The EU-US Data Privacy Framework, explained for vendor reviews
Solomon Amos · 7 Sep 2026 · 10 min read
Regulatory evidence
Build a home for your community, events, and courses — all under your own
For each regulation, how many of the requirements it places on your vendors CircleCo’s public evidence reaches. Open one for every item with its date and source.
What the vendor lists, typed; public items can be read now, the rest are available on request.
11 documents listed on CircleCo’s trust centre
trust.circle.soAnswers the vendor publishes to questions buyers ask, quoted with the link to where it says so.
Where data is hosted or processed
Where can I find Circle's Data Processing Addendum (DPA)?
“Circle's DPA can be found at https://circle.so/dpa. Our DPA binds Circle to appropriate security, prompt breach notification, cooperation with you and regulators, assistance with data-subject requests, and flow-down obligations to sub-processors. These practices are compliant with the GDPR.”
as of 21 Sep 2026Source
Where data is hosted or processed
Where does Circle host customer data?
“Circle hosts all data in AWS US-East-1 (Northeast US). Please note that Circle doesn't currently offer the option to host data in any other locations. This means that by using Circle's services, personal data will be processed in the United States. All such transfers are covered by our Data Processing Addendum (DPA), which includes the EU Standard Contractual Clauses, the UK Addendum, and the Swiss Addendum to ens...”
Regions named: EU, UK, USas of 21 Sep 2026Source
Encryption
How does Circle encrypt customer data?
“All datastores with customer data, in addition to S3 buckets, are encrypted at rest with strong encryption (AES-256 and B-crypt). Sensitive collections and tables also use row-level encryption. This means the data is encrypted even before it hits the database so that neither physical access, nor logical access to the database, is enough to read the most sensitive information. Circle also uses TLS 1.2 or higher eve...”
as of 21 Sep 2026Source
Incident and breach notification
How quickly will I be notified if a breach involving my data or community data occurs?
“Circle maintains a robust protocol for investigating and reporting security incidents. In the event of a relevant incident, Circle will notify customers (or other affected data subjects, as applicable) without undue delay, as required under applicable privacy laws. More information can be found on this in our DPA (please see references to "Security Incident" throughout the document).”
as of 21 Sep 2026Source
Penetration testing
Does Circle conduct penetration tests?
“Circle engages with one of the best penetration testing consulting firms in the industry at least annually. Our current preferred penetration testing partner is Redseer Security. All areas of the Circle product (web + mobile) and cloud infrastructure are in-scope for these assessments, and source code is fully available to the testers in order to maximize the effectiveness and coverage.”
as of 21 Sep 2026Source
Data retention and deletion
What is the data retention period for information used by AI features?
“Circle retains data according to your contract and standard retention practices (see our Data Processing Addendum). AI model providers do not store or retain Inputs.”
as of 21 Sep 2026Source
Solomon Amos · 7 Sep 2026 · 10 min read
CertReports Research · 18 Sep 2026 · 12 min read
This maps third-party obligations to the vendor evidence that may support them. It is not legal advice and never a statement that a vendor or its customers comply; confirm scope and sufficiency with your counsel or auditor. “No public evidence” means nothing public was found at the last check. Citations link to the official text.