Last updated: August 22, 2026 — draft until reviewed by counsel; it forms part of the Terms for every customer account from the date it is published.
1. Parties and roles
This Data Processing Agreement ("DPA") is between the customer holding a CapacityLab account ("Customer", the controller) and CapacityLab (operator: _legal entity and registered address to be completed by the owner_; "CapacityLab", the processor). It applies whenever CapacityLab processes personal data contained in the Customer's systems, provider accounts, diagnostics and reports ("Customer Data"). CapacityLab's own processing of account, billing and security data, for which it is the controller, is described in the Privacy Policy.
2. Subject matter, duration, nature and purpose
- Subject matter: connecting the Customer's infrastructure providers, capturing application and topology metadata, running the diagnostics the Customer orders, and producing evidence, Decisions and reports.
- Duration: for as long as the Customer holds an account, plus the retention in Annex A.
- Nature: collection, storage, structuring, analysis and deletion, automated; no profiling of individuals, no decisions producing legal effects.
- Purpose: the service described in the Terms and nothing else.
- Data subjects and categories: Annex A.
3. CapacityLab's obligations (Article 28(3))
1. Instructions. CapacityLab processes Customer Data only on the Customer's documented instructions — the Terms, this DPA and the actions the Customer takes in the console or through the API — unless EU or member-state law requires otherwise, in which case CapacityLab informs the Customer before processing, where the law allows. CapacityLab tells the Customer if it believes an instruction infringes data protection law. 2. Confidentiality. Every person CapacityLab authorises to process Customer Data is bound by confidentiality. Access is limited to what the role needs and is reviewed quarterly. 3. Security. CapacityLab implements the measures in Annex B, which it maintains at least at the level published on the Security page. 4. Subprocessors. The Customer gives general authorisation to the subprocessors listed on the Security page. CapacityLab gives at least 30 days' notice of any intended addition or replacement, by email to the account owner and on that page. The Customer may object on reasonable data-protection grounds within that period; if the objection cannot be resolved, the Customer may terminate the affected service. CapacityLab binds every subprocessor to obligations no less protective than this DPA and remains liable for their performance. 5. Data subject rights. Taking into account the nature of the processing, CapacityLab assists the Customer with appropriate technical and organisational measures to respond to requests under Chapter III of the GDPR: the console offers export and deletion for account data, and CapacityLab responds to the Customer's requests concerning Customer Data within 10 working days. 6. Assistance with Articles 32–36. CapacityLab assists the Customer with security, breach notification, data protection impact assessments and prior consultation, taking into account the information available to it. 7. Personal data breach. CapacityLab notifies the Customer without undue delay and no later than 72 hours after becoming aware of a personal data breach affecting Customer Data, by email to the account owner, with the information in Article 33(3) as far as known, and supplements it as the investigation proceeds. The procedure is described in CapacityLab's incident-response runbook. 8. Deletion and return. At the end of the service — account closure — CapacityLab deletes or returns Customer Data at the Customer's choice and deletes existing copies, unless EU or member-state law requires storage. Immutable evidence of completed runs is retained pseudonymously for the period in Annex A; provider credentials are revoked immediately. 9. Audit. CapacityLab makes available all information necessary to demonstrate compliance with Article 28 and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer, on 30 days' notice, no more than once a year unless a breach or a supervisory authority requires otherwise, during business hours and without disrupting other customers. The published security documentation and self-assessment are the first line of evidence.
4. Customer's obligations
The Customer warrants that it has a lawful basis for the Customer Data it submits, that its instructions comply with applicable law, and that it does not submit special categories of personal data, credentials of third parties it is not authorised to use, or data of persons it is not permitted to process.
5. International transfers
Customer Data is stored in the EU (Railway, Google Cloud europe-west3). Where a subprocessor operates outside the EEA, the transfer relies on the EU–US Data Privacy Framework where the subprocessor is certified, otherwise on the European Commission's Standard Contractual Clauses (Module 3, processor to processor) — available on request.
6. Liability and precedence
Liability under this DPA is subject to the limitations in the Terms. Where this DPA and the Terms conflict on the processing of personal data, this DPA prevails.
7. Contact
security@capacitylab.dev — for instructions, objections to subprocessors, data subject requests and breach communication.
Annex A — Processing details
| Data subjects | Categories of data | Retention | | -------------------------------------- | ------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------- | | The Customer's users of the console | email, provider account identifier, display name, role, action log (who did what, from which address) | account life; pseudonymised at closure; action log 365 days (sign-ins 180) | | Persons named in the Customer's systems | whatever the Customer's application metadata, logs or topology carry (typically service names; occasionally an email or IP in a log line) | raw load-test output 30 days (365 on request); results and reports for the account's life, pseudonymous after closure | | The Customer's end users | none intended: diagnostics target synthetic load; CapacityLab does not read end-user traffic | — |
Provider credentials the Customer connects are encrypted at rest and decrypted only in memory for the duration of a call; they are not personal data but are treated with the same measures.
Annex B — Technical and organisational measures
As published on the Security page and maintained in CapacityLab's security documentation: OAuth-only sign-in with no passwords; tenant isolation enforced in every query and checked by a linter and tests; provider credentials encrypted at rest (AES-256-GCM) and never logged; TLS everywhere; an append-only action log with client address and operator-read transparency; audit-log and artifact retention with proof of deletion; vulnerability handling with a published disclosure policy and safe harbor; dependency and image scanning with a known-exploited-vulnerabilities check on every release; backups and a disaster-recovery plan; quarterly access review; an incident-response runbook with notification within 72 hours.