Legal summary
Data Processing Addendum
Controller and processor terms for Capell accounts, marketplace services, and hosted customer instances.

| Documented instructions | Covered in this document |
|---|---|
| Verified deletion | Covered in this document |
| Subprocessor controls | Covered in this document |
Sections
Plain-language summary: Capell controls its own account, commerce, security and legal records. For personal data a customer places in a Capell-hosted instance, the customer is the controller and Capell is its processor.
Scope, roles and instructions
This addendum applies while Capell processes customer-controlled personal data to provision, host, secure, support or deprovision a managed customer instance. The customer determines the purposes and means of that processing and instructs Capell through the service, support requests and any written agreement. Capell processes that data only on documented instructions, including transfers, unless UK law requires otherwise; where legally permitted, Capell will tell the customer before that required processing.
Capell remains an independent controller for its account, marketplace, payment-reference, fraud-prevention, licence, security, support-administration and legal-compliance records.
Data and duration
Hosted data may include customer users, website visitors, content, form submissions, files, database records, logs and identifiers chosen by the customer. Processing lasts while the hosted service is active and through verified deprovisioning, subject to the limited controller-side records described below.
People, security and confidentiality
Capell limits access to people and providers who need it to operate or support the service and who are bound by confidentiality. Appropriate technical and organisational measures include access controls, encrypted transport, protected credentials, logging, backups where configured, vulnerability response and separation of customer instances. No system is risk-free.
Subprocessors and transfers
The customer authorises the providers listed on the Subprocessors List. Capell remains responsible for imposing materially equivalent data-protection duties on subprocessors. Material changes will be published or notified through an agreed route so a customer can raise a reasoned data-protection objection. Region and transfer information follows the selected hosting service and provider terms.
Assistance and incidents
Taking account of the processing and information available, Capell will provide reasonable assistance with data-subject requests, security assessments, breach notifications, impact assessments and regulator consultation. Capell will notify the customer without undue delay after becoming aware of a personal-data breach affecting data processed for that customer and provide available information for the customer's assessment. Capell does not promise a fixed 24-hour response.
Deletion, return and audit
On a valid deprovision request, Capell starts deletion of managed application and database resources. The instance stays marked as deleting until authoritative checks show zero remaining managed resources and continuing cost; unavailable automated verification requires manual reconciliation. On completion, Capell will delete or return customer-controlled data as agreed, unless law requires retention.
Account, commerce, security, fraud-prevention, legal-claim and deletion-evidence records that Capell controls may be retained only for those purposes. On reasonable notice, Capell will provide information needed to demonstrate compliance and permit proportionate audits, subject to confidentiality, security and avoiding disclosure of other customers' data.