Skip to main content

Security

Details about Circleback's security, data privacy, and compliance

Circleback is SOC 2 Type II and EU-U.S. Data Privacy Framework-certified and uses industry-leading practices to handle customer data, including encrypting data at rest and in transit.

We do not use customer data to train models. Our security portal at security.circleback.ai has more information, including a report of an external pentest done on our infrastructure.

Circleback is also HIPAA-compliant and can sign BAAs with enterprise customers.

GDPR

Circleback supports customers’ obligations under the GDPR (EU) 2016/679. When we process personal data on your behalf, we do so as a processor under our Data Processing Agreement (DPA), and as described in our Privacy Policy.

Transfers of personal data from the EEA or the United Kingdom to Circleback in the United States can rely on Circleback’s EU-U.S. Data Privacy Framework certification, including the UK Extension to the EU-U.S. DPF for UK transfers. For unresolved complaints about personal data received under the UK Extension, Circleback cooperates with the UK Information Commissioner’s Office (ICO).

Workspace admins can also control how long meeting data is kept. See Data retention settings.

For questions about your Circleback account data, email [email protected]. If you are a meeting participant and want to exercise privacy rights over meeting data, contact the Circleback customer who organized the meeting; we will assist that customer as required under our DPA.

Agreements

You can review Circleback’s security portal and legal agreements here:

Did this answer your question?