Legal
Privacy Policy
How CircuIQ handles personal information across this website, the client portal, and consulting engagements.
Who we are
This website and the CircuIQ client portal are operated by Gestures Broadly LLC d/b/a CircuIQ, an Oklahoma limited liability company. In this policy, “we” and “us” mean that company. CircuIQ is a trading name; the contracting entity is Gestures Broadly LLC.
For customers with a signed Master Service Agreement, this policy is incorporated into that agreement by reference. Where it and your agreement conflict, your agreement governs.
What this policy covers
This policy covers three surfaces:
- This website — the public pages, the enquiry forms, and the chat widget.
- The client portal — the account you sign into, and the links we send you for intake, scheduling, proposals, reports, and sign-offs.
- Consulting engagements — the discovery, audit, and build work itself, including the calls we record with your knowledge.
What we collect
When you browse this website
Page views and a small number of interaction events, recorded by our own analytics running on our own servers. We do not use Google Analytics, advertising pixels, or any third-party tracker, and we do not sell or share browsing data with anyone.
Analytics uses a random session identifier stored in your browser’s sessionStorage, which your browser discards when you close the tab. Signing in sets cookies that are strictly necessary to keep you signed in. We set no advertising cookies.
We also record how you arrived — the site that linked to you and any campaign tags in the link you followed (utm_source and similar) — so we can tell which of our efforts actually reach people. This is stored against the session identifier, not against you, and is kept on our own servers. We record the referring site’s address and page, never its query string.
When you get in touch
What you give us: name, email address, phone number, company, and whatever you tell us about your business in a form, a chat, or a booking. If you book a call we also record the time you chose and your time zone.
During an engagement
- Answers to intake forms and questionnaires — process descriptions, tools you use, and where work gets stuck.
- Call recordings and transcripts, where a discovery or audit call is recorded. We tell you before recording. If you would rather we did not, say so and we will take notes instead.
- Documents you upload, and business profile details needed to set up the engagement.
- Where tax reporting requires it: your W-9 details, including a taxpayer identification number. TINs are encrypted in our database.
- Signature evidence for anything you e-sign — the typed signature, per-page initials, timestamp, IP address, and browser user agent. This exists so an executed agreement can be shown to be genuine, and is retained with the agreement.
If you connect QuickBooks
Only if you choose to. We receive an access token and the accounting data your connection scope permits. You can disconnect at any time from your account, which revokes our access.
Payments
Card and bank details go directly to Stripe. We receive a confirmation and a reference, not your card number.
Why we use it
- To answer your enquiry and schedule a call.
- To perform the engagement you have asked for, and to produce its deliverables.
- To operate your account, send the transactional email an engagement requires, and take payment.
- To keep an audit trail of approvals, signatures, and deliveries — for your protection and ours.
- To meet legal and tax obligations.
- To understand which pages of this website are useful, in aggregate.
We do not use your data to train machine-learning models for our own purposes, and we do not sell personal information.
On “aggregated data”. Your Master Service Agreement permits us to use anonymised, aggregated data. That means statistics that cannot identify you or your business — never your records, your documents, or your transcripts.
Who we share it with
We use the service providers below. Each receives only what it needs for its function, and each is bound to protect it. We do not share personal information with anyone else except where the law requires it, or where you ask us to.
| Provider | What it does | What it receives |
|---|---|---|
| Supabase | Application hosting, database, file storage, and authentication | Effectively all account and engagement data, including uploaded documents |
| Microsoft 365 | Transactional email — intake links, scheduling, proposals, reports | Recipient name and email address, and the contents of the message |
| Resend | Backup transactional email provider, used only if Microsoft 365 delivery is unavailable | Recipient name and email address, and the contents of the message |
| Stripe | Payment processing for fees and deposits | Payment details, submitted directly to Stripe. We never receive or store full card numbers. |
| Intuit (QuickBooks) | Accounting integration — only if you choose to connect it | The QuickBooks data your connection scope permits, plus the connection tokens |
| Tax1099 | TIN/EIN verification during onboarding, where required for tax reporting | Business legal name and taxpayer identification number |
| Anthropic and/or OpenAI | Optional analysis of audit-call material, where a frontier model is configured for an engagement | Call transcripts and engagement notes for the engagement being analysed |
What does not leave our own systems
Two things people usually assume are sent to a third party, and are not: call transcription and the default analysis of discovery calls both run on models hosted on our own infrastructure. Where an engagement is configured to use a frontier model for deeper audit analysis instead, that is listed in the table above and we will tell you.
How long we keep it
- Engagement data — for the duration of the engagement. After termination we make your data available for export for 30 days, after which we may delete it, as set out in your agreement.
- Signed agreements and their signature evidence — retained as business records for as long as they may be needed to establish or defend a legal claim. An executed agreement is never edited after the fact.
- Tax records — for the period the law requires.
- Website analytics — retained in aggregate.
How we protect it
- Traffic to and from this site and the portal is encrypted in transit.
- Taxpayer identification numbers are encrypted in the database.
- Client-facing pages — intake, scheduling, proposals, reports, sign-offs — are reached through single-purpose, unguessable links tied to one engagement, rather than pages anyone can browse to.
- Access to customer data is limited to those who need it to do the work.
- If we become aware of a breach affecting your data, we will notify you without unreasonable delay and in any event within 72 hours of discovery.
No system is perfectly secure, and we will not claim otherwise. What we commit to is the controls above and telling you promptly if something goes wrong.
Your choices and rights
You can ask us to give you a copy of the personal information we hold about you, correct it, delete it, or stop using it for a particular purpose. Email privacy@circuiq.com and we will respond within 30 days.
You can decline call recording, disconnect QuickBooks at any time, and unsubscribe from anything that is not transactional. Some requests we cannot fully honour — we cannot delete a signed agreement or a tax record we are required to keep — and we will tell you plainly when that is the case, and why.
California residents
You have the right to know what we collect and why, to request deletion, and to not be discriminated against for exercising either. We do not sell or share personal information as those terms are defined by the CCPA.
UK and EEA residents
Where the UK GDPR or EU GDPR applies, we rely on performance of a contract, our legitimate interest in operating and improving the service, and compliance with legal obligations. You have the right to access, rectification, erasure, restriction, portability, and objection, and the right to complain to your supervisory authority. Where we process personal data on your behalf as a processor, we will enter into a Data Processing Addendum on written request, as your agreement provides.
International transfers
We are based in the United States and our service providers store and process data in the United States. If you are outside the US, using the service involves transferring your information there.
Children
This is a service for businesses. It is not directed to children, and we do not knowingly collect information from anyone under 16. If you believe a child has given us information, contact us and we will delete it.
Contact
Privacy questions and requests: privacy@circuiq.com. Anything else about your engagement: reply to the person you have been dealing with, or use the contact page.
Gestures Broadly LLC d/b/a CircuIQ · an Oklahoma limited liability company
Changes to this policy
If we change this policy we will update the version and date at the top of the page. For changes that materially affect how we handle your information, we will tell customers directly rather than relying on you to notice.
- 1.1 — disclosed referrer and campaign-tag collection in section 3. Still first-party and cookieless; no new recipient of your data.
- 1.0 — first published version.