CAPITIS
Sign inCreate sandbox key

Data Processing Addendum

Version 1.0 · Effective 4 August 2026

This Addendum forms part of the Terms of Service between you ("Customer") and Single.id Limited trading as Capitis ("Capitis", "we"). It applies automatically from the moment you send us personal data — you do not need to sign or request it. If your procurement process needs a countersigned copy, email legal@capitis.app and we will sign this text unchanged.

"Data Protection Law" means the UK GDPR and the Data Protection Act 2018 as amended by the Data (Use and Access) Act 2025, the EU GDPR (Regulation 2016/679), and any other data protection or privacy law applicable to a party. The terms controller, processor, data subject, personal data, processing and personal data breach carry their meanings under that law.

1. Who is responsible for what

You are the controller. We are your processor. For the personal data you send us about your end-users — hashed identifiers, clicks, conversions — you decide why and how it is processed. We act only on your instructions. You are responsible for having a lawful basis, for serving privacy notices to your users, and for obtaining consent where consent is what your market requires.

We are a controller for our own account data. Your name, email, sign-in records, API usage logs and billing records are ours to control. That processing is described in the Privacy Policy and is not covered by this Addendum.

The affiliate networks are independent controllers. When a shopper clicks a Capitis tracking link, the click passes to the affiliate network behind that merchant (Awin, Admitad, Rakuten and so on) carrying the tracking reference the network requires. The network processes that click under its own privacy policy, for its own purposes, as an independent controller — not as our subprocessor and not as yours. Neither we nor you control what the network does with it. Your privacy notice must tell your users that this onward disclosure happens. See §8.

2. Your instructions

We process personal data only on your documented instructions. Your instructions are: this Addendum, the Terms of Service, the documented behaviour of the API and dashboard, and any further written instruction we accept.

We will tell you if, in our opinion, an instruction breaches Data Protection Law. We may refuse an instruction that would, and we may suspend processing until it is resolved.

We will not sell your end-users' personal data, and we will not use it to train machine learning models, for advertising of our own, or for any purpose other than providing the Services to you.

3. Confidentiality and people

Everyone we authorise to process your data is bound by a written duty of confidentiality that survives the end of their engagement. Access is granted on a need-to-know basis and removed when the need ends.

4. Security

We implement the technical and organisational measures described in Annex II and set out in full on the Security page, which is incorporated into this Addendum. We may change specific measures as technology moves, but not in a way that materially reduces overall protection.

5. Subprocessors

You give us general written authorisation to appoint subprocessors. Our current subprocessors, what each one does and where it is located, are published at capitis.app/legal/subprocessors.

Before we add or replace a subprocessor we will give you at least 30 days' notice by email and by updating that page. If you have a reasonable, data-protection-based objection, tell us within those 30 days and we will work with you to find an alternative. If we cannot, you may terminate the affected Services without penalty and receive a pro-rata refund of any prepaid fees.

We impose data protection obligations on every subprocessor that are no less protective than those in this Addendum, and we remain fully liable to you for their performance.

6. Helping you meet your obligations

Data subject rights. If one of your end-users contacts us directly with a rights request, we will not respond substantively — we will pass it to you without undue delay, because we usually cannot identify a data subject from a hash alone. We will give you reasonable technical assistance to answer requests yourself, including deletion and export. Individual identifiers can be revoked immediately through the dashboard or the API.

Assessments and consultation. We will give you reasonable assistance with data protection impact assessments, prior consultation with a regulator, and security-incident obligations, taking into account the nature of the processing and the information available to us.

Complaints. The Data (Use and Access) Act 2025 requires controllers to make it easy for individuals to complain and to respond to them. Where a complaint concerns processing we carry out for you, we will support your response.

7. Personal data breaches

If we become aware of a personal data breach affecting your data, we will notify you without undue delay and in any event within 48 hours of becoming aware. The notification will describe what happened, the categories and approximate volume of data and data subjects affected, the likely consequences, and the measures taken or proposed. Where we cannot provide all of it at once, we will provide it in stages without further undue delay.

We will not notify a regulator or your data subjects on your behalf unless you instruct us to, or the law requires us to.

Security contact: security@capitis.app.

8. International transfers

Where your data sits. All Capitis production infrastructure — application servers, the primary database, the cache — is hosted in the United Kingdom (Manchester). We do not replicate end-user personal data — identifiers, clicks and conversions — outside the UK. The limited Customer contact data that is processed outside the UK, and the safeguard covering each transfer, is set out at capitis.app/legal/subprocessors.

Sending data to us from the EEA. On 19 December 2025 the European Commission renewed its adequacy decisions for the United Kingdom, valid until 27 December 2031. Transfers from the EEA to Capitis therefore rely on that adequacy decision and need no additional safeguard. If the adequacy decision is revoked, suspended or allowed to lapse, the parties will from that date be deemed to have entered into the EU Standard Contractual Clauses, Module Two (controller to processor), Commission Implementing Decision (EU) 2021/914, with the annexes below completed by Annexes I–III of this Addendum, the optional docking clause included, clause 11(a) redress option not selected, clause 17 governed by Irish law and clause 18(b) naming the courts of Ireland.

Sending data to us from the UK. Domestic; no transfer safeguard needed.

Onward transfers from us. Some subprocessors are outside the UK. Each transfer is covered by the UK International Data Transfer Addendum (version B1.0) to the EU Standard Contractual Clauses, or by the provider's own approved mechanism where one applies. The mechanism used for each subprocessor is stated on the subprocessors page.

Affiliate networks. The onward disclosure of click data to affiliate networks described in §1 is a controller-to-controller disclosure made on your instruction, not a processor transfer. The network determines its own transfer mechanism. You are responsible for making the disclosure lawful at your end — that is the whole point of the privacy-notice requirement in the Publisher Policy.

9. Audit

We will make available all information reasonably necessary to demonstrate compliance with this Addendum, including our security documentation and a completed security questionnaire, on request and no more than once a year.

You may audit us in person, or through an independent auditor who is not our competitor and who signs a confidentiality agreement, on 30 days' written notice, no more than once in any twelve months, during business hours, and without unreasonably disrupting our operations. You bear the cost. The once-a-year limit does not apply after a personal data breach affecting your data, or where a regulator requires an audit.

10. Deletion and return

On termination or expiry, and at your choice, we will delete or return your end-users' personal data. Unless you tell us otherwise within 30 days of termination, we will delete it within 30 days of that period ending and confirm deletion in writing on request.

We may keep data where the law requires, and we keep aggregated, statistical data that cannot be attributed to any individual. Backups roll off on their own cycle, described on the Security page; data in backups is not restored into production after a deletion request.

11. Liability, order of precedence and law

Each party's liability under this Addendum is subject to the limitations and exclusions in the Terms of Service. Nothing in this Addendum limits either party's liability where Data Protection Law does not allow it to be limited.

If this Addendum conflicts with the Terms of Service on a data protection matter, this Addendum wins. If it conflicts with the Standard Contractual Clauses where those apply, the Clauses win.

This Addendum is governed by the laws of England and Wales, except where the Standard Contractual Clauses specify otherwise.


Annex I — Details of the processing

A. Parties. Data exporter: the Customer, acting as controller, whose details are those held in its Capitis account. Data importer: Single.id Limited trading as Capitis, 20 Wenlock Road, London, England, N1 7GU, acting as processor. Contact: privacy@capitis.app.

B. Description of the transfer.

Categories of data subjectsThe Customer's end-users (shoppers who click Capitis tracking links or whose identifiers the Customer submits); the Customer's own personnel who hold Capitis accounts.
Categories of personal dataPseudonymous identifiers: HMAC-SHA256 hashes of email address, phone number, payment card token, bank-link reference or wallet address, each stored under a further keyed hash at rest. Customer-assigned end-user references. Click records: timestamp, IP address, user agent, country derived from IP, referring URL, destination merchant, campaign and label metadata, tracking token. Conversion records: order value, currency, merchant, commission amount and status, order reference supplied by the network.
Special category dataNone. The Customer must not submit special category data, criminal offence data, or data concerning children under 16.
FrequencyContinuous, for the duration of the Terms of Service.
Nature and purposeIssuing and resolving affiliate tracking links; recording clicks and attributing conversions; matching identifiers across publishers so that a returning shopper can be recognised; calculating commission and platform fees; producing reports for the Customer; detecting fraud and policy abuse.
RetentionHashed identifiers: until revoked by the Customer or its end-user, or until account deletion. Click and conversion records: for the life of the account, because they are the commission audit trail and a network may reverse a conversion months later. Operational logs: 90 days. Billing records: 7 years, as UK tax law requires.
Subprocessor processingAs set out in Annex III, for the duration and purposes stated there.

C. Competent supervisory authority. Where the EU Standard Contractual Clauses apply under §8, the supervisory authority of the EEA member state in which the Customer is established, or the Irish Data Protection Commission where the Customer is not established in the EEA. For UK processing, the Information Commissioner's Office.


Annex II — Technical and organisational measures

The full description is published at capitis.app/legal/security and forms part of this Addendum. In summary:

  • Pseudonymisation. Identifiers are never received in raw form. They arrive as HMAC-SHA256 hashes and are stored under a second keyed hash using a server-side secret held only in the API environment, so a stolen database alone does not permit matching against a guessed value.
  • Encryption. TLS 1.2 or above for all data in transit, with HTTP Strict Transport Security and a hardened set of browser security headers. Data at rest is protected by host access control and a default-deny host firewall; disk-level encryption on the host is a published gap, listed at capitis.app/legal/security.
  • Access control. Administrative access to the host is by SSH key only, with password authentication and password-based root login disabled at the server, over a firewall that permits no other inbound traffic. Every API request is scoped to a single publisher.
  • Tenant separation. Every query filters by publisher at the application layer; API keys are stored hashed and are scoped to one account.
  • Resilience. Nightly database backups, size-verified on write, retained for 14 days; health and readiness checks on every service with automatic restart.
  • Logging. Application and access logging with credential redaction; a per-publisher audit log of security-relevant actions.
  • Secure development. Code review, and linting, type checking and the automated test suite run in continuous integration on every change; typed schemas validated at the API boundary; database changes applied only through reviewed migration files.
  • Incident response. A documented process, a named contact, and the 48-hour notification commitment in §7.

The Security page also lists, openly, the measures we have not yet implemented. That list is part of this Annex; we would rather you knew.


Annex III — Authorised subprocessors

The current list, with each subprocessor's role, location and transfer mechanism, is maintained at capitis.app/legal/subprocessors and is incorporated here. Changes are notified as set out in §5.


Questions about this Addendum: legal@capitis.app · Privacy: privacy@capitis.app

Single.id Limited, 20 Wenlock Road, London, England, N1 7GU — Company Number 17044105