This European Privacy Policy contains information on how we collect, store, process, transfer, share, and use information relating to an identified or identifiable individual in the European Economic Area (“EEA”), Switzerland, and the United Kingdom (“UK”) (“personal data”) and information regarding our use of cookies and similar technologies. This European Privacy Policy applies solely to residents of the EEA, Switzerland, and the UK (“you”). Please ensure that you have read and understood this European Privacy Policy before accessing or using the Services. Unless otherwise expressly stated, all terms in this section have the same meaning as defined in our Privacy Policy or as otherwise defined in the EU General Data Protection Regulation and the UK General Data Protection Regulation (together, the “GDPR”).
Who Is Responsible For Your Personal Data
We process most of the personal data that our customers and their users upload to the Services as a processor on behalf of the relevant customer. This means that the relevant customer determines how and why we process that personal data. If a customer has uploaded your personal data to our Services, you should consult that customer's privacy notice (either in their community, on their website, or as otherwise provided to you) for information about how that personal data is processed.
We do, however, process some personal data as a controller as described in our Privacy Policy and this European Privacy Policy. This means that, with respect to the processing of personal data described in our Privacy Policy and this European Privacy Policy, Circle determines how and why your personal data is processed.
How To Contact Us
Circle is responsible and the data controller for processing your personal data. Please contact legal@circle.so or write to us at 228 Park Ave S, PMB 52933, New York, NY 10003 if you have any questions, comments, and requests regarding this European Privacy Policy.
Personal Data We Collect From You When You Use the Services and How We Use It
We may collect a variety of personal data from or about you or your devices from various sources, as described below.
If you do not provide your personal data when requested, you may not be able to use our Services if that personal data is necessary to provide you with our Services or if we are legally required to collect it.
Prospective Customers
When you contact us to express an interest in our Services or with a query about becoming a customer of our Services, we will collect the following personal data:
| How we use it | Lawful basis we rely on |
|---|---|
| We use this information to communicate with you, including responding to your queries, comments or requests for further information about our Services. | The processing is necessary to take steps at your request prior to entering into a contract or for our legitimate interests, namely communicating with prospective customers. |
| We use this information to send you promotional emails in accordance with your preferences. | The processing is necessary for our legitimate interests, namely to promote our Services. Alternatively, we will use your personal data in this way to the extent you give us your consent to do so. |
| How we use it | Lawful basis we rely on |
|---|---|
| We use this information to address your questions, issues and concerns. | The processing is necessary to take steps at your request prior to entering into a contract or for our legitimate interests, namely communicating with prospective customers. |
| How we use it | Lawful basis we rely on |
|---|---|
| We use this information to communicate with you, including responding to your queries, comments or requests for further information about our Services. | The processing is necessary for the performance of a contract to which you are a party or for our legitimate interests, namely communicating with prospective or existing customers. |
| We use this information to send you promotional emails in accordance with your preferences. | The processing is necessary for our legitimate interests, namely to promote our Services. Alternatively, we will use your personal data in this way to the extent you give us your consent to do so. |
Customer Admins
When you sign up to our Services as a customer, or if a customer designates you as an admin user on their account, we will collect the following personal data:
| How we use it | Lawful basis we rely on |
|---|---|
| We use this information to communicate with you about the customer's account, including responding to your queries, comments or requests for further information about our Services, or sending you service-related communications (such as billing information and renewal reminders). | The processing is necessary for the performance of a contract or for our legitimate interests, namely communicating with customers and administering agreements with customers. |
| We use this information to send you promotional emails in accordance with your preferences. | The processing is necessary for our legitimate interests, namely to promote our Services. Alternatively, we will use your personal data in this way to the extent you give us your consent to do so. |
| If you are the customer, (i.e., if you sign up to the Services as a customer in your personal capacity rather than as an admin on behalf of a customer), we use this information to set up and authenticate your account on the Services. | The processing is necessary for the performance of a contract with you, namely our Terms of Service. |
| How we use it | Lawful basis we rely on |
|---|---|
| We use this information to populate your profile on the Services. | The processing is necessary for the performance of a contract with you, namely our Terms of Service. Alternatively, we will process your personal data with your consent. |
If you are the customer (i.e. if you sign up to the Services or a free trial as a customer in your personal capacity rather than as an admin on behalf of a customer), we will also collect the following information:
| How we use it | Lawful basis we rely on |
|---|---|
| We use this information to populate your profile on the Services. | The processing is necessary for the performance of a contract with you, namely our Terms of Service. |
| How we use it | Lawful basis we rely on |
|---|---|
| We use this information to authenticate you and give you access to the Services. | The processing is necessary for the performance of a contract with you, namely our Terms of Service. |
| How we use it | Lawful basis we rely on |
|---|---|
| We use this information to process payments for the Services. | The processing is necessary for the performance of a contract with you, namely our Terms of Service. |
| We use this information to verify your identity in connection with the detection and prevention of fraud or financial crime. | The processing is necessary for our and third parties' legitimate interests, namely the detection and prevention of fraud and financial crime. |
| How we use it | Lawful basis we rely on |
|---|---|
| We use this information to provide you the features and functionality of the Services. | The processing is necessary for the performance of a contract with you, namely our Terms of Service. |
| We use this information to tailor the content of the promotional emails we send to you. | The processing is necessary for our and third parties' legitimate interests, namely informing our marketing strategy, product development and internal analytics purposes, and otherwise to improve the Services. |
| How we use it | Lawful basis we rely on |
|---|---|
| We use this information to authenticate you and allow you to log in to your account on the Services. | The processing is necessary for the performance of a contract with you, namely our Terms of Service. |
All customer users
| How we use it | Lawful basis we rely on |
|---|---|
| We use this information to identify ways in which we can improve our Services, such as identifying errors and potential new features and functionalities. | The processing is necessary for our legitimate interests, namely identifying and resolving errors and informing our product development, and otherwise improving the performance of our Services. |
| How we use it | Lawful basis we rely on |
|---|---|
| Remove such content. | The processing is necessary to comply with a legal obligation to which we are subject (to the extent that obligation arises under UK, EEA, or Member State law). Otherwise, the processing is necessary for our legitimate interests, the interests of our users and the public, namely ensuring that the Services are not used to distribute harmful or illegal material. |
| Report such content to applicable law enforcement authorities. | The processing is necessary to comply with a legal obligation to which we are subject (to the extent that obligation arises under UK, EEA, or Member State law). Otherwise, the processing is necessary for our legitimate interests, the interests of our users and the public, namely ensuring that the Services are not used to distribute harmful or illegal material. |
Prospective customers and all customer users
| How we use it | Lawful basis we rely on |
|---|---|
| We do not monitor how individuals interact with us on social media; however, we may use this information to respond to your comments or posts that are addressed to us or reference us. | The processing is necessary for the performance of a contract with you or for our legitimate interests, namely promoting our Services through operating our social media page. |
Information We Collect About You Automatically
We also automatically collect personal data indirectly about how you access and use the Services, and information about the device you use to access the Services, or otherwise engage with us. We collect the following information in this way:
| How we use it | Lawful basis we rely on |
|---|---|
| We use information about how you use and connect to the Services to present the Services to you on your device. | The processing is necessary for the performance of a contract with you or for our legitimate interests, namely to provide the Services to the user. |
| We use this information to monitor and detect fraud or suspicious activity on our Services. | The processing is necessary for our legitimate interests, namely monitoring fraud. |
| We use this information to monitor the performance of the Services to identify errors and ways in which we can improve the Services, including developing new features of the Services. | The processing is necessary for our legitimate interests, namely for product development and internal analytics purposes, and otherwise to improve the safety, security and performance of our Services. Alternatively, we will use your personal data in this way to the extent you have given us your consent to do so. |
| How we use it | Lawful basis we rely on |
|---|---|
| We use information about how you use and connect to the Services to present the Services to you on your device. | The processing is necessary for the performance of a contract with you or for our legitimate interests, namely to provide the Services to the user. |
| We use this information to monitor and detect fraud or suspicious activity on our Services. | The processing is necessary for our legitimate interests, namely monitoring fraud, or to comply with a legal obligation in the EEA, the UK or Switzerland. |
| We use this information to monitor the performance of the Services to identify errors and ways in which we can improve the Services, including developing new features of the Services. | The processing is necessary for our legitimate interests, namely for product development and internal analytics purposes, and otherwise to improve the safety, security, and performance of our Services. Alternatively, we will use your personal data in this way to the extent you have given us your consent to do so. |
| We use this information to monitor the performance of the Services to identify errors and ways in which we can improve the Services, including developing new features of the Services. | The processing is necessary for our legitimate interests, namely for product development and internal analytics purposes, and otherwise to improve the safety, security, and performance of our Services. Alternatively, we will use your personal data in this way to the extent you have given us your consent to do so. |
We only rely on our or a third party’s legitimate interests to process your personal data when these interests are not overridden by your rights and interests.
We may link or combine the personal data you provide and the information we collect automatically. This allows us to provide you with a personalized experience regardless of how you interact with us.
We may anonymize and aggregate any of the personal data we collect (so that it does not directly identify you), and may use the anonymized and aggregated information or disclose it as set out in our Privacy Policy.
We do not carry out any automated decision-making that produces legal or similarly significant effects for you.
Cookies and Similar Technologies Used on Our Services
Our Services use cookies and similar technologies such as pixels and Local Storage Objects (LSOs) like HTML5 (together, “cookies”) to distinguish you from other users of our Services, improve your experience, analyze usage, and determine other products or services of interest. Please see our Cookie Policy for more information about these practices and your choices regarding cookies.
Cookies are small text files that are stored on your device and may include a unique anonymous identifier. When you visit a website, the site asks your browser to store a cookie on your device. On each subsequent visit, your browser sends the cookie back to the website so it can recognize your device and remember your preferences. To learn more about cookies, visit this site.
We use the following cookies:
| Category | Purpose | Legal basis |
|---|---|---|
| Strictly necessary cookies | We use strictly necessary cookies to enable core functionality. These are required for full functionality of our Services. If you disable these cookies, certain parts of the website or our Services may not function properly for you. | We use strictly necessary cookies based on the performance of our contract with you, and where appropriate, our legitimate interests in delivering a secure and functioning service. |
| Analytics cookies | We use analytics cookies to help us improve or optimize the experience we provide. They allow us to measure how visitors interact with our website, which we use to improve the user experience and performance of our Services. | We use analytics cookies with your consent. These cookies are set on your device after you provide consent through our cookie banner. |
| Advertising cookies | We use advertising and similar non-essential cookies to promote our Services and market to you on third-party websites. | We use advertising and similar non-essential cookies with your consent. These cookies are set on your device after you provide consent through our cookie banner. |
How Long Will We Store Your Personal Data
We retain personal data for no longer than is necessary. We determine the retention period by taking into account various criteria, such as the type of services provided to you, the nature and length of our relationship with you, possible re-enrollment with our Services, the impact on the Services we provide to you if we delete some information from or about you, and mandatory retention periods provided by law and the statute of limitation:
| Category of personal data | How long we keep it |
|---|---|
| Your contact details | If you are a prospective customer, we will keep your contact details for 3 years from the last contact we had with you (such as the last email we sent you or the last time you contacted us). If you are a customer user, we will keep your contact details for the duration of our agreement with the customer and for 6 years thereafter. |
| Queries and comments you submit to us | If you are a prospective customer, we will keep the content of any correspondence from you for 3 years from the last contact we had with you (such as the last email we sent you or the last time you contacted us). If you are a customer user, we will keep the correspondence you send us for the duration of our agreement with the customer and for 6 years thereafter. |
| Password information | If you are the customer user, we will store your password for the duration of our agreement with you. If you change or reset your password, we will delete your previous password and only store the new password. |
| Marketing preferences | If you are a prospective customer, we will keep your marketing preferences for 3 years from the last contact we had with you (such as the last email we sent you or the last time you contacted us). If you are a customer user, we will keep your marketing preferences for as long as you are designated a customer admin and for 3 years thereafter. |
| Information about your device and how you use the Services | We will keep this information for no longer than 3 years. |
Recipients of Personal Data
We may share your personal data as follows:
| Recipients | Why we share your personal data with these recipients | How these recipients will use your personal data |
|---|---|---|
| Service providers |
We will share your personal data with companies that provide services to us, such as:
| These recipients will use your personal data as processors on our instructions. |
| Advertising partners | We may share your personal data with our advertising partners as further described in the "online advertising" section below. | These recipients will process personal data to optimize the advertising shown on our Services, measure the effectiveness of such advertising and serve advertising about Circle on other websites that you visit. We will only share your personal data in this way to the extent you have given us your consent to do so. |
| Buyers of our business | We may share personal data with other parties in connection with a transaction or potential transaction where we merge with another organization, file for bankruptcy, or sell some or all of our assets or stock. For instance, if we sell the Services to a third party, we will share the personal data we have collected through the Services with that buyer. | These recipients will use your personal data to complete a transaction to buy all or the part of our business that includes the Services. The lawful basis we rely on for sharing personal data with these recipients is that it is necessary for our and the recipient's legitimate interests, namely completing a transaction to buy all or part of our business. |
| Law enforcement, regulators and other parties (including emergency response services) for legal or safety reasons | We may share your personal data with third parties as required by law or if we reasonably believe that such action is necessary to (i) comply with the law and the reasonable requests of law enforcement; (ii) detect and investigate illegal activities and breaches of agreements; and/or (iii) exercise or protect the rights, property, or personal safety of Circle, its users or others. | These recipients will use your personal data in the performance of their regulatory or law enforcement role. The lawful basis we rely on for sharing personal data with these recipients is that the processing is either necessary to comply with a legal obligation to which we are subject, or is necessary for our legitimate interests, namely enforcing our rights or complying with requests from regulatory authorities. |
Marketing and Advertising
Promotional emails
From time to time we may contact you with information about our products and services, including sending you marketing messages and asking for your feedback on our products and services.
For some marketing messages, we may use personal data we collect about you to help us determine the most relevant marketing information to share with you.
Where we rely on your consent to process your personal data for marketing purposes, you can withdraw your consent at any time and free of charge. For instance, you can click on the “unsubscribe” link at the bottom of our marketing emails or you can update your preferences via the Services. We will apply your preferences going forward and this will not affect the lawfulness of the processing before you withdrew your consent.
Online advertising
We work with online advertising networks and advertising partners to tailor the ads played or displayed to you on our Services and on other websites, apps, or services. The ads you see online are tailored to your interests based on information collected about you, including information about your age, demographic, location, as well information about your internet usage over time, such as the websites you visit, the products and pages you view and the links you click on (including links in ads played or displayed to you).
Typically, this information is collected through cookies or similar tracking technologies. When you visit the Services we will ask for your consent to place cookies and similar tracking technologies on your device to:
We may use certain forms of display advertising and other advanced features through third party service providers like Google Universal Analytics, such as Remarketing with Google Analytics, Google Display Network Impression Reporting, the DoubleClick Campaign Manager Integration, and Google Analytics Demographics and Interest Reporting. These features enable us to use first-party cookies (such as the Google Analytics cookie) and third-party cookies (such as the DoubleClick advertising cookie) or other third-party cookies together to inform, optimize, and display ads based on your past visits to the Site. You can opt-out of certain Google advertising products by visiting the Google Ads Preferences Manager, currently available at https://google.com/ads/preferences.
You may learn more about Google’s practices with Google Analytics by visiting Google’s privacy policy at http://www.google.com/policies/privacy/partners. You can also view Google’s currently available opt-out options at https://tools.google.com/dlpage/gaoptout.
Controlling the ads you see online
Please see our Cookie Policy for details of the third parties that collect information about your use of the Services for advertising purposes.
We will only collect and share information about your use of the Services for advertising purposes to the extent you have given us your consent to do so.
Withholding or withdrawing consent, or opting out of the use of advertising cookies, will mean that information about your use of the Services will not be shared with advertising networks to allow us to target advertising on other websites.
If you opt-out of advertising by opting out of the use of, or withholding or withdrawing your consent to advertising cookies, you will still get ads when you browse the internet, and those ads may still be relevant to your interests. However, this advertising may be based on the content of the site you visit or, for advertising on social media, your approximate location or demographic information associated with your social media profile, rather than your recent browsing activity. As a result, you may still see advertising relevant to your location, demographic or other information on the websites you visit even if you reject cookies on the Services.
Storing and Transferring Your Personal Data
Security. We implement appropriate technical and organizational measures to protect your personal data against accidental or unlawful destruction, loss, change or damage. We will never send you unsolicited emails or contact you by phone requesting your account ID, password, credit or debit card information or national identification numbers. As no electronic transmission or storage of information can be entirely secure, we can make no guarantees as to the security or privacy of your personal data.
International Transfers of Your Personal Data. The personal data we collect may be transferred to and stored in countries outside of the jurisdiction you are in where we and our third-party service providers have operations, including in the United States.
In the event of such a transfer, we ensure that: (i) the personal data is transferred to countries recognized as offering an equivalent level of protection (“Adequacy”); or (ii) the transfer is made pursuant to appropriate safeguards, such as standard data protection clauses adopted by the European Commission or approved under the GDPR (“Standard Contractual Clauses”). When we transfer your personal data to recipients in the United States, we ensure that such transfers are:
If you wish to enquire further about the safeguards use or to obtain a copy of these safeguards if relevant, please contact us using the details set out in the “How to Contact Us” section above.
Your Rights in Respect of Your Personal Data
In accordance with the GDPR, you have the following rights in respect of your personal data that we hold:
Right of access. You have the right to obtain.
Right of portability. You have the right, in certain circumstances, to receive a copy of the personal data you have provided to us in a structured, commonly used, machine-readable format that supports re-use, or to request the transfer of your personal data to another person.
Right to rectification. You have the right to obtain rectification of any inaccurate or incomplete personal data we hold about you without undue delay.
Right to erasure. You have the right, in some circumstances, to require us to erase your personal data without undue delay if the continued processing of that personal data is not justified.
Right to restriction. You have the right, in some circumstances, to require us to limit the purposes for which we process your personal data if the continued processing of the personal data in this way is not justified, such as where the accuracy of the personal data is contested by you.
Right to withdraw consent. If you have provided consent for the processing of your personal data, you have the right to withdraw your consent at any time free of charge. If you withdraw your consent, this will not affect the lawfulness of our use of your personal data before your withdrawal.
Right to object to direct marketing. You have the right to object at any time to the processing of your personal data for direct marketing, including any profiling related to such marketing. If you object, we will immediately stop processing your personal data for these purposes.
You also have the right to object to any processing based on our legitimate interests where there are grounds relating to your particular situation. There may be compelling reasons for continuing to process your personal data, and we will assess and inform you if that is the case.
You also have the right to lodge a complaint to a supervisory authority, including in your country of residence, place of work, or where an incident took place.
If you wish to exercise one of these rights, please contact us using the How To Contact Us section above.
Due to the confidential nature of data processing, we may ask you to confirm your identity when exercising the above rights. Please note that there are exceptions and limitations to each of these rights, and that while any changes you make will be reflected in active user databases instantly or within a reasonable period of time, we may retain personal information for backups, archiving, prevention of fraud and abuse, analytics, satisfaction of legal obligations, or where we otherwise reasonably believe that we have a legitimate reason to do so.
Changes to This European Privacy Policy
We may update this European Privacy Policy from time to time and so you should review this page periodically. When we change this European Privacy Policy in a material way, we will update the “Effective Date“ above. Changes to this European Privacy Policy are effective when they are posted on this page.