Last updated: September 2026
[legal entity name] (“DocuCircuit,” “we,” “us”) provides a platform for recurring operational forms, inspections, and reporting. This policy explains what we collect, why, and your choices. For a plain-language summary see Your data stays yours.
When a company subscribes to DocuCircuit, that company is the controller of the information its people enter, and we are its processor — we handle that information on the company’s instructions. For our own marketing site and account signups, we are the controller.
We do not sell personal information, and we do not use customer content to train AI models or to build features for other customers.
On plans that include the AI assistant, we send the text of the inspection step being reviewed to our AI provider (Anthropic, PBC) to generate suggestions. Under Anthropic’s commercial terms, that data is not used to train their models. Customers on the Standard plan have no data sent to any AI provider.
We rely on a small set of infrastructure providers. The current list, with what each one does and where it is located, is at /legal/subprocessors. We will post there before adding or replacing a sub-processor.
Each customer chooses a retention period for their records (default: 5 years). We keep customer content for at least that period while the account is active. A customer can export their complete record set as a single file at any time from within the product.
When an account closes, the customer can export first; we then keep the data read-only for a short grace period and permanently delete it, unless a legal hold or a legal obligation requires us to retain it. Deleting an organization removes its reports, signature evidence, incidents, defects, and people; a single tamper-proof entry recording that the deletion happened is kept.
Encryption in transit (TLS) and at rest; strict per-company data isolation enforced in the application; least-privilege access; passwordless authentication. Signed records and the activity log are stored append-only and carry a cryptographic integrity seal, so tampering is detectable. No system is perfectly secure, but we take measures appropriate to the sensitivity of the data.
If we become aware of a security incident affecting customer content, we will notify affected customers without undue delay and share what we know and what we are doing about it.
Our infrastructure is currently located in the United States. If you use DocuCircuit from outside the U.S., your information is transferred to and processed in the U.S. Where required, transfers of personal data out of the EEA/UK rely on the applicable Standard Contractual Clauses, incorporated by reference into our Data Processing Agreement.
Depending on where you live, you may have rights to access, correct, delete, or export your personal information. If your data was entered into a customer’s workspace, contact that company; otherwise contact us. We will not discriminate against you for exercising these rights.
DocuCircuit is a workplace tool and is not directed to anyone under 18.
We’ll post changes here and update the date above. Material changes affecting customers will also be sent by email.
[legal entity name], [mailing address]. wesleymaupin@gmail.com