Data Processing Agreement
This Data Processing Agreement (DPA) applies to Chaos Circle's processing of personal data on behalf of customers who are subject to GDPR or other data protection regulations that require a DPA.
Scope
This DPA applies when Chaos Circle processes personal data as a data processor on behalf of a customer acting as a data controller, in connection with the Chaos Circle platform and services.
Processing Activities
Chaos Circle processes personal data for the purpose of providing the execution intelligence platform, including storing assessment responses, generating AI-powered insights, and managing user accounts and organizations.
Security Measures
Chaos Circle implements AES-256 encryption, role-based access control, multi-factor authentication, audit logging, and SOC 2 Lite compliant security practices to protect personal data.
Sub-processors
We use approved sub-processors including Neon (database), OpenAI (AI processing), Stripe (payments), Resend (email), and WorkOS (SSO). A complete list is available on request.