Privacy Policy
Last updated: 31 May 2026
1. Who We Are
Circinova (sole trader) ("Circinova", "we", "us", "our") is a sole trader based in the United Kingdom. We operate a cloud-hosted SOC2 compliance automation platform available at circinova.com.
For the purposes of UK GDPR and EU GDPR, Circinova acts in two distinct capacities:
- Data Controller: in respect of the personal data we collect about you as an individual user or account holder — such as your name, email address, and billing information — we determine the purposes and means of processing and are therefore the data controller.
- Data Processor: in respect of personal data that may be contained within the compliance evidence and integration data you submit through the Service (such as GitHub organisation member data or AWS IAM user lists), we process that data on your instructions as a data processor. Our obligations in this capacity are set out in our Data Processing Agreement (available at circinova.com/legal/dpa).
If you have any questions about this Privacy Policy or our data practices, please contact us at privacy@circinova.com.
2. What Data We Collect
2.1 Account and Identity Data
When you register for an account, we collect your name, work email address, company name, and password (stored as a bcrypt hash). If you register via a third-party OAuth provider (such as GitHub), we receive your name and email address from that provider.
2.2 Integration Credentials
To connect cloud and development services, we collect and store OAuth access tokens (e.g. GitHub OAuth tokens) and cloud provider credentials (e.g. AWS IAM access key IDs and secret access keys). These credentials are encrypted at rest using Fernet symmetric encryption with keys stored in AWS Secrets Manager.
2.3 Compliance Evidence Data
When the Service collects compliance evidence from your connected integrations, it retrieves and stores data such as: GitHub organisation members, repository settings, branch protection rules, and workflow run histories; AWS IAM users, roles, policies, and configuration data; and other technical artefacts relevant to SOC2 evidence collection. This data may contain personal data relating to your employees or service accounts.
2.4 Billing and Payment Data
We collect billing information including your payment method details (processed and stored by Stripe; Circinova does not store full card numbers), invoicing address, VAT number (if provided), and transaction history.
2.5 Usage and Analytics Data
We collect data about how you interact with the Service, including pages visited, features used, session duration, click events, and error logs. This is collected via PostHog (see Section 6) and our own application logs. We also collect technical data such as IP address, browser type and version, operating system, and referring URLs.
2.6 Communications Data
If you contact us for support or send us an email, we collect the content of your communications and any personal data you include therein.
2.7 Cookies and Tracking Technologies
We use cookies and similar tracking technologies as described in our Cookie Policy at circinova.com/legal/cookies.
3. How We Use Your Data
We use the personal data we collect for the following purposes:
3.1 Providing and Improving the Service
We use your account data, integration credentials, and compliance evidence data to provide the Service, including authenticating your identity, connecting to your integrations, collecting and presenting compliance evidence, and generating compliance reports.
3.2 Billing and Account Management
We use your billing and payment data to process subscription payments, issue invoices, manage your account, and communicate with you about your subscription (including renewals, payment failures, and plan changes).
3.3 Security and Fraud Prevention
We use technical data and logs to monitor for suspicious activity, detect and prevent fraud, investigate security incidents, and maintain the integrity and security of the Service.
3.4 Product Improvement and Analytics
We use anonymised and aggregated usage data to understand how our users interact with the Service, identify areas for improvement, and develop new features. Where analytics data is linked to identifiable individuals, we process it on the basis of our legitimate interests.
3.5 Customer Support
We use communications data to respond to your support requests, troubleshoot issues, and improve our support processes.
3.6 Legal and Compliance Obligations
We may use and retain your data as required to comply with applicable laws, regulations, court orders, or lawful requests from public authorities.
3.7 Marketing Communications
With your consent, we may send you promotional emails about new features, product updates, and offers. You can withdraw your consent at any time by clicking the unsubscribe link in any marketing email or by contacting us at privacy@circinova.com.
4. Legal Basis for Processing
We process your personal data under the following legal bases under UK GDPR Article 6:
| Processing Activity | Legal Basis | |--------------------|----------- | | Providing the Service (account, credentials, evidence) | Article 6(1)(b) — performance of a contract | | Billing and payment processing | Article 6(1)(b) — performance of a contract | | Security monitoring and fraud prevention | Article 6(1)(f) — legitimate interests (to protect our platform and customers) | | Usage analytics and product improvement | Article 6(1)(f) — legitimate interests (to improve and develop our Service) | | Responding to support requests | Article 6(1)(b) — performance of a contract | | Retaining financial records | Article 6(1)(c) — legal obligation (HMRC record-keeping requirements) | | Sending marketing emails | Article 6(1)(a) — consent | | Processing data on behalf of customers (as Processor) | Article 6(1)(b) — performance of our contract with the Customer (DPA) |
Where we rely on legitimate interests, you have the right to object to that processing. Where we rely on consent, you may withdraw your consent at any time without affecting the lawfulness of processing before withdrawal.
5. Data Sharing
We share your personal data with the following categories of recipients:
5.1 Service Providers and Sub-processors
We work with trusted third-party service providers who process data on our behalf as sub-processors:
| Sub-processor | Purpose | Location | Safeguard | |---------------|---------|----------|-----------| | Amazon Web Services (AWS) | Cloud hosting, storage, compute, secrets management | United States (us-east-1, N. Virginia) | AWS Data Processing Addendum | | Stripe, Inc. | Payment processing and billing | USA | SCCs; Stripe Data Processing Agreement | | PostHog, Inc. | Product analytics and session recording | USA (EU Cloud available) | SCCs; PostHog DPA |
5.2 Business Transfers
If Circinova is involved in a merger, acquisition, or sale of all or a portion of its assets, your personal data may be transferred to the acquirer. We will provide notice before your personal data is transferred and becomes subject to a different privacy policy.
5.3 Legal Requirements
We may disclose your personal data if required to do so by law, court order, or governmental authority, or where we believe in good faith that disclosure is necessary to protect our legal rights, prevent fraud, or protect the safety of any person.
5.4 With Your Consent
We will not share your personal data with any other third party without your explicit consent.
6. International Transfers
Circinova's primary infrastructure is hosted on AWS in the us-east-1 (N. Virginia) region in the United States. Customer data is stored and processed in the United States. Transfers of personal data from UK or EEA users to Circinova's infrastructure are covered by appropriate safeguards as described below.
Where data is transferred to sub-processors or to our infrastructure located outside the UK or EEA, we ensure appropriate safeguards are in place, including:
- UK International Data Transfer Agreements (IDTAs) or Standard Contractual Clauses (SCCs) approved by the ICO or the European Commission, incorporated into our agreements with those sub-processors.
- For US sub-processors, we verify that additional technical and contractual safeguards are in place to protect your data.
You can request a copy of the relevant transfer safeguards by contacting privacy@circinova.com.
7. Data Retention
We retain your personal data only for as long as necessary for the purposes for which it was collected, or as required by law. Our standard retention periods are:
| Data Category | Retention Period | |---------------|-----------------| | Account data (name, email, company) | Duration of account + 90 days post-termination | | Integration credentials (tokens, keys) | Duration of active integration; deleted promptly upon disconnection | | Compliance evidence data | Per Customer instruction; deleted within 90 days of account termination | | Billing and payment records | 7 years from the date of the transaction (HMRC requirements) | | Audit logs (access logs, activity logs) | 7 years | | Support communications | 3 years from last interaction | | Marketing consent records | 3 years from last interaction or withdrawal of consent |
Following account termination, we will retain your data for 90 days to allow for data export, after which all Customer Data will be permanently deleted from our systems.
8. Your Rights
Under UK GDPR, you have the following rights in relation to your personal data. These rights apply where we are acting as data controller. Where we act as data processor (for compliance evidence data), you should direct requests to the Customer who acts as data controller.
Right of access: You have the right to request a copy of the personal data we hold about you and information about how we process it.
Right to rectification: You have the right to request that we correct any inaccurate or incomplete personal data we hold about you.
Right to erasure ("right to be forgotten"): You have the right to request that we delete your personal data in certain circumstances, such as where it is no longer necessary for the purposes for which it was collected.
Right to restriction of processing: You have the right to request that we restrict our processing of your personal data in certain circumstances, for example while a dispute about accuracy is resolved.
Right to data portability: Where processing is based on consent or contract and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller.
Right to object: You have the right to object to processing based on legitimate interests (including profiling) and to processing for direct marketing purposes.
Rights related to automated decision-making and profiling: You have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects on you. Circinova does not currently make such automated decisions.
Right to withdraw consent: Where processing is based on consent, you may withdraw your consent at any time without affecting the lawfulness of processing carried out before withdrawal.
To exercise any of these rights, please submit a request to privacy@circinova.com. We will respond within one calendar month of receiving your request (or within three months for complex requests, with notice). We may ask you to verify your identity before fulfilling a request.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk if you believe we have not complied with applicable data protection law.
9. Cookies
We use cookies and similar tracking technologies on our website and within the Service. For full details of the cookies we use, their purpose, and how to manage your preferences, please see our Cookie Policy at circinova.com/legal/cookies.
10. Security
We take the security of your personal data seriously and implement appropriate technical and organisational measures to protect it against unauthorised access, loss, destruction, or alteration:
- Encryption at rest: All data stored in our databases (AWS RDS PostgreSQL) and object storage (AWS S3) is encrypted using AES-256.
- Encryption in transit: All communications with the Service are encrypted using TLS 1.2 or higher.
- Credential security: GitHub OAuth tokens and AWS IAM credentials are encrypted at rest using Fernet symmetric encryption, with encryption keys stored in AWS Secrets Manager.
- Access controls: Access to production systems is restricted to authorised Circinova engineers via role-based access controls and multi-factor authentication.
- Penetration testing: We conduct annual third-party penetration tests of our infrastructure and application.
- Vulnerability management: We monitor our software dependencies for vulnerabilities and apply security patches promptly.
No method of data transmission or storage is 100% secure. While we take extensive precautions, we cannot guarantee the absolute security of your data.
11. Children
The Service is intended for business use by adults and is not directed at children under the age of 18. We do not knowingly collect personal data from anyone under 18. If you become aware that a child under 18 has provided us with personal data, please contact us at privacy@circinova.com and we will take steps to delete such data.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our data practices, legal requirements, or the Service. We will notify you of material changes by sending an email to the address associated with your account at least 30 days before the changes take effect. We will also update the "Last updated" date at the top of this policy.
We encourage you to review this policy periodically. Your continued use of the Service after the effective date of a revised policy constitutes your acceptance of the changes.
13. Contact and DPO
For any questions, concerns, or requests relating to this Privacy Policy or our handling of your personal data, please contact:
Data Privacy Team Circinova (sole trader) Email: privacy@circinova.com United Kingdom
Information Commissioner's Office (ICO) ICO Registration Number: pending registration — see ico.org.uk Website: ico.org.uk Telephone: 0303 123 1113
If you are located in the European Economic Area and have concerns about our processing of your personal data, you may also contact the supervisory authority in your country of residence.