Privacy Policy Capibaira B.V.

1. Controller

Capibaira B.V.
E-mail: [email protected]

Last updated: July 15, 2026.

2. Roles

2.1 For the SaaS service, the Customer is the controller for any personal data in Content; Capibaira acts solely as processor.
2.2 For website visits, support, invoicing, its own security, and its own business operations, Capibaira is independent controller.

3. Data we process

3.1 Website visits: truncated IP address, user agent, timestamps, and visited pages.
3.2 Website security: use of Google reCAPTCHA for protection against abuse/bots (this may place functional cookies).
3.3 SaaS usage: customer content designated or submitted by the Customer for the agreed service, generated results, translations and audio if enabled, technical metadata, request IDs, status codes, timestamps, customer configuration, and usage data.
3.4 Customer portal and administration: business email address, login metadata, role, customer account, portal actions, and result reference codes.
3.5 Invoicing and customer contact: company name, Chamber of Commerce and VAT number, billing address, business email, and phone number.

The standard service is intended for public or publicly intended website content. Sensitive internal content, special categories of personal data, application form data, medical data, financial personal data, passwords, and children’s data must not be processed through the standard service without a separate written agreement.

Capibaira processes customer content only to provide, manage, secure, and support the agreed service. Customer content is processed separately per customer and protected with appropriate technical and organizational measures.

4. Purposes and legal bases

4.1 Performance of the agreement: providing functionality, support, and invoicing.
4.2 Legitimate interest: security, logging, abuse prevention, monitoring, result refresh, quality control, and performance improvement.
4.3 Legal obligation: compliance with fiscal retention requirements.
4.4 Capibaira never sells or trades personal data.
4.5 Capibaira does not use customer content for marketing or cross-customer analytics.
4.6 Capibaira does not use customer content for its own model training without separate written consent.

5. Recipients and subprocessors

5.1 Infrastructure, storage, security, authentication, and monitoring: Google Cloud, primarily in an EU region.
5.2 AI processing, translation, and audio/TTS if enabled: OpenAI, unless otherwise stated in the customer agreement.
5.3 DNS, CDN/proxy, and protection of public endpoints: Cloudflare.
5.4 Email providers: for support, portal, and invoicing communication.
5.5 Website security: Google reCAPTCHA (only on capibaira.com).
5.6 Other vendors: monitoring, error tracking, and analytics (without tracking cookies where possible).
5.7 Capibaira’s primary infrastructure runs in an EU region. If subprocessors process data outside the EEA, appropriate safeguards apply, such as Standard Contractual Clauses (SCCs) or another valid transfer mechanism.

6. Security

6.1 TLS encryption in transit.
6.2 Encryption at rest.
6.3 Application-layer encryption for newly persistently stored tenant content and generated results.
6.4 Logging and monitoring.
6.5 Logical separation of customer accounts.
6.6 Access control and server-side authorization for portal and administration functions.
6.7 Raw customer content is not available as a standard admin or support function.
6.8 Backups and recovery procedures.

7. Retention periods

7.1 Generated results, translations, and audio: up to 12 months, unless agreed otherwise.
7.2 Technical logs: up to 90 days, unless longer retention is required for security, incident investigation, or legal obligations.
7.3 Security, audit, and administration logs: up to 12 months, unless agreed otherwise or legally required.
7.4 Portal user data: while access is active and up to 6 months after, unless longer retention is needed for legal, security, or invoicing purposes.
7.5 Backups: for a limited period necessary for incident recovery.
7.6 Invoicing and administrative data: as required by statutory fiscal retention obligations.
7.7 Support and communication data: as long as reasonably necessary for handling and follow-up of requests.
7.8 For functionality where output can be regenerated, each customer can configure whether raw source content is not retained, retained temporarily, or retained as long as needed for the agreed service. If source content is not or no longer retained, regeneration is only possible after the customer provides the source content again.

8. Data subject rights

8.1 Access to personal data.
8.2 Rectification or deletion of personal data.
8.3 Restriction of processing.
8.4 Objection to processing.
8.5 Data portability.
8.6 Requests can be sent to [email protected]. Capibaira will respond within statutory deadlines.

9. Cookies

9.1 Capibaira uses necessary technologies to make capibaira.com work properly and securely, such as language preferences and contact form protection with Google reCAPTCHA.
9.2 Capibaira uses Google Analytics only after the visitor has given consent through the cookie banner.
9.3 Visitors can reject non-essential cookies and reopen their cookie settings later through the link in the footer.

10. Data breaches

10.1 In case of a security incident that likely poses a risk to data subjects, Capibaira will report this in accordance with GDPR to the Dutch Data Protection Authority and, if necessary, to the affected data subjects.

11. Changes

11.1 Capibaira may amend this Privacy Policy. Material changes will be communicated in time and published on capibaira.com.

Back to overview