Data Processing Addendum
Last updated · Circo, Inc.
In plain English
- This addendum applies automatically when a company uses Capable. There is nothing extra to sign, but we will countersign a copy on request.
- The company controls its stakeholder data. We process it only to run Capable, on the company’s instructions.
- We give 30 days’ notice before adding a sub-processor, and you can object.
- We tell you about a personal data breach without undue delay, and within 72 hours at most.
- EU, UK, and Swiss transfers are covered by the Standard Contractual Clauses and the UK Addendum, incorporated here by reference.
- Under US state privacy laws we are your service provider: we do not sell, share, or reuse your data.
This summary helps you read the document. The numbered sections below are what bind.
Contents
- 1.Scope and precedence
- 2.Definitions
- 3.Roles of the parties
- 4.Processing on instructions
- 5.Capable personnel
- 6.Sub-processors
- 7.Security
- 8.Personal data breach notification
- 9.Data subject requests and assistance
- 10.International transfers
- 11.Audits and information
- 12.Return and deletion
- 13.US state privacy law terms
- 14.Liability and general terms
- 15.Annex 1: Details of processing
- 16.Annex 2: Technical and organizational measures
- 17.Annex 3: Sub-processors
1. Scope and precedence
This Data Processing Addendum (“DPA”) forms part of the Terms of Service or other written agreement (the “Agreement”) between Circo, Inc. (“Capable”) and the customer that uses Capable (“Customer”). It applies whenever Capable processes Customer Personal Data in providing the Service.
The DPA takes effect when the Agreement does and lasts as long as Capable processes Customer Personal Data. If the DPA conflicts with the Agreement on the processing of personal data, the DPA controls. If the DPA conflicts with the Standard Contractual Clauses, the Standard Contractual Clauses control.
2. Definitions
- “Data Protection Laws” means all laws on privacy and personal data that apply to a party’s processing under the Agreement, including the EU General Data Protection Regulation 2016/679 (“GDPR”), the GDPR as it forms part of UK law with the UK Data Protection Act 2018 (“UK GDPR”), the Swiss Federal Act on Data Protection (“FADP”), and the California Consumer Privacy Act as amended (“CCPA”) and similar US state laws.
- “Customer Personal Data” means personal data within Customer Data, as defined in the Agreement, that Capable processes on Customer’s behalf.
- “Standard Contractual Clauses” or “SCCs” means the clauses annexed to European Commission Implementing Decision (EU) 2021/914.
- “UK Addendum” means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner, version B1.0, in force from March 21, 2022.
- “Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data.
- “Sub-processor” means a third party Capable engages to process Customer Personal Data.
“Controller”, “processor”, “data subject”, “personal data”, “processing”, “supervisory authority”, “business”, “service provider”, “sell”, and “share” have the meanings given in the applicable Data Protection Laws.
3. Roles of the parties
For Customer Personal Data, Customer is the controller, or a processor acting for its own controller, and Capable is a processor, or a sub-processor. Capable is an independent controller only of the account, billing, security, and operational data described in the Privacy Policy, and this DPA does not apply to that data.
Customer is responsible for having a lawful basis for the processing, for giving data subjects any required notices, including to stakeholders it invites or records, and for the accuracy of the data and the lawfulness of its instructions. Annex 1 describes the processing.
4. Processing on instructions
Capable processes Customer Personal Data only on Customer’s documented instructions, unless the law requires otherwise. In that case Capable will tell Customer before processing, unless the law prohibits it. The Agreement, this DPA, and Customer’s configuration and use of the Service, including which features and integrations it turns on, are Customer’s complete instructions. Other instructions require written agreement.
Capable will tell Customer if it believes an instruction violates Data Protection Laws, and may pause the relevant processing until the instruction is confirmed or changed.
Capable does not use Customer Personal Data to train AI models and requires its AI model providers not to do so.
5. Capable personnel
Capable limits access to Customer Personal Data to personnel who need it to provide, support, or secure the Service. Those people are bound by written confidentiality obligations and receive training on data protection and security.
6. Sub-processors
Authorization. Customer gives Capable general authorization to engage Sub-processors. The current list is in Annex 3 and on the sub-processor page.
Flow-down. Capable will impose data protection terms on each Sub-processor that are no less protective than this DPA, to the extent relevant to its service, and remains liable to Customer for each Sub-processor’s performance of those obligations.
Notice of changes. Capable will give at least 30 days’ notice before a new Sub-processor starts processing Customer Personal Data, by updating the sub-processor page and emailing the owners of paying workspaces and anyone who subscribes to updates. In an emergency, such as replacing a failed provider to keep the Service running, Capable may give shorter notice and will explain why.
Objection. Customer may object on reasonable data protection grounds by emailing privacy@capable.so within the notice period. The parties will discuss the concern in good faith. If Capable cannot offer a reasonable alternative, Customer may terminate the affected part of the Service and receive a pro-rata refund of prepaid fees for the unused period.
7. Security
Capable implements and maintains the technical and organizational measures in Annex 2, which are designed to protect Customer Personal Data against Personal Data Breaches and to ensure a level of security appropriate to the risk. Capable may update the measures over time, but will not materially reduce the overall protection they provide.
8. Personal data breach notification
Capable will notify Customer of a Personal Data Breach without undue delay, and in any event within 72 hours after becoming aware of it, by email to the workspace owners and admins.
The notice will describe, as far as then known, the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed to address it, with a contact for more information. Where information is not yet available, Capable will provide it in stages as it learns more.
Capable will take reasonable steps to contain and remedy the breach and will cooperate with Customer so that Customer can meet its own notification duties. Notice of a breach is not an admission of fault. Unsuccessful attempts that do not compromise security, such as blocked sign-in attempts or network scans, are not Personal Data Breaches.
9. Data subject requests and assistance
The Service lets Customer’s admins find, correct, export, and delete stakeholder data. If Customer cannot handle a data subject request with those tools, Capable will give reasonable assistance.
If Capable receives a request directly from a data subject about Customer Personal Data, it will direct the person to Customer and will not respond itself, except to confirm the referral or where the law requires.
Taking into account the nature of the processing and the information available to it, Capable will reasonably assist Customer with data protection impact assessments and prior consultations with supervisory authorities.
10. International transfers
Capable processes Customer Personal Data in the United States. Capable may transfer it to other countries only with the safeguards Data Protection Laws require.
EEA transfers. For transfers of Customer Personal Data subject to the GDPR to a country without an adequacy decision, the SCCs are incorporated into this DPA by reference, with Customer as data exporter and Capable as data importer, completed as follows:
- Module Two (controller to processor) applies where Customer is a controller. Module Three (processor to processor) applies where Customer is a processor.
- Clause 7 (docking clause) applies.
- Clause 9: Option 2 (general written authorization) applies, with the notice period in Section 6 of this DPA.
- Clause 11: the optional language does not apply.
- Clause 13: the competent supervisory authority is the one determined by Customer’s establishment or representative under Article 3 GDPR, as set out in Clause 13.
- Clause 17: the SCCs are governed by the law of Ireland.
- Clause 18: disputes are resolved by the courts of Ireland.
- Annex I is completed by Annex 1 of this DPA, Annex II by Annex 2, and Annex III by Annex 3.
UK transfers. For transfers subject to the UK GDPR, the UK Addendum is incorporated by reference. Table 1 is completed with the parties’ details in Annex 1. Table 2 refers to the SCCs as completed above. Table 3 is completed by Annexes 1 to 3. In Table 4, either party may end the UK Addendum as permitted by its Section 19.
Swiss transfers. For transfers subject to the FADP, the SCCs apply as completed above, with these changes: the Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority; references to the GDPR include the FADP; references to member states include Switzerland, so that data subjects in Switzerland may bring claims there.
If a transfer mechanism is invalidated or replaced, the parties will cooperate to adopt a valid alternative.
11. Audits and information
Capable will make available the information reasonably needed to demonstrate compliance with this DPA and Article 28 of the GDPR. Capable meets this first by providing its security documentation, answers to a reasonable security questionnaire once per year, and any available third-party audit reports or certifications, all under confidentiality.
If that information is not enough to demonstrate compliance, or if a supervisory authority requires it or a Personal Data Breach has occurred, Customer may conduct an audit, by itself or through an independent auditor bound by confidentiality who is not a Capable competitor. Customer must give at least 30 days’ notice and a proposed scope. Audits take place during business hours, no more than once per year unless required by a supervisory authority or following a breach, in a way that does not disrupt the Service or expose other customers’ data. Customer bears its own audit costs.
12. Return and deletion
Customer can export Customer Personal Data at any time during the Agreement using the Service’s export tools.
After the Agreement ends, Customer Personal Data remains available for export in read-only mode for 90 days. Within 30 days after that period, Capable deletes Customer Personal Data from its production systems. Copies in backups expire on their normal cycle within a further 30 days and are isolated from further processing until they do. Capable may retain Customer Personal Data longer only where the law requires, and continues to protect it under this DPA while it does.
On written request, Capable will confirm deletion in writing.
13. US state privacy law terms
Where the CCPA or a similar US state law applies, Customer is a business and Capable is its service provider or processor. Capable processes Customer Personal Data only for the business purpose of providing the Service described in the Agreement, and Capable:
- will not sell or share Customer Personal Data;
- will not retain, use, or disclose it for any purpose other than performing the Service, including any commercial purpose, or outside the direct business relationship with Customer, except as the law permits a service provider to do;
- will not combine it with personal information Capable receives from other sources, except as the law permits;
- will comply with the applicable law and give the personal information the same level of privacy protection the law requires of Customer;
- will notify Customer if it determines it can no longer meet these obligations; and
- grants Customer the right, on notice, to take reasonable steps to stop and remediate unauthorized use of the personal information, and to take reasonable steps to confirm that Capable uses it in line with the law, through the process in Section 11.
Capable certifies that it understands and will comply with these restrictions.
14. Liability and general terms
Each party’s liability under this DPA and the SCCs, taken together, is subject to the limitations of liability in the Agreement, except where Data Protection Laws or the SCCs do not allow liability to data subjects to be limited.
This DPA is governed by the law that governs the Agreement, except where the SCCs or Data Protection Laws require otherwise. To receive a countersigned copy, email legal@capable.so.
15. Annex 1: Details of processing
| Data exporter | Customer, as identified in its Capable account. Contact: the workspace owner. Activities: using Capable to manage its capitalization. Role: controller or processor. |
|---|---|
| Data importer | Circo, Inc., 1625 San Carlos Ave, Unit D, San Carlos, CA 94070, USA. Contact: privacy@capable.so. Activities: providing the Capable service. Role: processor. |
| Data subjects | Customer’s founders, directors, officers, employees, former employees, contractors, advisors, investors, and other securityholders; their spouses where spousal consents are collected; Customer’s authorized users. |
| Categories of personal data | Identity and contact details; stakeholder relationship; employment dates; equity holdings, grants, vesting, exercises, transfers, and repurchases; board and stockholder approvals; documents, certificates, and electronic signatures with their audit trails (IP address, browser details, timestamps); HR system data if connected; user account and role data; AI requests and outputs. |
| Sensitive data | Government-issued tax identification numbers, such as Social Security numbers, where Customer records them. Safeguards: encryption in transit and at rest, role-based access limiting who can view them, audit logging. Capable is not designed for special categories of data under Article 9 GDPR. |
| Frequency | Continuous for the term of the Agreement. |
| Nature of processing | Collection, storage, organization, calculation, retrieval, display, transmission, export, and deletion, as needed to host and operate the Service. |
| Purpose | Providing the Service under the Agreement, including support, security, and features Customer enables. |
| Retention | For the term of the Agreement, then as described in Section 12 of this DPA. |
| Transfers to Sub-processors | As listed in Annex 3, for the purposes stated there and for the term of the Agreement. |
16. Annex 2: Technical and organizational measures
Encryption
- All connections to the Service use TLS 1.2 or higher, with HTTP Strict Transport Security.
- Data at rest is encrypted by our infrastructure providers: the database (Turso) and file storage (Railway, and Vercel for legacy files).
Identity and access for customer users
- Passwordless sign-in by email link or Google; no reusable passwords are stored.
- TOTP two-factor authentication for any user, which a workspace owner can require for the whole company.
- Single sign-on with SAML 2.0 or OpenID Connect on plans that include it.
- Role-based access set per company (Owner, Admin, HR admin, Billing admin, Read only). Stakeholders can see only their own records.
- Every database query is scoped to a company the user belongs to, which keeps customers’ data logically separated.
- The AI connector uses OAuth 2.1 with PKCE, short-lived access tokens, and tokens users can revoke. Changes proposed through AI tools require approval by an authorized admin.
Access by Capable personnel
- Production access is limited to the engineers who operate the Service, using accounts protected by single sign-on and multi-factor authentication.
- Personnel access customer data only to provide requested support, to investigate security or abuse, or where the law requires.
- Secrets are held in managed environment variable stores, not in source code.
Logging and monitoring
- An audit log records every cap table transaction, correction, export, and document download, with the actor and time.
- Electronic signatures record consent, IP address, browser details, timestamps, and a hash of the signed document.
- Application and infrastructure logs are monitored for errors and suspicious activity.
Storage, availability, and recovery
- Uploaded files are kept in private storage with no public URLs. Every read goes through an authorized application route.
- The database is backed up continuously, with point-in-time restore for 30 days.
- The Service runs on managed cloud infrastructure with provider-level redundancy.
Secure development
- Every deployment comes from a reviewed commit that passes type checking and the automated test suite.
- Database schema changes are applied deliberately, never by a live request.
- Dependencies are monitored for known vulnerabilities, and we accept reports under our responsible disclosure policy.
Organizational measures
- Personnel sign confidentiality agreements and receive security and privacy training.
- Sub-processors are reviewed before engagement and bound by written data protection terms.
- An incident response process covers triage, containment, customer notification within 72 hours, and follow-up review.
- AI requests send only the data needed for the request, and model providers may not train on it.
- Data is deleted after termination on the schedule in Section 12.
17. Annex 3: Sub-processors
Capable uses the following Sub-processors. Changes are announced as described in Section 6.
| Sub-processor | Purpose | Location |
|---|---|---|
| Vercel Vercel Inc. | Application hosting, content delivery, legacy file storage, and the AI Gateway that routes AI requests to model providers | United States |
| Turso ChiselStrike, Inc. | Primary database | United States (AWS us-west-2) |
| Railway Railway Corporation | Private S3-compatible file storage and Redis cache | United States |
| Stripe Stripe, Inc. | Subscription billing and payment processing | United States |
| Resend Plus Five Five, Inc. | Transactional email delivery | United States |
| OpenAI OpenAI, LLC | AI model provider for the in-app assistant, import mapping, and connector features, reached through Vercel AI Gateway | United States |
| Anthropic Anthropic, PBC | AI model provider for the in-app assistant, import mapping, and connector features, reached through Vercel AI Gateway | United States |
| Google Google LLC | Sign in with Google | United States |
| Finch Finch | HRIS and payroll connectivity, only for companies that connect an HR system (only if enabled) | United States |
| Cloudflare Cloudflare, Inc. | DNS for capable.so | Global network |