Legal · Effective September 26, 2026
Records of Processing (RoPA)
This is a public summary of the records of processing activities that United Technology Services Inc. keeps under Article 30 of the GDPR for CaptivaHQ. The full records are available to supervisory authorities on request. Our role in each activity — controller or processor — decides which document governs it: the Privacy Policy for controller activities and the DPA for processor activities.
1. Who we are
United Technology Services Inc. — operator of CaptivaHQ
Data protection contact: [email protected]
Legal: [email protected]
2. Activities where UTS is processor
| Activity | Data subjects and data | Recipients | Retention |
|---|---|---|---|
| Providing the CaptivaHQ platform to customers | Customers' staff, clients, prospects, suppliers and contacts: contact details, communications, records, documents, transactions | Platform sub-processors | Term of subscription, plus 30-day export window and deletion as in the DPA |
| AI features (drafting, summaries, search, enrichment, agents, voice) | As above, limited to the content each request needs | AI model providers; public search and geocoding services for outward-looking features | AI transactions 7 days; redacted model-call log 90 days |
| Connected integrations (email, calendar, meetings) | Mailbox and calendar content, meeting transcripts pulled in at the customer's instruction | Platform sub-processors | While the integration is connected; deleted within 30 days of disconnection |
3. Activities where UTS is controller
| Activity | Data subjects and data | Lawful basis | Retention |
|---|---|---|---|
| Account management and sign-in | Authorized Users: name, email, organisation, sign-in tokens, authentication audit | Contract | Life of the account; authentication audit 3 years |
| Billing and AI metering | Billing contacts: name, company, address, tax details, payment token; usage records | Contract; legal obligation (tax records) | As required by tax law, typically 7 years |
| Security and abuse prevention | Users and visitors: IP address, device and log data, usage patterns | Legitimate interests | Up to 3 years, longer for an active investigation |
| Support and service communications | Users who contact us: name, email, message content | Contract; legitimate interests | Up to 3 years after the last contact |
| Closed-beta registrations | People who submit the website form: name, email, company, phone, business answers, consent record | Consent; legitimate interests | Kept only as an email while we act on the request; deleted on request |
| Website analytics and advertising measurement | Website visitors who accept cookies: cookie identifiers, pages, referrer, approximate location | Consent | Google's retention settings, up to 14 months for analytics |
4. Transfers
Transfers outside the EEA, UK and Switzerland are covered by adequacy decisions, the EU-US Data Privacy Framework where the recipient is certified, or the Standard Contractual Clauses. Recipients and locations are on the sub-processors page.
5. Security measures
A general description of our technical and organisational measures is in the Security overview.
Published for CaptivaHQ by United Technology Services Inc. · All documents: captivahq.com/legal. Questions: [email protected].