Data Processing Agreement
Version 1.0 · effective 2026-07-10.
This Data Processing Agreement ("DPA") forms part of the agreement between the customer organization ("Controller") and CAPAPath ("Processor") for use of the CAPAPath service. It governs CAPAPath's processing of personal data on the Controller's behalf and is intended to satisfy Article 28 of the EU/UK General Data Protection Regulation (GDPR). Where it conflicts with the Terms of Service on the subject of data protection, this DPA governs.
1. Roles
The Controller determines the purposes and means of processing the personal data in its quality records. CAPAPath acts as Processor and processes that data only to provide the service. Each party complies with its own obligations under applicable data-protection law.
2. Subject-matter and duration
The subject-matter is the provision of the CAPAPath CAPA/quality-management service. Processing continues for the term of the Controller's subscription and the limited wind-down period described in section 9.
3. Nature, purpose, and scope
CAPAPath hosts a system of record for corrective and preventive action and related quality processes. Processing consists of the storage, organization, retrieval, and display of the records the Controller enters, and the operations needed to run, secure, and back up the service. CAPAPath processes the data only on the Controller's documented instructions, which include using the service through its normal features and this DPA, unless law requires otherwise (in which case CAPAPath informs the Controller first, unless that law forbids it).
4. Types of personal data and data subjects
See Annex I.
5. Processor obligations
CAPAPath, as Processor:
- processes personal data only on the Controller's documented instructions;
- ensures persons authorized to process the data are bound by an appropriate duty of confidentiality;
- implements appropriate technical and organizational security measures (Annex II);
- engages sub-processors only as permitted by section 6, under written terms no less protective than this DPA;
- assists the Controller, taking account of the nature of processing, in responding to data subjects exercising their rights;
- assists the Controller with its obligations on security, breach notification, and data protection impact assessments;
- returns or deletes the personal data at the end of the service, at the Controller's choice (section 9); and
- makes available the information needed to demonstrate compliance and allows for and contributes to audits (section 8).
6. Sub-processors
The Controller gives CAPAPath general authorization to engage the sub-processors listed in Annex III to process personal data. CAPAPath remains responsible for its sub-processors' performance. CAPAPath will give the Controller advance notice of any intended change to that list — by updating this page and its version — so the Controller has the opportunity to object on reasonable data-protection grounds.
7. International transfers
Where processing involves transferring personal data outside the UK/EEA, CAPAPath carries out that transfer only under an approved transfer mechanism — such as the UK IDTA or the European Commission's Standard Contractual Clauses — which are incorporated into this DPA by reference for any such transfer.
8. Security, breach notification, and audit
CAPAPath maintains the security measures in Annex II and will notify the Controller without undue delay after becoming aware of a personal-data breach affecting the Controller's data, with the information the Controller reasonably needs to meet its own notification duties. On reasonable request and notice, CAPAPath makes available information to demonstrate compliance with this DPA and the security documentation described on the Compliance page.
9. Return and deletion
The Controller can export its records and their audit history at any time, itself, from within the service. On termination, the Controller may export its data during a wind-down period, after which CAPAPath deletes it, save where law requires retention. Immutable audit entries are retained as described in the Privacy Policy.
10. Acceptance
An organization accepts this DPA from within its CAPAPath settings. Acceptance is recorded with the version, the accepting user, and the time, so both parties have a durable record of what was agreed.
Annex I — Details of processing
Categories of data subjects: the Controller's personnel and authorized users, and any individuals identified within the quality records the Controller enters (for example, people named in a complaint, deviation, or audit finding).
Categories of personal data: account data (name, email address, role, and electronic-signature records) and any personal data the Controller chooses to include in the content of its quality records. The Controller should avoid entering special-category data except where necessary for a record.
Annex II — Security measures
- encryption of data in transit, and at rest at the hosting layer;
- per-organization isolation, with every request authorized against the signed-in user's organization and role, and row-level security in the database as a backstop;
- passwords stored only as salted hashes; optional email one-time-code sign-in;
- an append-only audit trail enforced by the database, not by convention;
- regular backups of the database.
These measures are described in more detail, with the regulatory controls they support, on the Compliance page.
Annex III — Sub-processors
- Cloud hosting and database: Runs the application servers and the PostgreSQL database that stores your records.
- Transactional email: Delivers sign-in one-time codes, invitations, and system notifications.
Contact
Data-protection questions: reach us through /contact.
This DPA is a good-faith template and not legal advice. Have your own counsel review it before relying on it.