1Subject Matter and Duration
We process personal data on your behalf for the duration of your subscription to the Service, plus the post-termination retention period described in our Privacy Policy (Section 7), after which the data is deleted or returned in accordance with Section 9 below.
2Nature and Purpose of Processing
We process personal data as necessary to provide the Service: receiving and storing job, site, and asset records; sending job-status notifications and reminders; storing job photos and customer signatures; generating quotes, invoices, and compliance certificates; and using AI-assisted classification to triage inbound job reports (see Privacy Policy Section 5). We do not process the data for any purpose beyond providing the Service, unless required by law.
3Categories of Data Subjects and Personal Data
3.1 Data subjects: your own team members (owner, office, engineer, manager roles), and your end-customers — the individuals whose sites, assets, or jobs you manage through the Service.
3.2 Categories of personal data: names, contact details (email, phone, address), site/property information, job history and notes, photos and signatures captured during job completion, and, where applicable, billing contact details. No special category data (as defined by UK GDPR Article 9) is knowingly processed by the Service.
4Your Instructions
4.1 We will process personal data only on your documented instructions, including with regard to transfers of personal data to a third country, unless required to do otherwise by UK law — in which case we will inform you of that legal requirement before processing, unless the law prohibits this.
4.2 Your use of the Service's normal functionality (creating jobs, inviting users, configuring enabled features, sending notifications) constitutes your documented instruction for the corresponding processing. Any instruction outside that normal functionality should be sent in writing to support@circuitos.app.
5Confidentiality
We ensure that any person authorised to process personal data (including our own staff and contractors) has committed to confidentiality or is under an appropriate statutory obligation of confidentiality.
6Security
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in line with Article 32 UK GDPR, including: encryption of data in transit and at rest via our infrastructure providers; role-based access control and row-level data isolation between Customer organisations; server-enforced two-factor authentication and rate limiting on authentication endpoints; access-controlled, signed-link-only storage for photos and signatures (not publicly browsable); and regular dependency and security review of the Service codebase.
7Sub-processors
7.1 You provide general authorisation for us to engage the sub-processors listed in our Privacy Policy (Section 6), and any successor or additional sub-processor we may engage from time to time to provide the Service.
7.2 We will impose data protection terms on any sub-processor we engage that protect personal data to at least the same standard as this DPA, and remain fully liable to you for that sub-processor's performance of its data protection obligations.
7.3 We will give you reasonable notice (via the Service, our website, or direct communication) of any intended change to our sub-processors, giving you the opportunity to object on reasonable data-protection grounds before the change takes effect.
| Sub-processor | Purpose | Region |
|---|---|---|
| Supabase | Database, authentication, file storage | US/EU (project-specific) |
| Anthropic | AI-powered issue classification | US |
| Postmark | Sending/receiving transactional email | US |
| Vercel | Application hosting | Global edge network, primary US |
| GoCardless | Payment collection | UK |
Where a sub-processor is located outside the UK, transfers are made under the UK International Data Transfer Agreement (or the equivalent addendum to the EU Standard Contractual Clauses), consistent with Privacy Policy Section 6.
8Data Subject Rights
Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures, insofar as reasonably possible, to fulfil your obligation to respond to requests from data subjects exercising their UK GDPR rights (access, rectification, erasure, restriction, portability, and objection). Where an end-customer contacts us directly about their own data, we will forward the request to you and provide reasonable assistance, consistent with Privacy Policy Section 8.
9Assistance with Your Compliance Obligations
9.1 We will assist you, taking into account the nature of processing and the information available to us, in ensuring compliance with your obligations under Articles 32 to 36 UK GDPR (security of processing, breach notification, data protection impact assessments, and prior consultation with the ICO where required).
9.2 We will notify you without undue delay after becoming aware of a personal data breach affecting personal data we process on your behalf, providing the information reasonably available to us to help you meet your own 72-hour ICO notification obligation.
10Deletion or Return of Data
At your election, and subject to the retention periods described in Privacy Policy Section 7 (which reflect our own legitimate need to retain certain records for a limited period after termination, including for data export and legal defence purposes), we will delete or return all personal data processed on your behalf at the end of the provision of the Service, and delete existing copies unless UK law requires us to retain the data.
11Audits and Compliance Information
We will make available to you all information reasonably necessary to demonstrate compliance with this DPA, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate — provided you give reasonable prior written notice, conduct the audit during business hours, take reasonable steps to avoid causing damage or disruption to our systems or other customers, and keep the results confidential. We may charge a reasonable fee for audits requested more than once in any 12-month period.
12Liability and Governing Law
Liability under this DPA is governed by the liability provisions of the Terms of Service. This DPA is governed by the law of Scotland, consistent with Terms of Service Section 13, and the courts of Scotland have exclusive jurisdiction over any dispute arising from it.