Circle European Privacy Policy

This Privacy Policy was updated on, and its effective date is: October 6, 2021.

This European Privacy policy contains information on how we collect, store, process, transfer, share use data that identifies or is associated with residents of the European Economic Area (“EEA”), Switzerland, and the United Kingdom (“UK”) ("personal data") and information regarding our use of cookies and similar technologies. This European Privacy Policy applies solely to residents of the EEA, Switzerland, and the UK (“you”). Please ensure that you have read and understood this European Privacy Policy before accessing or using the Website, App, or Services. Unless otherwise expressly stated, all terms in this section have the same meaning as defined in our Privacy Policy or as otherwise defined in the General Data Protection Regulation (“GDPR”).

CircleCo, Inc. is the controller of the personal data we hold about you in connection with your use of the Website, App, or Services. This means that we determine and are responsible for how your personal data is used.

Personal Data We Collect From You When You Use the Services and How We Use It

We collect personal data as set out in the “Information Collected” and “Information Used” sections of our Privacy Policy. We will indicate to you where the provision of certain personal data is mandatory. If you choose not to provide such personal data, we may not be able to provide those parts of the Website, App, or Services to you or respond to your other requests.

The table at Annex 1 sets out in detail the categories of personal data we collect about you and how we use that information when you use the Website, App, or Services, as well as the legal basis which we rely on to process the personal data and recipients of that personal data.

Information We Collect About You Automatically

We also automatically collect personal data indirectly about how you access and use the Website, App, or Services, and information about the device you use to access the Website, App, or Services, or otherwise engage with us. Please see the “Information That May Be Collected Automatically Through Our Website, App, or Services” section of our Privacy Policy for more information about what data we collect and how we use it.

The table at Annex 2 sets out in detail the categories of personal data we collect about you automatically and how we use that information. The table also lists the legal basis which we rely on to process the personal data and recipients of that personal data. For more information on cookies and other tracking technologies we use, please see our Cookie Policy.

We may link or combine the personal data you provide and the information we collect automatically. This allows us to provide you with a personalised experience regardless of how you interact with us.

We may anonymise and aggregate any of the personal data we collect (so that it does not directly identify you), and may use the anonymised and aggregated information or disclose it as set out in our Privacy Policy.

How Long Will We Store Your Personal Data

We will usually store the personal data we collect about you for no longer than necessary for the purposes set out in Annexes 1 and 2, including for the purposes of our legitimate business interests and satisfying any legal or reporting requirements, and in accordance with our legal obligations and legitimate business interests.

To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and the applicable legal requirements.

Recipients of Personal Data

We may share your personal data with the recipients as set out in the “Information Usage” section of our Privacy Policy (as required in accordance with the purposes set out in Annexes 1 and 2).

Marketing and Advertising

From time to time we may contact you with information about our products and services, including sending you marketing messages and asking for your feedback on our products and services.

For some marketing messages, we may use personal data we collect about you to help us determine the most relevant marketing information to share with you.

We will only send you marketing messages if you have given us your consent to do so. You can withdraw your consent at a later date by clicking on the “unsubscribe” link at the bottom of our marketing emails or by updating your preferences via the App settings.

Storing and Transferring Your Personal Data

Security.We implement appropriate technical and organisational measures to protect your personal data against accidental or unlawful destruction, loss, change or damage. We will never send you unsolicited emails or contact you by phone requesting your account ID, password, credit or debit card information or national identification numbers.

International Transfers of Your Personal Data.The personal data we collect may be transferred to and stored in countries outside of the jurisdiction you are in where we and our third-party service providers have operations, including in the United States. If you are accessing our Site from the EEA, your personal data will be processed outside of the EEA.

In the event of such a transfer, we ensure that: (i) the personal data is transferred to countries recognised as offering an equivalent level of protection; or (ii) the transfer is made pursuant to appropriate safeguards, such as standard data protection clauses adopted by the European Commission.

If you wish to enquire further about these safeguards used, please contact us using the details set out at the end of this European Privacy Policy.

Your RIghts in Respect of Your Personal Data

In accordance with applicable privacy law, you have the following rights in respect of your personal data that we hold:

Right of access. You have the right to obtain.

Right of portability. You have the right, in certain circumstances, to receive a copy of the personal data you have provided to us in a structured, commonly used, machine-readable format that supports re-use, or to request the transfer of your personal data to another person.

Right to rectification. You have the right to obtain rectification of any inaccurate or incomplete personal data we hold about you without undue delay.

Right to erasure. You have the right, in some circumstances, to require us to erase your personal data without undue delay if the continued processing of that personal data is not justified.

Right to restriction. You have the right, in some circumstances, to require us to limit the purposes for which we process your personal data if the continued processing of the personal data in this way is not justified, such as where the accuracy of the personal data is contested by you.

Right to withdraw consent. If you have provided consent for the processing of your personal data, you have the right to withdraw your consent. If you withdraw your consent, this will not affect the lawfulness of our use of your personal data before your withdrawal.

You also have the right to object to any processing based on our legitimate interests where there are grounds relating to your particular situation. There may be compelling reasons for continuing to process your personal data, and we will assess and inform you if that is the case. You can object to marketing activities for any reason.

You also have the right to lodge a complaint to your local data protection authority. Information about how to contact your local data protection authority is available here.

If you wish to exercise one of these rights, please contact us using the contact details at the end of this European Privacy Policy.

Due to the confidential nature of data processing, we may ask you to provide proof of identity when exercising the above rights. This can be done by providing a scanned copy of a valid identity document or a signed photocopy of a valid identity document.

Cookies and Similar Technologies Used on Our Website, App and Services

Our Website, App and Services use cookies and similar technologies such as pixels and Local Storage Objects (LSOs) like HTML5 (together “cookies”) to distinguish you from other users of our Website, App, and Services. This helps us to provide you with a good experience when you browse our Website, App, or Services and also allows us to monitor and analyse how you use and interact with our Website, App, or Services so that we can continue to improve our Website, App, and Services. It also helps us determine products and services that may be of interest to you. Please see our Cookie Policy for more information about these practices and your choices regarding cookies.

Our Policy Towards Children

The Website, App, and Services are not directed at persons under 16. We do not knowingly collect or solicit personal data from any persons under the age of 16. In the event that we learn that we have inadvertently collected personal data from a child under age 13, we will delete that information as quickly as possible. If you believe that we might have any information from a child under 13, please contact us using the details at the end of this European Privacy Policy.

Changes to This European Privacy Policy

We may update this European Privacy Policy from time to time and so you should review this page periodically. When we change this European Privacy Policy in a material way, we will update the "Effective Date" above. Changes to this European Privacy Policy are effective when they are posted on this page.

Contact Us

Please contact legal@circle.so if you have any questions, comments and requests regarding this European Privacy Policy.

ANNEX 1 - PERSONAL DATA YOU PROVIDE TO US

Category of Personal Data

Category of Personal Data

Legal Bases for Processing

Recipients of Personal Data

Contact information, such as your first name, last name, email address and phone number.

We may use this information to set up and authenticate your account on the Website, App, or Services.

The processing is necessary for the performance of a contract with you and to take steps prior to entering into a contract with you, namely our Terms of Service.

We share your personal data with Autopilot in order to processmarketing communications.

We may use this information to communicate with you, including sending service-related communications.

The processing is necessary for the performance of a contract with you, namely our Terms of Service.

We may use this information to deal with inquiries and complaints made by or about you relating to the Website, App, or Services.

The processing is necessary for our legitimate interests, namely administering the Website, App, or Services, and for communicating with you effectively to respond to your queries or complaints.

We may use this information to send you unsolicited marketing communications in accordance with your preferences.

We will only use your personal data in this way to the extent you have given us consent to do so.

Account and log-in information. This is information you choose to put in your Account profile such as username, phone number, and mailing address.

We use this information to allow you to populate your profile with relevant information.

The processing is necessary for the performance of a contract and to take steps prior to entering into a contract, namely our Terms of Service.

We may share this information with any enabled Single-Sign On provider in order to authenticate users’ logins.

We use this information to provide to you the features and functionality of the Website, App, or Services.

The processing is necessary for the performance of a contract and to take steps prior to entering into a contract, namely our Terms of Service.

Payment and transaction information, such as your credit/debit card, payment authentication code, billing address, and other information such as date and time of your transaction.

We may use this information to process the payments you make or receive through the Website, App, or Services.

 

The processing is necessary for the performance of a contract, namely our Terms of Service.

We may share this information with Stripe in order to identify you so that you can make and receive payments through the Website, App, or Services.

We may use this information to verify your identity in connection with the detection and prevention of fraud or financial crime.

The processing is necessary for our and third partiers' legitimate interests, namely the detection and prevention of fraud and financial crime.

Information about your activity on the Website, App, or Services, such as your comments on any blog posts or information about any products and services you have purchased.

We use this information to provide to you the features and functionality of the Website, App, or Services.

The processing is necessary for the performance of a contract and to take steps prior to entering into a contract, namely our Terms of Service.

We do not share this information with any third-party provider. However, please note other users of the Website, App or Services may view any content you make public.

Chat, comments and opinions. When you contact us directly, e.g., by email or phone we will record your comments and opinions.

We may use this information to address your questions, issues and concerns.

The processing is necessary for our legitimate interests, namely communicating with you and responding to queries, complaints and concerns.

We may share any information you provide to us when you contact us with Helpscout, the provider of our customer support platform, in order to process any customer support queries you might submit to us.

 

We may use this information to improve the Website, App, and Services.

The processing is necessary for our legitimate interests (to develop and improve our Website, App, and Services).

Information received from third party social networks, such as Instagram and Facebook. If you interact with the Services through a social network or link your Circle account with certain social networks such as Facebook, Instagram or Twitter, we may receive information from the social network such as your name, age, photos, email address, phone number, location, workplace, friends list, and any other information you permit the social network to share with third parties. The data we receive is dependent on your privacy settings with the social network.

We use this information to allow you to populate your profile with relevant information.

The processing is necessary for the performance of a contract and to take steps prior to entering into a contract, namely our Terms of Service.

We may share this information with the social network you link within your profile, such as Twitter or LinkedIn, in order to enable you to populate your profile and enable the connection to your social network profile.

We use this information to provide to you the features and functionality of the Website, App, or Services.

The processing is necessary for the performance of a contract and to take steps prior to entering into a contract, namely our Terms of Service.

We may share this information with any enabled Single-Sign On provider in order to authenticate users’ logins. For example, if you login to your Account using your social network login credentials (e.g., Twitter or Facebook login credentials), we may share that information with the social network or other Single-Sign On provider and the administrator of your Account in order to allow you to access the features and functionality of the Website, App or Services.

Your preferences, such as preferences set for notifications, marketing communications, how the Website, App, or Services are displayed and the active functionalities on the Website, App, or Services.

We use this information to provide notifications, send news, alerts and marketing communications and provide the Website, App, or Services in accordance with your choices.

 

The processing is necessary for our legitimate interest, namely ensuring the user receives the correct marketing and other communications, and that this is displayed in accordance with the user's preferences.

We may share this information with Sendgrid in order to send email notifications to those that have that preference turned on.

We use this information to ensure that we comply with our legal obligation to send only those marketing communications to which you have consented.

The processing is necessary for compliance with a legal obligation to which we are subject.

All personal data set out above.

We may use all the personal data we collect to operate, maintain and provide to you the features and functionality of the Website, App, or Services, to communicate with you, to monitor and improve the Website, App, and Services and business, and to help us develop new products and services.

The processing is necessary for our legitimate interests, namely, to administer and improve the Website, App, and Services.

 


ANNEX 2 - PERSONAL DATA COLLECTED AUTOMATICALLY

Category of Personal Data

How We May Use It

Legal Basis for the Processing

Recipients of Personal Data

Approximate location information. Other than information you choose to provide to us, we do not collect information about your precise location. Your device’s IP address may however help us determine an approximate location.

We may use information you provide to us about your location to monitor and detect fraud or suspicious activity in relation to your account.

The processing is necessary for our legitimate interests, namely, to protect our business and your account from fraud and other illegal activities.

We may share this information with the following:

  • AWS
  • Baremetrics
  • Bugsnag
  • Cloudflare
  • Google Analytics
  • Mixpanel
  • Segment
  • TrackJS
  • We share this information to these third-party recipients for purposes of personalize our service and data analytics.

We may use this information to tailor how the Website, App, or Services are displayed to you (such as the language in which it is provided to you).

The processing is necessary for our legitimate interest, namely tailoring our service so that it is more relevant to our users.

Information about how you access and use the Website, App, or Services. For example, how frequently you access the Website, App, or Services, the time you access the Website, App, or Services and how long you use it for, the approximate location that you access the Website, App, or Services from, the site from which you came and the site to which you are going when you leave our Website, the Website pages you visit, the links you click, whether you open emails or click the links contained in emails, whether you access the Website, App, or Services from multiple devices, and other actions you take on the Website, App, or Services.

We may use information about how you use and connect to the Website, App, or Services to present the Website, App, or Services to you on your device.

 

The processing is necessary for our legitimate interests, namely, to tailor the Website, App, or Services to the user.

We may use this information to determine products and services that may be of interest to you for marketing purposes.

The processing is necessary for our legitimate interests, namely, to inform our direct marketing.

We may use this information to monitor and improve the Website, App, or Services and business, resolve issues and to inform the development of new products and services.

 

The processing is necessary for our legitimate interests, namely, to monitor and resolve issues with the Website, App, or Services and to improve the Website, App, and Services generally.

Log files and information about your device. We also collect information about the tablet, smartphone or other electronic device you use to connect to the Website, App, or Services. This information can include details about the type of device, unique device identifying numbers, operating systems, browsers and applications connected to the Website, App, or Services through the device, your mobile network, your IP address and your device’s telephone number (if it has one).

We may use information about how you use and connect to the Services to present the Services to you on your device.

 

The processing is necessary for our legitimate interests, namely, to tailor the Services to the user.

We may use this information to monitor and improve the Website, App, or Services and business, resolve issues and to inform the development of new products and services.

 

The processing is necessary for our legitimate interests, namely, to monitor and resolve issues with the Website, App, or Services and to improve the Website, App, and Services generally.