Data Processing Addendum
Last updated: 10 August 2026
This Data Processing Addendum (the “DPA”) forms part of, and is subject to, the Terms of Services (the “Terms”) between Capitan Ltd. (company no. 515184711), of Alfei Menashe, Israel (“Capitan Ltd.”, “we”, “our” or “us”), and the Customer (“you” or the “Customer”).
It applies where, and to the extent that, we process Personal Data on the Customer’s behalf in the course of providing the Services. Any capitalized but undefined term in this DPA has the meaning given to it in the Terms or in our Privacy Policy.
Where this DPA conflicts with the Terms, the Privacy Policy or any other policy of ours, this DPA prevails in respect of the processing of Personal Data.
1. Definitions
- “Applicable Data Protection Law” means all laws relating to the processing of Personal Data that apply to a party, including, as applicable: the Israeli Privacy Protection Law, 5741-1981 and the regulations made under it (including the Privacy Protection (Data Security) Regulations, 5777-2017); Regulation (EU) 2016/679 (the “GDPR”); the UK GDPR and the Data Protection Act 2018; and the California Consumer Privacy Act.
- “Personal Data” means any information within the Customer Data that relates to an identified or identifiable individual, or that otherwise constitutes personal data, personal information or equivalent under Applicable Data Protection Law.
- “Data Subject”, “Controller”, “Processor”, “Processing” and “Supervisory Authority” have the meanings given to them in the GDPR, and equivalent terms under other Applicable Data Protection Law shall be read accordingly.
- “Sub-processor” means any third party engaged by us to process Personal Data on the Customer’s behalf in connection with the Services.
- “Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data processed by us on the Customer’s behalf.
- “Standard Contractual Clauses” means the standard contractual clauses for the transfer of personal data to third countries approved by the European Commission, and, for the United Kingdom, the International Data Transfer Addendum issued by the Information Commissioner.
2. Roles of the Parties
The parties acknowledge that, in respect of Personal Data contained in Customer Data, the Customer is the Controller and Capitan Ltd. is the Processor. The Customer determines the purposes and means of the processing; we process such Personal Data only on the Customer’s behalf and under its instructions.
This allocation reflects the nature of the Platform. Because the Platform is a no-code environment, the Customer decides what data models, forms, records, workflows and reports to build, what Personal Data to collect through them, who may access it, and for how long it is kept. We provide the tools; the Customer determines the processing.
This DPA does not apply to Personal Data for which we act as Controller, including User Data and Prospect Data as described in our Privacy Policy, which governs that processing.
The subject matter, duration, nature and purpose of the processing, the types of Personal Data and the categories of Data Subjects are set out in Annex I.
3. The Customer’s Obligations
The Customer warrants and undertakes that:
- it has, and will maintain throughout the term, a lawful basis for the processing of Personal Data through the Services, and has provided all notices and obtained all consents required under Applicable Data Protection Law;
- its instructions to us will comply with Applicable Data Protection Law, and it is solely responsible for the accuracy, quality and legality of the Personal Data and of the means by which it acquired that data;
- it is responsible for the configuration of its Customer Solutions, including the permission schemes, retention settings, access rules and integrations it establishes, and for ensuring that they are appropriate to the sensitivity of the Personal Data it processes; and
- it will not submit to the Platform any special categories of personal data within the meaning of Article 9 of the GDPR, or data relating to criminal convictions and offences, unless the parties have agreed in writing to the additional measures appropriate to such data.
The Customer acknowledges that we have no visibility into, and exercise no control over, the content the Customer chooses to place in its Account.
4. Our Obligations as Processor
Documented instructions: We will process Personal Data only on the Customer’s documented instructions, including with regard to transfers, unless required to do otherwise by a law to which we are subject. In that case we will inform the Customer of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest. The Terms, this DPA, the Customer’s use and configuration of the Services, and any written instructions the Customer gives through the support channels described in the Terms, together constitute the Customer’s documented instructions.
Unlawful instructions: We will inform the Customer without undue delay if, in our opinion, an instruction infringes Applicable Data Protection Law. We may suspend performance of the affected instruction until it is confirmed, amended or withdrawn.
Confidentiality: We will ensure that persons authorised to process the Personal Data are bound by an appropriate obligation of confidentiality, whether contractual or statutory, and that access is limited to those personnel who need it to perform our obligations under the Terms.
Security: We will implement and maintain the technical and organisational measures set out in Annex II, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing, and the risks to Data Subjects. We may update those measures from time to time provided that the level of protection is not materially reduced.
Records: We will maintain records of the categories of processing carried out on the Customer’s behalf, as required by Article 30(2) of the GDPR.
5. Sub-processors
The Customer grants us general written authorisation to engage Sub-processors for the provision of the Services. The Sub-processors engaged as at the date of this DPA are listed in Annex III.
Where we engage a Sub-processor, we will impose on it, by written contract, data protection obligations that are no less protective than those set out in this DPA, and we remain fully liable to the Customer for the performance of that Sub-processor’s obligations.
We will give the Customer at least thirty (30) days’ prior notice of the addition or replacement of any Sub-processor. The Customer may object on reasonable data protection grounds within that period by notice to [email protected]. If the parties cannot resolve the objection in good faith, the Customer may terminate the affected subscription and receive a refund of fees pre-paid for the unused remainder of the term, which shall be the Customer’s sole remedy.
6. Location of Processing and International Transfers
Personal Data processed by us on the Customer’s behalf is stored and processed in Israel, save to the extent otherwise stated in Annex III in respect of a Sub-processor. Certain limited categories of Personal Data are processed outside Israel by Sub-processors, as identified in Annex III – in particular, device identifiers and notification content necessary to deliver push notifications to mobile devices, and recipient details and message content necessary to deliver transactional email.
Israel is a jurisdiction recognised by the European Commission, the UK Secretary of State and the Swiss Federal Data Protection and Information Commissioner as offering an adequate level of protection for personal data. Transfers of Personal Data from the EEA, the United Kingdom and Switzerland to us in Israel are made on that basis.
Where a Sub-processor processes Personal Data in a jurisdiction that is not subject to such a recognition, that processing is governed by our agreement with that Sub-processor, which incorporates the data protection terms and international transfer mechanisms that the provider makes available, including the Standard Contractual Clauses where applicable. If a recognition of adequacy on which a transfer relies is withdrawn or invalidated, the parties will cooperate in good faith to put an alternative lawful transfer mechanism in place without undue delay.
7. Assistance with Data Subject Requests
The Platform provides the Customer’s Account Admins with the ability to access, correct, export and delete Personal Data held in the Account. The Customer will use those facilities to respond to requests from Data Subjects in the first instance.
Taking into account the nature of the processing, we will assist the Customer by appropriate technical and organisational measures, insofar as this is possible, in fulfilling its obligation to respond to requests to exercise rights under Applicable Data Protection Law.
If we receive a request from a Data Subject relating to Personal Data processed on the Customer’s behalf, we will not respond to it directly other than to acknowledge receipt and to direct the Data Subject to the Customer, and we will forward the request to the Customer without undue delay.
8. Assistance with Impact Assessments and Consultation
Taking into account the nature of the processing and the information available to us, we will provide the Customer with reasonable assistance in relation to its obligations under Articles 32 to 36 of the GDPR (or equivalent provisions of other Applicable Data Protection Law), including data protection impact assessments and prior consultation with a Supervisory Authority. We may charge a reasonable fee for assistance that goes materially beyond the provision of our standard documentation.
9. Personal Data Breach
We will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Personal Data processed on the Customer’s behalf.
Our notification will describe, to the extent then known to us and insofar as reasonably possible: the nature of the breach, including where possible the categories and approximate number of Data Subjects and records concerned; the likely consequences of the breach; the measures taken or proposed to address it and to mitigate its adverse effects; and a contact point for further information. Where we cannot provide all of that information at once, we will provide it in phases as it becomes available.
We will cooperate with the Customer and take such reasonable steps as the Customer directs to assist in the investigation, mitigation and remediation of the breach. Our notification is not, and shall not be construed as, an acknowledgement of fault or liability.
It is the Customer’s responsibility, as Controller, to determine whether a Personal Data Breach requires notification to a Supervisory Authority or to Data Subjects, and to make any such notification.
10. Return and Deletion
Upon termination or expiry of the Customer’s subscription, we will, at the Customer’s election, delete or return the Personal Data processed on its behalf, in accordance with Section 15 of the Terms: for thirty (30) days following termination we will make the Customer Data available for export on written request, and thereafter we will delete it, and will do so within ninety (90) days of termination.
Personal Data contained in routine backups will be deleted in the ordinary course of our backup cycle, and until deletion will remain subject to the security measures and confidentiality obligations of this DPA. We may retain Personal Data to the extent, and for as long as, required by a law to which we are subject, and in that case will continue to protect it in accordance with this DPA.
We will confirm deletion in writing upon the Customer’s reasonable request.
11. Audits
We will make available to the Customer all information reasonably necessary to demonstrate compliance with the obligations set out in this DPA, and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by it.
The Customer agrees that such information and audit rights are satisfied by our provision of documentation describing the measures set out in Annex II, and by our response, no more than once in any twelve (12) month period, to a reasonable written security questionnaire submitted to [email protected]. We will respond to such a questionnaire within thirty (30) days.
Where a Supervisory Authority with jurisdiction over the Customer requires an inspection that cannot be satisfied in that manner, the parties will cooperate in good faith to agree the scope, timing and cost of it.
Any audit is subject to reasonable prior written notice, must be conducted during normal business hours, must not unreasonably disrupt our business, must not grant access to the data or systems of any other customer, and is subject to the confidentiality obligations in the Terms.
12. Liability
Each party’s liability arising out of or in connection with this DPA is subject to the exclusions and limitations of liability set out in Section 13 of the Terms, and any claim under this DPA counts towards, and does not increase, the aggregate cap set out there, except to the extent that Applicable Data Protection Law prevents such limitation.
13. Term
This DPA takes effect on the date the Customer accepts the Terms or otherwise begins using the Services, and continues for as long as we process Personal Data on the Customer’s behalf. Sections 9 to 12 survive termination for as long as we retain any such Personal Data.
14. Governing Law
This DPA is governed by the laws of the State of Israel, and the competent courts of Tel Aviv-Yafo have exclusive jurisdiction, as provided in Section 17 of the Terms – save that, where the Standard Contractual Clauses apply to a transfer, the governing law and forum provisions of those clauses prevail in respect of that transfer.
15. Contact
All notices and requests under this DPA should be sent to [email protected], or by post to Capitan Ltd., Alfei Menashe, Israel.
Annex I – Description of the Processing
Controller: the Customer, as identified in the applicable Order Form.
Processor: Capitan Ltd. (company no. 515184711), Alfei Menashe, Israel.
Subject matter of the processing: the provision of the Capitán no-code business platform and related Services under the Terms.
Nature and purpose of the processing: hosting, storage, organisation, structuring, retrieval, consultation, use, transmission, backup, erasure and destruction of Personal Data, as necessary to operate the Account and the Customer Solutions the Customer builds, and to provide support, maintenance and security for the Services.
Duration of the processing: for the term of the Customer’s subscription, followed by the export and deletion periods described in Section 10 of this DPA.
Frequency of the processing: continuous, for as long as the Customer uses the Services.
Categories of Data Subjects: determined by the Customer through its configuration of the Platform, and typically including the Customer’s employees, contractors, job applicants, customers, suppliers, visitors and other individuals whose records the Customer chooses to maintain in its Account.
Categories of Personal Data: determined by the Customer, and typically including:
- identification and contact details (such as name, employee or record identifier, email address, telephone number, address);
- organisational details (such as role, department, site, manager, permissions and account credentials);
- records created within the Customer Solutions – for example workforce and attendance records in Capitán HR, task and assignment records in Capitán PM, production, quality and traceability records in Capitán MES, and maintenance and service records in Capitán FM;
- content submitted to the Account, including free-text fields, comments, documents, images and attachments; and
- technical and usage data generated by use of the Platform, such as IP addresses, device and browser information, activity logs and audit trails.
Special categories of personal data: none is intended or required. The Platform is not designed for the processing of special category data, and the Customer undertakes in Section 3 not to submit such data without prior written agreement between the parties.
Annex II – Technical and Organisational Measures
The following measures are in place as at the date of this DPA. We review them periodically and may update them in accordance with Section 4, provided that the level of protection is not materially reduced.
Encryption in transit: All communication between users’ devices and the Platform is encrypted in transit using industry-standard transport layer security (HTTPS/TLS).
Authentication and access control: Access to the Platform requires authentication. Multi-factor authentication is available and may be enabled by the Customer for its Users; it is not enforced by default. Within the Platform, role-based access control restricts each User to the records and functions permitted by the role assigned to them by the Customer’s Account Admin. Access by our own personnel to production systems is limited to those individuals who require it in order to operate and support the Services.
Confidentiality of personnel: Personnel authorised to process Personal Data are bound by obligations of confidentiality, as provided in Section 4 of this DPA.
Segregation of Customer environments: Each Customer’s data is held within its own Account, and access is scoped to that Account.
Backups: Routine backups are performed as part of the ordinary operation of the Platform. As stated in Section 4 of the Terms, backups are a disaster-recovery measure and not an archiving service, and the Customer remains responsible for maintaining its own copies of business-critical data.
Sub-processor controls: Sub-processors are engaged under written contracts imposing data protection obligations no less protective than those in this DPA, as provided in Section 5.
Annex III – Sub-processors
The following Sub-processors are engaged as at the date of this DPA:
- OMC – Israel. Hosting and operation of the Platform and its databases. Personal Data involved: all Customer Data held in the Account.
- Google (Firebase Cloud Messaging) – United States and other locations operated by the provider. Delivery of push notifications to mobile devices. Personal Data involved: device identifiers (push tokens) and the content of the notification message.
- SMTP2GO – United States. Delivery of transactional email, such as account, notification and password-reset messages. Personal Data involved: recipient name, email address and message content. Message data is retained by the provider for up to 35 days by default.
- Multisend – Israel. Delivery of transactional SMS messages. Personal Data involved: recipient telephone number and message content.
Error monitoring and diagnostics are performed using our own internal platform tooling and do not involve a Sub-processor.
An up-to-date list of Sub-processors is available on request from [email protected]. Changes are notified in accordance with Section 5.