CaptivaHQ← Back to sign in
Compliance hub

Everything you need to trust us with your data.

CaptivaHQ is built EU-sovereign by default and is designed to meet the legal regimes of every market we operate in. Below are the customer-facing artefacts. If you need a signed copy, a country variant, or a custom DPA, contact [email protected].

Universal documents

Apply to every customer regardless of region.

  • Privacy PolicyHow we collect, use, and protect your personal data.Open →
  • Terms of ServiceThe contract between you and CaptivaHQ.Open →
  • Data Processing Agreement (DPA)GDPR Art. 28 controller-to-processor terms.Open →
  • Cookie PolicyCategories of cookies, lifetimes, and how to opt out.Open →
  • Sub-processors listEvery third-party processor that touches your data.Open →
  • Acceptable Use PolicyWhat you can and can't do with the platform.Open →
  • Service Level Agreement (SLA)Uptime targets, credits, and incident response.Open →
  • Security overviewEncryption, access control, audit logging, retention.Open →
  • Standard Contractual ClausesEU SCCs (modules 1–4) for cross-border transfers.Open →
  • Records of Processing Activities (RoPA)Summary of processing activities (Art. 30).Open →

Regional documents

Country- and language-specific artefacts. Each region inherits the universal set above plus any local additions.

🇪🇺

European Union

GDPR + ePrivacy + NIS2 baseline applies.
EU
  • EU Privacy NoticeGDPR-aligned plain-language notice.
  • Cross-border transfer addendumSchrems II + adequacy + SCCs.
🇩🇪

Germany

BDSG, AVV, Impressum and TOMs required.
DE
  • ImpressumLegal entity disclosure (TMG § 5).
  • Auftragsverarbeitungsvertrag (AVV)German DPA template.
  • Technische und organisatorische Maßnahmen (TOM)Annex 1 of the AVV.
🇫🇷

France

CNIL, RGPD, and LCEN applicable.
FR
  • Mentions LégalesLCEN-compliant entity disclosure.
  • Conditions Générales d'UtilisationFrench ToS (CGU).
  • Politique de ConfidentialitéRGPD-aligned privacy notice.
🇪🇸

Spain

RGPD, LSSI-CE, and LOPDGDD applicable.
ES
  • Aviso LegalLSSI-CE entity disclosure.
  • Política de PrivacidadLOPDGDD-aligned privacy notice.
🇵🇹

Portugal

RGPD + Lei de Execução applicable.
PT
  • Política de PrivacidadeRGPD-aligned privacy notice.
  • Termos de ServiçoPortuguese ToS.
🇦🇹

Austria

DSG + ECG and TKG transparency rules apply.
AT
  • ImpressumECG / Mediengesetz disclosure.
  • DatenschutzerklärungDSG + GDPR privacy notice.
🇨🇭

Switzerland

Revised Federal Act on Data Protection (nFADP) since 1 Sep 2023.
CH
  • Privacy Notice (nFADP)Swiss FADP-aligned notice.
  • Data Processing Agreement (CH)nFADP processor addendum.
🇳🇱

Netherlands

GDPR + Uitvoeringswet AVG (UAVG).
NL
  • PrivacyverklaringAVG / UAVG privacy notice (Dutch).
  • Algemene VoorwaardenTerms of service (Dutch).
🇧🇪

Belgium

Bilingual notices (NL + FR) under APD/GBA.
BE
  • Privacy Notice — NLAVG-aligned privacy notice.
  • Politique de Confidentialité — FRRGPD-aligned privacy notice.
🇱🇺

Luxembourg

GDPR + Loi modifiée du 1er août 2018 (CNPD).
LU
  • Politique de ConfidentialitéCNPD-aligned privacy notice.
  • Conditions GénéralesLuxembourg terms of service.
🇺🇸

United States

Federal + state privacy laws (CCPA/CPRA, VCDPA, CTDPA, …).
US
  • California Privacy Notice (CCPA / CPRA)Right to know / delete / opt-out of sale.
  • Sub-processor + Vendor DisclosureAnnual disclosure required by several US states.
  • HIPAA Business Associate AddendumOn request, for healthcare customers.
🇨🇦

Canada

PIPEDA federal + Quebec Law 25 + provincial PHI laws.
CA
  • Canadian Privacy Notice (PIPEDA)Federal privacy notice.
  • Quebec Law 25 NoticeArticle 7 disclosure for QC residents.

CaptivaHQ S.A. — EU-sovereign by design. All processing in the European Union. Data residency: Scaleway (FR) + Hetzner (DE).

Questions: [email protected] · [email protected] · Sign in