Section 01
Scope and Incorporation
This Data Processing Addendum, referred to as the “DPA,”
applies when capture 5 processes personal information,
personal data, or similar protected customer information
on behalf of a client business in connection with the
capture 5 services.
This DPA applies together with the capture 5 Terms of Use,
Privacy Policy, Email Terms, Opt-Out Policy, accepted
checkout terms, campaign agreement, order form, statement
of work, and other applicable written service documents.
This DPA applies when required by applicable privacy law,
incorporated into an accepted order document, or otherwise
accepted by capture 5 for a specific client relationship.
This DPA governs data-processing responsibilities. It does
not replace the payment, service-term, renewal,
cancellation, refund, chargeback, or collection terms
stated in the applicable commercial documents.
Section 02
Data Protection Roles
For customer information provided by a client so capture 5
can deliver authorized reputation services on the client’s
behalf, the client generally acts as the controller,
business, data owner, or similar responsible party.
capture 5 generally acts as the processor, service
provider, contractor, or similar restricted processing
party.
-
The client controls the underlying customer relationship.
-
The client determines the business purpose for providing
customer information to capture 5.
-
The client is responsible for the lawful basis, notices,
consent, permission, and authority supporting the
processing.
-
capture 5 processes the information to provide, secure,
support, document, maintain, and improve the contracted
service.
-
capture 5 may also process information to honor opt-outs,
maintain suppression records, prevent fraud, comply with
law, resolve disputes, and enforce legal rights.
-
capture 5 does not sell client-provided customer email
data to advertisers or data brokers.
The client owns the customer relationship. capture 5
performs the authorized reputation work using the limited
first-party information supplied by the client.
Section 03
Processing Details
The parties intend this section to describe the subject
matter, duration, nature, purpose, data types, data-subject
categories, and related processing obligations.
Subject Matter
Processing of client-provided customer information for
managed review outreach and related reputation services.
Duration
Processing generally continues for the duration of the
active service relationship and for any additional period
reasonably necessary for suppression, legal, billing,
accounting, fraud-prevention, security, backup, dispute,
enforcement, audit, or compliance purposes.
Nature and Purpose
-
Receiving client-provided customer names and email
addresses.
-
Preparing and delivering authorized email-based review
outreach.
-
Placing the Human Trust Video within approved customer
communications where applicable.
-
Directing customers to approved review destinations.
-
Providing a direct customer contact path back to the
client business.
-
Monitoring review activity and preparing or posting
professional responses where included and supported.
-
Managing unsubscribe, suppression, bounce, complaint,
delivery, response, and service records.
-
Providing reporting, service monitoring, quality
control, performance oversight, and support.
-
Maintaining legal, billing, security, compliance, and
operational records.
Types of Personal Information
- Customer first name and last name.
- Customer email address.
-
Limited location or service context where necessary and
approved for the service.
-
Email delivery, unsubscribe, suppression, bounce,
complaint, response, and operational status.
-
Review content, rating, response status, or customer
concern information where supported and included.
-
Client-business contact information for authorized
users, billing contacts, support contacts, and service
contacts.
Categories of Data Subjects
- Recent customers of the client business.
-
Client owners, managers, employees, authorized users,
billing contacts, and service contacts.
-
Prospective client-business contacts who contact
capture 5 directly.
Section 04
Processing Instructions
capture 5 will process client-provided customer
information according to the client’s documented
instructions, applicable service documents, this DPA, the
Terms of Use, and the configuration reasonably necessary
to provide the services.
-
The client instructs capture 5 to process customer names
and email addresses for authorized managed reputation
services.
-
The client instructs capture 5 to use approved review
destinations, business voice instructions, Human Trust
Video placement, contact paths, and account settings.
-
The client instructs capture 5 to process delivery,
unsubscribe, suppression, bounce, complaint, response,
reporting, and operational information as needed.
-
The client authorizes capture 5 to use subprocessors and
service providers reasonably necessary to host, secure,
deliver, support, analyze, bill, and maintain the
service.
-
capture 5 may refuse an instruction that appears
unlawful, unsafe, deceptive, technically unreasonable,
non-neutral, privacy-risky, security-risky, or
inconsistent with capture 5 policies.
capture 5 will not follow instructions to filter, gate,
suppress, manipulate, fabricate, incentivize, or control
customer reviews based on sentiment.
Section 05
Client Business Responsibilities
The client is responsible for the customer relationship
and for ensuring that information submitted to capture 5
is lawful, accurate, appropriate, necessary, and
authorized for the requested service.
-
Maintain a genuine first-party relationship with each
submitted customer.
-
Provide only information the client has the right to
provide to capture 5.
-
Provide required notices and maintain all necessary
consent, lawful bases, permissions, and authority.
-
Do not submit customers whose applicable opt-out,
objection, restriction, or do-not-contact request must
be honored.
-
Promptly notify capture 5 of customer opt-outs,
suppression requests, privacy requests, corrections,
restrictions, disputes, or deletion requests.
-
Maintain accurate review links, business contact paths,
approved destinations, business details, and
customer-facing instructions.
-
Comply with applicable privacy, electronic-message,
advertising, consumer-protection, review-platform,
professional, industry, and local laws.
capture 5 is not responsible for the client’s privacy
notices, consent records, customer permissions, customer
disputes, business operations, products, services,
employees, contractors, platform accounts, or underlying
customer experience.
Section 06
Prohibited and High-Risk Information
capture 5 is designed to process limited customer
identifiers for managed reputation services. The client
must not submit sensitive, unnecessary, regulated, or
high-risk information unless capture 5 expressly agrees
in a signed written agreement.
-
No health information, medical records, treatment
details, diagnoses, patient notes, appointment details,
or protected health information.
-
No financial account numbers, payment-card numbers,
credit reports, government identifiers, Social Security
numbers, passport numbers, tax identifiers, or insurance
identifiers.
- No information about children.
-
No passwords, account credentials, authentication codes,
biometric information, or precise-location information.
-
No unnecessary information concerning race, ethnicity,
religion, political opinions, union membership, genetic
information, sexual orientation, criminal history, or
other legally sensitive categories.
-
No purchased, scraped, rented, brokered, cold-prospect,
competitor, or unrelated lead lists.
-
No information about people who did not have a genuine
customer experience with the client.
capture 5 may reject, delete, isolate, quarantine,
suppress, restrict, or stop processing prohibited
information without waiving a valid payment obligation
owed by the client.
Section 07
Security Measures
capture 5 uses reasonable administrative, technical, and
organizational safeguards intended to protect
client-provided customer information against unauthorized
access, loss, misuse, alteration, disclosure, or
destruction.
-
Access controls intended to limit access to authorized
personnel and service providers.
-
Business systems, hosting providers, email providers,
storage providers, and service tools selected to support
service delivery.
-
Confidentiality obligations or expectations for
personnel and contractors with access to service
information.
-
Operational processes intended to support suppression,
unsubscribe handling, service continuity, and data
accuracy.
-
Vendor and subprocessor management appropriate to the
nature of the services.
-
Security review and service controls appropriate to the
scale, risk, and nature of the processing.
No website, email system, network, storage system, payment
system, internet transmission, vendor platform, or
business process can be guaranteed to be completely
secure.
Section 08
Subprocessors and Service Providers
The client authorizes capture 5 to use subprocessors,
vendors, contractors, and service providers as reasonably
necessary to provide, host, secure, support, deliver,
monitor, improve, bill, and maintain the services.
- Email-delivery providers.
- Customer relationship management and automation providers.
- Hosting, storage, and infrastructure providers.
- Security, fraud-prevention, and monitoring providers.
- Analytics, reporting, and performance providers.
- Payment processors, billing systems, and checkout providers.
- Support, communication, and project-management providers.
- Professional advisers and operational contractors.
capture 5 uses reasonable efforts to require subprocessors
that process client-provided customer information to
protect the information through obligations appropriate to
their role and the services they provide.
capture 5 may add, replace, or remove subprocessors for
service quality, availability, security, cost,
compliance, vendor performance, technical, or operational
reasons.
Where legally required and commercially reasonable,
capture 5 may provide notice of a material subprocessor
change or make relevant subprocessor information available
upon request.
Section 09
Privacy Rights Requests
For client-provided customer information, capture 5
generally acts as a processor or service provider. The
client is generally responsible for responding to privacy
requests from its customers unless applicable law or a
written agreement states otherwise.
-
capture 5 may forward a customer privacy request to the
client.
-
capture 5 may ask the requester to contact the client
directly.
-
capture 5 may reasonably assist the client with access,
correction, deletion, restriction, objection, or
suppression requests where required and technically
feasible.
-
capture 5 may limit or delay assistance when a request
is excessive, unclear, unverifiable, unsupported,
unlawful, technically unreasonable, or outside the
service scope.
-
capture 5 may retain information when necessary for
suppression, legal, billing, tax, accounting, security,
fraud-prevention, dispute, audit, backup, or enforcement
purposes.
The client remains the primary customer contact because
the client owns the underlying customer relationship.
Section 10
Security Incidents and Data Breaches
If capture 5 becomes aware of a confirmed security
incident involving client-provided customer information
that requires notice under applicable law or this DPA,
capture 5 will use reasonable efforts to notify the
affected client without undue delay following confirmation
and appropriate internal review.
-
Notice may be sent to the client’s account, legal,
privacy, security, billing, or service contact.
-
capture 5 may investigate, contain, mitigate, remediate,
document, and communicate about the incident as
appropriate.
-
capture 5 may provide reasonably available information
about the incident, affected data categories, likely
consequences, and responsive steps where appropriate
and lawful.
-
The client is responsible for determining whether notice
to customers, regulators, insurers, platforms, or other
parties is required.
-
Notice of an incident is not an admission of fault,
liability, contractual breach, or legal violation.
Incidents caused by client systems, personnel,
contractors, devices, credentials, instructions,
platform accounts, or third-party systems outside
capture 5’s control remain the client’s responsibility.
Section 11
International Processing and Transfers
capture 5 operates from the United States, including New
Jersey.
Serving businesses across the United States, United
Kingdom, Canada, Australia, New Zealand, Ireland, and
English speaking countries may involve processing,
storage, access, or transfers across national borders.
-
Customer information may be processed in the United
States or other countries where capture 5 or its
authorized providers operate.
-
The client authorizes processing and transfers
reasonably necessary to provide the services.
-
The client is responsible for ensuring that its transfer
of customer information to capture 5 is lawful.
-
Where required, the parties may use appropriate
contractual, technical, organizational, or other lawful
transfer safeguards.
-
U.S.-based systems, vendors, and personnel may process
information because capture 5 is a U.S.-based service.
-
Country coverage does not mean capture 5 maintains an
office, legal entity, registration, approval, or
platform partnership in every market.
International clients remain responsible for determining
the notices, transfer mechanisms, consents, and legal
authority required in their jurisdictions.
Section 12
Deletion, Return, and Retention
Following the end of a client relationship, capture 5 may
delete, return, anonymize, de-identify, suppress, or retain
client-provided information according to applicable
service documents, legal requirements, backup cycles,
operational needs, and this DPA.
-
Billing, payment, tax, accounting, contract, legal,
security, collection, chargeback, fraud-prevention,
dispute, and enforcement records may be retained.
-
Unsubscribe and suppression records may be retained to
honor opt-outs and prevent unwanted sending.
-
Delivery, bounce, complaint, response, and operational
records may be retained for service documentation,
compliance, quality control, dispute resolution, and
legal protection.
-
Backup copies may remain until overwritten or removed
through ordinary backup cycles.
-
Aggregated or de-identified information may be retained
when it no longer reasonably identifies an individual.
A deletion request does not require capture 5 to delete
information that must or may lawfully be retained for
billing, legal, suppression, security, fraud-prevention,
audit, tax, accounting, dispute, backup, or enforcement
purposes.
Section 13
Audit and Compliance Assistance
Upon reasonable written request, capture 5 may provide
information reasonably necessary to assist a client in
verifying compliance with this DPA, subject to
confidentiality, security, privilege, trade-secret,
operational, and reasonable-scope limitations.
-
Requests must be written, specific, reasonable, and
related to the client information processed by
capture 5.
-
capture 5 may respond through policies, summaries,
security descriptions, written responses, provider
information, certifications, or other reasonable
documentation where available.
-
On-site inspections, penetration tests, system scans,
source-code reviews, employee interviews, vendor audits,
facility access, or access to unrelated client
information require express written approval.
-
An audit must not disrupt operations, compromise
security, expose another client’s information, reveal
confidential systems, or create an unreasonable burden.
-
capture 5 may charge reasonable fees for unusual,
excessive, or specially requested audit assistance when
permitted by law and the applicable agreement.
Section 14
No Sale of Client-Provided Customer Information
capture 5 does not sell or rent client-provided customer
email information to advertisers or data brokers.
Customer information submitted for the reputation service
is used to provide the service and related operational,
legal, security, compliance, billing, and support
functions.
-
Client-provided customer information is not used to
build unrelated advertising lists.
-
Client-provided customer email addresses are not sold to
advertisers.
-
Client-provided customer information is not used to
create fake reviews.
-
Client-provided customer information is not used to
gate, suppress, or manipulate review sentiment.
-
Aggregated or de-identified operational information may
be used to improve services and support business
operations.
capture 5 processes customer information to deliver the
reputation service, not to sell customer email addresses.
Section 15
U.S. State Privacy Service-Provider Terms
Where applicable U.S. state privacy law requires
processor, service-provider, contractor, or similar
restrictions, capture 5 will process client-provided
customer information for the business purposes of
providing the services and other purposes permitted by
applicable law.
-
capture 5 will not sell client-provided customer
information as defined by applicable law.
-
capture 5 will not share client-provided customer
information for cross-context behavioral advertising
where prohibited and where capture 5 is acting as a
restricted service provider for that information.
-
capture 5 will not retain, use, or disclose the
information outside the direct business relationship
except as permitted by applicable law, this DPA, or the
service documents.
-
capture 5 may use subprocessors subject to appropriate
processing restrictions.
-
capture 5 may use and retain information for security,
fraud prevention, debugging, legal compliance,
suppression, billing, internal operations, and service
improvement where permitted.
Section 16
Review Platform Independence
capture 5 may direct customers to review destinations
approved by the client. capture 5 is not itself a
third-party review platform and does not control Google,
Facebook, Yelp, Better Business Bureau, Trustpilot, or
other review destinations.
-
capture 5 does not control third-party platform privacy
practices.
-
capture 5 does not control platform publishing,
filtering, moderation, display, ranking, removal, or
account decisions.
-
Customers who follow an independent review link may be
subject to that platform’s privacy policy and terms.
-
The client remains responsible for platform accounts,
profile links, access permissions, review practices, and
compliance.
Section 17
Neutral Review Processing
capture 5 is designed to support neutral customer review
outreach following real customer experiences. This DPA
does not authorize review gating, rating filtering, fake
reviews, review suppression, or sentiment manipulation.
-
Eligible customers receive a neutral opportunity to
provide honest feedback.
-
Customers may receive a direct way to contact the
business when they need help.
-
capture 5 does not select customers based on an expected
rating.
-
capture 5 does not direct only favorable customers to
public review platforms.
-
capture 5 does not prevent dissatisfied customers from
accessing approved public review destinations.
-
capture 5 does not dictate, require, or pressure
customer sentiment or review wording.
Section 18
No Change to Commercial Obligations
This DPA does not modify or reduce the client’s payment,
initial-term, renewal, refund, recurring-payment,
failed-payment, chargeback, collection, cancellation, or
other commercial obligations.
- A data request does not cancel service.
- A deletion request does not cancel service.
- An opt-out request does not cancel service.
- A privacy rights request does not cancel service.
-
A suspension caused by improper information does not
automatically waive valid payment obligations.
-
A client’s failure to provide lawful or usable customer
information does not automatically waive valid payment
obligations.
Commercial obligations remain governed by the Terms of
Use, accepted checkout terms, campaign agreement, order
form, invoice, and other applicable service documents.
Section 19
Client Responsibility for Data-Related Claims
To the extent permitted by law and subject to the Terms of
Use, the client agrees to defend, indemnify, and hold
harmless capture 5 and its owners, officers, employees,
contractors, affiliates, agents, and authorized service
providers from applicable third-party claims,
investigations, complaints, losses, penalties, damages,
costs, and reasonable legal fees arising from:
- Client-provided customer information.
-
Missing notices, consent, lawful basis, permission, or
customer-contact authority.
-
Purchased, scraped, rented, cold, unrelated, or
otherwise improper lists.
-
Prohibited, sensitive, inaccurate, unnecessary, or
unlawful information supplied by the client.
-
Failure to honor opt-outs, suppression requests,
restrictions, or privacy rights requests.
-
Client instructions that violate law, platform rules,
customer rights, privacy obligations, or capture 5
policies.
-
Client operations, products, services, employees,
contractors, customer experience, or customer disputes.
Section 20
Conflict and Order of Precedence
If this DPA conflicts with the Terms of Use or another
service document, this DPA controls only for the specific
privacy-processing issue involving client-provided
customer information.
The Terms of Use, accepted checkout terms, campaign
agreement, order form, invoice, and payment terms control
commercial, billing, cancellation, refund, service-term,
collection, and general service-relationship matters.
A mutually signed written agreement that expressly
modifies this DPA controls for the specific client
relationship and subject matter covered by that agreement.
Section 21
Changes to This DPA
capture 5 may update this DPA to reflect changes in law,
services, security practices, subprocessors, email
systems, platform access, privacy requirements, service
providers, or business operations.
Updated terms will be posted with a revised effective
date. Material changes apply prospectively unless
applicable law or a mutually accepted agreement permits
different treatment.
Where a signed agreement requires a specific amendment or
notice process, that process controls for the applicable
client relationship.
Section 22
Contact capture 5
Questions about this Data Processing Addendum,
client-provided customer information, privacy requests, or
processing obligations may be sent using the contact
information below.
Use the subject line “Data Processing Question” for a
general DPA question or “Privacy Request” when the message
concerns an individual privacy request.