Capsakey

Data Processing Agreement

Version 1.0, 15 August 2026. Contact: info@capsakey.com

This Agreement forms part of the Terms of Service between Capsakey ("Processor") and the site owner installing the app ("Controller"), and applies whenever the Processor handles personal data on the Controller's behalf under Regulation (EU) 2016/679 ("GDPR").

1. Roles

The Controller determines the purposes and means. The Processor acts only on documented instructions from the Controller — using the app's own interface constitutes such instruction.

2. Subject matter, duration, nature and purpose

Subject matterStorage of, and controlled access to, files the Controller and their clients upload
DurationFor as long as the app is installed, plus the retention period in §8
Nature and purposePrivate file exchange between the Controller and their clients
Categories of data subjectThe Controller's clients, and the Controller's own staff
Categories of personal dataFile contents (determined entirely by the Controller); file metadata; site member identifiers; access logs; email addresses used for notification; and — read for the length of one request and never stored — member names, login emails and profile photo links
Special categoriesNot anticipated. The Processor does not inspect file contents and cannot detect them. A Controller intending to store special-category data must satisfy themselves that this service is appropriate

3. Processor obligations

The Processor shall:

  1. process personal data only on documented instructions, including for transfers;
  2. ensure that persons authorised to process are bound by confidentiality;
  3. implement the measures in §5;
  4. respect the conditions in §6 for engaging sub-processors;
  5. assist the Controller, by appropriate technical measures, in responding to data-subject requests — in practice the Controller can satisfy access, erasure and portability themselves, immediately, from their own dashboard;
  6. assist the Controller with Articles 32 to 36, including breach notification;
  7. at the Controller's choice, delete or return all personal data at the end of the service;
  8. make available the information needed to demonstrate compliance with Article 28.

4. What the Processor never does

The Processor does not read, index, scan, preview, transcode, profile, or train any model on file contents. No feature requires it and no code path performs it.

The Processor does not use the data for its own purposes, does not sell or share it, and operates no advertising or analytics integration in this product.

5. Technical and organisational measures (Article 32)

6. Sub-processors

The Controller gives general written authorisation for the sub-processors listed at /subprocessors. The Processor shall give 14 days' notice of any intended addition or replacement, during which the Controller may object on reasonable data-protection grounds and, if the matter cannot be resolved, terminate without penalty and export their data.

Each sub-processor is bound by obligations no less protective than those in this Agreement.

7. International transfers

Object storage is restricted to the European Union.

Cloudflare, Inc. and the email provider are incorporated in the United States. Where personal data is transferred outside the EEA, the transfer relies on the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), module processor-to-processor, incorporated by reference.

A Controller who requires an EU-incorporated provider throughout should say so before subscribing. The email component can be configured to an EU provider; the storage and compute provider cannot currently be changed.

8. Retention and deletion

Deletion of a file removes it from view immediately and from storage within 30 days, by an automatic sweep that runs many times a day. The delay is a recovery window and is the same on both sides.

The Controller can erase all of their data themselves, immediately, from the app's dashboard. No request, no ticket, no delay.

Uninstalling the app does not delete data, because uninstallation is often accidental or temporary — which is precisely why the self-serve erasure above exists as a separate, deliberate act.

Data-subject erasure is handled automatically: when a site member is anonymised at the platform, the Processor removes their access, anonymises their entries in the access log, and deletes the files they uploaded. Files the Controller sent to that member are retained, as they are the Controller's data and not the data subject's.

9. Breach notification

The Processor shall notify the Controller without undue delay and in any event within 24 hours of becoming aware of a personal data breach, with the nature of the breach, the categories and approximate number of data subjects and records concerned, likely consequences, and measures taken.

A notification to one Controller shall never disclose information about another Controller's tenant.

10. Audit

The Processor shall make available the information necessary to demonstrate compliance, and allow for audits by the Controller or an auditor they mandate, on reasonable notice, no more than once a year unless a breach has occurred, at the Controller's cost, and subject to confidentiality.

11. Liability and governing law

As set out in the Terms of Service. Governing law: France. Jurisdiction: the courts of France.