1Data We Collect
Customer users (people with a CircuitOS login)
- Name, email address, and password (handled via our authentication provider, Supabase)
- Organisation membership and role (owner / office / engineer / manager)
- Business details entered for the organisation: business address, VAT number, logo, labour rates, price list
- Messages sent to the in-app help assistant, and the transcript of that conversation if you ask to speak to a human
End-customers (people your business serves, who never log in)
- Name and contact details (email or phone) submitted via the report form or inbound email
- Site/location information
- Description of the issue reported
- Job photographs and completion signatures, where a Customer’s engineer uploads them
2How We Use This Data
- To operate the Service: creating and tracking jobs, sites, assets, invoices, and service contracts
- To power AI-assisted features: classifying incoming reports and determining job urgency (processed via Anthropic’s API — see Section 5)
- To send transactional notifications: e.g. emailing a Customer’s team about a new report or job update (sent via Postmark)
- To provide the public job-tracking page, so an end-customer can check progress on a reported issue without logging in
- To bill Customer for use of the Service (via GoCardless)
- To maintain the security and integrity of the Service
3Legal Basis
Broadly:
- Processing Customer user data: performance of a contract (the subscription agreement) and legitimate interests (securing and improving the Service)
- Processing end-customer data: we process this as a processor on behalf of Customer, who is the controller and is responsible for having its own lawful basis (typically legitimate interests or contract, for responding to a reported issue)
4Job Photos and Signatures
Job photos and customer signatures are stored in access-controlled storage and are only accessible via time-limited signed links generated for authorised Customer users — they are not publicly browsable. They are retained for the life of the job record plus 5 years, reflecting the negative prescription period for contract and negligence claims under the law of Scotland (the Prescription and Limitation (Scotland) Act 1973, as amended) — the governing law of these Terms — which is the realistic window in which a claim about the work performed could arise. Where the underlying Customer relationship is instead governed by the law of England and Wales, the equivalent period is up to 6 years under the Limitation Act 1980. After the applicable period, this data is deleted.
5AI Processing
Reports submitted via the web form and inbound email are sent to Anthropic’s Claude API to generate a classification and urgency rating. Anthropic does not use data submitted via its commercial API to train its models, and retains it only for a limited period for abuse and safety monitoring. We do not use this data to train our own AI models, and no de-identification is applied before sending, since the AI needs the real report content (site, issue, contact details) to classify it.
6Sub-processors and International Transfers
We share data with the following sub-processors, each acting under its own data processing terms with us:
| Sub-processor | Purpose | Region |
|---|---|---|
| Supabase | Database, authentication, file storage | US/EU (project-specific) |
| Anthropic | AI-powered issue classification | US |
| Postmark | Sending/receiving transactional email | US |
| Vercel | Application hosting | Global edge network, primary US |
| GoCardless | Payment collection | UK |
Where a sub-processor is located outside the UK, transfers are made under the UK International Data Transfer Agreement (or the equivalent addendum to the EU Standard Contractual Clauses).
7Data Retention
- Customer user account data: retained for the life of the subscription, plus 30 days after termination to allow for data export, then deleted.
- Job, customer, and site records: retained for the life of the job record plus 5 years after the org's account closes, matching the realistic window for a claim about the work performed to arise — see Section 4 for the basis.
- Invoice and other financial records: retained for 6 years from the end of the financial year they relate to, matching HMRC's UK accounting record-keeping requirement.
- Job photos and customer signatures: see Section 4.
8Your Rights
Under UK GDPR, individuals have the right to: access their data, request correction, request deletion, restrict or object to processing, and request portability, subject to certain exemptions. Requests can be sent to support@circuitos.app.
- If you’re a Customer user, contact us directly.
- If you’re an end-customer of one of our business customers, you should generally contact that business first, since they control the data — but you can also contact us and we will forward your request.
You also have the right to complain to the UK Information Commissioner’s Office (ico.org.uk).
9Security
- All connections to the Service are encrypted in transit (TLS/HTTPS).
- Database-level Row Level Security enforces that every organisation can only ever read or write its own data — this is enforced by the database itself, not just application code.
- Role-based access control (owner / office / manager / engineer) restricts what each Customer user can see and do within their own organisation.
- Job photos and customer signatures are stored in a private bucket, never publicly accessible, and served only via short-lived signed links generated for authorised users.
- Public, unauthenticated endpoints (the report form and tracking page) are rate-limited to reduce abuse.
10Children’s Data
The Service is not directed at children, and we do not knowingly collect data from children.
11Cookies
We use a single strictly-necessary authentication session cookie to keep Customer users signed in. We do not use analytics, advertising, or tracking cookies anywhere in the Service, including on the public report and tracking pages.
12Changes to This Policy
We may update this policy from time to time. For material changes, we’ll give at least 30 days’ notice by email before they take effect.