Skip to main content
circus
    • Creator App
      The dedicated app for running a community
    • Creator Fund
      How we'll pay creators on Circus
    • Creator Guide
      Step-by-step guide to getting started
    • Advertise
      Reach engaged Circus communities
    • Advertiser Guide
      Ad formats, specs, and how placements work
    • Safety hub
      Our approach to trust and safety
    • Community Guidelines
      Rules for all communities
    • Content Guidelines
      What's allowed on Circus
    • Moderation
      How moderation works
    • Parents & Guardians
      A guide for families
    • Report Form
      Flag harmful content or accounts
    • Support Services
      Crisis and mental health support lines
    • Law Enforcement
      Legal data requests
    • What is Circus?
      How communities, creators, and the platform fit together
    • All guides
      Guides and resources
    • Creator Guide
      Get started as a creator
    • Posting Guide
      Post types, formats, and what works
    • Advertiser Guide
      Ad formats, specs, and brand-safe advertising
    • Manifesto
      Our principles and what we stand for
    • Policies
      Every Circus policy in one place
    • Contact
      Get in touch with the right team
    • Engineering Blog
      Engineering decisions and technical writing from the team
    • Support
      Help with your account, app, and questions
Download on the App Store Get it on Google Play
Creator AppAdvertisersSafetyGuidesSupport
Company
ManifestoPoliciesContact
Download Circus

Data Processing Agreement

Effective 1 January 2026 · Last updated 21 May 2026

Introduction

This Data Processing Agreement (“DPA”) forms part of the agreement between you, the creator (“Controller”), and Circus Corporation, a Delaware corporation (“Circus” or “Processor”), and supplements the Circus Terms of Service.

This DPA applies where Circus processes personal data on your behalf in connection with your use of the Circus platform — for example, where you use Circus tools to manage paid memberships, communicate with fans, or run events. It is required under Article 28 of the UK GDPR and EU GDPR.

When this DPA applies — This DPA applies to creators who are themselves data controllers under UK or EU GDPR (generally: creators based in or offering services to people in the UK, EEA, or Switzerland, or who process personal data of UK/EEA residents). If you are unsure whether this applies to you, consult a data protection adviser.

1. Definitions

In this DPA:

  • “Applicable Data Protection Law” means the UK GDPR, the EU GDPR (Regulation (EU) 2016/679), the UK Data Protection Act 2018, and any other applicable data protection legislation, as amended from time to time.
  • “Controller” has the meaning given in Applicable Data Protection Law — in this DPA, the Creator.
  • “Data Subject” means an identified or identifiable natural person whose personal data is processed under this DPA.
  • “Personal Data” has the meaning given in Applicable Data Protection Law.
  • “Processing” has the meaning given in Applicable Data Protection Law.
  • “Processor” means Circus Corporation, processing personal data on behalf of the Controller.
  • “Sub-processor” means any third party appointed by Circus to process personal data under this DPA.

2. Subject matter, nature, and purpose

Circus processes personal data on your behalf for the purpose of providing the Circus creator platform, including member management, direct messaging, community features, and related features you use as a creator.

The categories of personal data processed include: names, email addresses, profile information, payment metadata (not payment card numbers — these are processed solely by our payment processor), engagement data, and any other personal data that members provide when joining your community on Circus.

The processing will continue for the duration of your use of the Circus platform and for any retention period required by applicable law thereafter.

3. Controller’s obligations

You, as the Controller, warrant and undertake that:

  1. You have a lawful basis under Applicable Data Protection Law for the processing described in this DPA.
  2. You have provided data subjects with all required privacy notices regarding the processing of their personal data through Circus.
  3. Your instructions to Circus in relation to the processing of personal data comply with Applicable Data Protection Law.
  4. You will notify Circus promptly of any changes to your processing instructions that may affect Circus’s obligations under this DPA.

4. Processor’s obligations

Circus will, in its capacity as Processor:

  1. Process personal data only on your documented instructions, except where required to do so by applicable law (in which case Circus will inform you of that legal requirement before processing, unless prohibited from doing so by law).
  2. Ensure that persons authorized to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
  3. Implement appropriate technical and organizational security measures as described in Section 7 of this DPA.
  4. Respect the conditions for engaging sub-processors as described in Section 5.
  5. Assist you, insofar as reasonably possible, in responding to requests from data subjects exercising their rights under Applicable Data Protection Law.
  6. Assist you in ensuring compliance with your obligations under Articles 32–36 of the GDPR (security, breach notification, data protection impact assessments, prior consultation).
  7. At your choice, delete or return all personal data to you after the end of the provision of services, and delete existing copies unless applicable law requires storage.
  8. Make available to you all information necessary to demonstrate compliance with the obligations laid down in Article 28 of the GDPR.

5. Sub-processors

You authorize Circus to engage sub-processors to assist in the provision of the Circus platform. Circus maintains a list of its current sub-processors and will notify you of any intended changes by publishing an updated list at circus.app/data-processing-agreement at least 14 days before the change takes effect. You may object to any new sub-processor on reasonable grounds by notifying privacy@circus.app within 14 days.

Circus’s principal sub-processors as at the effective date of this DPA include cloud infrastructure providers, payment processors, and email delivery services. The full current list is available at privacy@circus.app on request.

Circus ensures that all sub-processors are bound by data processing terms no less protective than this DPA.

6. International transfers

Where personal data is transferred to a country outside the UK or EEA that does not benefit from an adequacy decision, Circus will ensure appropriate safeguards are in place in accordance with Applicable Data Protection Law, including (where applicable) the use of UK International Data Transfer Agreements or EU Standard Contractual Clauses.

7. Security

Circus implements and maintains appropriate technical and organizational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures include:

  • Encryption of personal data in transit (TLS 1.2 or higher) and at rest.
  • Access controls limiting access to personal data to authorized personnel on a need-to-know basis.
  • Regular security assessments and penetration testing.
  • Incident response procedures and breach notification processes.

8. Data breach notification

Circus will notify you without undue delay — and in any event within 72 hours of becoming aware — of any personal data breach affecting data processed under this DPA that is likely to result in a risk to the rights and freedoms of data subjects. Such notification will include, to the extent then known: the nature of the breach; the categories and approximate number of data subjects and records affected; the likely consequences; and the measures taken or proposed to address the breach.

9. Data subject rights

If Circus receives a request from a data subject exercising rights under Applicable Data Protection Law that relates to data processed on your behalf, Circus will promptly forward that request to you. Circus will assist you in fulfilling such requests insofar as technically possible and consistent with the nature of the processing.

10. Audit rights

You may, upon reasonable written notice and no more than once per calendar year, request an audit of Circus’s data processing activities covered by this DPA. Such audits shall be carried out at your expense, during normal business hours, and in a manner that does not unreasonably disrupt Circus’s operations. Circus may satisfy this obligation by providing you with a copy of a relevant third-party audit report or certification (such as ISO 27001 or SOC 2) in lieu of a direct audit.

11. Term and termination

This DPA is effective from the date you accepted Circus’s Terms of Service and remains in force for the duration of your use of the Circus creator platform. It terminates automatically on the termination of your Circus account. Upon termination, Circus will delete or return personal data as described in Section 4(g).

12. Governing law and jurisdiction

This DPA is governed by the laws of the State of Delaware, United States. Where UK GDPR or EU GDPR obligations apply, this DPA is intended to satisfy those requirements in addition to Delaware law. Any disputes arising under this DPA shall be subject to the exclusive jurisdiction of the courts of Delaware.

Contact

Questions regarding this DPA or data protection matters: privacy@circus.app


© 2026 Circus Corporation. All rights reserved. Proprietary and confidential.

Contents

  1. Introduction
  2. 1. Definitions
  3. 2. Subject matter, nature, and purpose
  4. 3. Controller’s obligations
  5. 4. Processor’s obligations
  6. 5. Sub-processors
  7. 6. International transfers
  8. 7. Security
  9. 8. Data breach notification
  10. 9. Data subject rights
  11. 10. Audit rights
  12. 11. Term and termination
  13. 12. Governing law and jurisdiction
  14. Contact
circus

The fan app — communities for creators, sports teams, and universities.

Download on the App Store Get it on Google Play
Company
  • Manifesto
  • Contact
  • Brand
  • Changelog
  • Engineering Blog
  • Careers
  • Status
Community
  • Creators
  • Advertisers
  • Guides
  • Support
  • Account Actions
  • Report a Bug
Safety
  • Safety Hub
  • Moderation
  • Parents & Guardians
  • Report Form
  • Community Guidelines
  • Content Guidelines
  • Age Verification
  • Prohibited Communities
  • Law Enforcement
  • Support Services
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Data Practices
  • Copyright Policy
  • Accessibility
  • Licenses
  • Security
  • Bug Bounty
  • Data Requests
  • Online Safety Act
  • Digital Services Act
  • COPPA
  • Advertising Policy
  • AI Policy
  • Anti-Spam Policy
  • Refund Policy
  • Data Processing Agreement

© 2026 Circus Corporation. All rights reserved.

Delaware, United States