Third Party Index

Snapshot 19602

Document
Data processing addendum
URL
https://www.duocircle.com/legal/dpa/
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
49307 bytes
SHA-256 (raw)
f5b5722f432fd5b4ea1cbce4b43ac931472be77203d5d9ac7b2ca5c3f03240d8
SHA-256 (normalized text)
672946d904e2225d72d740675a3b82ada89075437c1adf43090262d8aa943fde

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Skip to main content
Data Protection Addendum
Last updated July 21, 2026
Built on Bonterms. This DPA incorporates the Bonterms Data Protection Addendum v2.0 (Attachment Version) by reference, with the DPA Details and Exhibits below. The standard is published under CC BY 4.0 and is designed for cross-border deployments under GDPR, UK GDPR, and equivalent data protection regimes.
This Data Protection Addendum applies to any processing of personal data DuoCircle performs on behalf of a Customer in connection with the DuoCircle Cloud Terms. Acceptance of the Cloud Terms incorporates this DPA by reference, and most customers do not need a counter-signed copy.
Bonterms publishes the v2.0 standard in three forms. We use the Attachment Version here because it attaches to the Main Agreement without a separate signature. Customers whose privacy program requires an executed document may request the Signable Version or the Cover Page Version, carrying the same DPA Details below, by emailing [email protected].
DPA Details
Key Terms
Field	Value
Main Agreement	The DuoCircle Cloud Terms, or the Order or Cover Page that incorporates them for Customer’s account
DPA Effective Date	The date Customer first accepted the Main Agreement
Subprocessor List	/legal/subprocessors/, with email notice to the technical contact on the account at least thirty days before a new subprocessor begins processing personal data
Designated EU Governing Law	Republic of Ireland
Designated EU Member State	Republic of Ireland
Processing Details
Item	Description
Customer (data exporter)	The legal entity on the account, acting as controller. Data protection contact: the contact designated on Customer’s account, or, if not designated, Customer’s billing contact
Provider (data importer)	DuoCircle LLC, 5965 Village Way, Suite 105-234, San Diego, CA 92130, United States, acting as processor. Data protection contact: [email protected]
Categories of data subjects	Customer’s employees, contractors, alumni, students, customers, vendors, and any other party who sends or receives email through Customer’s mail flow
Categories of customer personal data	Email envelope and header data including sender, recipient, subject, and routing information; message bodies and attachments where the service requires content inspection; account holder names, business email addresses, and authentication credentials; usage logs
Sensitive or special categories of personal data	None expected. Customer must not route data covered by HIPAA, PCI DSS Level 1 cardholder data, or comparable special-category regimes through services not specifically provisioned for that data class. Contact [email protected] before doing so.
Frequency of transfer	Continuous, for the duration of the Main Agreement
Nature of the processing	Receiving, scanning, filtering, authenticating, queuing, forwarding, archiving, and reporting on email and email metadata under Customer’s control, and providing related dashboards, alerts, and APIs
Purpose of the processing	Provision of email security, authentication, deliverability, and routing services as set out in the Cloud Terms
Duration of processing and retention	The term of the Main Agreement plus any retention period required by law or configured by Customer for archiving and reporting
Transfers to subprocessors	To the subprocessors listed at /legal/subprocessors/, for the purposes stated there, for the duration of the Main Agreement
Competent EU supervisory authority	The Data Protection Commission of Ireland
Security Measures
These are the technical and organizational measures required by the DPA Details. DuoCircle maintains an information security program aligned to the AICPA Trust Services Criteria for Security, Availability, Confidentiality, and Processing Integrity. SOC 2 Type II audits are performed annually by an independent CPA firm. Current controls are summarized at /legal/security/ and include:
Encryption in transit using TLS 1.2 or higher for all customer-facing endpoints, and encryption at rest for databases, object storage, and backups using industry-standard ciphers
Multi-factor authentication required for all production system access and for all administrative interfaces
Role-based access controls with least-privilege defaults; quarterly access reviews
Centralized logging, real-time alerting, and 24x7 on-call rotation
Vulnerability scanning, dependency monitoring, and timely patching
Independent penetration testing on a regular cadence
Documented incident response procedures with named breach-notification responsibilities
Background checks for employees with access to customer data, where permitted by law
Mandatory annual security training for all personnel
Vendor security review for any subprocessor with access to customer data
A current SOC 2 Type II report is available under NDA on request to [email protected]. The Bonterms Mutual NDA is published at /legal/mutual-nda/ for prospects who want to review the form before requesting the report.
Exhibit A – Cross-Border Transfer Mechanisms
For transfers of personal data out of the EEA, the United Kingdom, and Switzerland to a third country that has not received an adequacy decision, the parties agree that the EU Commission Standard Contractual Clauses (Module Two, Controller to Processor) apply, with the United Kingdom Addendum where applicable and the Swiss Federal Data Protection Authority’s amendments where applicable. The optional clauses are deemed selected as follows:
Module: Two (Controller to Processor)
Docking clause: Selected
Subprocessor authorization: Option Two, general written authorization, with the notice period and process set out above
Audit clause: As set out in the Security Measures above and Section 9 (Audits) of the Bonterms DPA
Governing law of the SCCs: Republic of Ireland
Forum for SCC disputes: Republic of Ireland
For onward transfers to subprocessors located in third countries, DuoCircle imposes equivalent terms via written agreement. Current subprocessors and their locations are listed at /legal/subprocessors/.
Exhibit B – Region-Specific Terms
Region-specific terms apply automatically to the extent the relevant data protection law governs Customer’s processing. This includes the UK GDPR for United Kingdom data subjects, the Swiss FADP for Swiss data subjects, the LGPD for Brazilian data subjects, the PIPL for People’s Republic of China data subjects, and the CCPA and CPRA for California consumers. Version 2.0 of the standard extends the same structure to other United States state privacy laws as they take effect. The Bonterms DPA Exhibit B region-specific terms are incorporated as published.
Additional Terms
The Bonterms DPA governs except as expressly stated in the DPA Details, the Security Measures, and the cross-border transfer mechanism designations above. There are no other modifications.
Earlier versions
This DPA was previously published on the Bonterms DPA Version 1.0 standard, which organized the same content as a DPA Setup Page and Schedules 1 through 4. Version 2.0 folds that content into a single DPA Details section with Exhibit A and Exhibit B, and it attaches to any main agreement rather than only to the Bonterms Cloud Terms. The commitments have not changed; the thirty-day subprocessor notice we have always given is now the standard’s own default.
Documents previously published as the DuoCircle Data Processing Agreement, the DuoCircle GDPR Privacy Policy, the DuoCircle Privacy Framework, and the DuoCircle Data Deletion Request page are superseded by this DPA together with the Privacy Notice and the Security Statement.
Questions about this document?
DuoCircle LLC, 5965 Village Way, Suite 105-234, San Diego, CA 92130. Email [email protected] for legal inquiries, or [email protected] for everything else.
All legal documents Talk to an expert