This page lists the sub-processors engaged to process personal data on behalf of our customers. It forms Annex 3 to our Data Processing Agreement.
| Sub-processor | Purpose | Data location |
|---|---|---|
| Supabase Supabase Pte. Ltd, Singapore |
Application database. Contact records, ticket and booking data, consent and opt-out records. | United Kingdom (London) |
| Vercel Vercel Inc., United States |
Application hosting. | United States |
| Twilio SendGrid Twilio Ireland Ltd, Ireland |
Marketing email delivery. | United States |
| Twilio Twilio Ireland Ltd, Ireland |
SMS and WhatsApp messaging. | United States |
| Meta Meta Platforms, Inc., United States |
WhatsApp message delivery. Receives recipient phone numbers and message content. | United States |
| Resend Plus Five Five, Inc., United States |
Transactional email. | United States |
| Stripe Stripe Payments Europe Ltd, Ireland |
Payment processing. Also acts as an independent controller, see section 4. | United States and Ireland |
Contact records, tickets and bookings are stored in the United Kingdom.
Application hosting, email delivery, SMS and WhatsApp messaging, and payment processing involve processing in the United States. Support and engineering personnel at certain sub-processors may access data from outside the United Kingdom and the European Economic Area.
Where Capacity contracts with an Irish entity of a supplier, that supplier's United States entity acts as a further sub-processor.
Transfers from the United Kingdom to the European Economic Area require no additional safeguard, the EEA being covered by UK adequacy regulations.
Transfers beyond the United Kingdom and the EEA are made under the International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses, supported by a transfer risk assessment, or under the UK Extension to the EU-US Data Privacy Framework where the recipient is certified. Section 14 of the DPA applies.
Stripe processes payment data as our sub-processor and, separately, as an independent controller for its own fraud prevention, anti-money-laundering and product development purposes. Processing in that second capacity is not carried out on our instructions, is not governed by the DPA, and is subject to Stripe's own privacy policy. Customers should identify Stripe as an independent controller in their own privacy notices.
Certain sub-processors hold security certifications. Capacity holds none.
We give at least 30 days' notice before adding or replacing a sub-processor, by updating this page and by email to the administrative contact on the customer's account. Additional recipients may be added to that notice by request to legal@getcapacity.co.
A customer may object within the notice period on reasonable grounds relating to data protection, by notice to legal@getcapacity.co stating those grounds. The parties will seek a resolution in good faith. Failing resolution within a reasonable period, the customer may terminate the affected part of the service, and fees paid in advance for the period after termination will be refunded. Section 8 of the DPA applies.
Version 1.0 is current. Superseded versions remain published.
legal@getcapacity.co, or Capacity Digital Ltd, 167-169 Great Portland Street, London W1W 5PF.