DCDocuCircuit← Home
Legal

Privacy Policy

Last updated: September 2026

Draft. Fill in the bracketed items ([legal entity name], address, governing law) and have a lawyer review before you sign a paying customer.

[legal entity name] (“DocuCircuit,” “we,” “us”) provides a platform for recurring operational forms, inspections, and reporting. This policy explains what we collect, why, and your choices. For a plain-language summary see Your data stays yours.

1. Who controls the data

When a company subscribes to DocuCircuit, that company is the controller of the information its people enter, and we are its processor — we handle that information on the company’s instructions. For our own marketing site and account signups, we are the controller.

2. What we collect

Customer content

  • Forms and templates a customer uploads or builds
  • Completed inspections and reports, including answers, photos, and timestamps
  • Electronic-signature evidence for records that are signed: the signer’s account and typed name, the exact wording they agreed to, a server timestamp, the IP address and browser used, and — only if the device allows it — approximate location. This is kept to make signed records verifiable and is never used for any other purpose.
  • Incident and near-miss reports, which may include injury details (health information)
  • Organization setup: departments, routing rules, the report inbox address
  • People a customer invites: name (if provided) and email address
  • An activity log of changes to records and settings — who did what, when, and from which IP. It cannot be edited or deleted by anyone, including us.

Account & usage data

  • Your email address and sign-in events (we use passwordless magic links)
  • Server logs (requests, timestamps, IP address, errors)
  • Early-access / contact form submissions

3. How we use it

  • To provide, secure, and support the service
  • To route completed reports to the recipients a customer configures
  • To send transactional email (sign-in links, invites, report notifications)
  • To improve reliability and fix problems
  • To comply with law and enforce our Terms

We do not sell personal information, and we do not use customer content to train AI models or to build features for other customers.

4. AI processing

On plans that include the AI assistant, we send the text of the inspection step being reviewed to our AI provider (Anthropic, PBC) to generate suggestions. Under Anthropic’s commercial terms, that data is not used to train their models. Customers on the Standard plan have no data sent to any AI provider.

5. Sub-processors

We rely on a small set of infrastructure providers. The current list, with what each one does and where it is located, is at /legal/subprocessors. We will post there before adding or replacing a sub-processor.

6. Retention & deletion

Each customer chooses a retention period for their records (default: 5 years). We keep customer content for at least that period while the account is active. A customer can export their complete record set as a single file at any time from within the product.

When an account closes, the customer can export first; we then keep the data read-only for a short grace period and permanently delete it, unless a legal hold or a legal obligation requires us to retain it. Deleting an organization removes its reports, signature evidence, incidents, defects, and people; a single tamper-proof entry recording that the deletion happened is kept.

7. Security

Encryption in transit (TLS) and at rest; strict per-company data isolation enforced in the application; least-privilege access; passwordless authentication. Signed records and the activity log are stored append-only and carry a cryptographic integrity seal, so tampering is detectable. No system is perfectly secure, but we take measures appropriate to the sensitivity of the data.

7a. Data breaches

If we become aware of a security incident affecting customer content, we will notify affected customers without undue delay and share what we know and what we are doing about it.

7b. International transfers

Our infrastructure is currently located in the United States. If you use DocuCircuit from outside the U.S., your information is transferred to and processed in the U.S. Where required, transfers of personal data out of the EEA/UK rely on the applicable Standard Contractual Clauses, incorporated by reference into our Data Processing Agreement.

8. Your rights

Depending on where you live, you may have rights to access, correct, delete, or export your personal information. If your data was entered into a customer’s workspace, contact that company; otherwise contact us. We will not discriminate against you for exercising these rights.

9. Children

DocuCircuit is a workplace tool and is not directed to anyone under 18.

10. Changes

We’ll post changes here and update the date above. Material changes affecting customers will also be sent by email.

11. Contact

[legal entity name], [mailing address]. wesleymaupin@gmail.com

Your dataPrivacy PolicyTerms of ServiceData Processing AgreementSub-processors