How CircuCity AI protects personal data and meets EU regulatory requirements.
CircuCity AI is fully committed to compliance with the General Data Protection Regulation (EU 2016/679). We have implemented comprehensive technical and organizational measures to protect personal data and uphold data subject rights. This page details our GDPR compliance framework, data processing practices, and your rights as a data controller or data subject.
A Data Processing Agreement is available to all customers upon request. The DPA covers:
As a data processor, we provide tools and processes to help you fulfill data subject requests:
Export a subject's data via dashboard or API. We respond within 30 days.
Update inaccurate data through dashboard settings or via support.
Delete conversations, knowledge base documents, or entire workspaces. Permanently removed within 30 days.
Suspend processing of a specific data subject while a request is verified.
Export data in JSON format for transfer to another service.
Opt out of analytics processing. Contact privacy@circucity.com.
We maintain the following measures to ensure data security:
All personal data is stored within the European Union (Hetzner, Falkenstein; AWS eu-central-1, Frankfurt). Where data transfers outside the EU are necessary (e.g., OpenAI inference in the US for chat response generation), we rely on:
In the event of a personal data breach:
Our Data Protection Officer oversees GDPR compliance and serves as the point of contact for supervisory authorities and data subjects.
Email: privacy@circucity.com
Privacy inquiries: privacy@circucity.com
Postal: CircuCity AI AB, Stockholm, Sweden
Response within 72 hours for all data subject requests.
You have the right to lodge a complaint with your local data protection authority. Our lead supervisory authority is: