While providing our Service, we may collect information about our customers’ Users on behalf of our customers. Our use of information on behalf of our customers is governed by our agreement with the applicable customer and the customer’s own privacy policies. We cannot control and are not responsible for the privacy policies or privacy practices of our customers or any other third parties.
Information We Collect And How We Use It
I. Personal Data That You Provide To Us
When you interact with the Website or the Service, CircleCI may gather information that, alone or in combination with other information, could be used to identify you (“Personal Data”), as described below. If you are an EU data subject, please see the “EU Data Subject” section below for information on your rights in relation to the Personal Data we hold about you.
a) Personal Data used to provide the Service and respond to requests
When users sign up for the Service, users are required to authenticate with their version control system identity (GitHub or Bitbucket). When users log in to the Service using sign-in services such as OAuth (for example, login with a GitHub account), these services will authenticate a user’s identity and provide the user with the option to share certain Personal Data, such as name and email address(es), with us. If you purchase one of our paid plans, we will also collect payment and billing information such as credit card details and billing address. We use this data to provide you with access to the Service and/or the Website, contact you regarding your access and use of the Service and/or the Website or to notify you of important changes to the Service. For EU data subjects, such use is necessary for the performance of the contract between you and us.
On some sections of the Website, you may complete a web form to give your Personal Data to us directly, such as on our “Contact Us” page. We also collect Personal Data (such as your name and contact details, phone number) when you request information, including a product demo, ask to download content (such as white papers), register for a webinar or other event, or subscribe to email lists. We will use your contact information to respond to your request. For EU data subjects, such use is necessary to respond to or implement your request. If you send us a request or question regarding the use of the Service (for example via a support email or via one of our feedback mechanisms), we may publish it (in anonymous form only) in order to help us clarify or respond to your request or to help us support other users.
CircleCI collects Personal Data that you provide through the Service only insofar as is necessary or appropriate to fulfill the purpose of your interaction with CircleCI, such as providing you with the Service and/or answering any requests regarding the Service as described above. You can always refuse to supply Personal Data, however doing so may prevent you from accessing the Service or engaging in certain activities on the Website or the Service.
b) Personal Data used to process applications for employment
When you submit a job application through the Website, we will collect your resume and any additional information that you elect to provide to us, including but not limited to employment history and education. We will use your contact details and data about your employment history and education to conduct job interviews, evaluate your application, and as is otherwise needed for recruitment. For EU data subjects, this use is necessary to respond to your request to process your application for employment.
c) Personal Data used for marketing
We will use your email to tell you about your Service usage, new features, solicit your feedback, or just keep you up to date with what’s going on with CircleCI and our products, upcoming events or other promotions. If you change your mind about receiving information from us or about the use of information volunteered by you, please send us a request specifying your new choice. Please contact us as specified under the “Contact Us” section. You may also choose to opt out of receiving such emails by following the unsubscribe instructions included in these emails, or by accessing the email preferences in your account settings page. If you download content from the Website, we may also use your phone number to contact you directly by phone, in connection with such new products and services, upcoming events or other promotions.
Where required by applicable law (for example, if you are an EU data subject), we will only send you marketing information by email or mail, or contact you by phone, if you consent to us doing so. When you provide us with your consent to be contacted for marketing purposes, you have the right to withdraw your consent at any time by following the instructions to “opt-out” of receiving marketing communication in each marketing email we send you. In addition, if at any time you do not wish to receive future marketing communications or wish to have your name deleted from our mailing or calling lists, please contact us at firstname.lastname@example.org. Please note that if you opt out from marketing communications, we may still contact you regarding issues related to our Service and to respond to your requests.
II. Automatically Collected Information
Like most hosted service operators, CircleCI collects information of the sort that web browsers and servers typically make available, such as the browser type, language preference, referring site and the date and time of each visitor request and store it in log files. CircleCI also collects Internet Protocol (“IP”) addresses, which can be used to identify the location from which your computer is connecting to the Website, for providing the Service and for support purposes.
Use of such automatically collected information is necessary for the performance of the contract between you and us, to the extent we process information that is needed for providing the Service and for support purposes, or is in our legitimate interest in understanding how the Service is being used by you and enhancing your experience on our Website and on the Service.
III. Information We Process On Behalf Of Our Customers
In providing the Service to our customers, we process on behalf of customers certain information that may include Personal Data, relating to customers’ employees, contractors or other users (“Users”) they transmit or otherwise submit to our Service. While our customers or Users decide what data to submit, this information typically includes email address and information relating to tests results.
CircleCI collects, aggregates, and stores metrics and data relating to, generated by, provided in connection with, or derived from customers’ use of the Service (“Usage Data”) in order to provide, maintain, support, enhance, develop and improve the Service and CircleCI’s service offerings. CircleCI will not disclose individual metric or usage data other than in an aggregated and de-identified form. For EU data subjects, this use of your Personal Data is necessary for our legitimate interests in understanding how the Service is being used by you and to improve your experience on it.
Bulletin Boards/Chat Rooms
If you submit a post or participate in a discussion on a bulletin board or chat room on the Website or the Service, you should be aware that any Personal Data you submit there can be read, collected, or used by other users of these forums, and could be used to send you unsolicited messages. We are not responsible for the Personal Data you choose to submit in these forums.
Disclosure Of Personal Data
CircleCI may also disclose Personal Data when required to do so by law, such as to comply with a subpoena, bankruptcy proceedings, or similar legal process, or in response to lawful requests by public authorities, including to meet national security or law enforcement requirements, or when CircleCI believes in good faith that disclosure is reasonably necessary to protect the property or rights of CircleCI, third parties, or the public at large.
EU Data Subjects
Scope: This section applies if you are an EU data subject (for these purposes, reference to the EU also includes the European Economic Area countries of Iceland, Liechtenstein, Norway and, where applicable, Switzerland).
Data Controller: CircleCI is the data controller of Personal Data provided to, or collected by or for, our Website and the Service, but we may act as data processor on behalf of our customers for Personal Data that we process on their behalf when providing the Service.
Your Rights: Subject to applicable law, you have the following rights in relation to your Personal Data:
- Right of access: If you ask us, we will confirm whether we are processing your Personal Data and, if so, provide you with a copy of that Personal Data along with certain other details. If you require additional copies of the data, we may need to charge a reasonable fee.
- Right to rectification: If your Personal Data is inaccurate or incomplete, you are entitled to ask that we correct or complete it. If we shared your Personal Data with others, we will tell them about the correction where possible. If you ask us, and where possible and lawful to do so, we will also tell you with whom we shared your Personal Data so you can contact them directly.
- Right to erasure: You may ask us to delete or remove your Personal Data, such as where you withdraw your consent. If we shared your data with others, we will tell them about the erasure where possible. If you ask us, and where possible and lawful to do so, we will also tell you with whom we shared your Personal Data with so you can contact them directly.
- Right to restrict processing: You may ask us to restrict or ‘block’ the processing of your Personal Data in certain circumstances, such as where you contest the accuracy of the data or object to us processing it. We will tell you before we lift any restriction on processing. If we shared your Personal Data with others, we will tell them about the restriction where possible. If you ask us, and where possible and lawful to do so, we will also tell you with whom we shared your Personal Data so you can contact them directly.
- Right to data portability: Effective 25 May 2018, you have the right to obtain your Personal Data from us that you consented to give us or that was provided to us as necessary in connection with our contract with you. We will give you your Personal Data in a structured, commonly used and machine-readable format. You may reuse it elsewhere.
- Right to object: You may ask us at any time to stop processing your Personal Data, and we will do so if we are processing your Personal Data for direct marketing and otherwise. However, if we are relying on a legitimate interest to process your Personal Data and we demonstrate compelling legitimate grounds for the processing we may continue.
- Rights in relation to automated decision-making and profiling: You have the right to be free from decisions based solely on automated processing of your Personal Data, including profiling, that produce a significant legal effect on you, unless such profiling in necessary for entering into, or the performance of, a contract between you and us or you provide your explicit consent.
- Right to withdraw consent: If we rely on your consent to process your Personal Data, you have the right to withdraw that consent at any time. Withdrawal of consent will not affect any processing of your data before we received notice that you wished to unsubscribe.
- Right to lodge a complaint with the data protection authority: If you have a concern about our privacy practices, including the way we handled your Personal Data, you can report it to the data protection authority that is authorized to hear those concerns.
You may exercise your rights by contacting us as indicated under “Contact Us” section below.
Data Transfers. We rely on the EU-U.S. and Swiss-U.S. Privacy Shield certification to transfer Personal Data and other information that we receive from the EU and Switzerland to CircleCI in the U.S. (for more information, please read the “Privacy Shield” section below).
We rely on our Privacy Shield certification to transfer Personal Data and other information that we receive from the EU and Switzerland to CircleCI in the U.S. and we process this data in accordance with the Privacy Shield Principles of Notice and Choice, Accountability for Onward Transfer, Security, Data Integrity and Purpose Limitation, Access, Recourse, Enforcement and Liability (“Privacy Shield Principles”), as described below.
Accountability for Onward Transfers: We may be accountable for the Personal Data we receive under the Privacy Shield that we may transfer to third-party service providers (as described in the “Disclosure of Personal Data” section above) if they process Personal Data in a manner inconsistent with the Privacy Shield Principles and we are responsible if they do so and for the harm caused.
Access: You have certain rights to access, correct, amend, or delete Personal Data where it is inaccurate, or has been processed in violation of the Privacy Shield Principles. When we process Personal Data on behalf of our customers, the customer will be responsible to respond to requests for exercising your rights. We honor all customers’ requests from their Users to access, correct, amend, or delete Personal Data.
- Email: email@example.com
- Phone: +1-800-585-7075
- Postal Mail:
Circle Internet Services, Inc.
201 Spear Street, Ste 1200
San Francisco, CA, 94105
CircleCI has further committed to refer unresolved privacy complaints under the Privacy Shield Principles to an independent dispute resolution mechanism. If you have an unresolved privacy or data use concern that we have not addressed satisfactorily, please contact our U.S.-based third party dispute resolution provider (free of charge) at https://feedback-form.truste.com/watchdog/request.
If your complaint is not resolved through these channels, under certain conditions a binding arbitration option may be available before a Privacy Shield Panel. For additional information, please visit: https://www.privacyshield.gov/article?id=ANNEX-I-introduction.
We are subject to the investigatory and enforcement powers of the Federal Trade Commission with respect to Personal Data received or transferred pursuant to the Frameworks.
Links to Other Websites
Social Media Widgets
Do Not Track
Currently, various browsers - including Internet Explorer, Firefox, and Safari - offer a “do not track” or “DNT” option that relies on technology known as a DNT header, which sends a signal to the websites visited by the user about the user’s browsers DNT preference setting. CircleCI does not currently commit to responding to browser’s DNT preference across its Sites and Services, because no common industry standard for DNT has been adopted by industry groups, technology companies or regulators, including no consistent standard of interpreting user intent. CircleCI takes privacy and choices regarding privacy seriously and will make efforts to continue to monitor the development around DNT browser technology and the implementation of a standard for DNT.
We take precautions to ensure the security of your Personal Data. We follow generally accepted standards to protect the Personal Data submitted to us, both during transmission and once we receive it. When you enter your login information on the Service, all information to and from the service is encrypted using Transport Layer Security (TLS). For more information on our data security policies, please check here.
That said, like any hosted service provider, we cannot guarantee that unauthorized third parties or unauthorized personnel will not gain access to your Personal Data despite our efforts. You should note that in using the Website and the Service, your information will travel through third-party infrastructures which are not under our control.
If you have any questions about security on the Website or the Service, you can contact us.
Circle Internet Services, Inc.
201 Spear Street, Ste 1200
San Francisco, CA, 94105