CapEngage AI Engagement Platform
Loading Intelligent Customer Journeys...
Real-Time CDP · Predictive Decisioning · 6 Native Channels
Connecting Real-Time Customer Signals...
Real-Time CDP · Predictive Decisioning · 6 Native Channels
Loading Intelligent Customer Journeys...
Real-Time CDP · Predictive Decisioning · 6 Native Channels
Establishes legally binding data processing terms between CapEngage and business clients, governing the processing of personal data under GDPR, CCPA/CPRA, and India DPDP Act 2023.
This Data Processing Addendum ('DPA') supplements the CapEngage Terms of Service or Master Services Agreement entered into by CapEngage Technology Solutions Pvt. Ltd. ('CapEngage', 'Processor') and the Customer ('Customer', 'Controller').
This DPA applies to all Personal Data processed by CapEngage on behalf of Customer in connection with providing the SaaS platform, AI autonomous agents, CDP, and omnichannel messaging services.
• Controller: Customer determines the purposes and means of processing Customer End-User Personal Data. • Processor: CapEngage processes Personal Data solely on documented instructions from Customer.
CapEngage shall process Personal Data solely for the following documented instructions:
1. Delivering, operating, and maintaining the contracted SaaS features. 2. Executing automated campaign dispatches, AI agent workflows, and behavioral segmentation as configured by Customer. 3. Fulfilling obligations set forth in the Terms of Service and this DPA.
CapEngage shall not sell, retain, use, or disclose Personal Data for any commercial purpose other than providing the contracted Services.
CapEngage implements and maintains appropriate technical and organizational security measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, or unauthorized disclosure.
Key TOMs include: • Encryption of Personal Data in transit (TLS 1.3) and at rest (AES-256). • Strict access control (MFA, SSO, RBAC) based on the principle of least privilege. • Multi-tenant database isolation preventing cross-tenant data access. • Regular vulnerability testing, penetration audits, and 24/7 security monitoring.
Customer grants general authorization to CapEngage to engage third-party sub-processors to assist in delivering the Services.
• List of Approved Sub-processors: Managed cloud infrastructure (AWS, GCP), messaging gateways (Meta WhatsApp API, Twilio, AWS SES), and enterprise AI inference infrastructure (OpenAI API, Anthropic API). • Sub-processor Obligations: CapEngage executes written contracts with each sub-processor imposing data protection obligations no less restrictive than those in this DPA. • Notice of Changes: CapEngage will notify Customer of any intended additions or replacements of sub-processors at least 14 days in advance, allowing Customer an opportunity to object on reasonable data protection grounds.
CapEngage will provide reasonable assistance to Customer, taking into account the nature of processing, to enable Customer to fulfill its obligations to respond to Data Subject requests (access, correction, erasure, portability) under GDPR, CCPA, or DPDP Act.
If CapEngage receives a Data Subject request directly, we will promptly notify Customer and direct the Data Subject to submit their request to Customer.
CapEngage will notify Customer without undue delay, and in any event within seventy-two (72) hours, upon becoming aware of a confirmed Personal Data Breach affecting Customer's data.
The notification will describe the nature of the breach, affected data categories, estimated number of impacted data subjects, and mitigation measures taken by CapEngage.
To the extent Personal Data transferred from the European Economic Area (EEA), United Kingdom, or Switzerland is processed outside those regions, the parties agree that Module 2 (Controller-to-Processor) of the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) and UK International Data Transfer Addendum shall apply and are hereby incorporated into this DPA.
CapEngage will provide Customer with reasonable documentation (such as SOC 2 summary reports or ISO certifications) to demonstrate compliance with this DPA.
Upon termination of the Services, CapEngage will, at Customer's choice, delete or return all Personal Data within thirty (30) days, except to the extent applicable law requires continued storage.
For legal notices, compliance inquiries, or formal correspondence
Global Headquarters
CapEngage Technology Solutions Pvt. Ltd.
1st Floor, Rajapushpa Summit, Nanakramguda Rd, Financial District, Hyderabad, Telangana 500032
Registered Legal Office
CapEngage Technology Solutions Pvt. Ltd.
Building No 4B, Flat No 304, Olympeo Riverside PH Karjat, Avasare, Raigarh, Maharashtra, India, 410101