How to read this register
CapoFine engages service providers only for defined platform or business purposes. Providers receive only the access needed for their service and are bound by contractual data-protection and security obligations.
The signed Data Processing Agreement remains the controlling register for a customer. Optional services process data only when the relevant integration or workflow is enabled.
Core platform subprocessors
- DigitalOcean, Amsterdam, the Netherlands: application code and web-server hosting.
- MongoDB Atlas, Frankfurt, Germany: database hosting for customer employee and platform data.
- Amazon Web Services, Frankfurt, Germany: encrypted object storage for uploaded files and documents.
- APIDeck, EEA infrastructure: optional HRIS integration connectivity with a zero-data-retention service model.
Website and commercial service providers
- Microsoft 365: meeting availability, Microsoft Teams events, calendar invitations, and assigned-host scheduling.
- Twenty CRM: contact, company, opportunity, note, task, source, and booking context for sales and customer follow-up.
- Supabase: first-party booking, lead, and private report storage when configured.
- Resend: transactional delivery of requested reports and assigned-host notifications when configured.
- Umami: self-hosted, cookie-free website analytics on approved EU infrastructure, loaded only after the visitor allows anonymous analytics.
Location and transfers
The standard platform processing described in the Data Processing Agreement takes place within the EEA. Frankfurt is used for core database and file storage. Amsterdam is used for application hosting and backup replication.
Where a website provider or customer-approved configuration involves processing outside the EEA, CapoFine uses an applicable transfer safeguard, such as an adequacy decision or the European Commission's Standard Contractual Clauses.
Changes and objections
Customers receive at least 30 days' written notice before a new platform subprocessor is engaged where the Data Processing Agreement requires it. A customer can submit a reasoned data-protection objection within 14 days of that notice.
For the current contractual register, supporting assurance information, or a question about a provider used in your configuration, contact privacy@capofine.com.