Captivo Access Privacy Policy
Last updated: 27 September 2026
This policy covers Captivo Access — time-boxed, recorded vendor access without a VPN. For our guest WiFi product see the Captivo Portal Privacy Policy. Our obligations as a processor are set out in the Captivo Access Data Processing Agreement.
1. Introduction
This policy explains what personal data Captivo Yazılım A.Ş. processes in Captivo Access. It is aligned with Turkish Law No. 6698 on the Protection of Personal Data (KVKK) and the General Data Protection Regulation (GDPR).
Captivo Access is offered two ways: hosted by us, or on your own server. In either case the connector that carries the traffic runs inside your own network. That distinction governs this whole policy — see section 10.
2. What we process (hosted use)
2.1 Account holders and console users
- Email address and name
- Passkey (WebAuthn) public key — no password is ever created or stored
- A TOTP secret for recovery, stored encrypted
- Session data: the token's hash, its expiry, the browser string and the IP address
- Role (ADMIN, OPERATOR, AUDITOR, STAFF, VENDOR)
2.2 Vendors (external users)
- Email address and name
- Invitation and acceptance records
- Grants: who may reach which resource, within which time window
- Access requests and the decisions on them
2.3 The session index — NOT the content
When a session is recorded, what reaches us is an index row: which user, which resource, when, how many bytes, which format. The recording itself does not — see section 3.
2.4 Audit records
Console actions and access decisions are kept in a chain in which later alteration is detectable. This record exists for accountability and is not deleted together with the access it describes.
2.5 The credential vault
Usernames and passwords or private keys for remote-desktop sessions are stored encrypted. They are decrypted only while the connection handshake is built, and never reach the vendor's browser.
2.6 Operational data
- The connector's online state, version and counters
- Reachability probes for your resources (latency, failure reason)
- Server logs, short-lived, for debugging
3. What we do NOT process
This section is the most important property of this product, and it is enforced technically rather than promised.
3.1 The content of session recordings
Screen streams, isolated-browser video and keystroke logs are processed and stored on your own connector's disk. They are encrypted with AES-256-GCM using a key the connector generates itself, and that key never leaves that machine. The control plane neither receives the content nor can decrypt it.
Command search also runs on the connector holding the recordings; the text being searched does not leave it.
3.2 Internal network addresses
The real internal addresses of your resources are never sent to the vendor's browser.
3.3 Remote-desktop credentials
As set out in 2.5: stored encrypted and never shown to the vendor.
4. Purpose and lawful basis
- Performance of a contract: creating the account, enforcing grants, establishing sessions
- Legitimate interest: security, preventing abuse, keeping the service running
- Legal obligation: retaining audit records for accountability
The lawful basis for recording a session is determined by you: you are the party that turns recording on and chooses its scope and duration. Informing your vendors that sessions are recorded is your obligation — see the Terms of Use.
5. Where data is held, and transfers
- Session recordings: on your connector only; never transferred anywhere
- Identity, grant, audit and index data: on our hosted infrastructure
- Recording content does not cross a border, because it does not leave your premises at all
We will tell you where our hosting is located and who our sub-processors are on request; see section 7 of the Data Processing Agreement.
6. Retention
- Session recordings: for the retention window you set in the console. The connector applies it to its own files, so the deletion happens on its disk.
- Audit records: kept longer than the access they describe, because that is what accountability requires; the period is set in the console.
- Account and grant data: for as long as the account is open; deleted on closure except where a legal retention duty applies.
- Server logs: short-lived, for debugging.
When you ask for a recording to be deleted, the request is recorded at once; the content goes when the connector confirms on its next connection. Until then the recording is marked erasure pending.
7. Security measures
- No passwords: authentication is by passkey (WebAuthn)
- Session recordings are encrypted with AES-256-GCM under a key that stays on the connector
- Vault credentials are stored encrypted and never shown to the vendor
- The connector dials outbound only; no inbound port is opened in your network
- Access is re-evaluated on every request; revoking a grant takes effect on the next one
- Audit records are kept in a chain in which alteration is detectable
- Tenant isolation is enforced in the database with row-level security
8. Sharing and sub-processors
We do not sell your personal data. It is shared only:
- with the hosting and email infrastructure we use to provide the service (sub-processors)
- with competent authorities where legally required
- with parties you designate by explicit instruction
A current list of sub-processors is available on request.
9. Your rights
- To learn whether your personal data is processed
- To request information about that processing
- To learn its purpose and whether the data is used accordingly
- To know the third parties to whom data is transferred, at home or abroad
- To have incomplete or inaccurate data corrected
- To have data erased or destroyed
- To have such corrections and erasures notified to recipients
- To object to an adverse outcome produced solely by automated analysis
- To seek compensation for damage arising from unlawful processing
Send requests to privacy@captivo.io.
10. Self-hosted deployments
When you run Captivo Access entirely on your own server, identity and directory data do not reach us either. In that case Captivo is not a processor and sections 2, 5, 6 and 8 of this policy do not apply: all of the data stays on your infrastructure and the controller's obligations are yours.
The software is offered under Apache-2.0. A self-hosted installation exchanges no data with us.
11. Cookies
The console uses only cookies strictly necessary for the service: the session cookie, the language preference, and short-lived flow cookies used for security. No advertising or third-party tracking cookies are used.
12. Changes to this policy
When this policy changes we update the date at the top of the page. Account holders are notified by email of any material change.
13. Contact
- Email: privacy@captivo.io
- Data Controller: Captivo Yazılım A.Ş.