CaptivaHQ
Industries

Find your industry

Property Management & HOAMaritime & Fleet OperationsIndustrial & ManufacturingLegal & LawFinancial ServicesHealthcare AdministrationInsuranceHospitality & RestaurantsGovernment & Public SectorSkilled TradesCustom CRM / ERPExplore all industries →
Modules AI Compare Pricing FAQ Docs Partners
Contact Us

← Legal hub

Legal · Effective September 26, 2026

Shared Responsibility Model

CaptivaHQ is software as a service. United Technology Services Inc. (“UTS”, “we”) runs the platform — the infrastructure, the application, the AI pipeline and their security. You, the customer, decide who gets in, what goes in and what the system is allowed to do. This page sets out that split. It forms part of the Terms of Service.

On this page

  1. The model at a glance
  2. Responsibility matrix
  3. What this means in practice
  4. Changes and questions

1. The model at a glance

Your data, users and decisionsCustomer
Workspace configuration, roles, integrations, agentsCustomer
Identity controls, audit trail, export toolsShared
Application, AI pipeline, tenant isolationCaptivaHQ
Hosting, network, databases, backups, patchingCaptivaHQ

The lower in the stack, the more of it is ours. Where a row says “Shared”, we provide the control and you decide how to use it.

2. Responsibility matrix

AreaCaptivaHQ (UTS) is responsible forThe customer is responsible for
Infrastructure and hosting Selecting and managing hosting providers; physical security (inherited from those providers); network, compute, databases and storage; capacity planning. The devices, networks and browsers your people use to reach the Service.
Application Building, testing, deploying and patching the application and its dependencies; fixing defects; keeping modules working as documented. Choosing modules and plans that fit your needs; reporting defects with enough detail to reproduce them.
Availability Monitoring, incident response, and meeting the Service Level Agreement for paid plans; publishing maintenance windows. Business-continuity plans for your own operations, including what you do if the Service or your internet connection is unavailable.
Data protection Encryption in transit and at rest; tenant isolation (a separate schema per workspace with row-level security); backups; deleting data on the schedule in the DPA. Deciding what data to put in; having a lawful basis and any consents needed; not uploading data the Service is not designed for (such as health records or card numbers); keeping your own exports where you need them.
Identity and access Secure sign-in (including single sign-on with Google and Microsoft), session management, role-based permissions, and a log of sign-ins and changes. Inviting and removing users promptly; assigning the least access each role needs; protecting passwords, API keys and MCP tokens; enforcing multi-factor authentication through your identity provider.
Configuration Secure defaults; documenting what each setting does. Custom fields, workflows, automations, sharing settings, client-portal access, and anything else you change from the defaults.
Integrations Building connectors securely; requesting only the scopes each feature needs; storing OAuth tokens encrypted; honouring disconnection. Deciding which third-party accounts to connect; your agreements with those providers; the data they hold before it reaches CaptivaHQ.
AI features Choosing and contracting model providers; not using your data to train foundation models; metering usage accurately; guardrails against prompt injection and unsafe actions; logging what agents do. Which AI features and agents are enabled and what they may do; reviewing AI output before relying on it or sending it out; approving agent actions; managing your AI credit balance; staying within fair use.
Security monitoring Monitoring the platform for threats and abuse; investigating incidents; notifying you of a personal-data breach affecting your workspace without undue delay. Watching for misuse by your own users; reviewing your workspace's audit trail; telling us at [email protected] if you suspect a compromise.
Sub-processors Vetting and contracting sub-processors on terms as protective as ours; keeping the list current; giving notice of changes. Reviewing the list and objecting to a new sub-processor within the notice period if you have reasonable grounds.
Compliance Complying with the laws that apply to us as a service provider and processor; the commitments in the DPA; answering reasonable security questionnaires. Complying with the laws that apply to your business and your use of the data — for example marketing-consent, employment, industry and record-keeping rules — and deciding whether the Service fits them.
Data subject requests Tools to find, export, correct and delete personal data; helping you respond when you need more than the tools. Receiving and answering requests from the people whose data you hold, as the controller of that data.
Billing Accurate invoices and metering; notice of price changes. Keeping a valid payment method and billing contact; managing user counts, modules and AI credits.
Offboarding Export tools, a 30-day export window after termination, then deletion as the DPA describes. Exporting what you need before the window closes; revoking API keys and integrations you no longer use.

3. What this means in practice

  • A lost laptop is yours to handle: remove the user or reset their sessions and keys. We will help you check the audit trail.
  • A vulnerability in CaptivaHQ is ours: we fix it, and tell affected customers where their data was at risk.
  • An email an AI agent sent on a workflow you approved is yours; an agent acting outside the permissions you set is ours to fix.
  • A regulator's question about why you hold a contact's data goes to you; a question about how we secure it, we answer with you.

4. Changes and questions

We update this model when the Service changes, under the change process in the Terms of Service. Questions: [email protected].

Published for CaptivaHQ by United Technology Services Inc. · All documents: captivahq.com/legal. Questions: [email protected].

CaptivaHQ

The AI-first Enterprise Operating System. Built by United Technology Services.

Modules AI Compare Pricing FAQ Docs Partners utsconsult.com Privacy Policy Terms of Service Legal
© 2026 United Technology Services Inc. CaptivaHQ is a product of UTS. All rights reserved. Enterprise operating system · AI-first ERP alternative · modular business platform