Legal · Effective September 26, 2026
Shared Responsibility Model
CaptivaHQ is software as a service. United Technology Services Inc. (“UTS”, “we”) runs the platform — the infrastructure, the application, the AI pipeline and their security. You, the customer, decide who gets in, what goes in and what the system is allowed to do. This page sets out that split. It forms part of the Terms of Service.
1. The model at a glance
Your data, users and decisionsCustomer
Workspace configuration, roles, integrations, agentsCustomer
Identity controls, audit trail, export toolsShared
Application, AI pipeline, tenant isolationCaptivaHQ
Hosting, network, databases, backups, patchingCaptivaHQ
The lower in the stack, the more of it is ours. Where a row says “Shared”, we provide the control and you decide how to use it.
2. Responsibility matrix
| Area | CaptivaHQ (UTS) is responsible for | The customer is responsible for |
|---|---|---|
| Infrastructure and hosting | Selecting and managing hosting providers; physical security (inherited from those providers); network, compute, databases and storage; capacity planning. | The devices, networks and browsers your people use to reach the Service. |
| Application | Building, testing, deploying and patching the application and its dependencies; fixing defects; keeping modules working as documented. | Choosing modules and plans that fit your needs; reporting defects with enough detail to reproduce them. |
| Availability | Monitoring, incident response, and meeting the Service Level Agreement for paid plans; publishing maintenance windows. | Business-continuity plans for your own operations, including what you do if the Service or your internet connection is unavailable. |
| Data protection | Encryption in transit and at rest; tenant isolation (a separate schema per workspace with row-level security); backups; deleting data on the schedule in the DPA. | Deciding what data to put in; having a lawful basis and any consents needed; not uploading data the Service is not designed for (such as health records or card numbers); keeping your own exports where you need them. |
| Identity and access | Secure sign-in (including single sign-on with Google and Microsoft), session management, role-based permissions, and a log of sign-ins and changes. | Inviting and removing users promptly; assigning the least access each role needs; protecting passwords, API keys and MCP tokens; enforcing multi-factor authentication through your identity provider. |
| Configuration | Secure defaults; documenting what each setting does. | Custom fields, workflows, automations, sharing settings, client-portal access, and anything else you change from the defaults. |
| Integrations | Building connectors securely; requesting only the scopes each feature needs; storing OAuth tokens encrypted; honouring disconnection. | Deciding which third-party accounts to connect; your agreements with those providers; the data they hold before it reaches CaptivaHQ. |
| AI features | Choosing and contracting model providers; not using your data to train foundation models; metering usage accurately; guardrails against prompt injection and unsafe actions; logging what agents do. | Which AI features and agents are enabled and what they may do; reviewing AI output before relying on it or sending it out; approving agent actions; managing your AI credit balance; staying within fair use. |
| Security monitoring | Monitoring the platform for threats and abuse; investigating incidents; notifying you of a personal-data breach affecting your workspace without undue delay. | Watching for misuse by your own users; reviewing your workspace's audit trail; telling us at [email protected] if you suspect a compromise. |
| Sub-processors | Vetting and contracting sub-processors on terms as protective as ours; keeping the list current; giving notice of changes. | Reviewing the list and objecting to a new sub-processor within the notice period if you have reasonable grounds. |
| Compliance | Complying with the laws that apply to us as a service provider and processor; the commitments in the DPA; answering reasonable security questionnaires. | Complying with the laws that apply to your business and your use of the data — for example marketing-consent, employment, industry and record-keeping rules — and deciding whether the Service fits them. |
| Data subject requests | Tools to find, export, correct and delete personal data; helping you respond when you need more than the tools. | Receiving and answering requests from the people whose data you hold, as the controller of that data. |
| Billing | Accurate invoices and metering; notice of price changes. | Keeping a valid payment method and billing contact; managing user counts, modules and AI credits. |
| Offboarding | Export tools, a 30-day export window after termination, then deletion as the DPA describes. | Exporting what you need before the window closes; revoking API keys and integrations you no longer use. |
3. What this means in practice
- A lost laptop is yours to handle: remove the user or reset their sessions and keys. We will help you check the audit trail.
- A vulnerability in CaptivaHQ is ours: we fix it, and tell affected customers where their data was at risk.
- An email an AI agent sent on a workflow you approved is yours; an agent acting outside the permissions you set is ours to fix.
- A regulator's question about why you hold a contact's data goes to you; a question about how we secure it, we answer with you.
4. Changes and questions
We update this model when the Service changes, under the change process in the Terms of Service. Questions: [email protected].
Published for CaptivaHQ by United Technology Services Inc. · All documents: captivahq.com/legal. Questions: [email protected].