CAPITIS
Sign inCreate sandbox key

Business contacts

Version 1.0 · Effective 26 August 2026

This notice is for people who have never used Capitis.

If you have arrived here from an email we sent you, or from a link in one of our messages, this page explains what information we hold about your business, where we got it, and how to make us delete it. That last one takes one email and we do not ask you to justify it.

Capitis is operated by SINGLE.ID LTD, a company registered in England and Wales under company number 17044105, with its registered office at 20 Wenlock Road, London, England, N1 7GU.

Why you are reading this and not our main Privacy Policy

Our Privacy Policy covers two groups: people who hold a Capitis account, and the shoppers whose clicks pass through our customers' tracking links. You are in neither group.

We research businesses that might one day want to use Capitis — publishers, shops, and the people who run them — and that research collects some information about real people. Data protection law applies to that whether or not you are a customer, so it gets its own notice rather than a paragraph buried in a policy written for somebody else.

What we collect

WhatDetail
Business detailsBusiness or brand name, website address, the e-commerce platform it runs on, category, and the town and country it operates in
Contact detailsPublicly published email addresses and telephone numbers from the business's own website. This can include a named individual's address — jane@example.com as well as info@example.com — where that address is published on the site
Public profilesLinks to the business's Instagram, TikTok, YouTube, Pinterest, LinkedIn, Facebook and X accounts, where the site links to them
Assessment notesOur own notes on whether the business looks like a fit, derived from the text published on its website

We do not collect special category data — nothing about health, beliefs, politics, ethnicity, sex life or trade union membership. We do not buy contact lists from data brokers. We do not attempt to find personal addresses, private phone numbers, dates of birth, or anything not published by the business itself.

Where we got it

Four places, all public:

  • Business and map listings — the same directory entries a shopper sees when searching for a business.
  • Common Crawl — a public archive of web pages, maintained by a non-profit, that anyone can download.
  • Online business directories.
  • The business's own website. Once we have a website address, we fetch a small number of its pages — normally the home page and a contact page — and read the contact details and social links published there.

Everything we hold was published openly by the business or listed in a public directory. None of it came from a private source, a purchased list, or another company's customer database.

The purpose: to work out which businesses might benefit from Capitis, and to contact the right ones.

The legal basis: legitimate interests (UK GDPR and EU GDPR Article 6(1)(f)). Our interest is finding customers for a business-to-business product. We have weighed that against your interests and concluded it is reasonable, because: the information is limited to what a business publishes about itself in order to be contacted; it concerns you in your professional capacity, not your private life; the volume is small and targeted rather than bulk; and you can stop it permanently with one email. We keep a written record of that assessment and will share it if you ask.

If you would rather we did not rely on that, say so and we will stop. See How to make us stop below — your right to object here is absolute, and we do not weigh it against anything.

The AI step, stated plainly

To judge whether a business is a fit, we send the text of its public web pages to Anthropic PBC in the United States, which runs the AI model that reads it and answers a fixed set of questions about the business. We send the page text and nothing else — no contact list, no notes on individuals, no data about anyone else. The transfer is covered by Standard Contractual Clauses with the UK International Data Transfer Addendum. Anthropic is listed on our subprocessors page.

No automated decision is made about you that produces a legal or similarly significant effect. The model's output is a note that helps a person decide whether to write to you.

Where the data is held

On our production database in Manchester, United Kingdom. Backup copies are held on the same host and on a second machine we control, which is a laptop and therefore travels with the person who owns it — we are not going to claim it never leaves the country. Our Security page sets out how those copies are protected, including the parts we have not finished.

It is not sold, licensed, shared with any affiliate network or merchant, or passed to anyone else for their own use.

How long we keep it

Twelve months from the date we collected it, unless you have become a customer — in which case the Privacy Policy takes over — or you have asked us to delete it sooner, which we do straight away.

If you ask us to stop contacting you, we keep the minimum needed to honour that: your email address or domain on a suppression list, so that a later research run does not find you again and start over. That is the one thing we keep after an erasure request, and we keep it precisely so the erasure sticks.

How to make us stop

Email privacy@capitis.app with the business name or the email address we used. You do not need to explain why, prove who you are beyond confirming control of the address, or use any particular wording. "Remove me" is enough.

We will:

  • delete the record within 30 days, and normally within a few working days;
  • add you to the suppression list so it does not come back; and
  • confirm to you when it is done.

We do not charge for this and we will not treat you differently for asking.

Your other rights

You can also ask us to give you a copy of what we hold, correct anything wrong, restrict what we do with it, or give you a portable copy. Same address — privacy@capitis.app — and we respond within 30 days.

Complaining

Tell us first at privacy@capitis.app and we will look into it and tell you what we have done.

If that does not satisfy you, you can complain to the UK Information Commissioner's Office (ico.org.uk, helpline 0303 123 1113), or to the data protection authority in your own EU or EEA country. You can go to them directly without coming to us first.

How the removal actually works, and the one manual step

In the spirit of the rest of these pages, the mechanics — because a promise you cannot check is worth very little.

When we remove you, three things happen. Your details are added to a do-not-contact list. That list is also sent upstream to the shared research database we draw from, so other work using the same source stops contacting you too. Then your records are deleted.

The order matters. The do-not-contact entry is written first and kept after your records are gone. If we deleted everything, the next research run would simply find you again and start over — so we keep the minimum needed to remember that you asked. That entry is checked on every import, so a removal cannot quietly undo itself.

The twelve-month deletion runs nightly, without anyone having to remember it.

The one manual step: your email has to reach a person, who then runs the removal. We have not automated that, because a removal request can arrive worded in a hundred ways and we would rather read it than have a machine guess. It is done within a few working days, and always within the 30 days stated above.


Questions or removal requests: privacy@capitis.app · Legal: legal@capitis.app

SINGLE.ID LTD, 20 Wenlock Road, London, England, N1 7GU — Company Number 17044105 (registered in England and Wales).