Captivo AccessLast updated: 26 September 2026

Captivo Access — Data Processing Agreement (DPA)

KVKK / GDPR compliant processor agreement

What this agreement covers

This agreement covers Captivo Access only. The guest WiFi and captive portal service (Captivo Portal) is covered by a separate agreement: Captivo Portal DPA. Prepared under KVKK art.12 and GDPR art.28.

Session recordings never leave your infrastructure

Session recording content — screen streams, keystroke logs, isolated browser video — is processed and stored on the connector running inside the Controller's own network, encrypted with a key the connector generates itself. Captivo never receives, stores or is able to decrypt that content: the key is never transmitted to Captivo. Search runs on the connector that holds the recordings.

1. Parties and definitions

  • Controller: the organisation using Captivo Access to give third-party vendors access to its internal systems.
  • Processor: Captivo — in respect of the index and identity data listed below, and nothing else.
  • Data subject: vendor personnel granted access, and the console users who administer it.
  • Connector: software the Controller runs inside its own network, which holds the session recordings.

2. Data processed by Captivo

Only the following is processed on Captivo infrastructure:

  • Identity and account data (email, name, passkey public key)
  • Grants (who, which resource, which time window)
  • The session index: which recording, which resource, which user, start and end time, byte count, format
  • Audit records (console actions, access decisions)

3. Data Captivo does NOT process

The following never reaches Captivo infrastructure and cannot be read by Captivo:

  • Session recording content (screen, terminal output, video)
  • Keystroke logs — the text and commands a vendor typed
  • Credentials for the target systems (these stay on the connector)
  • The recording encryption key

4. Retention, backup and risk of loss

Because session recordings sit on the Controller's own hardware, backing them up is the Controller's obligation. Captivo holds no second copy.

  • If the connector's volume is lost the recordings are lost permanently; Captivo cannot restore them.
  • The recording encryption key file must be backed up with the volume. Without it the recordings cannot be read, and it cannot be reissued.
  • The retention window is set in the console; when it expires the connector performs the deletion on its own disk and reports the result to Captivo.

5. Erasure requests and timing

A data subject's erasure request, or the Controller's decision to destroy a recording, is recorded in the console immediately. Because the content is on the connector, the deletion is carried out the next time that connector connects.

  • The recording is marked "erasure pending" in Captivo and stays so until the connector confirms.
  • If the connector is offline, erasure is delayed. Captivo does not report it as complete.
  • For the purposes of KVKK art.7 / GDPR art.17 deadlines, keeping the connector reachable is the Controller's responsibility.

6. Availability limit

A session recording is searchable and playable only while the connector holding it is online. When a connector is offline the console states that the search answer is incomplete; it does not report "no results".

7. Sub-processors

Session recording content is disclosed to no sub-processor; it does not leave the Controller's infrastructure. Hosting and email sub-processors are used for the index and identity data processed by Captivo; the current list is available on request.

8. Security measures

  • Recordings are encrypted at rest with AES-256-GCM (key held on the connector)
  • The connector makes outbound connections only; no inbound port is opened
  • Vendors authenticate with passkeys; there is no shared password
  • Grants carry a start and end time and expire on their own
  • Console actions are written to a tamper-evident audit chain

9. Self-hosted deployment

When Captivo Access is run entirely on the Controller's own servers, the index and identity data do not reach Captivo either. In that case Captivo is not a processor and this agreement does not apply.

10. Breach notification

Captivo notifies the Controller within 24 hours of becoming aware of a breach of its own infrastructure. Detecting and notifying a breach of the infrastructure hosting the connector is the Controller's responsibility; Captivo has no access to it.

11. Term and governing law

This agreement applies for as long as Captivo Access is used. When the service ends, the index and identity data held by Captivo are deleted within 30 days; the recordings on the connector remain under the Controller's control. Disputes are governed by the laws of the Republic of Türkiye, with the courts of Istanbul having jurisdiction.

Acceptance

By using Captivo Access you accept this Data Processing Agreement. It applies from the date the service is first used.

Questions about this agreement: support@captivo.io