CAPTiXCapture opportunities
pl·fr·en
Book a demo
← Home

Data Processing Terms

CAPTiX's GDPR Article 28 data processing terms: how we process personal data on behalf of customers, sub-processing, international transfers and security.

Effective date: 2026-08-07

1. Scope and acceptance

These CAPTiX Data Processing Terms ("Terms") apply whenever CAPTiX sp. z o.o. ("CAPTiX", "we") processes personal data on behalf of a customer ("Customer", "you") in connection with the Aikando software and related XR/AR hardware, mobile applications or web applications ("Products"), regardless of whether the Customer contracts directly with CAPTiX or through an authorised reseller ("Partner"). By first accessing or starting to use the Products, the Customer agrees to be bound by these Terms, which constitute a binding data processing agreement between the Customer and CAPTiX within the meaning of Article 28 of Regulation (EU) 2016/679 ("GDPR") and equivalent data protection laws applicable to the processing. These Terms are incorporated by reference into, and form an integral part of, the agreement governing the Customer's use of the Products, regardless of whether that agreement was entered into directly with CAPTiX or through a Partner.

2. Definitions

"GDPR" means Regulation (EU) 2016/679. The terms "personal data", "processing", "controller", "processor", "data subject" and "personal data breach" have the meanings given to them in the GDPR. "Sub-processor" means any processor engaged by CAPTiX to process personal data on behalf of the Customer. "Products" means the Aikando software, integrations with XR/AR hardware, and related mobile or web applications provided by CAPTiX. "Recordings" means any video or audio recordings created as a result of a voluntary, user-initiated use of the optional recording feature of the Products, as described in section 6.

3. Roles of the parties

With respect to personal data that the Customer or its authorised users ("Users") upload, generate or otherwise input into the Products, the Customer is the controller and CAPTiX is the processor, with CAPTiX processing that personal data only on the Customer's documented instructions (including instructions given through the Products' configuration settings), unless required to do otherwise by European Union or Member State law to which CAPTiX is subject; in such a case, CAPTiX shall inform the Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.

With respect to account administration, billing, licence management, security event logging and service telemetry that CAPTiX collects to operate, secure and maintain the Products and its relationship with the Customer, CAPTiX acts as an independent controller and determines the purposes and means of that processing on its own.

4. Subject matter, duration, nature and purpose of processing

Subject matter: providing the Products to the Customer. Duration: for the term of the agreement between the Customer and CAPTiX, whether entered into directly or through a Partner, plus the retention periods described in sections 6 and 12. Nature: the automated collection, storage, organisation, retrieval, use and deletion of personal data to the extent necessary for the Products to function. Purpose: providing, supporting, securing and maintaining the Products, including account activation and licence verification, technical support and diagnostics, and, where the Customer activates the relevant optional feature, the recording, cloud storage and cross-platform access to training session content described in section 6.

5. Categories of data subjects and categories of personal data

Data subjects: the Customer's Users, meaning employees and contractors who use the Products, and, incidentally, third parties who may appear in Recordings made using the point-of-view (POV) recording feature.

Categories of personal data:

CAPTiX does not intentionally process special categories of personal data within the meaning of Article 9 of the GDPR, and does not analyse or classify Recordings to detect such data.

6. Optional feature: recordings, cloud backup and cross-platform access

CAPTiX may provide the Customer with an optional feature allowing Users to record Product sessions and, if the Customer activates the relevant setting, to store those Recordings in the cloud and access them from multiple devices or platforms. This feature is disabled by default until and unless the Customer activates it, and may be disabled by the Customer at any time. Recording of each session is always initiated by a deliberate, manual action of the User; the Products do not record continuously or without the User's knowledge.

Where this feature is activated:

The above technical parameters (retention period, backup cycle and choice of sub-processor) are default settings that CAPTiX may update as this feature is further developed, provided the safeguards described above regarding location, encryption, access control and no further use are maintained, and provided that any change of sub-processor follows the notice-and-objection procedure described in section 8. Updating these technical parameters does not require a new version of these Terms.

7. CAPTiX's obligations as processor

CAPTiX undertakes to:

8. Sub-processing

The Customer generally authorises CAPTiX to use sub-processors, in particular for hosting, infrastructure and technical support, subject to the provisions of this section. The current list of sub-processors is published at https://www.captix.eu/subprocessors.

Before adding a new sub-processor or replacing an existing one, CAPTiX will update this page and give at least 14 days' notice by updating the "last updated" date and the change log on that page. The Customer may object to a new sub-processor on reasonable data protection grounds within that period by contacting privacy@captix.eu; if the parties cannot reach agreement, the Customer may terminate the affected part of the Products without penalty. CAPTiX will ensure that each sub-processor is bound by data protection obligations no less protective than those set out in these Terms, and remains liable to the Customer for the performance of those obligations by each sub-processor.

Where the Customer's agreement is entered into through a Partner, the Partner may access the Customer's personal data only to the extent strictly necessary to provide support in connection with the Products, acting in that capacity as a sub-processor of CAPTiX. The Partner's access is subject to confidentiality obligations, role-based access control and event logging, and the Partner shall return or delete such personal data once its role has ended, in accordance with the Partner's agreement with CAPTiX. This section, together with the Partner's agreement with CAPTiX, constitutes the sub-processing terms that the Partner must accept before being given access to the Customer's personal data.

9. International transfers

Where a sub-processor processes personal data outside the EEA, CAPTiX will do so only on the basis of a transfer mechanism recognised under applicable data protection law, such as the European Commission's Standard Contractual Clauses or an appropriate adequacy decision, and will disclose the transfer mechanism and safeguards used on request. CAPTiX complies with the data protection laws applicable to it and to the provision of the Products in the Customer's jurisdiction. If the Customer's agreement is transferred to a new Partner, previously processed personal data is transferred to that new Partner on the same basis described in this section.

10. Security measures

CAPTiX implements technical and organisational measures appropriate to the risk, including, among others: access control based on the principle of least privilege, multi-factor authentication for administrative access, encryption of data in transit and, where technically feasible, at rest, logging and monitoring of access to personal data, a security incident management process, regular testing and updating of security measures, segregation of environments, backup and restore procedures, vulnerability management, and regular staff training. On request, CAPTiX will provide the Customer with a description of the security measures currently in place, to the extent reasonably necessary to assess compliance.

11. Right to audit

The Customer may audit CAPTiX's compliance with these Terms, including by way of an on-site inspection, no more than once per calendar year, on at least 14 days' prior written notice, except where the Customer has a reasonable suspicion of a security incident, a breach of these Terms or a material data protection incident, in which case this restriction does not apply. The audit may cover only compliance with these Terms and applicable data protection law. The Customer bears the costs of the audit.

12. Term, deletion and return of data

These Terms remain in effect for as long as CAPTiX processes personal data on the Customer's behalf under the agreement governing the Customer's use of the Products. Upon termination of the agreement, CAPTiX will, at the Customer's choice, delete or return all personal data and copies of it within 30 days, unless applicable law requires further storage, and will confirm deletion in writing on request. This does not apply to data anonymised in accordance with section 14, except to the extent it would allow identification of the Customer, its processes, facilities, materials, metrics or know-how.

13. Rights of data subjects

CAPTiX assists the Customer, in accordance with section 7, in responding to requests from data subjects. Data subjects wishing to exercise their rights should, as a general rule, contact the Customer directly as the controller of their personal data; any requests received by CAPTiX in error will be forwarded to the Customer without undue delay.

14. Aggregated and anonymised data

Notwithstanding the processing described above, and subject to the exclusion for Recordings described in section 6, the Customer agrees that CAPTiX may anonymise and aggregate technical, telemetry and usage data generated in the course of providing the Products, and may use such anonymised and aggregated data for its own purposes, including improving the Products, developing machine-learning models, and statistical, research and marketing purposes. Once anonymised in a way that no longer allows identification of a natural person, such data ceases to be personal data and becomes the sole property of CAPTiX.

15. Updates to these terms

CAPTiX may update these Terms to reflect changes to the Products, applicable law, or its processing activities. Material changes will be reflected by updating the effective date at the top of this page; if a change would reduce the level of safeguards the Customer relies on, CAPTiX will give the Customer reasonable advance notice.

16. Governing language

These Terms have been drawn up in English, which is the governing version. Translations into other languages are provided for information only; in the event of any discrepancy, the English version prevails.

17. Contact

Questions about these Terms or about CAPTiX's processing of personal data can be sent to privacy@captix.eu.