Who we are
CapoFine is registered in Estonia. In this notice, CapoFine, we, us, and our refer to the same service provider.
For information collected through this website, sales conversations, support, and our own business administration, CapoFine generally acts as controller. For candidate and employee data that a customer submits to Hire, Onboard, or Grow, the customer generally acts as controller and CapoFine acts as processor under the customer agreement and Data Processing Agreement.
Information we collect
- Website and sales details, such as your name, work email, company, timezone, request, source page, product interest, campaign context, booking time, and assigned host.
- Information used to produce a requested Plan Finder recommendation or ROI report, including the answers and assumptions you provide.
- Account and work details submitted by a customer, such as name, email address, profile photo, job title, department, start date, preferred language, working days, team, and manager.
- Candidate and employee journey information, including applications, communications, interview feedback, tasks, meetings, goals, learning progress, survey responses, missions, story activity, results, and uploaded files.
- Optional information selected by a customer, such as biography, LinkedIn or GitHub profile, personal website, or personality profile.
- Technical and security information, such as IP address, device and browser information, session data, usage statistics, login and access events, and diagnostic logs.
Why we use personal data
- To respond to enquiries, arrange meetings, provide requested reports, prepare relevant sales conversations, and administer customer relationships.
- To provide, secure, support, maintain, and improve Hire, Onboard, Grow, and the website.
- To perform a contract, take steps requested before a contract, and administer billing, support, and service delivery.
- To pursue legitimate interests in operating a secure business-to-business service, understanding service use, preventing abuse, and improving customer experience, where those interests are not overridden by individual rights.
- To send optional analytics or marketing communications only where the required consent or another lawful basis applies.
- To meet legal obligations and establish, exercise, or defend legal claims.
Customer-controlled platform data
Customers determine why candidate and employee data is processed in CapoFine and are responsible for an appropriate legal basis, required notices, permissions, and instructions. We process that data only on documented customer instructions, except where law requires otherwise.
We do not sell or rent customer personal data, use it for unrelated advertising, or use it to profile people outside the agreed service purposes. People authorised to process customer data are bound by confidentiality and receive access only where needed for their work.
Service providers and recipients
We use service providers where needed to operate the platform and website. The platform register includes DigitalOcean for application hosting in Amsterdam, MongoDB Atlas for database hosting in Frankfurt, Amazon Web Services for file storage in Frankfurt, and APIDeck for optional HRIS integrations in the EEA.
The website can also use Microsoft 365 for scheduling and Microsoft Teams invitations, Twenty CRM for sales records and follow-up, Supabase for first-party booking, lead, and private report storage, and Resend for transactional email delivery. Access is limited to the relevant purpose and configuration.
If you allow anonymous analytics, CapoFine uses a self-hosted Umami instance on approved EU infrastructure to measure pageviews, referral and campaign information, and approved conversion events. We do not send names, email addresses, company names, form answers, notes, or report contents to Umami.
We may also disclose information where required by law, to protect rights and security, or as part of a corporate transaction subject to appropriate safeguards.
Data location and international transfers
The standard CapoFine platform processing described in our Data Processing Agreement is carried out within the European Economic Area. Core employee data is hosted in Frankfurt, uploaded files are stored in Frankfurt, application services are hosted in Amsterdam, and backups are held in Frankfurt and Amsterdam.
If a service or customer-approved configuration requires a transfer outside the EEA, we use an applicable safeguard, such as an adequacy decision or the European Commission's Standard Contractual Clauses, and provide advance information where the customer agreement requires it.
Retention, export, and deletion
We retain website and business information only for as long as needed for the purpose described in this notice, the customer relationship, security, accounting, or another legal obligation.
Optional Umami analytics is retained for no longer than 13 months and is then deleted.
Customer platform data is retained during the service term. At termination, the standard Data Processing Agreement provides for return or deletion within 30 days, including database records, uploaded files, logs, and backups after their retention period. A customer agreement may set a different 60-day or 90-day migration period. Written deletion confirmation is available.
Customers can request a standard export of platform data in commonly used formats such as CSV or JSON. Uploaded files can be supplied as a compressed archive.
Your rights
Depending on the circumstances, you may have rights to access, correct, erase, restrict, or object to processing, to receive portable data, and to withdraw consent without affecting earlier lawful processing.
If your request concerns data held in a customer's CapoFine workspace, contact that customer first because it controls the data. We assist customers with verified requests. For data we control, contact privacy@capofine.com. We may need to verify your identity before acting.
You may lodge a complaint with the Estonian Data Protection Inspectorate or another competent supervisory authority. We encourage you to contact us first so we can try to resolve the concern.
Security and incidents
We use technical and organisational safeguards that include encryption in transit and at rest, role-based access, least-privilege permissions, secure authentication, logging, monitoring, encrypted backups, recovery testing, confidentiality commitments, security training, and incident response procedures.
When we act as processor, we notify the affected customer of a personal data breach without undue delay and, where possible, within 24 hours after becoming aware. The customer remains responsible for notifications to authorities and affected people, and we provide reasonable assistance.
Cookies, communications, and children
Necessary browser storage supports requested website journeys. Optional analytics is activated only after the required choice. Booking a meeting or requesting a report does not automatically subscribe you to marketing. See the cookie notice for the current browser-storage details.
CapoFine is a business service for organisations and their workforce. The website is not directed to children. Customers must not submit children's data unless they have a lawful purpose, appropriate authority, and a written agreement that permits it.
Contact and changes
Privacy questions can be sent to privacy@capofine.com. Data deletion requests can be sent to datadeletion@capofine.com. Security incidents can be reported to security@capofine.com. General enquiries can be sent to hello@capofine.com.
We may update this notice when our services, providers, or legal obligations change. We will publish the current version here and communicate material changes where required.