Privacy Policy
Last updated: 2026-07-10.
Our role
For your account and login data, CAPAPath is the data controller. For the quality records your organization enters into the service, your organization is the controller and CAPAPath acts as its data processor, handling that data only on your organization's instructions. A data processing agreement (DPA) is available on request.
What we collect
- Account. Your email and a hashed password. Passwords are stored only as a salted hash — never in plain text — and are never logged.
- Profile and role. Your display name and the access role assigned to you.
- Quality records. The content your organization enters — events, investigations, actions, and related items — which may include the names of personnel and product, supplier, or lot identifiers.
- Audit trail and signatures. To meet regulatory record-keeping requirements, the service records who did what and when, and captures your printed name, timestamp, and the meaning of each electronic signature you apply.
- Server logs. IP address, user agent, and request paths, kept up to 30 days for security and abuse prevention.
How we use it
To run the service, keep your account and records secure, send you due-date and escalation notifications, and maintain the audit trail. We do not sell personal data, show third-party advertising, or use your data to train AI models.
Sub-processors
- Self-hosted infrastructure — the app and your data run on servers we operate. Your data is not handed to a third-party database, authentication, or hosting provider.
- Email delivery — a transactional email provider delivers verification and notification messages, which include the recipient's email address.
- Error monitoring — when the app hits an error, a diagnostic report (stack trace and request context) may be sent to an error-monitoring provider so we can fix it.
Cookies
CAPAPath sets an HttpOnly cookie for your signed-in session. We do not use cookies for analytics, advertising, or cross-site tracking.
Retention and the audit trail
The audit trail, record versions, and electronic signatures are append-only and immutable by design: they cannot be altered or selectively deleted, and are retained for as long as the associated record must be kept to meet your organization's regulatory and record-keeping obligations. Because that data is required to comply with a legal obligation, it is exempt from erasure-on-request (e.g. GDPR Art. 17(3)(b)). Account and profile data can be corrected or removed subject to those retention requirements.
Your rights (GDPR / CCPA)
You can view and update your profile in the app. To request access to, correction of, or deletion of your personal data — subject to the retention limits above — . EU residents may also lodge a complaint with their local supervisory authority.
Children
The service is intended for business use by authorized personnel and is not directed to children. We do not knowingly collect personal information from children.