Last updated: 23 March 2026
Circuit (meetcircuit.com) is operated from London, UK. We provide attendance tracking infrastructure for recurring cultural events.
All production data is stored in London, UK (AWS eu-west-2) via Neon PostgreSQL.
Circuit and event organisers act as joint controllers under GDPR Article 26 for attendance data collected via check-in. Circuit provides the infrastructure (hardware and software). The organiser determines the purpose (attendance tracking for their events). Both parties’ decisions are necessary for the processing to occur. A joint controller agreement governs the allocation of responsibilities between Circuit and each organiser.
Circuit acts as Data Controller for guest profile data — the optional profile that guests may create to view their attendance history.
Cross-venue recognition (where your attendance is visible to multiple organisers) requires your separate, explicit consent. This consent is independent of your RSVP consent and can be withdrawn at any time.
Legal basis for processing: contract performance (organiser service), legitimate interest (service operation, security), and consent (marketing, profile features, cross-venue recognition, Who’s Here).
Collected by the organiser via Circuit:
Visit counts, streak calculations, core member status, and retention metrics — all computed from attendance records.
Production data is stored in the EU (London, UK).
US-based processors (Vercel, Stripe, Resend, Anthropic, Klaviyo) operate under Standard Contractual Clauses (SCCs) or equivalent safeguards.
We do not transfer data outside the EU/US corridor.
We do not use third-party tracking cookies. We do not use analytics cookies. We do not run advertising scripts.
Email tracking. Some emails sent through Circuit by organisers — for example event invitations or broadcasts to a list — include open and click tracking via our email provider so the organiser can tell what’s landing. Every such email carries a one-click unsubscribe link; using it removes you from that organiser’s future emails immediately. Tracking is per-organiser; some organisers do not send tracked emails at all.
Under the UK GDPR and EU GDPR, you have the right to:
This feature allows guests to make themselves visible to other attendees at a specific event.
Visibility is opt-in and lasts for 24 hours from the time of check-in. You can withdraw your visibility at any time.
Only your name and avatar (if set) are shown. Your email and attendance history are never visible to other guests.
Enterprise API responses can be configured to return hashed email addresses (SHA-256) instead of plaintext, providing an additional privacy layer.
Outbound webhooks are signed with a customer-provided secret for integrity verification.
All API access is logged in audit records, including the requesting IP address and API key identifier.
Circuit uses Anthropic (Claude) to provide natural language insight queries, recognition email composition, and report narration.
AI processing is scoped to the organiser’s own data. Guest information from other organisers is never included.
All queries, generated SQL, and AI responses are logged in Circuit’s database for audit and debugging purposes.
Anthropic processes data under their data processing terms. Data sent to Anthropic is not used to train their models.
Organisers are Data Controllers for the guest data they collect through Circuit.
Organisers must ensure they have a lawful basis for collecting guest email addresses and attendance data (typically: contract performance or legitimate interest).
Organisers should inform their guests that attendance is recorded via Circuit and direct them to this privacy policy.
If an organiser receives a data subject access request from a guest, Circuit will assist in fulfilling it.
Circuit is not directed at individuals under 16 years of age. We do not knowingly collect personal data from children.
We may update this policy. Material changes will be communicated via email to organisers and posted on this page at least 30 days before they take effect.
The “Last updated” date at the top of this page indicates when the policy was last revised.
Questions or requests? Contact privacy@meetcircuit.com
To lodge a complaint, contact the Information Commissioner’s Office (ICO) at ico.org.uk/make-a-complaint/