CircleCI

circleci.com · facts updated 2 weeks ago

Privacy facts at a glance
Jurisdictions
US · EU · UK
Retention
No specific data retention period is stated in the excerpted documents.
Breach notification
The trust center lists 'Data Breach Notifications' as a topic but no specific notification SLA is stated in the excerpted documents.
Transfer mechanism
EU-US Data Privacy Framework, UK Extension to EU-US DPF, and Swiss-US Data Privacy Framework
DPA available
Yes
Certifications
SOC 2 Type II · FedRAMP Tailored LI-SaaS · CSA STAR Level 1 · EU-US DPF · Swiss-US DPF · UK Extension to EU-US DPF · CSA AI Trustworthy Pledge 2025
GDPR addressed
Yes
CCPA addressed
Yes

Tracked documents

Privacy policy
https://circleci.com/legal/privacy/ checked 8 hours ago
Terms of service
https://circleci.com/legal/terms-of-use/ checked 6 hours ago
Security / trust page
https://circleci.com/security/ checked 6 hours ago

Recent changes

major Subprocessor list 2 weeks ago

CircleCI replaced the 'CSA STAR for AI' certification with the 'CSA AI Trustworthy Pledge 2025' on its subprocessor/security documentation.

major Privacy policy 2 weeks ago

CircleCI replaced its March 27, 2025 privacy policy with a May 31, 2026 version that restructures data categories, removes explicit references to financial data (credit card, billing/shipping address), protected classification data (age, gender), and commercial/professional data categories, while adding new specific data elements including browser fingerprints, sign-on tokens, and audit log entries.

Subprocessor list 3 weeks ago

Document updated.

Subprocessor list 3 weeks ago

Document updated.

minor Subprocessor list 1 month ago

CircleCI's subprocessor list replaced the 'CircleCI Trust Center Sub-processor Update' and 'CircleCI Trust Center' entries with a single consolidated 'CircleCI Trust Center CircleCI Trust Center' entry, reflecting a structural reorganization of the listing rather than a substantive change in subprocessors.

major Subprocessor list 1 month ago

CircleCI has updated its sub-processor list, with the specific changes available at https://trust.circleci.com, but the diff does not detail which sub-processors were added or removed.

minor Security / trust page 1 month ago

CircleCI added a 'Startup program' entry to their security/trust page.

moderate Terms of service 1 month ago

CircleCI added a 'Startup program' section to its Terms of Service.

Public summary; per-account review history visible to subscribers tracking this vendor.

Track CircleCI in your workspace.

Get notified when CircleCI adds a subprocessor, changes retention, updates their DPA, or quietly amends their privacy posture.

Start tracking — 14-day trial
No card required.