All legal documents

Data Protection & GDPR Statement

Our public data-protection commitments, governance controls, processor requirements, individual-rights process, and regional compliance framework.

Operational draft — legal sign-off required

This draft reflects the intended systems and consent controls. A qualified privacy professional should verify the facts, vendor contracts, and applicable regional scope before publication.

Last updated: 19 August 2026

1. Our Commitment

CAPSULES DIRECT LTD is accountable for personal information used in its business. We apply the principles of lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; security; and accountability. This statement supplements our detailed Privacy Notice and Cookie and Analytics Notice.

2. Governance And Records

  • Maintain a record of processing that maps the information, purpose, people, source, legal basis, system, recipient, transfer, retention period, and owner.
  • Assign a data protection lead and review the need for a statutory DPO as the business, monitoring, and risk profile changes.
  • Complete legitimate-interest assessments where legitimate interests are the legal basis.
  • Complete data-protection impact assessments before high-risk monitoring, profiling, sensitive-data use, or major new technology.
  • Build privacy checks into procurement, system design, integrations, forms, portal roles, and product changes.
  • Review this framework, vendor inventory, access, retention, incidents, and rights requests at least annually.

3. Systems And Processor Controls

SystemControl commitment
Odoo Enterprise on Odoo.shUse a written processor agreement; select an appropriate hosting region; restrict production, backup, support, integration, and developer access; review subprocessors and optional IAP features; and test export, deletion, and incident procedures before portal launch.
Google WorkspaceEnsure the Cloud Data Processing Addendum applies; use the most suitable data-region setting available to our edition; enforce MFA and least privilege; control external sharing, groups, mobile access, and third-party apps; and set retention rules that match the record schedule.
Google AnalyticsUse prior opt-in; basic consent mode; no advertising storage or personalisation; no User-ID or direct identifiers; six-month cookies; limited event retention; restricted access; and no data sharing or Ads linking unless separately assessed and consented.

A provider contract does not remove our responsibility as controller. Before material processing begins, we identify each party's role, document instructions, review security and subprocessors, set deletion/return terms, and establish a lawful transfer mechanism where required.

4. Privacy By Design And Security

  • Collect only fields needed for a stated business purpose and avoid free-text collection where structured choices are sufficient.
  • Keep the public website separate from customer and operational records and do not send portal, account, order, or form identifiers to analytics.
  • Use role-based access, MFA where available, secure authentication, encryption in transit, backups, logging, vulnerability and dependency management, and access reviews.
  • Use test or synthetic data in development wherever practical and prevent production data from entering unapproved tools.
  • Remove access promptly when a worker or supplier changes role or leaves, and investigate unusual access or export activity.

5. Individual Rights And Complaints

Rights requests and privacy complaints may be submitted to privacy@capsules.com or the privacy form on our Contact page. We log the request, acknowledge UK complaints within 30 days, verify identity proportionately, search reasonably and proportionately, coordinate with processors, record any exemption relied on, and respond within the applicable statutory period.

We do not penalise anyone for exercising a privacy right. Where a US state provides an appeal right, a requester can appeal a refusal. People may also complain to the ICO, an EEA supervisory authority, the California Privacy Protection Agency, a state attorney general, or another regulator with jurisdiction.

6. Breach And Incident Response

Staff and suppliers must report suspected loss, unauthorised access, misdirection, disclosure, alteration, or unavailability promptly. We contain and investigate the incident, preserve evidence, assess the people and information affected, document the decision, and notify regulators, customers, or individuals within the time and threshold required by applicable law. UK GDPR notification to the ICO is made without undue delay and, where feasible, within 72 hours when the statutory risk threshold is met.

7. International And Regional Compliance

We treat UK GDPR as the operational baseline for core business records, add EU GDPR and national ePrivacy controls for relevant EEA activities, and apply US notice, access, deletion, correction, portability, opt-out, appeal, and universal opt-out requirements where a state law applies. California visitors receive a notice at collection and supported Global Privacy Control signals are honored.

For restricted transfers, we document the destination, recipient, data, purpose, safeguard, and any transfer-risk or data-protection test. We use adequacy, approved contractual clauses or addenda, a qualifying data-privacy framework, or another lawful mechanism and add supplementary measures where needed.

8. Review And Accountability

This statement is owned by our data protection lead. Questions and evidence requests can be sent to privacy@capsules.com. It is reviewed at least annually and after a material system, vendor, processing, legal, or organisational change. This version takes effect on 19 August 2026.