1. Scope and status
This Data Processing Addendum (“DPA”) forms part of the Terms of Service or another written agreement between SPACEMANCODES LTD (“Capturewell”, “Processor”, “we”) and the customer using the Service (“Customer”, “Controller”, “you”). It applies only where Capturewell processes Customer Personal Data on Customer’s behalf.
“Data Protection Laws” means the UK GDPR, the Data Protection Act 2018, PECR, and other data-protection law applicable to the processing. “Customer Personal Data”, “Controller”, “Processor”, “Data Subject”, “Personal Data Breach”, and “processing” have the meanings given by applicable Data Protection Laws.
Capturewell is a controller, not a processor, for account administration, billing, security, support, and its own proportionate service analytics. Those activities are covered by the Privacy Notice rather than this DPA.
2. Processing details
| Subject matter | Rendering customer-selected public webpages, storing and delivering capture outputs temporarily, executing bounded Recipes, and supporting related templates, schedules, webhooks, and customer-storage delivery. |
|---|---|
| Duration | For the term of the customer agreement and the limited deletion or backup period described in this DPA. Capture files are normally retained for the configured window, currently 24 hours. |
| Nature and purpose | Accessing a target URL, loading and preparing visible page content in an isolated browser, generating an image or PDF, applying requested transformations, returning or delivering the output, and securing, diagnosing, and deleting that processing. |
| Data subjects | People whose information appears on a target webpage or in Customer Content, including website visitors, authors, customers, staff, contractors, and members of the public. |
| Data types | Target URLs; visible text, images, names, contact details, identifiers, online activity, and other webpage content; capture output and metadata; Recipe instructions and bounded page observations; uploaded watermarks; and integration destinations supplied by Customer. |
| Special-category data | Not intentionally required. It may appear incidentally on a customer-selected public webpage. Customer must not instruct us to process special-category or criminal-offence data unless it has a valid legal basis and has assessed and documented the additional safeguards required. |
3. Customer instructions and responsibilities
The agreement, Customer’s authorised use of Service controls and API requests, and documented support instructions are Customer’s complete instructions to us. We will process Customer Personal Data only on those instructions, including for international transfers, unless UK law requires otherwise. If law permits, we will tell Customer before processing under a legal requirement.
Customer determines the purpose and lawfulness of each capture. Customer must provide required privacy information, establish a lawful basis, respect Data Subject rights, minimise the data submitted, and avoid sensitive data that is unnecessary for the intended output. Customer must not instruct us to process data in breach of Data Protection Laws.
We will tell Customer if, in our reasonable opinion, an instruction infringes Data Protection Laws and may pause the affected processing while the parties resolve it. We are not required to perform an instruction that is technically infeasible, outside the Service, unlawful, or inconsistent with the agreement.
4. Capturewell obligations
Capturewell will:
- ensure people authorised to process Customer Personal Data are bound by confidentiality;
- implement appropriate technical and organisational security measures and maintain them in light of risk, technology, cost, and the nature of the processing;
- assist Customer, taking account of the nature of processing and information available to us, with Data Subject requests, security, breach notification, data-protection impact assessments, and regulator consultation;
- keep records and provide information reasonably necessary to demonstrate compliance with Article 28 of the UK GDPR; and
- delete or return Customer Personal Data as described below when processing ends, unless law requires retention.
If we receive a request directly from a Data Subject about Customer Personal Data, we will not respond on Customer’s behalf unless authorised or legally required. We will direct the person to Customer where practicable and notify Customer when appropriate.
5. Security measures
Measures applicable to the Service include:
- TLS for data in transit, private storage, and encrypted fields for sensitive integration destinations and secrets;
- time-limited signed file access, account-level authorisation, hashed API keys, and least-privilege operational access;
- isolated browser rendering, public-address and redirect validation, blocked private-network access, bounded requests, and renderer authentication;
- request validation, rate limits, audit-capable operational records, dependency maintenance, and incident investigation procedures;
- short capture-file retention, cleanup of temporary working files, account deletion controls, and separation of customer-owned storage; and
- resilience measures appropriate to the configured hosting, database, queue, and storage services.
Customer is responsible for its own access controls, endpoint security, credential rotation, webhook verification, storage permissions, and secure handling of downloaded outputs.
6. Personal Data Breaches
We will notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data. As information becomes available, the notice will describe the nature of the breach, likely consequences, measures taken or proposed, and a contact point. Information may be provided in phases.
Notification is not an admission of fault or liability. Customer is responsible for deciding whether to notify a regulator or Data Subject and for making those notifications, with our reasonable assistance.
7. Subprocessors
Customer gives general written authorisation for us to use subprocessors to provide the Service. We will impose data-protection terms offering materially equivalent protection and remain responsible for each subprocessor’s performance of its obligations to us.
| Provider | Processing | When used |
|---|---|---|
| Amazon Web Services | Isolated browser-rendering compute and associated technical infrastructure. | All rendered captures. |
| Cloudflare | Network services and private S3-compatible capture storage. | When configured for the production deployment. |
| OpenAI | Planning bounded browser actions from Recipe instructions and limited page observations. | Only when AI-assisted Recipes are enabled and Customer uses one. |
Application hosting and storage are deployment-specific. Before production processing, the current complete subprocessor and location record is available from [email protected]. We will provide notice of a new subprocessor where required. Customer may object on reasonable data-protection grounds; the parties will work in good faith on a solution, which may include stopping the affected feature if no reasonable alternative is available.
8. International transfers
Where Customer Personal Data is transferred outside the UK to a destination without an applicable UK adequacy regulation, we will put in place a lawful transfer mechanism. This may be the UK International Data Transfer Agreement, the UK Addendum to EU Standard Contractual Clauses, or another approved safeguard. The relevant terms are incorporated into this DPA to the extent required by law.
We will assess transfer risk and apply supplementary technical or organisational measures where appropriate. Customer authorises transfers needed to provide the Service subject to these safeguards.
9. Return and deletion
During the agreement, Customer can download active capture outputs and delete captures and configuration through the Service. Capture files are automatically removed after the configured retention window. At Customer’s choice when processing ends, and subject to available product functions, we will delete or return remaining Customer Personal Data.
Account closure deletes private capture files and associated account records after pending billing and delivery work is safely stopped. Deletion does not affect copies Customer sent to its own storage. Limited backups may remain until overwritten under the ordinary backup cycle, protected from further use, and specific records may be retained where UK law requires it.
10. Information and audits
On reasonable written request, we will provide information necessary to demonstrate compliance with this DPA, which may include security summaries, policies, or independent assurance reports when available. Customer must keep that information confidential and use it only for compliance review.
If that information is insufficient, Customer may request an audit no more than once in any 12-month period, unless a confirmed breach or regulator requires more. Audits must be proportionate, during normal business hours, avoid access to other customers’ data, and not unreasonably disrupt the Service. Customer bears its audit costs unless the audit finds a material breach by us.
11. Priority, liability, and law
If this DPA conflicts with the main agreement about processing Customer Personal Data, this DPA controls. All other conflicts are resolved under the main agreement. Liability arising under this DPA is subject to the exclusions and limits in the Terms or other main agreement, to the extent permitted by law.
This DPA ends when we no longer process Customer Personal Data, except for provisions that must survive to protect retained data. The governing-law and dispute provisions in the main agreement apply.