DATA PROCESSING ADDENDUM
Revised and effective: September 1, 2026
This Data Processing Addendum ("DPA") supplements and forms part of the Services Agreement found at https://capacity.com/services-agreement/ (the "Agreement") between Subscriber ("Customer" or "Controller") and AI Software, LLC and its affiliates (referred to herein as "Capacity"). Capacity updates this DPA from time to time. The current version of this DPA is available at https://capacity.com/capacity-DPA/
1. DEFINITIONS
1.1 "Applicable Data Protection Laws" means all data protection and privacy laws applicable to the Processing of Personal Data under this DPA, including where applicable:
- EU GDPR (Regulation (EU) 2016/679)
- UK GDPR and the UK Data Protection Act 2018
- Swiss nFADP (Federal Act on Data Protection, effective September 1, 2023)
- California Consumer Privacy Act / CPRA
- Canada's PIPEDA and applicable provincial equivalents
- Brazil's LGPD (Lei Geral de Proteção de Dados)
- Other applicable U.S. state privacy laws
- Any successor or replacement legislation in any applicable jurisdiction
1.2 "Controller," "Processor," "Data Subject," "Personal Data," "Processing," and "Supervisory Authority" have the meanings given under Applicable Data Protection Laws.
1.3 "Data Subject Rights" means the rights of individuals under Applicable Data Protection Laws, including rights of access, rectification, erasure, restriction, portability, objection, opt-out of sale or sharing, and rights relating to automated decision-making.
1.4 "EU SCCs" means the Standard Contractual Clauses annexed to European Commission Implementing Decision 2021/914 of 4 June 2021.
1.5 "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data Processed under this DPA.
1.6 "Sensitive Data" means Personal Data classified as a special category or subject to enhanced protections under Applicable Data Protection Laws, including health data, biometric data, genetic data, racial or ethnic origin, political opinions, religious beliefs, trade union membership, sexual orientation, and government-issued identification numbers.
1.7 "Services" means the products and services provided by Capacity to Customer under the Agreement, including AI-enabled voice, chat, SMS, email, and agent-assist functionality.
1.8 "Subprocessor" means any third party engaged by Capacity to Process Personal Data on Customer's behalf.
1.9 "UK Addendum" means the UK International Data Transfer Addendum issued by the UK ICO under section 119A(1) of the Data Protection Act 2018.
2. ROLES AND SCOPE
2.1 Roles. Customer acts as Controller (or as a Processor on behalf of another Controller). Capacity acts as Processor.
2.2 Scope. This DPA applies to the Processing of Personal Data by Capacity in connection with the Services. Details of the Processing are set out in Annex I.
2.3 Independent Controller Processing. Notwithstanding its role as Processor, Capacity may Process certain Personal Data as an independent Controller for the following purposes: account administration; billing; security and fraud prevention; compliance with legal obligations; and development and improvement of Capacity's AI models and services. Such processing is governed by Applicable Data Protection Laws and Capacity's Privacy Policy.
3. SUBSCRIBER REPRESENTATIONS
Subscriber represents and warrants that on the effective date of this DPA and during its term:
- (a) Personal Data has been and will be collected and Processed by Subscriber in accordance with Applicable Data Protection Laws;
- (b) the Processing of Personal Data in accordance with this DPA by Capacity will not violate Applicable Data Protection Laws;
- (c) Subscriber shall provide Data Subjects with appropriate opt-outs where required under Applicable Data Protection Laws, and shall inform Capacity of any exercise of such rights by a Data Subject; and
- (d) Subscriber will take all steps necessary to ensure it achieves the foregoing, including by providing Data Subjects with appropriate privacy notices, obtaining any required consent, and ensuring there is a lawful basis for Capacity to Process Personal Data.
4. PROCESSING INSTRUCTIONS
4.1 Capacity shall Process Personal Data only on Customer's documented instructions and as necessary to provide the Services, except where otherwise permitted under the Agreement, this DPA or required by applicable law.
4.2 Capacity shall not combine or use Customer's Personal Data in a manner that makes such data individually identifiable to or recoverable by another customer.
4.3 If Capacity believes an instruction infringes Applicable Data Protection Laws, it shall notify Customer without undue delay.
5. SUBPROCESSORS
5.1 General Authorization. Customer authorizes Capacity to engage Subprocessors. The current Subprocessor list is maintained at https://trust.capacity.com/subprocessors. Capacity's affiliates that Process Personal Data in connection with the Services are not Subprocessors but remain subject to obligations equivalent to those in this DPA, and Capacity is responsible for their compliance.
5.2 Notice and Objection. Capacity will provide at least 30 days' prior notice of new or replacement Subprocessors. Customer may object on reasonable data protection grounds within 30 days. If no resolution is reached in good faith, Capacity may not appoint the Subprocessor, or Customer may discontinue use of the affected Service functionality.
5.3 Obligations. Capacity shall impose data protection obligations on Subprocessors equivalent to those in this DPA and shall remain responsible for Subprocessor compliance.
6. SECURITY
6.1 Technical and Organizational Measures. Capacity shall implement and maintain appropriate technical and organizational measures to protect Personal Data against unauthorized access, loss, disclosure, or destruction, as further described in Annex III.
6.2 Confidentiality. Capacity shall ensure that personnel authorized to Process Personal Data are subject to binding confidentiality obligations and receive appropriate data protection training.
6.3 Incident Notification. Upon becoming aware of a Personal Data Breach, Capacity shall notify Customer without undue delay and, where feasible, within 72 hours. Notification shall include: (a) the nature of the breach; (b) categories and approximate number of Data Subjects and records affected; (c) likely consequences; and (d) measures taken or proposed. Capacity shall cooperate with Customer in investigating and remediating the breach.
7. DATA SUBJECT RIGHTS AND ASSISTANCE
7.1 Capacity shall provide reasonable assistance to Customer in responding to Data Subject Rights requests and, where required by law, in conducting DPIAs and consulting with Supervisory Authorities.
7.2 If Capacity receives a Data Subject Rights request directly, it shall promptly refer the Data Subject to Customer and not respond substantively without Customer's authorization, unless required by law.
7.3 Unless prohibited by law, Capacity shall notify Customer without undue delay of any: (a) binding request from a governmental authority to disclose Personal Data; (b) complaint or inquiry from a Data Subject or Supervisory Authority; or (c) legal obligation requiring Processing contrary to Customer's instructions.
8. INTERNATIONAL DATA TRANSFERS
8.1 General. Where Personal Data is transferred from the EEA, UK, or Switzerland to Capacity in the United States, or to any country not recognized as providing adequate protection under Applicable Data Protection Laws, such transfers shall be made pursuant to a valid mechanism under Applicable Data Protection Laws.
8.2 Standard Contractual Clauses. To the extent a transfer is not covered by another adequate mechanism, the EU SCCs apply as follows:
- (a) Module 2 (Controller to Processor) applies where Customer is a Controller;
- (b) Module 3 (Processor to Processor) applies where Customer is itself a Processor;
- (c) Clause 7 (docking) does not apply;
- (d) Clause 9 Option 2 applies; Subprocessor changes are governed by Section 5 of this DPA;
- (e) Clause 11 optional language does not apply;
- (f) Clause 17 — Irish law governs;
- (g) Clause 18(b) — courts of Ireland have jurisdiction;
- (h) Annex I of the SCCs is completed by Annex I of this DPA; Annex II by Annex III of this DPA; Annex III by the Subprocessor list.
8.3 UK Addendum. For transfers from the United Kingdom, the UK Addendum applies and is incorporated by reference, completed as follows: Table 1 = Annex I of this DPA; Table 2 = EU SCCs above; Table 3 = Annex I, Annex III, and Subprocessor list; Table 4 = either party may terminate per the UK Addendum.
8.4 Switzerland. For transfers from Switzerland, references to "GDPR" in the SCCs include the Swiss nFADP; "Member State" includes Switzerland; the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner.
8.5 Other Jurisdictions. For transfers from Canada, Brazil, or other jurisdictions with cross-border transfer restrictions, Capacity shall comply with applicable transfer mechanisms under local law.
8.6 Conflict. In the event of conflict between this DPA and the EU SCCs or UK Addendum, the EU SCCs or UK Addendum prevail with respect to the relevant transfer.
8.7 Alternative Mechanisms. If any transfer mechanism referenced in this Section becomes unavailable or invalid, the parties shall cooperate in good faith to implement an alternative. If no alternative is available, Customer may suspend affected transfers or terminate the impacted Services without penalty.
9. US STATE PRIVACY LAWS
9.1 CCPA / CPRA. Where the CCPA/CPRA applies, Capacity acts as a "Service Provider" and "Contractor" and shall:
- (a) not sell or share California Personal Information;
- (b) not retain, use, or disclose California Personal Information outside the direct business relationship, except as permitted by law;
- (c) certify its understanding of these restrictions; and
- (d) notify Customer if it can no longer meet its Service Provider obligations under the CCPA.
9.2 Not a Sale. The disclosure of Personal Data by Customer to Capacity under this DPA does not constitute a "sale" or "share" under any applicable U.S. privacy law. No monetary or other valuable consideration is exchanged in connection with such disclosure beyond fees paid for the Services.
9.3 Other States. For other applicable U.S. state privacy laws, Capacity shall comply with the obligations applicable to a "processor" or equivalent role, consistent with this DPA.
10. AUDIT AND ACCOUNTABILITY
10.1 Records. Capacity shall maintain records of Processing activities as required by Applicable Data Protection Laws.
10.2 Certifications. Capacity undergoes independent security audits, including SOC 2 Type II certification. Upon written request and subject to confidentiality obligations, Capacity will provide relevant certification reports and security documentation sufficient to demonstrate compliance with this DPA.
10.3 Audits. Where certifications do not adequately address Customer's verification needs under Applicable Data Protection Laws, Customer may, with 30 days' prior written notice, conduct one audit per calendar year at Customer's expense by Customer or a mutually agreed independent auditor. Audits shall: (a) be subject to mutual confidentiality obligations; (b) minimize disruption to Capacity's operations; and (c) not require access to other customers' data or Capacity's proprietary systems beyond what is necessary.
11. DATA RETURN AND DELETION
Data return and deletion will be handled according to the Agreement.
12. LIABILITY
Any liability imposed on or incurred by Capacity under this DPA shall be subject to the liability terms and any exclusions or limitations of liability under the Agreement. To the extent required by Applicable Data Protection Laws or the EU SCCs, nothing in this Section limits either party's liability to Data Subjects under Article 82 GDPR or Clause 12 of the EU SCCs.
13. GENERAL
13.1 Governing Law. This DPA is governed by the law governing the Agreement, subject to mandatory requirements of Applicable Data Protection Laws.
13.2 Updates. Capacity may update this DPA from time to time to reflect changes in Applicable Data Protection Laws or the Services. Capacity will provide reasonable notice of material changes. Continued use of the Services after the effective date of an update constitutes acceptance. Updates to the EU SCCs or UK Addendum require mutual agreement.
13.3 Severability. If any provision of this DPA is found invalid or unenforceable, the remaining provisions remain in full force.
ANNEX I — DESCRIPTION OF PROCESSING
1. Parties
Data Exporter (Controller/Processor): Name: Customer, as identified in the Agreement. Activities: Use of Capacity's SaaS Services including voice AI, chat, SMS, email, agent assist, ASR/TTS, transcription, analytics, and related features. Role: Controller (or Processor acting on behalf of a Controller).
Data Importer (Processor): Name: AI Software, LLC and its affiliates. Address: As specified in the Agreement. Activities: Hosting, storing, transmitting, analyzing, and Processing Personal Data to provide the Services, and for permitted independent controller purposes as described in Section 2.3 of the DPA. Role: Processor (and independent Controller for purposes in Section 2.3 of the DPA).
2. Categories of Data Subjects
- Customer employees and contractors
- End users of Customer's services (including callers, chat users, SMS recipients)
- Customers, clients, or patients of Customer
- Business prospects and partners
- Website visitors and event attendees
3. Categories of Personal Data
| Category | Examples |
|---|---|
| Account & Identity Data | Names, email addresses, phone numbers, job titles, company names, user IDs |
| Communications Data | Voice recordings, audio files, call transcripts, chat messages, SMS content, email content |
| Acoustic & Speech Data | Voice patterns, audio characteristics, ASR transcripts, TTS parameters |
| Scheduling & Interaction Data | Booking data, meeting metadata, interaction summaries, notes |
| Technical Data | IP addresses, device identifiers, browser type, log files, authentication records |
| AI-Generated Data | Summaries, classifications, and insights derived from user interactions |
4. Sensitive Data
Special category data is not required for the Services. If Customer elects to process Sensitive Data through the Services, Customer is responsible for identifying the applicable lawful basis and ensuring appropriate safeguards. Capacity shall Process such data solely on Customer's instructions.
Note: Voice and audio data may incidentally capture health information, emotional state, or characteristics that constitute Sensitive Data in some jurisdictions. Customer is responsible for assessing and addressing this risk in its own privacy notices and lawful basis determinations.
5. Frequency and Nature
Ongoing and continuous during the term of the Agreement. Processing includes collection, storage, transmission, analysis, transcription, and AI processing.
6. Purpose
Provision of the Services; customer support; security and fraud prevention; legal compliance; and development and improvement of Capacity's AI models and services.
7. Retention
Per the Agreement and applicable legal requirements.
8. Competent Supervisory Authority
- Irish Data Protection Commission (EEA transfers)
- UK Information Commissioner's Office (UK transfers)
- Swiss Federal Data Protection and Information Commissioner (Swiss transfers)
ANNEX II — INTERNATIONAL TRANSFER TERMS
Incorporated by reference. The EU SCCs (Module 2 and Module 3), UK Addendum, and Swiss nFADP transfer mechanisms are incorporated per Section 8 of this DPA. This Annex serves as Annex I of the EU SCCs as completed by the parties.
ANNEX III — TECHNICAL AND ORGANIZATIONAL SECURITY MEASURES
Capacity maintains an Information Security Management Program aligned with SOC 2 Type II, ISO 27001, and ISO 42001 standards. Key measures include:
- Governance: Designated security leadership; annual risk assessments; documented security policies reviewed annually; vendor risk management program.
- Access Controls: Role-based access control (RBAC); least privilege enforcement; multi-factor authentication (MFA) for privileged accounts; access reviews; immediate revocation upon role change or termination.
- Encryption: TLS 1.2+ in transit; AES-256 at rest; encrypted backups; secure key management systems.
- Logical Segregation: Logical isolation of customer environments; tenant separation; production/non-production separation.
- Logging and Monitoring: Centralized logging of authentication and administrative actions; anomaly detection; log retention policies.
- Secure Development: Version-controlled repositories; peer code review; static and dynamic analysis; vulnerability scanning; change management; separation of development and production duties.
- Vulnerability Management: Regular scanning; risk-based patch management; annual penetration testing by independent third parties.
- Incident Response: Documented incident response plan; defined escalation paths; root cause analysis; customer notification within 72 hours of a confirmed Personal Data Breach.
- Business Continuity: Documented BCP and DRP; redundant infrastructure; backup with defined retention; periodic DR testing.
- Personnel: Background checks where legally permitted; confidentiality agreements; security awareness training; role-specific training for engineering staff.
- Physical: Hosting in secure, SOC 2 and ISO 27001-certified data centers operated by leading cloud providers.
- Data Lifecycle: Retention controls; secure deletion procedures; media sanitization.
ANNEX IV — SUBPROCESSOR LIST
Current Subprocessor list: https://trust.capacity.com/subprocessors
ANNEX V — DATA RESIDENCY (Optional — Applicable Only If Separately Executed)
This Annex applies only where expressly executed as part of Customer's Service Order.
1. Designated Region. Capacity shall ensure that Customer Personal Data is primarily stored and processed within the agreed Designated Region:
- ☐ European Union
- ☐ United Kingdom
- ☐ United States
- ☐ Other: _______
2. Permitted Cross-Border Processing. The following may occur outside the Designated Region, subject to applicable transfer mechanisms: security monitoring; encrypted backup storage; incident response; subprocessor support services.
3. Changes. Capacity will provide 30 days' prior written notice before materially changing the Designated Region.
This document is a working draft for legal review and does not constitute legal advice.