kaptto

Data Processing Agreement (DPA) — kaptto

Version 1.1 · Last updated: April 2026

This Data Processing Agreement ("DPA") supplements the Terms of Service between the customer ("Controller") and kaptto ("Processor"), in accordance with Article 28 of the GDPR.

1. Definitions

For the purposes of this DPA: (a) "Controller" means the customer of kaptto; (b) "Processor" means kaptto; (c) "Personal Data" means any information relating to an identified or identifiable natural person; (d) "GDPR" means Regulation (EU) 2016/679. Undefined terms have the meaning given to them by the GDPR.

2. Subject Matter

This DPA governs the processing of Personal Data by kaptto in the context of providing the review and NPS management services contracted by the Controller.

3. Nature, Purpose and Duration

Nature: computerised processing in support of customer feedback management. Purpose: as set out in the Terms of Service. Duration: for as long as the contract is in force, plus the retention period set out in the Privacy Policy.

4. Categories of Data Subjects and Types of Data

Data subjects: platform users (Controller's staff) and end customers who submit reviews. Types of data: name, email, phone, review content, technical metadata (IP, browser, timestamp). Special categories of data (health, biometrics, etc.) are not processed unless an end customer voluntarily includes them in a comment, in which case they will be processed with the same confidentiality.

5. Processor's Obligations

kaptto undertakes to: (a) process the data only on documented instructions from the Controller; (b) ensure confidentiality of authorised personnel; (c) implement appropriate technical and organisational measures (Article 32 GDPR); (d) assist the Controller in complying with Articles 32 to 36; (e) delete or return the data at the end of the contract; (f) facilitate audits subject to reasonable prior notice.

6. Controller's Rights and Obligations

The Controller: (a) ensures the legal basis for processing (consent, contract, etc.); (b) responds to data subject rights requests (with the Processor's assistance); (c) instructs the Processor in writing on the processing; (d) is responsible for properly configuring the platform features and team access.

7. Sub-processors

The Controller authorises the engagement of the sub-processors listed in section 5.1 of the Privacy Policy. The addition of new sub-processors will be communicated 30 days in advance, and the Controller may object. In case of unresolved objection, an alternative solution or termination without penalty will be negotiated.

8. International Transfers

Transfers outside the European Economic Area are made under the Standard Contractual Clauses (SCC) approved by the European Commission or other adequate safeguards under the GDPR.

9. Security Measures

kaptto implements: (a) encryption at rest (AES-256) and in transit (TLS 1.2+); (b) role-based access control (RBAC); (c) centralised activity logging (audit log); (d) regular backups with a minimum 7-day retention; (e) periodic security testing; (f) internal privacy policies and staff training.

10. Data Breach Notification

kaptto will notify the Controller without undue delay (and in any event within 48 hours) after becoming aware of a Personal Data breach affecting the Controller's data, providing the information necessary for the Controller to comply with Article 33 GDPR.

11. Audit

The Controller has the right to audit compliance with this DPA upon 30 days' prior notice, during business hours, at most once per year (except in case of confirmed incident). kaptto will provide updated compliance reports (e.g. SOC 2, ISO 27001 where applicable) which may replace on-site audits.

12. Final Provisions

This DPA prevails over the Terms of Service in case of conflict relating to Personal Data processing. Designated privacy contact: privacidade@kaptto.pt. Governing law: Portuguese law. Forum: courts of Lisbon.