Privacy Policy
Last updated: September 7, 2026
1. Introduction
The privacy of our users and of the people whose data they share is of utmost importance to us. This platform (the "Platform" or "Circli") is operated by Circli Servicios Tech S.A.S., a company duly registered with the Public Registry of the Province of Mendoza under File N° eSAS-000542, with registered office in the City of Mendoza, Argentina. This Privacy Policy describes what personal data we process, for what purposes, with whom we share it, and what rights you have over your information, in accordance with Argentine Law 25,326 on Personal Data Protection and other applicable legislation. By using the Platform, you accept the practices described in this policy.
2. Roles and responsibilities
Circli may act as either a controller or a processor of your personal data, depending on the context: (a) When you create an account directly at circli.app, browse the site, or contact us, Circli is the controller of that data. (b) When you use Circli as part of an event organized by a third party (such as a fair, congress or conference), the event organizer is the controller of the data generated within that event, and Circli acts as a processor on behalf of the organizer. In these cases: • The organizer defines the purposes of the processing within the event. • Circli processes the data following the organizer's documented instructions, under a Data Processing Agreement signed with each organizer. • To exercise your rights regarding event-generated data, your first point of contact is the event organizer. Circli cooperates with the organizer to respond to your request. • The organizer maintains its own privacy notice describing the event-specific uses. We recommend you read it. (c) For aggregated and anonymous technical data (usage metrics, fraud prevention), Circli maintains its own responsibility for limited purposes related to operating the Platform securely.
3. Limitation of liability for organizer's uses
When Circli acts as a processor on behalf of an event organizer, Circli is not liable for: • The organizer's use of the data outside the Circli Platform (e.g., exports, post-event communications, organizer's own integrations). • Obtaining the data subject's consent for purposes the organizer defines on its own. • Leaks, unauthorized access or improper uses of the data occurring in the organizer's infrastructure, devices or processes, or in those of third parties contracted by the organizer. • Compliance with laws applicable to the organizer in its own jurisdiction and regarding its own uses. This limitation does not apply when the incident occurs within Circli's infrastructure or results from Circli's failure to follow the organizer's documented instructions.
4. Personal data we collect
We collect only the personal data necessary to provide the service, in the following categories: • Account data: mobile phone number (used for WhatsApp authentication and interaction), name or alias, and optionally email. • Event data (when you use Circli as part of an event): name, company, professional role or category, optional profile photo, connections generated with other attendees, and activity records within the event. • Contact data voluntarily shared by you: name and phone number of third parties you choose to add to your circle on the Platform. • Community participation data (Circli Networks): your network profile, the answers you give in the membership application form, what you post in the feed and in comments, and — if the network runs courses — your progress, your quiz answers and their result, your private study notes, any certificates you earn and the participation points you accumulate. • Membership payment data: when a network charges for membership, the payment is processed by Mercado Pago. Your card or bank account details are received and stored by Mercado Pago, not by Circli. On our side we only keep the record of the transaction: the payment reference, the amounts and the date. • Browser notification data: if you turn on web notifications, we store the delivery address issued by your browser, the two keys used to encrypt the notification body, the device type and a truncated version of your user-agent so we can diagnose a delivery failure. We delete that address when you turn notifications off from your profile, when your browser's push service tells us it is no longer valid, and when your account is deleted. • Approximate location data, only in an event's game activity: when you scan an exhibitor stand's code we may record the location reported by your device and behavioural signals about the scan. This is used exclusively to detect cheating in the game; we do not build any profile of you from it, nor use it for advertising. • Technical data: IP address and user-agent. In consent records and agreement acceptances we always store them as a salted hash, never in plaintext. In security, administrative-access audit and fraud-prevention logs we may keep them in the clear for as long as that purpose requires. In the measurement of our own website we store the country inferred from the IP and the user-agent, plus an identifier derived from both that does not allow the original IP to be recovered. • Cookies and similar technologies: see dedicated section below.
5. Purpose and use of data
We use the personal data collected for the following purposes: • Service provision: enabling you to create your circle, manage your contacts and participate in events using the Platform. • Operating events for organizers who contract the Platform, always in accordance with the organizer's documented instructions. • Operating communities for network owners who contract the Platform: administering your membership, showing your profile to other members according to what you choose to share, moderating content, running courses and issuing certificates, and — where the network charges — handling membership billing. • Security and fraud prevention: detecting abusive uses, protecting service integrity and detecting cheating in an event's game activities. • Service communications: operational notifications, technical support, notices about changes to this policy or terms. Depending on the event or network, these may reach you via WhatsApp, email or browser notification. You can opt out of each channel separately, as explained in the notifications section. • Compliance with legal obligations: responding to requirements from competent authorities or fulfilling applicable regulations. • Aggregated and anonymous product improvement: statistical analysis that does not allow identification of individual users. • Measuring our acquisition campaigns, only on our website and on free-plan events: we share pseudonymized identifiers with Meta and Google to learn which ads work. If you register for a free-plan event, this purpose is disclosed to you and you accept it on the registration form. On paid-plan events we run no measurement of our own on attendees. We do not use your data for our own commercial purposes other than the above. We do not sell, lease or transfer your data to third parties.
6. Processors and sub-processors
To operate the Platform we work with the following providers. Each processes data in a specific role and for a specific purpose, under agreements imposing confidentiality, security and purpose-limitation obligations. Processors (they process data on our behalf and on our instructions): • Meta Platforms, Inc. (WhatsApp Business Cloud API) — messaging with users — United States. • Vercel, Inc. — application hosting and storage of files uploaded to the Platform (profile photos, decks, logos, community materials) — United States and São Paulo, Brazil. • Supabase, Inc. — database — São Paulo, Brazil. • OpenAI, L.L.C. — natural-language processing and audio transcription (bot assistance, profile and recommendation features), under business terms that do not allow model training on our data — United States. • Resend, Inc. and Google LLC (mail delivery) — delivery of Platform emails — United States. • Upstash, Inc. — rate limits and temporary verification codes — United States. • Functional Software, Inc. (Sentry) — application error logging — United States. • HubSpot, Inc. — business contact management (organizers and prospects, not attendees) — United States. • Google LLC (Google Wallet) — issuing the access pass, when the event enables it — United States. • Google LLC, Apple Inc., Mozilla Foundation and Microsoft Corporation (browser push services) — delivery of browser notifications to the device that enabled them. They only carry the notification: the content travels encrypted with your own browser's keys — United States. Independent controllers (they decide for themselves how they process what they receive): • Mercado Pago (Mercado Libre S.R.L.) — billing for community memberships. It receives and decides on your payment method data, which is not replicated in our systems; its own privacy policy applies. We do not determine the region in which it processes that data. • Google LLC (Google Analytics, Google Ads) — measurement of our site and campaigns — United States. • Meta Platforms, Inc. (Pixel, Conversions API) — measurement of our campaigns — United States. • Giphy, Inc. — GIF search; if you use the picker, your browser connects directly to their service — United States. The advertising measurement described above happens only on our website, subject to your cookie consent, and on free-plan events, subject to the acceptance you give when registering. The up-to-date list is available on the Sub-processors page.
7. Cookies and similar technologies
The Platform uses cookies and similar technologies in three categories: • Essential: necessary for site operation and session. They do not require your consent. • Analytics: help us understand how the site is used. If you visit from outside the European Economic Area, the United Kingdom or Switzerland they are on by default and you can reject them at any time from the cookie banner; inside those regions they only run after you accept. • Marketing: used to measure and optimize advertising campaigns. Same rule: on by default outside the European Economic Area, the United Kingdom and Switzerland, with an opt-out at any time from the banner; inside those regions only after you accept. How long they last. The essential cookies that keep you signed in (your account, the organizer panel, a network owner's panel) last seven (7) days from the moment you sign in; using the Platform does not extend that window. Those serving a single step — verifying your phone, completing a Google sign-in, confirming a second factor — live only as long as that step and are deleted when it ends. The cookie remembering your trusted device for two-factor authentication lasts seven (7) days. Your choice about analytics and marketing is not stored in a cookie but in your browser's local storage, and remains until you change it or clear the site's data. You can change your preferences at any time via the "Cookies" link in the footer.
8. Use of artificial intelligence
We use third-party artificial-intelligence services to process natural-language queries and categorize content from the bot. Data sent to these services is processed under enterprise/business terms that prohibit its use for model training. You may request human review of any automated response at any time by contacting us. Suggestions about who to connect with. When an event or a network enables networking suggestions, we send the artificial-intelligence provider only the professional fields of the profiles: role, company, category, what you are looking for, what you offer and — if you filled it in — your bio, all truncated. We never send your name, phone number, email address or photo: profiles travel numbered, not identified. So that we can review and improve the quality of those suggestions, we keep a copy of the queries sent to the model, pseudonymized before storage — people's identifiers are replaced by a pseudonym and the text is stripped of names, phone numbers, emails and web addresses. Those copies are deleted automatically after one year. The pseudonym is always computed the same way precisely so that, if you request erasure of your data, we can also find and delete the queries in which you appeared as a candidate. If your event enables filling your profile by voice, your recording is sent to that provider for the sole purpose of transcribing it and suggesting fields to you. Circli does not keep the audio once transcribed, and you can always type instead of recording.
9. Events as a special context
When an organizer contracts the Platform to run an event, certain visitor data is shared with that organizer (for example: name, company, professional category, connections generated during the event). The organizer is the controller of that data. Each event has its own complementary privacy notice with event-specific uses. We recommend you read it when you join an event. What else happens inside an event. If the event enables chat, you can message other attendees: those messages are not end-to-end encrypted, the organizing team does not read your private messages and only sees one if somebody reports it for moderation. If the event uses live activities (questions to the speaker, polls, word clouds), we store your answer linked to your account even when it is displayed on screen without your name. If there is QR check-in, your entry is recorded, with the time and who checked you in. And if the event runs a game activity with booth scanning, what the data-collection section says about the approximate location of the scan applies. Professional events with Exhibitors. When you take part in an event that features Exhibitors (for example, a fair with booths run by wineries, brands or companies) and you scan an Exhibitor's booth QR code, you authorize your contact and professional profile data (name, company, role, email, WhatsApp, scan history and any other data you have entered in your event profile) to be made available to the Event Organizer through the Organizer Panel. The Organizer is responsible for delivering that data to the Exhibitor whose booth you scanned, exclusively so that the Exhibitor may contact you commercially in relation to the interest you expressed. The onward delivery from the Organizer to the Exhibitor is governed by the contract between them: the Exhibitor becomes an independent controller for any subsequent processing, pursuant to Article 11 of Argentine Law 25,326. Circli does not deliver your data directly to Exhibitors. You retain at all times the rights of access, rectification, deletion, opposition and consent revocation, which you may exercise with the Event Organizer or, subsidiarily, with privacidad@circli.app.
10. Minimum age and responsible communication
The Platform is intended for individuals over eighteen (18) years of age. If you declare you are under 18, you cannot use it. When an event involves the promotion of alcoholic beverages, we apply the requirements of Argentine Law 24,788 on responsible communication, including age gates and applicable legal disclaimers.
11. Storage and international transfers
The Platform runs on international infrastructure providers, so your data is processed outside Argentina: • Database: hosted in São Paulo, Brazil. • Files you upload (profile photos, decks, logos, community materials): in our hosting provider's storage, which operates in the United States and São Paulo, Brazil. • Web and bot application: some functions run in São Paulo, Brazil, and the rest in our hosting provider's default region, in the United States. • Email, error logging, rate limiting, artificial intelligence and delivery of browser notifications: United States. • Billing for community memberships: processed by Mercado Pago, which decides for itself where and how it processes payment method data. We do not determine its processing region; if an international transfer is involved, the safeguards described below apply, along with its own privacy policy. • Content delivery network: global — public content may be served from the node closest to you. Neither Brazil nor the United States appears on the Argentine list of countries with an adequate level of protection. Accordingly, these international transfers are made under the safeguards provided by AAIP Disposition N° 60/2016 (model contractual clauses) and related regulations. We maintain agreements with each provider imposing confidentiality, security, purpose-limitation and return-or-destruction obligations. You can request the current detail of which service processes which data and in which region by writing to privacidad@circli.app. By using the Platform you expressly authorize this international transfer.
12. Data retention
We retain personal data only for the time necessary to fulfill the purposes described or as required by law. Typical periods: • Active account data: until you close your account. • Event data (activated profile): up to twenty-four (24) months post-event, with the organizer's authorization under art. 25 inc. 2 of Law 25,326. • Pre-registered users who did not activate a profile: deleted within seven (7) calendar days after the event closes, keeping only aggregate event figures. • Event chat messages: open-channel messages are deleted automatically after twelve (12) hours; direct messages after one hundred and eighty (180) days. • Community content (posts, comments, library, courses): kept for as long as the network exists, because it is the community's body of work rather than an operational log. You can delete your own posts and comments at any time; a library contribution you can withdraw while it is awaiting approval, and once published it is the network's council that takes it down. An erasure request covers all of it. • Notifications already delivered to your in-Platform inbox: thirty (30) days in events, ninety (90) days in communities. • Activity logs inside an event and support logs: ninety (90) days. • Pseudonymized copies of the queries sent to the artificial-intelligence model: one (1) year. • Browser notification subscription: for as long as you keep it active. It is deleted when you turn it off, when your browser revokes it and when your account is deleted. • Backups: kept for the retention window our database provider applies and continuously overwritten; deleted data may survive in them until the corresponding copy expires. • Records of consent and its withdrawal: kept for as long as they may be needed to evidence compliance and to defend against claims. After these periods, data is destroyed or irreversibly disassociated, except where legal obligations require its retention. What survives an erasure, and why. When we delete your personal data, some records are not deleted because they are evidence of something that happened rather than a description of you: invoices and payment receipts, which tax rules require us to keep for up to ten (10) years; audit logs of access and administrative actions; the record that an access pass was issued; and the record that a message was sent. None of those records is used to contact you again or to reconstruct your profile.
13. Your rights over your data
Under Argentine Law 25,326 you have the following rights over your personal data: • Access: request and receive information about the data we process. • Rectification: ask us to correct inaccurate or outdated data. • Erasure: ask for deletion of your data when applicable. • Objection: object to processing in certain circumstances. • Confidentiality: have your data treated with privacy. • Withdrawal of consent: withdraw your consent when it is the basis of processing. How to exercise them: • If your data was generated within an event operated on the Platform → contact the event organizer first; they are the controller of that data. Circli cooperates with the organizer. • If your data was generated inside a Circli Networks community → for the answers in your membership application the controller is the network owner; for your account and cross-cutting data, Circli. Write to us at privacidad@circli.app either way and we will route it. • If your data was generated by direct use of the landing or app outside an event — including creating an account with email and password or with your Google account → contact us at privacidad@circli.app. Statutory deadlines we observe (Law 25,326): access requests are answered within ten (10) calendar days of receipt; rectification, update or erasure requests are resolved within five (5) business days. Where your data was disclosed to a third party, we notify them of the rectification or erasure within the fifth business day. You also have the right to file complaints with the Agency for Access to Public Information (AAIP). If you reside in the European Union, you may exercise equivalent rights under the GDPR.
14. Data security
We implement reasonable technical and organizational measures in line with AAIP Resolution N° 47/2018 and industry best practices, including: • Encryption in transit (HTTPS/TLS) and at rest, as provided by our infrastructure providers. • Access controls with a second factor on the admin and organizer panels, and the principle of least privilege. • Salted hashing of IP and user-agent in consent records and agreement acceptances. • Backups managed by our database provider. • Confidentiality duties for personnel with access to personal data. In the event of a security incident affecting your personal data, we commit to notifying within seventy-two (72) hours of reasonable confirmation, in line with international best practices.
15. Registration and supervisory authority
We process our personal-data databases in accordance with AAIP regulations and are arranging their registration with the National Registry of Personal Data Bases. We will publish the registration number here once granted. The Agency for Access to Public Information (AAIP) is the body overseeing compliance with Law 25,326 in the Republic of Argentina. You have the right to file complaints with it.
16. Privacy in Circli Networks
If you participate in a private Circli Networks circle (a paid-membership community), these additional rules apply: • Dual controllership. The network owner is the controller of the data you complete in the application form (motives, context, answers to the questionnaire) — that data is visible to the network's council and is not exposed to the public. Circli is the controller for cross-cutting data (identity and sign-in credentials — your email, or your phone if you gave one —, payment data, audit logs, subscriptions) and acts as processor when operating the platform on the owner's behalf. • Visibility default: members-only. Your network profile (display name, photo, headline, bio) is visible only to active members of the same network, and only if you choose to appear in the directory. • Your contact details are published one by one, and only if you switch them on. There is a separate toggle for each channel: email, WhatsApp, LinkedIn, X, Instagram, Telegram, GitHub and website. In a community they all start off: a profile you never touched publishes no contact detail at all, not even to fellow members. If the network additionally restricts contact to internal messaging, that restriction adds to your choice and never overrides it: between the two, the more closed one always wins. • Confidentiality — Chatham House. Anything that circulates inside the network (posts, weekly brief, intro threads, concierge messages) you may use as information but may not attribute without permission. This is a community norm, not a legal obligation, but breaking it may lead to council sanctions. • Double-opt-in introductions. When you ask to be introduced to another member, we store the reason and context you write. Your contact details are not revealed until both parties have accepted. The network owner or council takes part in the approval and sees that request; a record of each introduction is retained in our systems for audit. This is separate from the directory: if you appear in the directory, other members can see your profile and contact you through the channels you have switched on. • Courses, assessments and certificates. If the network runs courses, we record your progress, your quiz answers and their result, and the practice steps you tick off. The network owner and council see aggregate figures for the course — how many people reached each lesson and how many finished it — not your individual result. Your study notes are private: no screen shows them to another member or to the owner. If you complete a course you can obtain a certificate with a verification page on the internet, reachable by anyone holding the link: the link is not guessable, and sharing it is your decision. • Participation and reputation. If the network enables them, you accumulate points, badges and participation levels derived from what you do inside the community, visible to other members and to the council. We do not use them outside the network or for advertising. • If you follow a network without being a member. Networks may have a public page where you leave your email — and, if you want, your WhatsApp — to receive updates. We use that data only to send you those updates and to know which link you arrived from; you can unsubscribe from any of those messages. • Paid membership. If the network charges, the payment is processed by Mercado Pago and your payment method data stays with Mercado Pago, not with Circli. The network owner sees the amount due to them, never your card details. • Community messages. A community's chat is not end-to-end encrypted and, unlike an event's chat, is not deleted automatically: it is kept for as long as the network exists. Do not use it for confidential information. • Deletion. You may request deletion of your network data by writing to privacidad@circli.app or through the request form on the site. We delete your profile, your posts and comments, your participation in intro threads, your notes and your course progress. Invoices and audit logs are retained as legally required (up to ten years). If you have an outstanding charge or an open dispute, deletion is deferred until it is resolved and we tell you so when we reply. Operational detail in the Circli Networks Member Handbook.
17. Notices and notifications
We contact you through three channels, and you can leave all three: • WhatsApp. The bot only replies when you write to it, apart from notices for the event you are taking part in. Reply STOP to stop receiving messages, or MUTE to pause them. Each event also has its own opt-out. • Email. All of our update emails carry an unsubscribe link and the standard header that lets you unsubscribe from your own mail program. Strictly operational emails — an access code, a payment confirmation, the reply to a request you made — have no opt-out, because they are part of the service you asked for. • Browser notifications. These are optional and start off: you only receive them if you enable them from your profile. You can turn them off there, and in that case we delete your device's delivery address. You can also revoke the permission from your browser settings: that stops delivery immediately, and we delete the address as soon as the push service tells us it is no longer valid. Opting out of a channel does not cancel your account or your membership, and does not remove your access to anything. If you want to stop receiving everything and also have your data deleted, that is an erasure request: use the request form or write to privacidad@circli.app.
18. Changes to this policy
This Policy may be updated to reflect regulatory changes, new functionality, or improvements in our practices. When changes are substantial, we will notify you through the usual channels (website, app, email or WhatsApp). The date of last update appears at the top of the document.
19. Contact
For inquiries, complaints or to exercise rights over your data, write to privacidad@circli.app. You may also reach us via the contact form on the site. Controller: Circli Servicios Tech S.A.S., City of Mendoza, Argentina.