Data Processing Addendum
This addendum forms part of the Terms of Service between Circulr (the processor) and the customer (the controller). It governs personal data the customer puts into the service. Where it conflicts with the Terms, this addendum wins for data protection.
1. Roles
The customer is the controller and determines the purposes and means of processing. Circulr is the processor and acts only on documented instructions. Using the product is an instruction: importing a contact instructs us to store it; enabling AI research instructs us to send page text to the vendor named in subprocessors.
Circulr is an independent controller for a narrow set of data — account identities, billing records, and the operational logs used to keep the service running and secure. That is covered by the Privacy Policy.
2. Subject matter and duration
Processing lasts for the term of the agreement plus the retention periods in section 7. The subject matter is the operation of publication-management software.
3. Categories of data and data subjects
- Data subjects: the customer's staff; real estate agents and other professionals the customer covers; contacts at partner and advertiser businesses; event attendees; people appearing in photographs.
- Personal data: names, business contact details, employer and role, professional licence identifiers, photographs including images of faces, event attendance, interview recordings and transcripts, free-text notes written by the customer.
- Special categories: none are required by the service. The customer should not enter them. Photographs may permit inference of characteristics; we do not process them for that purpose.
4. Our obligations
- Process only on the customer's documented instructions, including on international transfers.
- Ensure people authorised to process the data are bound by confidentiality.
- Apply the technical and organisational measures in section 5.
- Engage subprocessors only under section 6.
- Assist the customer with data-subject requests, and with security, breach-notification and impact-assessment obligations, taking into account the nature of processing.
- Delete or return the data at the end of the agreement, per section 7.
- Make available the information needed to demonstrate compliance, and allow audits under section 9.
5. Security measures
Each of the following is implemented today, not aspirational.
- Separation between publishers. Every table carrying customer data is protected by database-level row security keyed to the publication, so one publisher’s queries cannot return another’s rows even if application code is wrong. This is verified by an automated test on every change.
- Encryption. Traffic is encrypted with TLS 1.2 or better and the domain is on the HSTS preload list. Integration credentials you save are encrypted with AES-256-GCM before they are written to the database. Off-site backups are encrypted before they leave our infrastructure.
- Access control. Roles run from viewer to owner. Two-factor authentication is available to every account and a workspace owner can require it. Staff access to a workspace for support is signed, time-limited, recorded and revocable.
- Stored files. Uploaded originals and photo renditions are kept in private storage and served through short-lived signed links. Uploaded files are identified by inspecting their contents rather than trusting what the uploader claims.
- Browser protections. A Content-Security-Policy with a per-request nonce blocks injected scripts. Session cookies are HttpOnly, Secure and short-lived.
- Backups. Encrypted database and file backups are taken nightly to separate infrastructure and kept for 90 days. Restores are rehearsed.
- Auditing. Application events, column-level changes to contacts and companies, and every staff support action are recorded and queryable.
We do not hold a SOC 2 report or ISO 27001 certification. We would rather say so than imply otherwise; if an audit report is a requirement for you, tell us before you buy.
6. Subprocessors
The customer gives general authorisation for the subprocessors listed on the subprocessors page. We impose data-protection obligations on each of them no less protective than these, and remain liable for their performance.
We will give at least 30 days' notice before adding a subprocessor that handles customer data. The customer may object on reasonable data-protection grounds within that period; if we cannot resolve the objection, the customer may terminate the affected part of the service.
7. Retention, return and deletion
- The customer can export their data at any time from the workspace settings. The export link is valid for 7 days.
- On a deletion request we place a 30-day hold, during which it can be reversed, and then purge the workspace.
- Encrypted backups are retained for 90 days. Deleted data remains in them until they age out, after which it is gone. We do not restore an individual record from a backup to satisfy a deletion.
- Operational logs are purged after 90 days.
8. Personal data breach
We will notify the customer without undue delay and in any case within 72 hours of becoming aware of a personal data breach affecting their data, with the nature of the breach, the categories and approximate number of records, the likely consequences, and the measures taken. Where we do not have all of it at once, we will provide it in phases. Notice goes to the workspace owners on file, so those addresses should be kept current.
9. Audits
On reasonable written notice, and no more than once a year unless a breach or a regulator requires otherwise, we will answer a security questionnaire and provide documentation about the measures in section 5. On-site audits are by agreement, at the customer's cost, subject to confidentiality and to not compromising other customers.
10. International transfers
Data is processed in the United States. Where a customer transfers personal data subject to UK or EU data protection law, the parties agree to the relevant Standard Contractual Clauses, which are incorporated by reference, with Circulr as importer and the customer as exporter.
11. Contact
Data-protection matters: privacy@circulr.io. Security reports: security@circulr.io.