Circinova

Data Processing Agreement

Last updated: 31 May 2026

This Data Processing Agreement ("DPA") forms part of the agreement between Circinova (sole trader) ("Processor") and the Customer ("Controller") as defined below, and supplements the Terms of Service available at circinova.com/legal/terms (the "Main Agreement"). In the event of a conflict between this DPA and the Main Agreement, this DPA shall prevail with respect to the processing of personal data.

By using the Service, the Customer acknowledges and agrees to the terms of this DPA.


1. Definitions

For the purposes of this DPA, the following definitions apply in addition to those in the Main Agreement:

"GDPR" means, as applicable: Regulation (EU) 2016/679 of the European Parliament and of the Council (EU GDPR); and the UK General Data Protection Regulation as defined in section 3(10) of the UK Data Protection Act 2018 (UK GDPR), each as amended or replaced from time to time.

"Controller" means the entity that determines the purposes and means of processing Personal Data. For the purposes of this DPA, the Customer is the Controller in respect of Compliance Evidence Data.

"Processor" means the entity that processes Personal Data on behalf of the Controller. For the purposes of this DPA, Circinova is the Processor.

"Personal Data" means any information relating to an identified or identifiable natural person, as defined in Article 4(1) of the GDPR, that is contained within Customer Data submitted to the Service.

"Processing" (and "Process", "Processed") means any operation or set of operations performed on Personal Data, as defined in Article 4(2) of the GDPR, whether or not by automated means.

"Data Subject" means the identified or identifiable natural person to whom the Personal Data relates.

"Sub-processor" means any third party engaged by Circinova to Process Personal Data on behalf of the Controller.

"Compliance Evidence Data" means the compliance evidence, integration outputs, and related data that the Service collects from the Controller's connected integrations (such as GitHub and AWS), which may contain Personal Data relating to the Controller's employees or service accounts.

"Security Incident" means any accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data processed under this DPA.

"Supervisory Authority" means the Information Commissioner's Office (ICO) in the United Kingdom or, as applicable, a relevant supervisory authority in an EU member state.


2. Scope and Roles

2.1 Subject Matter

This DPA governs the Processing of Personal Data by Circinova (as Processor) on behalf of the Customer (as Controller) in connection with Circinova's provision of the Service under the Main Agreement.

2.2 Nature and Purpose of Processing

Circinova processes Personal Data as instructed by the Controller for the purpose of providing the Service, which includes: connecting to the Controller's third-party integrations (GitHub, AWS, and others); collecting and storing compliance evidence data; presenting evidence within the Service dashboard; and generating compliance reports and audit trails.

2.3 Types of Personal Data

The Personal Data processed under this DPA may include: names and email addresses of the Controller's employees or contractors (as retrieved from GitHub organisation membership data or AWS IAM user records); usernames and identifiers associated with cloud service accounts; and any other personal data incidentally contained in compliance evidence artefacts submitted to or collected by the Service.

2.4 Categories of Data Subjects

Data Subjects whose Personal Data may be processed under this DPA include employees, contractors, and service account holders of the Controller whose data appears in the Controller's GitHub organisation or AWS environment.

2.5 Duration of Processing

Circinova will process Personal Data for the duration of the Subscription Term and for 90 days following termination, after which it will be deleted in accordance with Section 10.


3. Processing Instructions

3.1 Controller's Instructions

Circinova shall process Personal Data only on documented instructions from the Controller. The Main Agreement and this DPA constitute the Controller's initial documented instructions. The Controller may provide additional instructions via the Service's settings and configuration options or in writing to legal@circinova.com.

3.2 Notification of Incompatible Instructions

If Circinova considers that an instruction from the Controller infringes applicable data protection law, Circinova shall promptly inform the Controller. Circinova shall be entitled to suspend processing until the instruction is clarified or amended.

3.3 Legal Obligations

Circinova may process Personal Data beyond the Controller's instructions where required to do so by applicable law, in which case Circinova shall (to the extent permitted by law) notify the Controller prior to commencing such processing.


4. Confidentiality of Processing

4.1 Personnel Obligations

Circinova shall ensure that all personnel authorised to process Personal Data under this DPA are subject to appropriate confidentiality obligations, whether by contract or by applicable professional or statutory obligations. Such obligations shall survive the termination of the relevant personnel's engagement with Circinova.

4.2 Need-to-Know Basis

Access to Personal Data shall be granted only to Circinova personnel and Sub-processors who require such access in order to carry out their responsibilities in connection with the provision of the Service.


5. Security of Processing

5.1 Technical and Organisational Measures

In accordance with Article 32 of the GDPR, Circinova shall implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk to the rights and freedoms of Data Subjects. These measures include:

(a) Pseudonymisation and Encryption: All Personal Data stored in the Service is encrypted at rest using AES-256. Integration credentials (including GitHub OAuth tokens and AWS IAM access keys) are encrypted using Fernet symmetric encryption with keys stored in AWS Secrets Manager. All data in transit is encrypted using TLS 1.2 or higher.

(b) Ongoing Confidentiality, Integrity, and Availability: Circinova implements controls including role-based access controls, network isolation via AWS VPC, and automated backup and recovery procedures.

(c) Resilience: The Service is hosted on AWS ECS Fargate with automated scaling. Database services (AWS RDS PostgreSQL) use Multi-AZ deployments to ensure resilience.

(d) Restoration of Access: Circinova maintains documented incident response and disaster recovery procedures to ensure that access to Personal Data can be restored promptly in the event of a technical incident.

(e) Testing and Evaluation: Circinova conducts annual third-party penetration testing and ongoing vulnerability assessments of its systems and processes, and regularly reviews the effectiveness of its security measures.

5.2 Access Controls

Circinova restricts access to Personal Data and production systems to authorised personnel only. Multi-factor authentication is required for all Circinova engineers accessing production systems. Privileged access is reviewed at least quarterly.


6. Sub-processors

6.1 Authorised Sub-processors

The Controller hereby grants Circinova general authorisation to engage the Sub-processors listed below. Circinova shall ensure that each Sub-processor is subject to a written agreement that imposes data protection obligations no less protective than those imposed on Circinova under this DPA.

| Sub-processor | Purpose | Location | Safeguard | |---------------|---------|----------|-----------| | Amazon Web Services, Inc. (AWS) | Cloud infrastructure, hosting, database, object storage, and secrets management | United States (us-east-1, N. Virginia) | AWS Data Processing Addendum | | Stripe, Inc. | Payment processing and billing | United States | Standard Contractual Clauses; Stripe DPA | | PostHog, Inc. | Product analytics (where enabled by Customer) | United States | Standard Contractual Clauses; PostHog DPA |

6.2 Changes to Sub-processors

Circinova shall provide the Controller with at least 30 days' prior written notice before engaging any new Sub-processor or making material changes to an existing Sub-processor's role. Notice will be given by email to the account holder's address and/or via the Service. If the Controller objects to a new Sub-processor on reasonable data protection grounds, the parties shall work together in good faith to resolve the objection. If the objection cannot be resolved, the Controller may terminate the Main Agreement and this DPA on written notice without penalty.

6.3 Responsibility for Sub-processors

Circinova remains responsible for the acts and omissions of its Sub-processors in respect of their obligations under this DPA to the same extent as if Circinova had performed those acts or omissions itself.


7. Data Subject Rights Assistance

7.1 Assistance Obligation

Circinova shall, taking into account the nature of the Processing, assist the Controller by appropriate technical and organisational measures in fulfilling its obligation to respond to requests from Data Subjects exercising their rights under Chapter III of the GDPR (including rights of access, rectification, erasure, restriction, portability, and objection).

7.2 Forwarding Requests

If Circinova receives a request from a Data Subject that relates to Personal Data processed on behalf of the Controller, Circinova shall promptly notify the Controller and shall not respond to the Data Subject directly (unless authorised by the Controller or required by law).

7.3 Self-Service Tools

Where technically feasible, Circinova will provide the Controller with self-service tools within the Service to facilitate the Controller's compliance with Data Subject requests (such as the ability to export or delete specific user data).


8. Security Incident Notification

8.1 Notification Timeline

Circinova shall notify the Controller without undue delay, and in any event within 72 hours of becoming aware of a Security Incident that involves Personal Data processed under this DPA. Notification shall be made to the email address associated with the Controller's account or as otherwise agreed in writing.

8.2 Content of Notification

The notification shall include, to the extent known at the time:

  • (a) a description of the nature of the Security Incident, including the categories and approximate number of Data Subjects affected and the categories and approximate number of Personal Data records affected;
  • (b) the name and contact details of Circinova's data protection contact from whom further information may be obtained;
  • (c) the likely consequences of the Security Incident; and
  • (d) a description of the measures taken or proposed to be taken to address the Security Incident, including measures to mitigate its possible adverse effects.

Where it is not possible to provide all such information at the time of initial notification, Circinova may provide it in stages without undue delay.

8.3 Assistance

Circinova shall cooperate with the Controller and take such reasonable commercial steps as the Controller may request to assist with any investigation of a Security Incident, including providing access to relevant logs and records.

8.4 Controller's Notification Obligations

The parties acknowledge that the Controller (not Circinova) is responsible for determining whether the Security Incident triggers any obligation to notify Data Subjects or Supervisory Authorities under applicable law, and for making any such notifications.


9. Data Protection Impact Assessments

Where Circinova determines, or where the Controller reasonably requests, that the nature of the Processing is likely to result in a high risk to the rights and freedoms of Data Subjects, Circinova shall provide the Controller with such reasonable assistance as the Controller requires to conduct a Data Protection Impact Assessment (DPIA) in accordance with Article 35 of the GDPR. Circinova shall also provide reasonable assistance to the Controller in connection with any prior consultation with a Supervisory Authority required under Article 36 of the GDPR.


10. Return and Deletion of Data

10.1 Post-Termination

Upon termination or expiry of the Main Agreement for any reason, and upon written request from the Controller, Circinova shall, at the Controller's option: (a) return to the Controller all Personal Data processed under this DPA in a structured, commonly used, and machine-readable format; or (b) securely delete all Personal Data processed under this DPA.

10.2 Retention Period

Circinova will retain the Controller's Personal Data for a period of 90 days following termination of the Main Agreement to allow the Controller to export its data. At the end of this 90-day grace period, all Personal Data will be permanently deleted from Circinova's systems.

10.3 Legal Retention

Notwithstanding Section 10.1, Circinova may retain Personal Data (or copies thereof) to the extent required by applicable law (such as for financial record-keeping under UK tax law), in which case Circinova shall notify the Controller of such retention and shall continue to protect such Personal Data in accordance with this DPA.

10.4 Confirmation

Upon the Controller's written request, Circinova shall provide written confirmation that deletion has been completed.


11. Audits and Inspections

11.1 SOC2 Report

Circinova shall make available to the Controller, upon written request, its most recent SOC2 Type II audit report (when available) or equivalent third-party security assessment. Such report shall be provided under the same confidentiality obligations as the Main Agreement.

11.2 On-Site Audits

The Controller (or a third-party auditor mandated by the Controller that is not a competitor of Circinova) may, on at least 30 days' prior written notice, request an on-site audit of Circinova's data processing facilities and practices. Such audits shall be conducted during normal business hours, shall not unreasonably interfere with Circinova's operations, and shall be conducted at the Controller's sole cost and expense. Circinova may require the auditor to sign a confidentiality agreement before commencing the audit. The parties shall work in good faith to agree the scope and timing of any audit.

11.3 Frequency

Unless required by a Supervisory Authority or following a confirmed Security Incident, audits shall not be conducted more than once per calendar year.


12. International Transfers

12.1 US Infrastructure and International Transfers

Circinova's primary infrastructure is located in the United States (AWS us-east-1, N. Virginia). Personal Data processed by Circinova on behalf of the Controller is therefore transferred to and stored in the United States, which is a third country outside the UK and EEA. Circinova shall ensure that such transfers and any further transfers to Sub-processors located outside the UK or EEA are subject to appropriate safeguards in accordance with Article 46 of the GDPR and the UK GDPR.

12.2 Transfer Mechanisms

For transfers to Sub-processors located in third countries, Circinova relies on the following transfer mechanisms as applicable: (a) the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses; (b) the EU Standard Contractual Clauses (Module 3: Processor to Sub-processor); or (c) any other mechanism approved by the ICO or the European Commission.

12.3 Additional Safeguards

Where required by applicable law or guidance from the ICO, Circinova shall implement additional technical and contractual safeguards (such as pseudonymisation or encryption prior to transfer) to ensure an equivalent level of data protection in the destination country.


13. Governing Law

This DPA and any dispute or claim arising out of or in connection with it shall be governed by and construed in accordance with the laws of England and Wales. The parties submit to the exclusive jurisdiction of the courts of England and Wales.


14. Contact

For any questions or notices under this DPA, please contact:

Circinova (sole trader) — Data Privacy Email: legal@circinova.com United Kingdom Trading as: Circinova (sole trader)


Annex A: Description of Processing

This Annex A forms part of the DPA and describes the Processing activities carried out by Circinova as Processor on behalf of the Customer as Controller.

A.1 Subject Matter and Duration of Processing

The subject matter of the Processing is the provision of the Circinova SOC2 compliance automation Service, as described in the Main Agreement. Processing will take place for the duration of the Subscription Term and for up to 90 days following termination, as set out in Section 10.

A.2 Nature of Processing

The Processing activities include: collection of data from the Controller's connected integrations (GitHub, AWS) via authenticated API calls using credentials provided by the Controller; storage of collected compliance evidence in encrypted databases and object storage; indexing and querying of stored evidence for presentation within the Service dashboard; generation of compliance reports and audit trails; and deletion of evidence data in accordance with Controller instructions or upon termination.

A.3 Purpose of Processing

The Processing is carried out for the purpose of enabling the Controller to automate the collection and management of SOC2 compliance evidence and related compliance artefacts for the Controller's internal compliance programme.

A.4 Types of Personal Data

The types of Personal Data that may be processed include:

  • Names and email addresses of the Controller's employees and contractors (retrieved from GitHub organisation member lists and AWS IAM user records)
  • Usernames and account identifiers associated with the Controller's GitHub and AWS accounts
  • GitHub activity data (such as commit authors, pull request reviewers, and approvers) to the extent that such data relates to identifiable individuals
  • AWS access records and CloudTrail log entries attributable to specific IAM users

A.5 Categories of Data Subjects

Data Subjects include:

  • Employees and contractors of the Controller who are members of the Controller's GitHub organisation
  • Employees and contractors of the Controller who hold AWS IAM user accounts within the Controller's AWS environment
  • Any other individuals whose personal data appears incidentally within compliance evidence artefacts collected from the Controller's systems

A.6 Special Category Data

The parties do not anticipate that the Processing will involve special category personal data (as defined in Article 9 of the GDPR). The Controller must not submit special category personal data to the Service without prior written agreement from Circinova.

A.7 Controller's Contact for DPA Matters

The Controller shall provide Circinova with a designated contact for DPA-related matters via the account settings within the Service or by notifying legal@circinova.com.