CircuitSync
Log in Create an Account

Data Processing Agreement

Last updated 30 June 2026 · Version 2026-06-30

This Data Processing Agreement ("DPA") forms part of the agreement between the club or organisation using CircuitSync (the "Controller", "you") and HARMN LLC, 7901 4th St N STE 300, Saint Petersburg, FL 33702 (the "Processor", "we", "us"), operator of the CircuitSync service at circuitsync.app. It governs our processing of personal data on your behalf under Article 28 of the EU General Data Protection Regulation (GDPR) and the equivalent UK GDPR.

Where you enter or manage the personal data of your members and drivers in CircuitSync, you are the controller of that data and we are your processor. For personal data relating to your own account and billing, we act as an independent controller under our Privacy Policy.

1. Subject matter and duration

We process personal data only to provide the CircuitSync live event-timing and club-management service for the duration of your subscription, plus any retention grace period described in our Terms of Service, after which the data is deleted or returned as set out below.

2. Nature and purpose of processing

Hosting, storing, synchronising (including offline synchronisation), displaying, and emailing the personal data you enter, so that you can register drivers, run events, time runs, publish results, and communicate with participants.

3. Categories of data subjects and personal data

  • Data subjects — your club administrators, staff, and drivers/participants.
  • Personal data — names, usernames, email addresses, phone numbers, club roles, car details and numbers, event registrations, run times and results, marketing preferences, and any notes you record about a driver.

We do not require special-category data. Please do not enter health, biometric, or other special-category data into free-text fields.

4. Our obligations as processor

  • Instructions — we process the data only on your documented instructions, which include your use of the service's features, unless required otherwise by law (in which case we will inform you where permitted).
  • Confidentiality — personnel authorised to process the data are bound by confidentiality.
  • Security — we implement appropriate technical and organisational measures (Article 32), including encryption in transit, access controls and tenant isolation (row-level security), authentication with optional two-factor, and least-privilege access to production data. See Annex 1.
  • Assisting you — taking into account the nature of the processing, we assist you in responding to data-subject requests and in meeting your security, breach-notification, and impact-assessment obligations. The service provides self-serve data export and an erasure-request path (see Annex 2).
  • Breach notification — we will notify you without undue delay after becoming aware of a personal-data breach affecting your data.
  • Deletion or return — on termination, we delete or return the personal data (at your choice) after the retention grace period, unless retention is required by law.
  • Audits — we make available the information necessary to demonstrate compliance with Article 28 and allow for and contribute to reasonable audits.

5. Sub-processors

You authorise us to engage the sub-processors listed below to provide the service. We impose data-protection terms on each that are no less protective than this DPA, and we remain responsible for their performance. We will give you reasonable notice of any intended change so you may object.

Sub-processorPurposeLocation
CloudflareWeb app hosting and content deliveryGlobal edge network
SupabaseAuthentication, database, and file storageUnited States
PowerSyncReal-time data synchronisation for offline useUnited States
ResendTransactional and notification emailUnited States
StripeSubscription billing and paymentsUnited States
PostHogProduct analytics (only with end-user consent)European Union

6. International transfers

CircuitSync is operated by HARMN LLC, a United States company, and personal data is primarily stored and processed in the United States. Where personal data of UK or EEA data subjects is transferred outside the UK/EEA, the transfer is made under appropriate safeguards, including the Standard Contractual Clauses and each sub-processor's data-processing terms.

7. Liability and precedence

This DPA is incorporated into and subject to the Terms of Service. In the event of a conflict between this DPA and the Terms on the subject of data protection, this DPA prevails.

Annex 1 — Technical and organisational measures

  • Encryption of data in transit (HTTPS/TLS).
  • Tenant isolation and access control via database row-level security.
  • Authentication with hashed credentials and optional two-factor authentication.
  • Least-privilege access to production systems and audit logging of sensitive actions.
  • Suppression of emails to addresses that have bounced or complained.

Annex 2 — Data-subject request assistance

  • Access and portability — account holders can download a machine-readable copy of their personal data from their account settings.
  • Erasure — account holders can request erasure from their account settings; driver records are irreversibly anonymized so that event results remain accurate while personal identifiers are removed.
  • Rectification — account holders and club staff can correct records directly in the service.

Contact

To request a signed copy of this DPA, add sub-processor notifications, or raise a data-protection matter, contact support@circuitsync.app.

CircuitSync

Live timing for autocross and track events.

Product Features Offline Pricing Roadmap
Account Create an account Log in Help center Contact
Legal Privacy Policy Terms of Service Cookie Notice Data Processing Agreement
© CircuitSync. All rights reserved. Built for motorsport clubs.