← Trust Centre

Data Processing Agreement

Cytundeb Prosesu Data

Last updated: March 2026

Overview

This Data Processing Agreement (DPA) sets out the responsibilities of Capsiynau when processing personal data on behalf of customers.

For the purposes of UK GDPR: You (the customer) act as the Data Controller · Capsiynau acts as the Data Processor


Scope of Processing

Categories of data processed:

  • Audio and video recordings submitted for transcription
  • Generated transcripts and caption data
  • Account and user information
  • Usage and session data

Processing activities: speech-to-text transcription, caption generation and formatting, translation and language analysis, transcript storage and retrieval, user account management.


Security Measures

MeasureDetail
Encryption in transitTLS 1.2 / TLS 1.3
Encryption at restAES-256
Access controlRole-based, with row-level security
Infrastructure isolationLogical separation between customer accounts
AuthenticationSecure sign-in with session management
MonitoringAutomated security logging and alerting

Sub-Processors

Capsiynau uses the following sub-processors to deliver the service. All sub-processors are required to meet security and compliance standards equivalent to those in this agreement.

ProviderPurposeLocation
SupabaseDatabase and authenticationEU / USA
Cloudflare R2File storageEU / USA
VercelAPI and web hostingGlobal edge
RailwayBackground processing workerUSA
UpstashJob queue (Redis)EU / USA
OpenAITranscription and translationUSA
AssemblyAISpeech transcriptionUSA
AnthropicLanguage processingUSA
Google CloudSpeech-to-Text (Chirp 2)EU / USA
ResendTransactional emailUSA
StripeBilling and paymentsUSA

Data Transfers

Capsiynau aims to process data within UK or European cloud regions wherever possible. Where data is transferred to providers outside the UK or EEA, appropriate safeguards are applied in accordance with UK GDPR, including Standard Contractual Clauses (SCCs) where required.


Data Breach Procedures

In the event of a personal data breach:

  • Capsiynau will investigate immediately upon discovery
  • Affected customers will be notified without undue delay and within 72 hours where required
  • Appropriate mitigation actions will be taken
  • Regulatory reporting to the ICO will occur if required under UK GDPR Article 33

Duration

This agreement applies for the duration of your use of the Capsiynau platform and terminates when your account is closed or the service agreement ends.


Contact

For DPA enquiries or to request a countersigned copy (Studio tier): privacy@capsiynau.com