This page describes how customer data held in Capacity is protected and where it is stored. The binding statement of these measures is Annex 2 of the Data Processing Agreement.
Contact records, tickets and bookings are stored in the United Kingdom. Application hosting, email delivery, SMS and WhatsApp messaging, and payment processing involve processing in the United States. Every sub-processor, its purpose and its data location is listed on the sub-processor page.
Transfers beyond the United Kingdom and the European Economic Area are made under the International Data Transfer Agreement, the UK Addendum to the EU standard contractual clauses, or the UK Extension to the EU-US Data Privacy Framework, as set out in section 14 of the DPA.
Data is encrypted in transit using TLS. The database and its backups are encrypted at rest.
Access to production systems is restricted to personnel requiring it for their role, granted by role rather than by default, and withdrawn on change of role or departure. Multi-factor authentication is required on accounts used to access production systems. Customer data is logically separated by account. Personnel with access are bound by written confidentiality obligations.
Backups run automatically on the managed infrastructure on which the platform is hosted.
Application and infrastructure logs are retained to permit review of access and changes.
Changes are reviewed before release. Dependencies are monitored for known vulnerabilities and updated.
Capacity holds no security certification. We are not ISO 27001 certified, we hold no SOC 2 report, and we hold no Cyber Essentials certificate.
Certain sub-processors hold certifications of their own. Those apply to those companies and should not be read as certifications held by Capacity.
Where we become aware of a personal data breach affecting customer data, we notify the affected customer without undue delay, and in any event within 72 hours, with the information available at the time and further information as it emerges.
The customer is the controller and decides whether to notify the Information Commissioner's Office or affected individuals.
Vulnerabilities may be reported to legal@getcapacity.co, with sufficient detail to reproduce the issue. We aim to acknowledge within five working days.
We will not pursue legal action in respect of testing carried out in good faith under this section, provided the reporter does not access, alter or delete data belonging to others, does not degrade the service, and allows a reasonable period for remediation before disclosure. Automated scanning of production, denial of service testing and social engineering are not authorised. No bounty is offered.
The following are published in full and are not gated:
Security questionnaires may be sent to legal@getcapacity.co.