CIRCUITLEAP PRIVACY POLICY
Effective Date: August 13, 2026
CircuitLeap, Inc. ("CircuitLeap," "we," "us," or "our") respects your privacy. This Privacy Policy explains how we handle personal information when you visit circuitleap.ai, contact us, apply for a role, request or use access to app.circuitleap.ai, or otherwise use our software and related services (collectively, the "Services").
We limit personal information to what is reasonably needed for business communications, recruitment, account access, security, support, service delivery, and legal obligations. We do not use personal information for cross-site behavioral advertising, behavioral profiling, or model training.
1. Scope and enterprise customers
CircuitLeap provides business-to-business Services. Enterprise customers may have separate negotiated agreements with CircuitLeap, including privacy, security, retention, and data-processing terms. Those agreements supplement this Policy and, if there is a conflict, control for that customer to the extent of the conflict.
CircuitLeap determines how and why it handles information about Website visitors, business contacts, applicants, platform accounts, support, security, and service administration.
When CircuitLeap processes personal information contained in information supplied by a customer ("Customer Content"), CircuitLeap acts on that customer's instructions under the applicable agreement. The customer controls that information and is normally the primary contact for related privacy requests.
2. Information we handle
Depending on how you interact with CircuitLeap, we may handle:
- Business and contact information, such as your name, work email, company, job title, and messages you send us.
- Applicant information, such as contact details, the role selected, information you provide about your suitability, and application materials later requested.
- Account and organization information, such as a corporate email address, internal account identifier, organization, role, permissions, platform preferences, and authentication records. Email may be used for sign-in, service communications, and password recovery. CircuitLeap does not maintain a general social profile or separate public display profile.
- Operational, security, and access information, such as authentication timestamps and IP addresses, ordinary device or browser information, service diagnostics, security events, and customer-provided network access rules needed to operate and protect the Services.
- Support information, including messages and files you or your organization send when requesting assistance.
- Customer Content, meaning technical engineering and design information submitted to or generated through the Services.
We receive information directly from you, from your organization, through authentication and operation of the Services, from systems connected at the customer's direction, and from providers used to operate the Services.
Providing contact or applicant information is voluntary, but we may be unable to respond or evaluate an application without the information needed for that purpose. Account and authentication information is necessary to provide and secure platform access.
The Services are not designed for consumer use or for health information, payment-card data, government identifiers, or other regulated sensitive personal information. Customer Content is business and technical information and is not intended to contain personal information. Customers and users should not submit personal information in Customer Content unless their agreement expressly permits it.
3. How we use personal information
We use personal information to:
- operate, maintain, troubleshoot, and secure the Services;
- respond to inquiries and platform-access requests;
- evaluate potential business relationships;
- review applications and communicate with applicants;
- authenticate users and administer customer organizations;
- enforce customer-approved network access restrictions;
- provide support and communicate about service or security changes;
- manage billing, capacity, reliability, and contractual obligations; and
- comply with law and establish or protect legal rights.
Where European data-protection law applies, the legal basis depends on the context. We rely on steps requested before entering a contract or performance of a contract; our legitimate interests in operating, securing, supporting, and improving business Services; consent where we specifically request it; and compliance with legal obligations.
You may object to processing based on legitimate interests. Where we rely on consent, you may withdraw it at any time without affecting processing that was already lawful.
4. Customer Content and service information
We use Customer Content only to provide, support, maintain, and secure the contracted Services, follow the customer's documented instructions, and comply with applicable law.
We do not use Customer Content to train CircuitLeap or third-party artificial-intelligence models, for advertising or marketing profiles, for analytics unrelated to the contracted Services, or to develop a product for another customer.
We may use limited operational information to maintain reliability, security, capacity, and cost, and to understand whether features are functioning and useful. Where practical, we keep this information separate from the substance of Customer Content and use aggregated or de-identified information. We do not use it to build behavioral profiles or track individuals across unrelated services.
5. How we disclose information
We disclose information only as reasonably needed:
- to providers that supply cloud hosting, databases, authentication, security, communications, support, recruitment, and business operations;
- to Google Forms or Google Workspace when you submit a contact, platform-access, or recruitment form;
- to Google or a customer-selected single sign-on provider when that authentication method is used;
- to a third-party AI provider only when a customer has contracted for or enabled a feature that requires that provider;
- to the customer organization that administers an authorized user's account;
- to an integration or third party at the customer's direction;
- when required by law or reasonably necessary to protect rights, safety, or security; or
- in connection with a merger, financing, acquisition, reorganization, or sale of the business, subject to applicable safeguards and customer agreements.
Providers may handle information only to supply services to CircuitLeap, subject to applicable contractual and legal obligations. Customers may request information about providers relevant to their Services.
We do not sell personal information or Customer Content. We do not share either for cross-context behavioral advertising.
6. Forms, authentication, cookies, and tracking
The public Website uses Google Forms or Google Workspace for contact, platform-access, and recruitment submissions. Google receives the information entered and may receive ordinary device and connection information when its service loads. Google's handling of information is described at https://policies.google.com/privacy.
The platform uses technologies needed for authentication, session management, security, and operation. If you use Google sign-in or customer-provided single sign-on, the identity provider handles the information needed to authenticate you under its applicable terms.
We do not use nonessential Website analytics or cross-site behavioral advertising. If we introduce nonessential analytics in the future, we will update this Policy and provide notice or choice where required.
Because CircuitLeap does not track people across unrelated websites for advertising, a browser Do Not Track signal does not change the Services. We honor legally recognized opt-out preference signals, including Global Privacy Control, where required.
7. Retention and deletion
We retain personal information only for as long as reasonably necessary for the purpose for which it was collected and for applicable contractual, legal, security, dispute, and recordkeeping requirements.
Inquiry and applicant information is retained while we handle the request or application and for a reasonable period afterward. Account, support, operational, and security information is retained while needed to operate and protect the Services and meet applicable customer agreements. Customer Content is retained according to the applicable customer agreement and the customer's instructions.
Transient processing resources are removed automatically after processing within a limited operational window. When information is no longer needed, we delete or de-identify it, subject to lawful exceptions and routine backup-deletion cycles.
8. Security
We use technical and organizational measures designed to protect information, including encryption in transit and at rest, access controls, customer isolation, authentication logging, and customer-approved network access controls. No method of transmission or storage can guarantee absolute security.
9. International processing
CircuitLeap is based in the United States and has most of its personnel in Portugal. Information may be processed in the United States, Portugal, and locations where our providers operate. Where applicable law requires safeguards for an international transfer, we use an appropriate legal mechanism. Customer-specific arrangements are addressed in the applicable customer agreement.
10. Your rights
Depending on your location and subject to legal exceptions, you may have rights to:
- access or obtain a copy of your personal information;
- correct inaccurate information;
- request deletion;
- object to or restrict certain processing;
- receive portable data where applicable;
- withdraw consent where processing relies on consent; and
- complain to a data-protection authority.
We may verify your identity and authority before acting on a request. Where the GDPR applies, we respond without undue delay and normally within one month.
For Customer Content or other information controlled by a customer, contact your organization's administrator or privacy contact first. CircuitLeap will assist the customer as required by the applicable agreement and law.
We do not use personal information to make automated decisions about individuals that produce legal or similarly significant effects.
11. On-premises deployments
Information processed solely inside a customer's on-premises installation remains in the customer's environment and is outside CircuitLeap's possession. This Policy applies to account, licensing, support, security, or diagnostic information that the customer sends to CircuitLeap.
12. Children's privacy
The Website and Services are business services and are not directed to children under 16. We do not knowingly collect their personal information. If you believe a child has provided information to us, contact us so we can review and delete it as appropriate.
13. Changes to this Policy
We may update this Policy to reflect changes to our Services, practices, or legal obligations. We will post the updated Policy, change its effective date, and provide additional notice where required.
14. Contact us
CircuitLeap, Inc.Attn: David Tournatory, Privacy Contact
101 Acacia Lane
Redwood City, CA 94062, USA
david.tournatory@circuitleap.ai
+1 415 987 9455