Skip to content

Legal

Data processing agreement

The terms that apply when Captivaq handles personal data on your behalf. It is published rather than sent on request, and it takes effect when you use the service, so a security review can read it today instead of waiting on a signature.

Effective . Logesta Labs LLC operates Captivaq.

1. When this applies

This agreement applies whenever Logesta Labs LLC processes personal data on behalf of a customer in the course of providing Captivaq. It forms part of, and is governed by, the Terms of Service, and it takes effect when you start using the service. There is nothing to sign to make it apply.

If your procurement process requires a countersigned copy, or your own template, email contact@captivaq.com and say which. We would rather agree paperwork than lose a review to it.

Where this page and the Terms disagree about the processing of personal data, this page governs. On every other subject the Terms govern.

2. Who is the controller and who is the processor

For the content you put into the platform, and for the personal data inside it, you are the controller and we are the processor. You decide what to upload, why, and how long to keep it. We act on your instructions.

For a narrow set of data we are the controller in our own right: the account record needed to identify you, the billing record, the security and audit logs we are obliged to keep, and the public procurement records we collect from government sources, which exist independently of any customer. The privacy policy covers that role. This page covers the processor role.

3. Our instructions, and their limits

We process personal data only to provide the service, to keep it secure and available, and where the law compels us. Your use of the platform is the instruction: uploading a resume instructs us to store and read it, asking for a bid draft instructs us to send the relevant content to the model provider named in section 6.

We do not sell personal data, do not share it for advertising, and do not use your content to train AI models. Our agreement with the model provider prohibits the provider from training on it either.

Two limits are yours to respect. Do not upload classified or export controlled material, or material under a non-disclosure agreement that forbids third-party processing. And do not upload special categories of personal data, which the product neither asks for nor needs. If we believe an instruction breaks applicable data protection law, we will tell you rather than carry it out.

4. Confidentiality

Access to customer content is limited to the people who need it to operate or support the service. Everyone with such access is bound by a duty of confidentiality that survives the end of their engagement. We do not read your bid content for any purpose other than running the service or answering a support request you raise.

5. Security measures

The technical and organisational measures we apply are described in full on the security page, which is incorporated into this agreement by reference. In summary: encryption in transit and at rest, tenant isolation enforced on the server, no password sign-in in production, a role permission matrix enforced at every mutation, scoped and hashed API keys, and an append-only audit trail of every action.

That page also states plainly what we do not have. There is no SOC 2 report, no ISO 27001 certificate and no FedRAMP authorisation today, and we will not imply otherwise in a contract. We may improve measures over time, and will not reduce the overall level of protection while this agreement is in force.

6. Subprocessors

You give general authorisation for us to engage subprocessors. Each one is bound by written terms no less protective than these, and we remain responsible to you for their performance. The current list, and what actually reaches each of them, is maintained in the privacy policy rather than duplicated here, so there is one list to keep accurate:

  • Google LLC. Runs the AI models behind matching, summarising and drafting.
  • Stripe, Inc.. Takes subscription payments and holds the billing record.
  • Cloud application hosting. Serves captivaq.com and app.captivaq.com.
  • Managed database hosting. Stores the account, the company profile and the bid content at rest.

Before we add or replace a subprocessor that handles customer content, we will give you at least 30 days notice by email to the workspace owner. If you reasonably object on data protection grounds within that window, you may terminate the affected subscription and receive a refund of any prepaid, unused fees.

7. Data subject requests

The product is built so you can answer most requests yourself: you can read, correct, export and delete the content in your workspace without asking us. If a data subject contacts us directly about content you control, we will not respond substantively; we will tell them to contact you and let you know. Where you still need help, we will provide reasonable assistance, at no charge for a request of ordinary scope.

8. If there is a breach

If we become aware of a personal data breach affecting your content, we will notify you without undue delay and in any case within 72 hours of becoming aware. The notice will describe what we know, which data and roughly how many records are involved, the likely consequences, and what we are doing about it, and we will follow up as the picture becomes clearer rather than waiting for it to be complete. Notifying your own regulator or your own data subjects remains your decision as controller, and we will give you what you need to make it.

9. Return and deletion

You can export your bid documents to PDF and Word, and delete content, at any time while the account is open. When the account closes, content is deleted within 30 days and rolls out of encrypted backups within a further 90. We keep only what law requires, principally billing records. The full schedule is in the privacy policy.

10. Audits and information

We will make available the information reasonably needed to demonstrate compliance with this agreement, and will answer security questionnaires for customers on an annual basis. Where an audit right applies to you under law, it is satisfied in the first instance by that information and by the security page. An on-site audit may be requested no more than once a year, on 30 days notice, during business hours, subject to confidentiality, and at your cost.

11. International transfers

The platform and every subprocessor operate in the United States, and that is where processing happens. If you are in Canada, using the service transfers your data to the United States, where it may be reachable by US courts and authorities under US law. We do not currently offer Canadian or European data residency. If your obligations under PIPEDA, Quebec’s Law 25, or another regime require a specific transfer mechanism or a privacy impact assessment, email contact@captivaq.com and we will complete what we can. Saying no is more useful to you than a clause we cannot honour.

12. Details of the processing

The annex a reviewer looks for, and the same facts the sections above rely on.

Subject matter
Providing Captivaq: finding public sector opportunities, assessing them against a company profile, and preparing bid documents.
Duration
For as long as the account is open, plus the deletion windows in section 9.
Nature and purpose
Storage, retrieval, analysis, AI-assisted assessment and drafting, notification by email, and export to PDF and Word, all on the customer’s instructions.
Categories of data subject
The customer’s own personnel: the people who hold accounts, and the employees and proposed staff described in resumes, key personnel records and past performance references the customer uploads. Government points of contact reach us from public procurement notices rather than from the customer.
Categories of personal data
Name, business email, business phone, job title, employment history, qualifications, security clearance level where the customer records it, and any personal data contained in documents the customer chooses to upload.
Special categories
None are requested and none are required. The customer should not upload them. See section 3 on instructions.

13. Changes to this agreement

We may update this page as the product or the law changes. A change that materially reduces your protection will be announced by email to the workspace owner at least 30 days before it takes effect, and continuing to use the service after that date accepts it. The effective date at the top of this page moves in the same commit as any change to its substance.

Ask us about this

Questions about this page, a privacy request, or a security review from your team all reach the same inbox: contact@captivaq.com. Say which section you are asking about and we will answer it directly.