Snapshot 19602
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Skip to main content Data Protection Addendum Last updated July 21, 2026 Built on Bonterms. This DPA incorporates the Bonterms Data Protection Addendum v2.0 (Attachment Version) by reference, with the DPA Details and Exhibits below. The standard is published under CC BY 4.0 and is designed for cross-border deployments under GDPR, UK GDPR, and equivalent data protection regimes. This Data Protection Addendum applies to any processing of personal data DuoCircle performs on behalf of a Customer in connection with the DuoCircle Cloud Terms. Acceptance of the Cloud Terms incorporates this DPA by reference, and most customers do not need a counter-signed copy. Bonterms publishes the v2.0 standard in three forms. We use the Attachment Version here because it attaches to the Main Agreement without a separate signature. Customers whose privacy program requires an executed document may request the Signable Version or the Cover Page Version, carrying the same DPA Details below, by emailing [email protected]. DPA Details Key Terms Field Value Main Agreement The DuoCircle Cloud Terms, or the Order or Cover Page that incorporates them for Customer’s account DPA Effective Date The date Customer first accepted the Main Agreement Subprocessor List /legal/subprocessors/, with email notice to the technical contact on the account at least thirty days before a new subprocessor begins processing personal data Designated EU Governing Law Republic of Ireland Designated EU Member State Republic of Ireland Processing Details Item Description Customer (data exporter) The legal entity on the account, acting as controller. Data protection contact: the contact designated on Customer’s account, or, if not designated, Customer’s billing contact Provider (data importer) DuoCircle LLC, 5965 Village Way, Suite 105-234, San Diego, CA 92130, United States, acting as processor. Data protection contact: [email protected] Categories of data subjects Customer’s employees, contractors, alumni, students, customers, vendors, and any other party who sends or receives email through Customer’s mail flow Categories of customer personal data Email envelope and header data including sender, recipient, subject, and routing information; message bodies and attachments where the service requires content inspection; account holder names, business email addresses, and authentication credentials; usage logs Sensitive or special categories of personal data None expected. Customer must not route data covered by HIPAA, PCI DSS Level 1 cardholder data, or comparable special-category regimes through services not specifically provisioned for that data class. Contact [email protected] before doing so. Frequency of transfer Continuous, for the duration of the Main Agreement Nature of the processing Receiving, scanning, filtering, authenticating, queuing, forwarding, archiving, and reporting on email and email metadata under Customer’s control, and providing related dashboards, alerts, and APIs Purpose of the processing Provision of email security, authentication, deliverability, and routing services as set out in the Cloud Terms Duration of processing and retention The term of the Main Agreement plus any retention period required by law or configured by Customer for archiving and reporting Transfers to subprocessors To the subprocessors listed at /legal/subprocessors/, for the purposes stated there, for the duration of the Main Agreement Competent EU supervisory authority The Data Protection Commission of Ireland Security Measures These are the technical and organizational measures required by the DPA Details. DuoCircle maintains an information security program aligned to the AICPA Trust Services Criteria for Security, Availability, Confidentiality, and Processing Integrity. SOC 2 Type II audits are performed annually by an independent CPA firm. Current controls are summarized at /legal/security/ and include: Encryption in transit using TLS 1.2 or higher for all customer-facing endpoints, and encryption at rest for databases, object storage, and backups using industry-standard ciphers Multi-factor authentication required for all production system access and for all administrative interfaces Role-based access controls with least-privilege defaults; quarterly access reviews Centralized logging, real-time alerting, and 24x7 on-call rotation Vulnerability scanning, dependency monitoring, and timely patching Independent penetration testing on a regular cadence Documented incident response procedures with named breach-notification responsibilities Background checks for employees with access to customer data, where permitted by law Mandatory annual security training for all personnel Vendor security review for any subprocessor with access to customer data A current SOC 2 Type II report is available under NDA on request to [email protected]. The Bonterms Mutual NDA is published at /legal/mutual-nda/ for prospects who want to review the form before requesting the report. Exhibit A – Cross-Border Transfer Mechanisms For transfers of personal data out of the EEA, the United Kingdom, and Switzerland to a third country that has not received an adequacy decision, the parties agree that the EU Commission Standard Contractual Clauses (Module Two, Controller to Processor) apply, with the United Kingdom Addendum where applicable and the Swiss Federal Data Protection Authority’s amendments where applicable. The optional clauses are deemed selected as follows: Module: Two (Controller to Processor) Docking clause: Selected Subprocessor authorization: Option Two, general written authorization, with the notice period and process set out above Audit clause: As set out in the Security Measures above and Section 9 (Audits) of the Bonterms DPA Governing law of the SCCs: Republic of Ireland Forum for SCC disputes: Republic of Ireland For onward transfers to subprocessors located in third countries, DuoCircle imposes equivalent terms via written agreement. Current subprocessors and their locations are listed at /legal/subprocessors/. Exhibit B – Region-Specific Terms Region-specific terms apply automatically to the extent the relevant data protection law governs Customer’s processing. This includes the UK GDPR for United Kingdom data subjects, the Swiss FADP for Swiss data subjects, the LGPD for Brazilian data subjects, the PIPL for People’s Republic of China data subjects, and the CCPA and CPRA for California consumers. Version 2.0 of the standard extends the same structure to other United States state privacy laws as they take effect. The Bonterms DPA Exhibit B region-specific terms are incorporated as published. Additional Terms The Bonterms DPA governs except as expressly stated in the DPA Details, the Security Measures, and the cross-border transfer mechanism designations above. There are no other modifications. Earlier versions This DPA was previously published on the Bonterms DPA Version 1.0 standard, which organized the same content as a DPA Setup Page and Schedules 1 through 4. Version 2.0 folds that content into a single DPA Details section with Exhibit A and Exhibit B, and it attaches to any main agreement rather than only to the Bonterms Cloud Terms. The commitments have not changed; the thirty-day subprocessor notice we have always given is now the standard’s own default. Documents previously published as the DuoCircle Data Processing Agreement, the DuoCircle GDPR Privacy Policy, the DuoCircle Privacy Framework, and the DuoCircle Data Deletion Request page are superseded by this DPA together with the Privacy Notice and the Security Statement. Questions about this document? DuoCircle LLC, 5965 Village Way, Suite 105-234, San Diego, CA 92130. Email [email protected] for legal inquiries, or [email protected] for everything else. All legal documents Talk to an expert