Established since 2023 · Early Member window open until 31 August. See what's included →

Global Mobility Circle

Circle Privacy Notice

Effective date: 5 June 2026

This Privacy Notice explains how Sovium Ltd (registered in England and Wales as SOVIUM LTD, company number 16837739, registered office Bmlg.02, 10 Barley Mow Passage, London, England, W4 4PH) ("Sovium", "we", "us", "our"), trading as Global Mobility Circle ("Circle"), collects and uses personal data when you interact with our website, the Circle Deals platform, our application and verification flows, and related services (the "Platform").

We are the controller of the personal data described in this Privacy Notice.

Contact (including privacy requests): membership@globalmobilitycircle.com

This Privacy Notice is intended for business users (Providers and Agents). Even where you act on behalf of a company, we may process personal data about you as an individual (for example, your name, work email, role, and verification information).


1. Key definitions

  • Personal data means information relating to an identified or identifiable individual.
  • Controller means the organisation that determines how and why personal data is processed. For the processing described here, we act as controller.

2. Personal data we collect

Depending on how you engage with Circle, we may collect:

2.1 Application and account data — name, email, phone number, messaging handles (for example, Telegram username, where provided), company name, website, role or title, jurisdictions or areas of interest, login and account settings, and communications with us.

2.2 Verification and due diligence data — information you provide in the verification questionnaire (professional background, service lines, jurisdictions, and supporting details); documents you upload (for example, company registration certificates or evidence of professional standing); the result of identity verification (see section 6); and information from publicly available sources (OSINT) used for verification, such as company websites, professional profiles, public registers, and reputable public sources.

2.3 Participation and operational data — Requests, Offers, Deals, Testimonials, and related metadata; introductions and request routing information; event participation; and internal moderation and standards records (for example, eligibility outcomes and compliance flags). We aim to minimise the collection of end-client data.

2.4 Technical data — device and log data (for example, IP address, browser type, and basic usage information), and cookie and similar-technology data as described in our Cookie Policy.

2.5 Payments and billing data (paid members) — payment status, invoices, billing contact details, and transaction references. Payment-card details are processed by our payment provider (Stripe). We do not receive or store full payment-card numbers.

Please avoid sharing unnecessary sensitive information (for example, health data) or extensive end-client data via forms or messages unless specifically requested and appropriate.


3. How we use personal data, and our lawful bases

Under UK GDPR we must have a lawful basis to process personal data. We process personal data for the following purposes:

3.1 To review applications and manage admissions. Assessing applications, conducting verification and due-diligence checks, requesting supporting information, making admission decisions, and onboarding. Lawful basis: legitimate interests (Art. 6(1)(f)) in running a vetted professional network and protecting its integrity; and/or steps to enter into a contract (Art. 6(1)(b)).

3.2 To deliver and operate Circle services. Providing access to the Platform and Circle Channels, enabling Requests, Offers, Deals, and communications, managing events, and maintaining internal records. Lawful basis: contract (Art. 6(1)(b)) and legitimate interests (Art. 6(1)(f)).

3.3 To ensure standards, safety, and compliance. Moderation, enforcing the Terms, preventing misuse, responding to complaints, security monitoring, and sanctions/AML/anti-bribery risk management. Lawful basis: legitimate interests (Art. 6(1)(f)) and legal obligation (Art. 6(1)(c)) where applicable.

3.4 To process payments and administer subscriptions. Billing, invoicing, payment processing, accounting, and fraud prevention. Lawful basis: contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)).

3.5 To communicate with you. Service communications (admissions, verification, support), operational notices, and policy updates. Lawful basis: contract (Art. 6(1)(b)) and legitimate interests (Art. 6(1)(f)).

3.6 Marketing communications. We may send limited business-to-business communications about Circle (for example, updates and events) where lawful. Lawful basis: legitimate interests (Art. 6(1)(f)) and/or consent (Art. 6(1)(a)) where required. You can opt out at any time.

3.7 Website analytics and improvement. Understanding website performance and improving the Platform. Lawful basis: consent where required for any non-essential cookies; legitimate interests for privacy-friendly, aggregated analytics and for security logging. See our Cookie Policy.


4. Special category and criminal offence data

We do not routinely intend to collect special category data (for example, health data or political opinions) or criminal-offence data. If such data is provided voluntarily, or becomes necessary in exceptional circumstances, we will handle it with additional safeguards and only where we have a lawful condition to do so. If, in future, we introduce sanctions or other screening that processes such data, we will update this Privacy Notice and put the required safeguards in place.


5. Identity verification

5.1 We use Stripe Identity to verify the identity of applicants. As part of that process, Stripe checks an identity document and may carry out a selfie and liveness check.

5.2 The document check, selfie, and liveness check are performed by Stripe under its own terms. We receive only the verification result and the identity details extracted from your document (such as name, date of birth, and document type and number). We do not receive or store the selfie, the liveness images, or any biometric data.

5.3 Lawful basis: legitimate interests (Art. 6(1)(f)) in operating a vetted network and preventing fraud and impersonation, and/or steps to enter into a contract (Art. 6(1)(b)).


6. Who we share personal data with

6.1 Service providers (processors) who help us operate Circle and the Platform, including:

  • Hosting and platform infrastructure: Vercel (website and application hosting, and privacy-friendly analytics).
  • Database and document storage: Supabase.
  • Payments and identity verification: Stripe.
  • Transactional email: Resend.
  • Email and productivity: Google Workspace.
  • Video calls and events: Zoom; Google Meet.
  • Messaging: Telegram; WhatsApp (used for communications with applicants and participants).
  • Advertising measurement: Meta Platforms Ireland Ltd (Meta Pixel — set only where you have consented via our cookie banner).

These providers process personal data under our instructions and appropriate contractual protections, except that messaging services (Telegram and WhatsApp) are third-party communication services that may process your data under their own terms; where you communicate with us using these services, we recommend using email for sensitive information. Meta likewise processes advertising-measurement data as a separate controller under its own privacy policy; see our Cookie Policy for details and your controls, including how to withdraw consent.

We may also use third-party identity, verification, registry, or screening services from time to time; where we do, we will update this list.

6.2 Professional advisers — lawyers, accountants, auditors, insurers, and other advisers, where necessary.

6.3 Authorities and third parties — where required by law or court order, or where necessary to protect rights, safety, or security, or to investigate wrongdoing.

6.4 Other participants — Circle is a network. Limited information may be shared with other participants for legitimate business collaboration (for example, a Request may include your name, role, and high-level context). We aim to minimise this sharing and we do not operate a public directory.


7. International transfers

Some of our service providers may be located outside the UK. Where we transfer personal data internationally, we rely on an appropriate safeguard or transfer mechanism, such as:

  • UK adequacy regulations — for example, for our database and document storage hosted in the EEA (Ireland);
  • the UK Extension to the EU–US Data Privacy Framework, where the provider is certified; or
  • the International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses.

8. Data retention

We keep personal data only for as long as necessary for the purposes described in this Privacy Notice, including to assess eligibility, maintain network integrity, manage memberships and services, comply with legal obligations, and handle disputes. Typically:

  • admissions, membership, and verification records — up to 24 months after the end of the relationship;
  • invoices and accounting records — up to 6 years;
  • longer where required by law or where necessary to establish, exercise, or defend legal claims.

9. Security

We implement appropriate technical and organisational measures to protect personal data, including access controls, confidentiality measures, and security monitoring. No system is completely secure, but we work to reduce risk.


10. Automated decision-making

We do not make decisions producing legal or similarly significant effects about you based solely on automated processing. Verification and admission decisions for Providers involve human review. Some routine activation steps may be automated; if you have any concerns about an automated step, you can contact us.


11. Your rights (UK GDPR)

Depending on the circumstances, you may have the right to:

  • access your personal data;
  • correct inaccurate data;
  • request deletion;
  • restrict processing;
  • object to processing based on legitimate interests;
  • data portability (where processing is based on contract or consent and is automated);
  • withdraw consent where we rely on consent.

To exercise your rights, contact us at membership@globalmobilitycircle.com. We may need to verify your identity before responding.


12. How to complain about how we handle your personal data

12.1 If you have a concern about how we handle your personal data, please contact us at membership@globalmobilitycircle.com. We will acknowledge your complaint, look into it, and respond to you. Our complaints process is described in our Complaints & Reporting Policy.

12.2 You also have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk. We would, however, appreciate the chance to address your concern first.


13. Third-party data and end-client information

If you provide personal data about another person (for example, an end-client), you confirm that you have a lawful basis and authority to share it, and that the sharing is limited to what is necessary. You must not enter end-client names or other directly identifying personal data into Requests, and you should conduct the exchange of identifying details and supporting documents off-platform, as required by the Terms. We recommend minimising end-client data at all times.


14. Cookies and similar technologies

We use cookies and similar technologies. Details and controls are provided in our Cookie Policy.


15. Children

The Platform is not intended for children, and we do not knowingly collect personal data from children.


16. Changes to this Privacy Notice

We may update this Privacy Notice from time to time. The updated version will be posted on the website with a new effective date. Material changes may also be communicated by email or a prominent notice.


17. Contact

For privacy queries and requests, contact: membership@globalmobilitycircle.com