Legal
Where each question is answered
Four documents, each covering a different question. If you are running a vendor assessment, the fastest route is to send us your questionnaire rather than reconstructing the answers from these pages.
- Contract
- Negotiated
- Data residency
- Selectable
- Disclosure
- 1 business day
Definition
What legal documentation does CirculeID publish?
Four things: what governs use of the platform, what personal data is processed and on what basis, how customer data is secured and how to report a vulnerability, and the data processing terms that accompany a customer agreement. The signed agreement itself is the governing document.
Nothing on this website overrides what you signed. These pages exist so that a reviewer can understand our positions before the paper reaches them, which usually removes a negotiation cycle.
By role
Where to start
| If you are | Start with | Because it answers |
|---|---|---|
| Procurement or legal | Terms | What governs, what is negotiable, and the order of precedence |
| A security reviewer | Security | Access controls, disclosure policy and incident commitments |
| A data protection officer | Privacy | What is processed, on what basis, for how long, and by whom |
| An architect | Platform security | Tenancy isolation, key custody, residency and the exit path |
Documents
The four pages
Terms
What governs use of the platform, what the agreement covers, and the positions we hold consistently across contracts.
Privacy
What personal data is processed and why, retention, your rights, and why scanning a passport creates no profile.
Security and disclosure
How to report a vulnerability, what we commit to in response, and where our access to customer data exists.
Technical controls
Encryption, tenancy isolation, key custody, audit logging and data residency, in implementation detail.
Certifications
What we hold, the certifying body and scope for each, and how to request evidence.
Where data lives
Residency by region, support coverage and the contracting entity question.
Answers
Frequently asked questions
Which document should I read first?
It depends on your role. Procurement and legal start with terms, then the data processing terms inside the agreement. A security reviewer starts with the security page and the technical controls. A DPIA starts with privacy. Each is linked below with what it actually answers.
Is there a public terms of service?
No, and that is deliberate. CirculeID is sold under a negotiated master agreement, so the document you sign governs. Publishing a competing public set would create two documents that could disagree, and the signed one would prevail anyway.
Can we send our own vendor assessment questionnaire?
Yes, and we would prefer it. A completed questionnaire answering your specific controls is more useful to both sides than you inferring answers from a page written for a general audience. Send it through the procurement route on the contact page.
Next step
Send your questionnaire
A completed vendor assessment beats a page written for a general audience. Procurement enquiries reach us at ceo@fistasolutions.com.