marketing for venues. Sell under your own brand, own the customer, and bring them back.

Product

Platform Integrations How it works

Company

Agency Security Careers Contact FAQ

Get started

Book a demo Sign in

Legal

Terms Privacy DPA Acceptable use Cookies
© Capacity Digital Ltd 2026 · Company No. 14487697 Cookie settings 167-169 Great Portland Street, London W1W 5PF