Legal summary
Data Processing Addendum
How controller and processor roles are assigned, what processing covers, and which security, assistance, deletion, and retention duties apply.
| Controller roles | Covered in this document |
|---|---|
| Processor terms | Covered in this document |
| Security measures | Covered in this document |
Sections
Plain-language summary: Capell is usually responsible for its own account and marketplace records. We may become a processor of customer-controlled data only when a separate service or agreement says so, and customers still operate their own Laravel installations.
Decide the role from the workflow
This addendum covers personal data used in account, marketplace, install, support, and hosted-service workflows. It provides contractual GDPR context for customers who need to identify controller and processor responsibilities.
Capell may act as an independent controller for account, security, marketplace integrity, author, payment, support, and legal-compliance records. Capell may act as a processor only where a separate service or agreement says so and limits us to processing customer content or customer-controlled personal data on documented instructions.
What the processing may cover
The data may include account details, verified domains, package-access records, install receipts, marketplace telemetry, support messages, security evidence, and operational logs needed to provide and protect Capell services.
Capell does not use customer-controlled personal data for unrelated advertising profiles. We limit processing to providing, securing, supporting, improving, and legally operating the relevant service.
Controls Capell applies
Capell uses practical application security controls, access restrictions, encrypted transport, hashed passwords, audit-friendly legal acceptance records, and operational review around marketplace and package workflows.
Controls the customer keeps
Customers remain responsible for their own Laravel application security, installed package review, deployment controls, database backups, user permissions, and any personal data they choose to process inside their own Capell installation.
Assistance, deletion, and return
Where legally required and technically possible, Capell will help with reasonable requests related to data subject rights, security incidents, audits, deletion, export, and return of customer-controlled personal data.
Records we may retain
Some records may need to be retained for security, fraud prevention, legal claims, licence compliance, marketplace integrity, accounting, or audit history.