This Data Protection Addendum applies to any processing of personal data DuoCircle performs on behalf of a Customer in connection with the DuoCircle Cloud Terms. Acceptance of the Cloud Terms incorporates this DPA by reference, and most customers do not need a counter-signed copy.
Bonterms publishes the v2.0 standard in three forms. We use the Attachment Version here because it attaches to the Main Agreement without a separate signature. Customers whose privacy program requires an executed document may request the Signable Version or the Cover Page Version, carrying the same DPA Details below, by emailing legal@duocircle.com.
DPA Details
Key Terms
| Field | Value |
|---|---|
| Main Agreement | The DuoCircle Cloud Terms, or the Order or Cover Page that incorporates them for Customer’s account |
| DPA Effective Date | The date Customer first accepted the Main Agreement |
| Subprocessor List | /legal/subprocessors/, with email notice to the technical contact on the account at least thirty days before a new subprocessor begins processing personal data |
| Designated EU Governing Law | Republic of Ireland |
| Designated EU Member State | Republic of Ireland |
Processing Details
| Item | Description |
|---|---|
| Customer (data exporter) | The legal entity on the account, acting as controller. Data protection contact: the contact designated on Customer’s account, or, if not designated, Customer’s billing contact |
| Provider (data importer) | DuoCircle LLC, 5965 Village Way, Suite 105-234, San Diego, CA 92130, United States, acting as processor. Data protection contact: legal@duocircle.com |
| Categories of data subjects | Customer’s employees, contractors, alumni, students, customers, vendors, and any other party who sends or receives email through Customer’s mail flow |
| Categories of customer personal data | Email envelope and header data including sender, recipient, subject, and routing information; message bodies and attachments where the service requires content inspection; account holder names, business email addresses, and authentication credentials; usage logs |
| Sensitive or special categories of personal data | None expected. Customer must not route data covered by HIPAA, PCI DSS Level 1 cardholder data, or comparable special-category regimes through services not specifically provisioned for that data class. Contact legal@duocircle.com before doing so. |
| Frequency of transfer | Continuous, for the duration of the Main Agreement |
| Nature of the processing | Receiving, scanning, filtering, authenticating, queuing, forwarding, archiving, and reporting on email and email metadata under Customer’s control, and providing related dashboards, alerts, and APIs |
| Purpose of the processing | Provision of email security, authentication, deliverability, and routing services as set out in the Cloud Terms |
| Duration of processing and retention | The term of the Main Agreement plus any retention period required by law or configured by Customer for archiving and reporting |
| Transfers to subprocessors | To the subprocessors listed at /legal/subprocessors/, for the purposes stated there, for the duration of the Main Agreement |
| Competent EU supervisory authority | The Data Protection Commission of Ireland |
Security Measures
These are the technical and organizational measures required by the DPA Details. DuoCircle maintains an information security program aligned to the AICPA Trust Services Criteria for Security, Availability, Confidentiality, and Processing Integrity. SOC 2 Type II audits are performed annually by an independent CPA firm. Current controls are summarized at /legal/security/ and include:
- Encryption in transit using TLS 1.2 or higher for all customer-facing endpoints, and encryption at rest for databases, object storage, and backups using industry-standard ciphers
- Multi-factor authentication required for all production system access and for all administrative interfaces
- Role-based access controls with least-privilege defaults; quarterly access reviews
- Centralized logging, real-time alerting, and 24x7 on-call rotation
- Vulnerability scanning, dependency monitoring, and timely patching
- Independent penetration testing on a regular cadence
- Documented incident response procedures with named breach-notification responsibilities
- Background checks for employees with access to customer data, where permitted by law
- Mandatory annual security training for all personnel
- Vendor security review for any subprocessor with access to customer data
A current SOC 2 Type II report is available under NDA on request to legal@duocircle.com. The Bonterms Mutual NDA is published at /legal/mutual-nda/ for prospects who want to review the form before requesting the report.
Exhibit A – Cross-Border Transfer Mechanisms
For transfers of personal data out of the EEA, the United Kingdom, and Switzerland to a third country that has not received an adequacy decision, the parties agree that the EU Commission Standard Contractual Clauses (Module Two, Controller to Processor) apply, with the United Kingdom Addendum where applicable and the Swiss Federal Data Protection Authority’s amendments where applicable. The optional clauses are deemed selected as follows:
- Module: Two (Controller to Processor)
- Docking clause: Selected
- Subprocessor authorization: Option Two, general written authorization, with the notice period and process set out above
- Audit clause: As set out in the Security Measures above and Section 9 (Audits) of the Bonterms DPA
- Governing law of the SCCs: Republic of Ireland
- Forum for SCC disputes: Republic of Ireland
For onward transfers to subprocessors located in third countries, DuoCircle imposes equivalent terms via written agreement. Current subprocessors and their locations are listed at /legal/subprocessors/.
Exhibit B – Region-Specific Terms
Region-specific terms apply automatically to the extent the relevant data protection law governs Customer’s processing. This includes the UK GDPR for United Kingdom data subjects, the Swiss FADP for Swiss data subjects, the LGPD for Brazilian data subjects, the PIPL for People’s Republic of China data subjects, and the CCPA and CPRA for California consumers. Version 2.0 of the standard extends the same structure to other United States state privacy laws as they take effect. The Bonterms DPA Exhibit B region-specific terms are incorporated as published.
Additional Terms
The Bonterms DPA governs except as expressly stated in the DPA Details, the Security Measures, and the cross-border transfer mechanism designations above. There are no other modifications.
Earlier versions
This DPA was previously published on the Bonterms DPA Version 1.0 standard, which organized the same content as a DPA Setup Page and Schedules 1 through 4. Version 2.0 folds that content into a single DPA Details section with Exhibit A and Exhibit B, and it attaches to any main agreement rather than only to the Bonterms Cloud Terms. The commitments have not changed; the thirty-day subprocessor notice we have always given is now the standard’s own default.
Documents previously published as the DuoCircle Data Processing Agreement, the DuoCircle GDPR Privacy Policy, the DuoCircle Privacy Framework, and the DuoCircle Data Deletion Request page are superseded by this DPA together with the Privacy Notice and the Security Statement.
Questions about this document?
DuoCircle LLC, 5965 Village Way, Suite 105-234, San Diego, CA 92130. Email legal@duocircle.com for legal inquiries, or support@duocircle.com for everything else.