Data Protection
Last updated: April 1, 2025
Circulic is committed to protecting personal data in compliance with the General Data Protection Regulation (GDPR) and other applicable data protection laws. This page outlines how we handle data protection responsibilities and your rights as a data subject.
Data Controller
Circulic Inc., located at 200 Innovation Drive, Suite 400, San Francisco, CA 94105, United States, acts as the data controller for personal data processed through the Circulic platform. For EU-based operations, our representative is Circulic EU B.V., Keizersgracht 520, 1017 EK Amsterdam, Netherlands. We determine the purposes and means of processing personal data collected through our platform and services.
Legal Basis for Processing
We process personal data under the following legal bases as defined by the GDPR: contractual necessity (to provide our platform services), legitimate interest (to improve our services, prevent fraud, and ensure security), consent (for marketing communications and optional analytics), and legal obligation (to comply with applicable laws and regulations). You may withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected. Active account data is retained for the duration of your account plus 30 days after closure. Transaction records are retained for 7 years to comply with financial regulations. Usage analytics are anonymized after 24 months. Backup data is purged within 90 days of deletion from production systems. You may request earlier deletion subject to legal retention requirements.
International Data Transfers
Your data may be transferred to and processed in countries outside the European Economic Area (EEA). We ensure adequate protection through EU Standard Contractual Clauses (SCCs) approved by the European Commission, adequacy decisions where applicable, and supplementary technical measures including encryption and access controls. Our primary data processing occurs in the United States and the European Union. A copy of our SCCs is available upon request.
Your Rights Under GDPR
As a data subject, you have the right to: access your personal data and obtain a copy; rectify inaccurate or incomplete data; erase your data ('right to be forgotten') under certain conditions; restrict processing of your data; data portability in a machine-readable format; object to processing based on legitimate interests; not be subject to automated decision-making including profiling; and lodge a complaint with your local supervisory authority. To exercise any of these rights, contact our DPO at the address below.
Data Protection Officer
Our Data Protection Officer can be reached at: dpo@circulic.com or by mail at Circulic Inc., Attn: Data Protection Officer, 200 Innovation Drive, Suite 400, San Francisco, CA 94105, United States. For EU-specific inquiries, you may also contact our EU representative at eu-privacy@circulic.com. We aim to respond to all data protection requests within 30 days.