Sirca handles company knowledge, so privacy and access control are part of the product—not an afterthought. This policy explains what we process, why, who receives it, and the choices available to customers and individuals.
1. Who we are and when this policy applies
Sirca Ltd ("Sirca", "we", "us") provides company context infrastructure through Sirca. You can contact us at info@sirca.io.
This policy applies to our website, application, APIs, support, and related services. It explains our handling of personal data under applicable privacy law, including the UK GDPR and Data Protection Act 2018.
For account, billing, security, support, and product-usage data, Sirca normally acts as a controller. For content that a customer connects to or uploads into a Sirca workspace, the customer normally determines why that content is processed and Sirca acts as its processor.
2. Data we process
Depending on how Sirca is used, we process:
- account and contact details, including name, work email, organisation, authentication identifiers, and membership;
- billing and subscription records. Stripe handles full payment-card details; Sirca receives payment status, customer, subscription, invoice, and usage-billing information;
- customer source content, such as documents, messages, issues, pages, comments, database records, metadata, links, user references, and source permissions;
- queries, answers, citations, entities, relationships, embeddings, evaluations, and other results created to provide the service;
- integration details, encrypted OAuth credentials, API-key records, provider configuration, sync state, and permission metadata;
- technical, security, and usage information, including IP address, device and browser data, request logs, audit events, error records, token usage, and model cost.
Please do not connect data that you are not authorised to process or make available to the users of your workspace.
3. Why we use data
We use data to provide and secure Sirca; authenticate users; connect and synchronise authorised sources; preserve source permissions; generate cited answers and knowledge-graph results; operate billing; provide support; detect abuse; monitor reliability; meet legal obligations; and improve the service.
Where Sirca is the controller, our legal bases are generally performance of a contract, our legitimate interests in operating and protecting the service, compliance with law, and consent where the law requires it. A customer using Sirca is responsible for establishing its own legal basis and giving required notices for the source content it directs us to process.
We do not sell personal data and do not use customer source content for third-party advertising.
4. AI processing and customer choice
Sirca may send relevant source content and instructions to an AI provider to perform extraction, evaluation, retrieval, or answer generation. The provider depends on the workspace configuration. Managed processing may use OpenRouter and models made available through it; a customer may instead configure a supported customer key or endpoint.
We limit the submitted data to what is needed for the requested processing. A customer should review its selected provider and model, including that provider's location, retention, and training terms, before using it with sensitive data.
5. Service providers and integrations
We use service providers to operate Sirca. Depending on the feature and deployment, these include Vercel for the web application and analytics, Railway for application hosting, Supabase for authentication, database, and content storage, Neo4j for graph storage, Stripe for billing, Resend for transactional email, and OpenRouter or another configured AI provider for model access.
When a customer connects a third-party source—such as Atlassian, Google, GitHub, or Slack—we exchange data with that provider at the customer's request and under the permissions granted during connection. We may also disclose data to professional advisers, a buyer in a corporate transaction, or an authority where required by law.
Providers may process data outside the United Kingdom. Where required, we use an appropriate transfer mechanism, such as an adequacy decision or contractual safeguards.
6. Security and access
Sirca uses technical and organisational measures designed to protect data, including encrypted transport, encryption of stored source credentials, tenant-scoped access controls, source-aware permissions, least-privilege service access, audit records, and restricted production secrets.
No internet service is completely secure. Customers are responsible for protecting their credentials, controlling workspace membership, choosing suitable source permissions, and promptly reporting suspected misuse to us.
7. Retention and deletion
We retain account, contract, billing, security, and audit records for as long as needed to provide the service, resolve disputes, prevent abuse, and meet legal or accounting requirements. Customer source content is retained while needed to operate the workspace or until it is deleted under customer instructions, subject to backups and legal obligations.
Disconnecting a source removes its stored access credentials. Where provider rules require more, we also erase affected cached data. For Jira and Confluence, Sirca reports stored Atlassian user references through Atlassian's Personal Data Reporting API and erases or refreshes affected copies when Atlassian returns a closed or updated account status. Atlassian source content is also scheduled for erasure when that source is disconnected.
Deletion from backups may occur on the backup lifecycle rather than immediately. We may retain minimal records where necessary to demonstrate compliance, prevent fraud, or establish or defend legal claims.
8. Your rights
Depending on your location, you may have rights to access, correct, erase, restrict, object to, or receive a portable copy of personal data, and to withdraw consent where processing relies on consent.
If your data appears in a workspace operated by your employer or another Sirca customer, contact that organisation first because it controls that source content. You can also email info@sirca.io. We may need to verify your identity and may retain information where the law permits or requires it.
You may complain to the UK Information Commissioner's Office or your local data protection authority. We would appreciate the opportunity to address your concern first.
9. Cookies, children, and changes
Sirca uses necessary storage and cookies for authentication, security, and service operation, and may use limited product analytics. Browser controls can restrict cookies, but necessary features may then stop working.
Sirca is a business service and is not directed to children. Do not submit children's personal data unless your organisation has a lawful, appropriate reason and authorisation to do so.
We may update this policy as Sirca or the law changes. We will publish the current version here and update the date above. If a change materially affects how we use data, we will provide additional notice where appropriate.