This agreement governs Capacity's processing of personal data on behalf of its customers. It applies automatically to that processing and forms part of the Terms of Service. It is made to satisfy Article 28 of the UK GDPR.
This agreement is between Capacity Digital Ltd, company number 14487697, of 167-169 Great Portland Street, London W1W 5PF ("Capacity"), and the customer that has entered into the Terms of Service (the "Customer").
It is accepted by opening an account or by continuing to use the service, and binds Capacity without signature. A countersigned copy is available on request to legal@getcapacity.co.
The Customer's account records the version in force on acceptance. Superseded versions remain published.
Customer Personal Data means personal data contained in Customer Data, as defined in the Terms of Service, processed by Capacity on the Customer's behalf. Data Protection Law means the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003, as amended or replaced. Controller, processor, data subject, personal data, processing, personal data breach and supervisory authority bear the meanings given in the UK GDPR.
In respect of Customer Personal Data the Customer is the controller and Capacity is the processor.
The Customer is responsible for the lawfulness of the data it processes through the platform and of the marketing it sends from it, including lawful basis under the UK GDPR and a valid basis under PECR for each channel and recipient. The Acceptable Use Policy applies. Nothing in this agreement constitutes a representation that the Customer's processing is compliant.
Capacity is a separate and independent controller of data processed for its own purposes, including account records, billing, support correspondence and aggregated service statistics. The Privacy Policy governs that processing, to which this agreement does not apply.
As set out in Annex 1. The processing continues for the term of the subscription and the period specified in section 12.
Capacity processes Customer Personal Data only on the Customer's documented instructions, including as to international transfers, unless required otherwise by law, in which case Capacity will notify the Customer before processing unless prohibited from doing so.
The Customer's instructions comprise this agreement, the Terms of Service, the documented functionality of the service, and any further written instruction accepted by Capacity. Configuration of the product, upload of data and initiation of a send are instructions.
Capacity will inform the Customer if, in its opinion, an instruction infringes Data Protection Law, and may decline an instruction that would place it in breach.
Capacity does not sell Customer Personal Data, does not use it to train models, and does not use it to market to the Customer's contacts.
Persons authorised to process Customer Personal Data are subject to binding obligations of confidentiality, and access is limited to those requiring it for their role.
Capacity implements appropriate technical and organisational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, having regard to the state of the art, the cost of implementation, the nature, scope, context and purposes of the processing, and the risk to data subjects. Those measures are set out in Annex 2, and may be varied provided the overall level of protection is not reduced.
The Customer gives general written authorisation for the appointment of sub-processors. Those currently engaged are listed at getcapacity.co/sub-processors, which constitutes Annex 3.
Capacity will give at least 30 days' notice before adding or replacing a sub-processor, by updating that page and by email to the administrative contact on the Customer's account.
The Customer may object within that period on reasonable grounds relating to data protection, by notice to legal@getcapacity.co stating those grounds. The parties will seek a resolution in good faith, which may include provision of the affected functionality by other means. Failing resolution within a reasonable period, the Customer may terminate the affected part of the service on written notice, and Capacity will refund fees paid in advance in respect of the period after termination. This is the Customer's exclusive remedy in respect of an objection.
Capacity imposes on each sub-processor data protection obligations no less protective than those in this agreement, and remains fully liable to the Customer for their performance.
The service provides functionality by which the Customer may locate, export, rectify and delete Customer Personal Data.
Where a data subject exercises a right that the Customer cannot satisfy through that functionality, Capacity will provide reasonable assistance, taking into account the nature of the processing and the information available to it. Where a data subject contacts Capacity directly, Capacity will not respond substantively, will direct the data subject to the Customer, and will inform the Customer promptly.
No charge is made for this assistance except where a request is manifestly unfounded or excessive, or where the assistance required exceeds the functionality of the service, in which case a reasonable charge will be agreed in advance.
Taking into account the nature of the processing and the information available to it, Capacity will provide reasonable assistance to the Customer in respect of its obligations under Articles 32 to 36 of the UK GDPR, being security, breach notification, data protection impact assessment and prior consultation.
Capacity will notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notification will describe, so far as known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Information not available at the time of notification will be provided in phases without further undue delay.
The Customer, as controller, determines whether to notify the supervisory authority or affected data subjects. Capacity will not make such notification on the Customer's behalf except on instruction.
Notification under this section is not an admission of fault or liability.
The Customer may export Customer Data at any time during the subscription. On termination or expiry Capacity will, at the Customer's election, return or delete Customer Personal Data. It remains available for export for 30 days after termination, after which it is deleted.
Deletion from live systems takes effect first. Copies held in backups are overwritten on the normal backup cycle and, until overwritten, remain subject to this agreement and are not processed for any other purpose. Capacity may retain data where required by law, for no longer than so required.
Capacity will make available the information necessary to demonstrate compliance with Article 28 and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer.
Capacity will first respond to a written request for information, including completion of a security questionnaire. Where that does not reasonably satisfy the Customer's obligations, an audit may be conducted subject to the following: not more than once in any 12 month period, unless a personal data breach has occurred or a supervisory authority requires otherwise; on at least 30 days' written notice; during business hours; without unreasonable disruption; subject to confidentiality; excluding the data and systems of other customers; and at the Customer's cost, save where the audit discloses a material breach by Capacity, in which case each party bears its own costs. An auditor mandated by the Customer must not be a competitor of Capacity.
Customer Personal Data is processed in the United Kingdom, the European Economic Area and the United States. The locations applicable to each sub-processor are set out on the sub-processor page.
Transfers from the United Kingdom to the EEA require no additional safeguard, the EEA being covered by UK adequacy regulations. Transfers beyond the United Kingdom and the EEA are made under the International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses, supported by a transfer risk assessment, or under the UK Extension to the EU-US Data Privacy Framework where the recipient is certified. The Customer authorises Capacity to enter into such instruments with sub-processors on its behalf where necessary to provide the service.
Access to Customer Personal Data by a sub-processor's personnel from outside the United Kingdom and the EEA is treated as a transfer and is covered by the same mechanisms.
Capacity maintains a record of the categories of processing carried out on the Customer's behalf in accordance with Article 30(2), and will make the relevant part available on request.
Liability under or in connection with this agreement is subject to the exclusions and limitations in the Terms of Service, and the caps in that agreement apply to this agreement and the Terms of Service in aggregate rather than separately. Nothing in this section limits liability to a data subject under Article 82 of the UK GDPR or any liability that cannot lawfully be limited.
In the event of conflict between this agreement and the Terms of Service in respect of the processing of Customer Personal Data, this agreement prevails. In the event of conflict with a transfer instrument, that instrument prevails.
Capacity may issue a new version of this agreement on at least 30 days' notice by email and by publication on this page, taking effect at the end of that period. Where a new version would materially reduce the Customer's rights or materially increase its obligations, and the Customer gives notice within that period that it does not accept the new version, the version previously accepted continues to apply until the end of the Customer's then-current subscription term. Amendments required by law, and amendments that do not materially affect the Customer, may be made on shorter notice.
This agreement is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction.
Provision of the Capacity platform as described in the Terms of Service and the Customer's order.
The term of the subscription and the period specified in section 12.
Hosting and storage; collection and organisation of contact records; ticket and booking transactions; transmission of marketing and transactional messages by email, SMS and WhatsApp on the Customer's instruction; segmentation; reporting and analytics on the Customer's own activity; support and troubleshooting at the Customer's request; backup and disaster recovery.
The service is not designed for the processing of special category data within the meaning of Article 9, or of criminal offence data, and must not be used for that purpose. Where the Customer collects accessibility or dietary requirements in connection with a booking, that data may constitute health data and the Customer is responsible for the additional conditions that apply to it.
Continuous, for the duration of the subscription.
Data is encrypted in transit using TLS. The database and its backups are encrypted at rest.
Access to production systems is restricted to personnel requiring it for their role, granted by role rather than by default, and withdrawn on change of role or departure. Multi-factor authentication is required on accounts used to access production systems. Customer data is logically separated by account. Access by Capacity personnel is limited to that necessary to operate and support the service.
The platform is hosted on managed cloud infrastructure with automated backups.
Application and infrastructure logs are retained to permit review of access and changes.
Changes are reviewed before release. Dependencies are monitored for known vulnerabilities and updated.
Personnel with access to Customer Personal Data are subject to written obligations of confidentiality. Capacity maintains an incident response process for suspected personal data breaches and a record of processing under Article 30(2).
Capacity holds no security certification. Certifications held by sub-processors apply to those companies and are not held by Capacity.
Published at getcapacity.co/sub-processors and forming part of this agreement. Changes are notified under section 8.
Version 1.0 is current and supersedes nothing. Superseded versions will remain published.
Enquiries, requests for a countersigned copy, sub-processor objections and audit requests: legal@getcapacity.co, or Capacity Digital Ltd, 167-169 Great Portland Street, London W1W 5PF.