Data Processing Terms
CAPTiX's GDPR Article 28 data processing terms: how we process personal data on behalf of customers, sub-processing, international transfers and security.
Effective date: 2026-08-07
1. Scope and acceptance
These CAPTiX Data Processing Terms ("Terms") apply whenever CAPTiX sp. z o.o. ("CAPTiX", "we") processes personal data on behalf of a customer ("Customer", "you") in connection with the Aikando software and related XR/AR hardware, mobile applications or web applications ("Products"), regardless of whether the Customer contracts directly with CAPTiX or through an authorised reseller ("Partner"). By first accessing or starting to use the Products, the Customer agrees to be bound by these Terms, which constitute a binding data processing agreement between the Customer and CAPTiX within the meaning of Article 28 of Regulation (EU) 2016/679 ("GDPR") and equivalent data protection laws applicable to the processing. These Terms are incorporated by reference into, and form an integral part of, the agreement governing the Customer's use of the Products, regardless of whether that agreement was entered into directly with CAPTiX or through a Partner.
2. Definitions
"GDPR" means Regulation (EU) 2016/679. The terms "personal data", "processing", "controller", "processor", "data subject" and "personal data breach" have the meanings given to them in the GDPR. "Sub-processor" means any processor engaged by CAPTiX to process personal data on behalf of the Customer. "Products" means the Aikando software, integrations with XR/AR hardware, and related mobile or web applications provided by CAPTiX. "Recordings" means any video or audio recordings created as a result of a voluntary, user-initiated use of the optional recording feature of the Products, as described in section 6.
3. Roles of the parties
With respect to personal data that the Customer or its authorised users ("Users") upload, generate or otherwise input into the Products, the Customer is the controller and CAPTiX is the processor, with CAPTiX processing that personal data only on the Customer's documented instructions (including instructions given through the Products' configuration settings), unless required to do otherwise by European Union or Member State law to which CAPTiX is subject; in such a case, CAPTiX shall inform the Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
With respect to account administration, billing, licence management, security event logging and service telemetry that CAPTiX collects to operate, secure and maintain the Products and its relationship with the Customer, CAPTiX acts as an independent controller and determines the purposes and means of that processing on its own.
4. Subject matter, duration, nature and purpose of processing
Subject matter: providing the Products to the Customer. Duration: for the term of the agreement between the Customer and CAPTiX, whether entered into directly or through a Partner, plus the retention periods described in sections 6 and 12. Nature: the automated collection, storage, organisation, retrieval, use and deletion of personal data to the extent necessary for the Products to function. Purpose: providing, supporting, securing and maintaining the Products, including account activation and licence verification, technical support and diagnostics, and, where the Customer activates the relevant optional feature, the recording, cloud storage and cross-platform access to training session content described in section 6.
5. Categories of data subjects and categories of personal data
Data subjects: the Customer's Users, meaning employees and contractors who use the Products, and, incidentally, third parties who may appear in Recordings made using the point-of-view (POV) recording feature.
Categories of personal data:
- Identification data: name, e-mail address and user identifiers necessary for login and licensing.
- Technical and usage data: session metadata, diagnostic logs and telemetry generated by the Products, to the extent collected for support, security and performance purposes.
- Account and cross-platform access data: account identifiers, login history and the list of devices or platforms linked to the account, where the optional cross-platform access feature described in section 6 is activated.
- Recordings: where the optional recording feature is activated, video and audio captured from a point-of-view (POV) perspective during a Product session, showing primarily the User's hands and immediate working environment, which may incidentally and unavoidably include the image or voice of third parties present in the recording frame.
CAPTiX does not intentionally process special categories of personal data within the meaning of Article 9 of the GDPR, and does not analyse or classify Recordings to detect such data.
6. Optional feature: recordings, cloud backup and cross-platform access
CAPTiX may provide the Customer with an optional feature allowing Users to record Product sessions and, if the Customer activates the relevant setting, to store those Recordings in the cloud and access them from multiple devices or platforms. This feature is disabled by default until and unless the Customer activates it, and may be disabled by the Customer at any time. Recording of each session is always initiated by a deliberate, manual action of the User; the Products do not record continuously or without the User's knowledge.
Where this feature is activated:
- Location: Recordings and their backups are stored solely on infrastructure located within the European Economic Area (EEA). CAPTiX will not transfer Recordings outside the EEA without the Customer's prior written consent.
- Retention: Recordings are stored by default for 90 days from the date of creation, after which they are automatically and permanently deleted, unless the Customer configures a different retention period in the Products' settings. The Customer is solely responsible for setting a retention period that complies with the laws applicable to it, including local rules on recording or monitoring in the workplace.
- Backups: backups are created at intervals of no more than 24 hours, encrypted at rest using AES-256 or an equivalent standard, encrypted in transit using TLS 1.2 or higher, and deleted within no more than 30 days of the deletion of the corresponding source data.
- Access control: accessing Recordings from multiple devices or platforms requires individual User authentication. CAPTiX provides the Customer's administrators with the ability to remotely revoke access from a given device, logs access events (who accessed a Recording, when and from which device) for a period of no less than 12 months, and applies session expiry in line with good security practice.
- Sub-processor: CAPTiX will use the sub-processor listed at https://www.captix.eu/subprocessors, located within the EEA, to provide the cloud storage element of this feature, and will follow the notice-and-objection procedure described in section 8 before using any sub-processor not yet listed there.
- No further use: Recordings are excluded from the scope of the aggregation and anonymisation rights described in section 14. CAPTiX does not use Recordings, including anonymised or aggregated derivatives of them, for machine-learning development, product research, statistical purposes or marketing purposes, unless the parties separately agree otherwise in writing for a specific, defined purpose.
The above technical parameters (retention period, backup cycle and choice of sub-processor) are default settings that CAPTiX may update as this feature is further developed, provided the safeguards described above regarding location, encryption, access control and no further use are maintained, and provided that any change of sub-processor follows the notice-and-objection procedure described in section 8. Updating these technical parameters does not require a new version of these Terms.
7. CAPTiX's obligations as processor
CAPTiX undertakes to:
- process personal data only on the Customer's documented instructions, unless required to do otherwise by law, in which case CAPTiX will inform the Customer beforehand, unless that law prohibits such information;
- ensure that persons authorised to process personal data have committed themselves to confidentiality;
- implement appropriate technical and organisational measures as described in section 9;
- assist the Customer, through appropriate technical and organisational measures, in responding to requests from data subjects exercising their rights under applicable data protection law;
- assist the Customer in complying with its obligations relating to the security of processing, breach notification and data protection impact assessments, taking into account the nature of the processing and the information available to CAPTiX;
- notify the Customer of a personal data breach without undue delay, and in any event within 48 hours of becoming aware of it;
- maintain a record of the categories of processing activities carried out on the Customer's behalf and make available to the Customer the information necessary to demonstrate compliance with this section.
8. Sub-processing
The Customer generally authorises CAPTiX to use sub-processors, in particular for hosting, infrastructure and technical support, subject to the provisions of this section. The current list of sub-processors is published at https://www.captix.eu/subprocessors.
Before adding a new sub-processor or replacing an existing one, CAPTiX will update this page and give at least 14 days' notice by updating the "last updated" date and the change log on that page. The Customer may object to a new sub-processor on reasonable data protection grounds within that period by contacting privacy@captix.eu; if the parties cannot reach agreement, the Customer may terminate the affected part of the Products without penalty. CAPTiX will ensure that each sub-processor is bound by data protection obligations no less protective than those set out in these Terms, and remains liable to the Customer for the performance of those obligations by each sub-processor.
Where the Customer's agreement is entered into through a Partner, the Partner may access the Customer's personal data only to the extent strictly necessary to provide support in connection with the Products, acting in that capacity as a sub-processor of CAPTiX. The Partner's access is subject to confidentiality obligations, role-based access control and event logging, and the Partner shall return or delete such personal data once its role has ended, in accordance with the Partner's agreement with CAPTiX. This section, together with the Partner's agreement with CAPTiX, constitutes the sub-processing terms that the Partner must accept before being given access to the Customer's personal data.
9. International transfers
Where a sub-processor processes personal data outside the EEA, CAPTiX will do so only on the basis of a transfer mechanism recognised under applicable data protection law, such as the European Commission's Standard Contractual Clauses or an appropriate adequacy decision, and will disclose the transfer mechanism and safeguards used on request. CAPTiX complies with the data protection laws applicable to it and to the provision of the Products in the Customer's jurisdiction. If the Customer's agreement is transferred to a new Partner, previously processed personal data is transferred to that new Partner on the same basis described in this section.
10. Security measures
CAPTiX implements technical and organisational measures appropriate to the risk, including, among others: access control based on the principle of least privilege, multi-factor authentication for administrative access, encryption of data in transit and, where technically feasible, at rest, logging and monitoring of access to personal data, a security incident management process, regular testing and updating of security measures, segregation of environments, backup and restore procedures, vulnerability management, and regular staff training. On request, CAPTiX will provide the Customer with a description of the security measures currently in place, to the extent reasonably necessary to assess compliance.
11. Right to audit
The Customer may audit CAPTiX's compliance with these Terms, including by way of an on-site inspection, no more than once per calendar year, on at least 14 days' prior written notice, except where the Customer has a reasonable suspicion of a security incident, a breach of these Terms or a material data protection incident, in which case this restriction does not apply. The audit may cover only compliance with these Terms and applicable data protection law. The Customer bears the costs of the audit.
12. Term, deletion and return of data
These Terms remain in effect for as long as CAPTiX processes personal data on the Customer's behalf under the agreement governing the Customer's use of the Products. Upon termination of the agreement, CAPTiX will, at the Customer's choice, delete or return all personal data and copies of it within 30 days, unless applicable law requires further storage, and will confirm deletion in writing on request. This does not apply to data anonymised in accordance with section 14, except to the extent it would allow identification of the Customer, its processes, facilities, materials, metrics or know-how.
13. Rights of data subjects
CAPTiX assists the Customer, in accordance with section 7, in responding to requests from data subjects. Data subjects wishing to exercise their rights should, as a general rule, contact the Customer directly as the controller of their personal data; any requests received by CAPTiX in error will be forwarded to the Customer without undue delay.
14. Aggregated and anonymised data
Notwithstanding the processing described above, and subject to the exclusion for Recordings described in section 6, the Customer agrees that CAPTiX may anonymise and aggregate technical, telemetry and usage data generated in the course of providing the Products, and may use such anonymised and aggregated data for its own purposes, including improving the Products, developing machine-learning models, and statistical, research and marketing purposes. Once anonymised in a way that no longer allows identification of a natural person, such data ceases to be personal data and becomes the sole property of CAPTiX.
15. Updates to these terms
CAPTiX may update these Terms to reflect changes to the Products, applicable law, or its processing activities. Material changes will be reflected by updating the effective date at the top of this page; if a change would reduce the level of safeguards the Customer relies on, CAPTiX will give the Customer reasonable advance notice.
16. Governing language
These Terms have been drawn up in English, which is the governing version. Translations into other languages are provided for information only; in the event of any discrepancy, the English version prevails.
17. Contact
Questions about these Terms or about CAPTiX's processing of personal data can be sent to privacy@captix.eu.