Legal · Effective September 26, 2026
Data Processing Agreement (DPA)
This Data Processing Agreement (“DPA”) applies whenever United Technology Services Inc. (“UTS”, “Processor”) processes personal data on behalf of a customer (“Customer”, “Controller”) in providing CaptivaHQ. It forms part of the Terms of Service automatically — no signature is needed — and prevails over them on data protection. If you need a countersigned copy, email [email protected].
1. Definitions and scope
- Data Protection Laws means all laws that apply to the processing, including the EU General Data Protection Regulation (“GDPR”), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and US state privacy laws such as the California Consumer Privacy Act as amended (“CCPA”).
- Customer Personal Data means personal data within Customer Data that UTS processes on the Customer's behalf.
- “Controller”, “processor”, “data subject”, “personal data breach”, “processing” and “supervisory authority” have the meanings given in the GDPR; “service provider”, “business”, “sell” and “share” have the meanings given in the CCPA.
- This DPA does not cover personal data UTS processes as a controller for its own purposes — such as account, billing and website data — which the Privacy Policy covers.
2. Roles and instructions
- The Customer is the controller (or a processor acting for its own controller) and UTS is the processor (or sub-processor) of Customer Personal Data.
- UTS processes Customer Personal Data only on the Customer's documented instructions. The Terms, this DPA and the Customer's configuration and use of the Service are those instructions. UTS will tell the Customer if it believes an instruction breaks Data Protection Laws.
- The Customer is responsible for the lawfulness of the instructions and of the data it provides, including notices and consents.
- The subject matter, duration, nature and purpose of processing, and the types of data and data subjects, are described in Annex 1.
3. Confidentiality
UTS ensures that everyone authorised to process Customer Personal Data is bound by a duty of confidentiality and processes it only as needed to provide the Service.
4. Security
UTS implements appropriate technical and organisational measures to protect Customer Personal Data, as described in the Security overview (Annex 2). UTS may update those measures, provided the overall level of protection does not decrease.
5. Sub-processors
- The Customer gives general authorisation for UTS to use the sub-processors on the sub-processors page (Annex 3).
- UTS imposes on each sub-processor data-protection obligations no less protective than this DPA, and remains liable for its sub-processors' performance.
- UTS gives at least 30 days' notice of a new sub-processor. The Customer may object in writing on reasonable data-protection grounds within that period. The parties will discuss the objection in good faith; if it cannot be resolved, the Customer may terminate the affected part of the Service and receive a refund of prepaid fees for it.
6. Assistance to the Customer
- Data subject requests. The Service provides tools to access, correct, export and delete personal data. UTS will forward to the Customer any request it receives directly and, taking into account the nature of the processing, help the Customer respond.
- Impact assessments and consultations. UTS will provide reasonable information the Customer needs for data-protection impact assessments and prior consultations with supervisory authorities.
- Assistance beyond what the Service's tools provide may be charged at reasonable cost, where the law allows.
7. Personal data breaches
UTS will notify the Customer without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notice will describe, as far as then known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed. UTS will take reasonable steps to contain the breach and will update the Customer as it learns more. Notification is not an admission of fault.
8. Return and deletion
For 30 days after the Service ends, the Customer may export Customer Personal Data with the Service's tools. UTS then deletes Customer Personal Data from active systems within a further 30 days, and from backups as they expire on the rolling backup cycle, unless the law requires it to be kept. Retained data remains protected by this DPA.
9. Audits
- UTS will make available the information reasonably needed to demonstrate compliance with this DPA, including answers to security questionnaires and, once available, independent audit reports.
- If that information is not sufficient, or a supervisory authority requires it, the Customer may carry out an audit, at most once a year, on 30 days' written notice, during business hours, under confidentiality, and at its own cost. Audits of sub-processors rely on those sub-processors' own reports.
10. International transfers
- Customer records stay in the Customer's regional cell. Some processing — the platform directory in France, AI inference, email delivery and billing — may involve transfers between the European Economic Area, the United Kingdom, Switzerland and the United States.
- Where Customer Personal Data subject to the GDPR is transferred to a country without an adequacy decision, the parties rely on the EU-US Data Privacy Framework where the recipient is certified, and otherwise on the Standard Contractual Clauses, which are incorporated into this DPA by reference.
- Transfers of UK and Swiss personal data use the UK International Data Transfer Addendum and the Swiss amendments described on the Standard Contractual Clauses page.
11. US state privacy laws
Where the CCPA or a similar US state law applies, UTS acts as a service provider or processor. UTS will not sell or share Customer Personal Data; will not retain, use or disclose it for any purpose other than providing the Service, or outside the direct business relationship with the Customer; will not combine it with personal data from other sources except as the law permits; will comply with those laws and provide the same level of privacy protection they require; and will notify the Customer if it can no longer meet these obligations. The Customer may take reasonable steps to stop and remediate unauthorised use.
12. Liability and term
Each party's liability under this DPA is subject to the limitations in the Terms, except where Data Protection Laws do not allow it. This DPA lasts as long as UTS processes Customer Personal Data.
Annex 1 — Details of processing
| Subject matter and duration | Providing CaptivaHQ under the Terms, for the term of the subscription and the export and deletion periods in Section 8. |
|---|---|
| Nature and purpose | Hosting, storage, retrieval, organisation, analysis (including by AI models), transmission, display and deletion, to provide the CRM, ERP, project, inventory, invoicing, scheduling, communication and AI features the Customer uses, and to secure and support them. |
| Data subjects | The Customer's employees, contractors and Authorized Users; its customers, prospects, suppliers, partners and their contacts; other individuals whose data the Customer puts into the Service. |
| Categories of personal data | Identity and contact details; job and organisation details; communications (emails, calendar events, call and meeting transcripts and recordings); records and documents; transaction, invoice and project data; location and address data; usage and log data. |
| Special categories | None intended. The Customer will not upload special-category data unless agreed in writing. |
| Frequency | Continuous, for as long as the Customer uses the Service. |
Annex 2 — Technical and organisational measures
As described in the Security overview.
Annex 3 — Sub-processors
As listed on the sub-processors page.
Published for CaptivaHQ by United Technology Services Inc. · All documents: captivahq.com/legal. Questions: [email protected].