Capacity
Platform How it works
TicketingSell under your own name For nightclubsBuilt around how the week runs
Integrations Book a demo
Sign in Book a demo

Security

Last reviewed 25 August 2026

This page describes how customer data held in Capacity is protected and where it is stored. The binding statement of these measures is Annex 2 of the Data Processing Agreement.

1. Data location

Contact records, tickets and bookings are stored in the United Kingdom. Application hosting, email delivery, SMS and WhatsApp messaging, and payment processing involve processing in the United States. Every sub-processor, its purpose and its data location is listed on the sub-processor page.

Transfers beyond the United Kingdom and the European Economic Area are made under the International Data Transfer Agreement, the UK Addendum to the EU standard contractual clauses, or the UK Extension to the EU-US Data Privacy Framework, as set out in section 14 of the DPA.

2. Encryption

Data is encrypted in transit using TLS. The database and its backups are encrypted at rest.

3. Access control

Access to production systems is restricted to personnel requiring it for their role, granted by role rather than by default, and withdrawn on change of role or departure. Multi-factor authentication is required on accounts used to access production systems. Customer data is logically separated by account. Personnel with access are bound by written confidentiality obligations.

4. Backups

Backups run automatically on the managed infrastructure on which the platform is hosted.

5. Logging

Application and infrastructure logs are retained to permit review of access and changes.

6. Development

Changes are reviewed before release. Dependencies are monitored for known vulnerabilities and updated.

7. Certifications

Capacity holds no security certification. We are not ISO 27001 certified, we hold no SOC 2 report, and we hold no Cyber Essentials certificate.

Certain sub-processors hold certifications of their own. Those apply to those companies and should not be read as certifications held by Capacity.

8. Incidents

Where we become aware of a personal data breach affecting customer data, we notify the affected customer without undue delay, and in any event within 72 hours, with the information available at the time and further information as it emerges.

The customer is the controller and decides whether to notify the Information Commissioner's Office or affected individuals.

9. Reporting a vulnerability

Vulnerabilities may be reported to legal@getcapacity.co, with sufficient detail to reproduce the issue. We aim to acknowledge within five working days.

We will not pursue legal action in respect of testing carried out in good faith under this section, provided the reporter does not access, alter or delete data belonging to others, does not degrade the service, and allows a reasonable period for remediation before disclosure. Automated scanning of production, denial of service testing and social engineering are not authorised. No bounty is offered.

10. Documentation

The following are published in full and are not gated:

  • Data Processing Agreement, including the description of processing, technical and organisational measures, and sub-processors
  • Sub-processor list
  • Acceptable Use Policy
  • Terms of Service and Privacy Policy

Security questionnaires may be sent to legal@getcapacity.co.

Capacity

Ticketing, bookings and marketing for venues. Sell under your own brand, own the customer, and bring them back.

Product

Platform Integrations How it works

Company

Agency Security Careers Contact FAQ

Get started

Book a demo Sign in

Legal

Terms Privacy DPA Acceptable use Cookies
© Capacity Digital Ltd 2026 · Company No. 14487697 Cookie settings 167-169 Great Portland Street, London W1W 5PF