Simplifai Privacy Policy
Revision: 20th of June 2023
This privacy policy (the “Policy”) has been compiled to better serve those who are concerned with how their personal data is being used, hereunder to inform you (“You” or “Your”) of Your rights as well as our policies and procedures regarding the processing of Your personal data.
Where the words “We“, “Us” or “Our” are used in this Policy, this refers to Simplifai AS, a limited liability company incorporated under the laws of Norway, bearing the Norwegian organisation no. 918 938 877 – and having its registered address at Drammensveien 133, 0277 Oslo, PO Box 1033. Please note that we are the data controller of Your personal data unless otherwise specified.
For the purposes of this Policy, the term “Services” means the software services delivered online to Our customers (“Customers”) or partners (“Partners”), including upgrades and updates that We may provide, if applicable.
Please read Our Policy carefully to get a clear understanding of how We collect, use, protect or otherwise handle Your personal data. Please click on any of the topics below to be directed to the relevant information.
- Personal data
- Collection
- Purpose
- Processing
- Legal basis
- Data controller
- What are your rights?
- Retention
- Third parties
- Security
- International Transfer
- Amendments
- Contact & Complaint
1. PERSONAL DATA
1.1. Personal data is information relating to a natural individual who can be identified, directly or indirectly by reference to an identification number or to one or more factors specific to his/her physical, physiological, mental, economic, cultural or social identity.
1.2. This Policy does not cover aggregated data from which the identity of an individual cannot be determined. We retain the right to use aggregated data in any way that We find appropriate.
2. COLLECTION
2.1. We collect personal data when You use Our Services, subscribe to a newsletter, respond to a survey or marketing communication, use our Website or certain Website features, fill out a form, open a support ticket or otherwise enter information on Our Website. If You have engaged one of Our Partners which facilitates Our Services independently or bundled or combined with their own services, they will also provide personal data to Us
3. PURPOSE
3.1 We process personal data to the extent necessary to enable You to make use of Our Services. We will process personal data for the purposes described herein and in order to offer, monitor, maintain, improve and analyse the Services and otherwise to fulfil Our legal obligations, including but not limited to processing pertaining to:
a) Analysis : Anonymous analysis to improve Our Services. Such analysis will be conducted using aggregated and anonymised personal data, and this data will not be used to identify You as a person.
b) Dispute : Handle disputes and provide assistance.
c) Improvement : Monitor, maintain, improve and analyse the Services.
d) Internal processing : Conduct internal investigations and risk assessments.
e) Marketing : If You have consented to online marketing, We may also process Your personal data in order to provide You with information on product updates, offers and news.
f) Notifications : We may use Your personal data to send You service or operating messages, such as updates, security alerts, and account alerts.
g) Order processing :Process orders and transactions and send appurtenant information and updates.
h) Sales : We may process Your personal data in order to contact You and propose meeting invitations and/or offer tailored information or offers on how We believe that Our Services or other products or services may be of interest to You and/or Your organisation. You may object to such processing by replying to any inquiry from Us or by contacting Us as specified in Clause 13.
i) Survey : Manage a survey or Your use of the Services.
j) Threat detection : Register and prevent fraud, spam, abuse, technical issues, security incidents and other harmful activities.
k) Tips and offers: We process Your Personal Data in order to offer certain features.
l) Verification : Verify You as a user and facilitate information that You have made available in the Services.
m) Webinars and courses : We process Your personal data in order to register and allow for Your participation in a webinar or course.
4. PROCESSING
4.1 By using the Services, We may process personal data about You, including but not limited to:
a) Billing information.
b) Details concerning Your use of the Services, e.g. duration, connection information, chat logs and Your questions and answers.
c) Device information.
d) E-mail address
e) Employer
f) IP address
g) Name
h) Phone number
i) Position
j) Username
k) Your name.
5. LEGAL BASIS
5.1. Unless otherwise provided, the legal basis for Our processing is Our legitimate interest to sell, administer and improve Our Services or other products and services or to monitor or improve our website or Our security posture.
5.2. Any personal data processed as part of sales or contract negotiations is processed on the basis of such processing being necessary for Us to enter into and perform and agreement with You, cf. Article 6 no. 1 (b) of the GDPR. Unless otherwise agreed, said lawful ground also applies to Our provision of any Services to You.
5.3. For certain processing operations such as those pertaining to our webinars and courses, You will be asked to confirm that You have read and consented to the contents of this Policy and to Our processing of Your personal data in accordance with Article 6 no. 1 (a) of the GDPR. We will consider any provision of personal data through contact forms as a valid consent, unless indicated otherwise.
5.4. If You wish to receive offers or newsletters from Us, You may consent to having Your personal data processed for the purpose of marketing. Such consent is not required in order to use the Services.
5.5. You may withdraw Your consent at any time by contacting Us as specified in Clause 13.
6. DATA CONTROLLER
6.1 Unless otherwise specified in the terms and conditions applicable to the Services You have requested, We are the data controller, where the processing of personal data is collected directly from You as a data subject. A data controller is the person who determines the purpose of the processing of personal data and the means to be used during such processing. It is the data controller that has the overall responsibility for the processing of Your personal data.
6.2. Please note that We are not acting as a data controller when processing Your personal data as part of Our provision of the Services to Our customers. For such processing operations, We will be acting as a data processor on behalf of such customers. Any inquiries You may have concerning Your personal data should be directed to the applicable customer.
6.3. If You are consenting to this Policy on behalf of a Customer, Partner or an organisation, You warrant and acknowledge that You:
a) Are solely responsible for ensuring that the relevant data subjects have been provided with all necessary information in respect of this Policy.
b) Have a lawful basis to transfer the personal data to Us.
c) Have sufficient power of authority to execute an agreement with Us
7. YOUR RIGHTS
7.1. As a data subject, You have the following rights:
a) Access: You may request a copy of Your personal data that We process.
b) Data portability: You may request to obtain the personal data that You have provided to Us or to have said data transferred to a third party in a structured, commonly used and machine-readable format.
c) Erasure: You may demand that We erase all of Your personal data, unless We are required by law to keep the data for a certain period of time.
d) Information: You are entitled to receive information concerning which categories of Your personal data that We process and how they are processed.
e) Objection: You may object to Our use of Your personal data for the purpose of direct marketing, including profiling for direct marketing purposes. You may also object to being subject to decision based solely on automated processing, including profiling, which produces legal effects that significantly affects You.
f) Rectification: You may require Your personal data to be rectified or supplemented.
g) Restriction: You may request that We restrict the processing of Your personal data.
8. RETENTION
8.1 We keep Your personal data only for as long as it is required for the reasons it was collected from You. The time period in which We store personal data varies, depending on the category and the nature of the personal data.
8.2. When Your personal data is no longer required for Our purposes, We have procedures to destroy, delete, erase or convert it into an anonymous form.
9. THIRD PARTIES
9.1 We may disclose Your personal data to individuals or organisations who are Our service providers and who are involved in database management, maintaining, reviewing and developing Our business systems, procedures and infrastructure, including testing or upgrading Our computer systems or who otherwise facilitates Our Services.
9.2. Third parties will only receive access to Your personal data for the purpose of fulfilling Our obligations to You, deliver the Services, fulfil Our legal obligations or if You have otherwise consented to such transfer or access. If We disclose personal data to organisations that perform services on Our behalf, We will require those service providers to use such personal data solely for the purposes of providing services to Us and to have appropriate safeguards for the protection of that personal data.
9.3. You acknowledge that We cooperate with government authorities and law enforcement officials to enforce and comply with any applicable law. Please note that there are circumstances where the use and/or disclosure of personal data may be justified or permitted or where We are obliged to disclose personal data without Your consent.
9.4. Where personal data may be subject to transfer to another organisation in contemplation of a merger, financing, reorganisation or dissolution transaction of all or part of Us, We will do this only if the involved parties have entered into an agreement under which the collection, use and disclosure of the personal data is restricted to those purposes that relate to the transaction, including a determination of whether or not to proceed with the transaction, and is to be used by the involved parties to carry out and complete the transaction. If another company acquires Us or Our business or assets, that company will possess the personal data collected by Us and will assume the rights and obligations regarding Your personal data as described in this Policy
10. SECURITY
10.1 Safeguarding Your personal data is Our highest concern. As such, We endeavour to maintain and employ reasonable measures for the physical, procedural and technical security with respect to the offices and information storage facilities involved with Your personal data, to prevent any loss, misuse, unauthorised access, disclosure, or modification of Your personal data. This also applies to Our disposal or destruction of Your personal data.
10.2. We restrict access to production environments and monitoring of Your activities to a limited number of individuals who have special access rights to such systems and are required to keep the personal data confidential. We use computer systems with limited access housed in facilities using physical security measures.
10.3. Your personal data is contained behind secured networks, and We securely encrypt, limit and restrict access to Your personal data using SSL. We encrypt all data at rest and any personal data is double encrypted with two keys at both the infrastructure and application level.
10.4. If any of Our employees misuses personal data, this will be considered as a serious offence for which disciplinary action may be taken, including termination of employment. If any individual or organisation misuses personal data – provided for the purpose of providing services to or for Us – this will be considered a serious issue for which action may be taken, including termination of any agreement between Us and that individual or organisation.
11. INTERNATIONAL TRANSFER
11.1. Your Personal Data may be transferred to — and maintained on — computers located inside of the European Economic Area and other countries which the European Commission has considered to have an adequacy of protection of personal data on the basis of article 45 of Regulation (EU) 2016/679.
11.2. Our employees in Ukraine and India may access Your personal data in connection with product updates, support or product enhancement, e.g. training of underlying machine learning models. You acknowledge that We may transfer Your personal data for the aforementioned purposes to the following processors by way of EU standard contractual clauses:
Simplifai Ukraine LLCC | Simplifai Cognitive Services Pvt Ltd |
USREOU 42910206 | CIN U74999PN2018FTC175269 |
Yaroslavskii lane, 1/304071, Kiev, Ukraina | Mahalunge, Fourth floor, The Pavilion, S.no. 105/1, Baner, Maharashtra 411026, India |
11.3. You may obtain a copy of the EU standard contractual clauses by contacting Us as specified in Clause 13.
12. AMENDMENTS
12.1. The privacy policy is governed by Norwegian law and may be updated from time to time due to amendments or expansions in the Services. In case of any material changes, We will contact You through the available channels such as e-mail or notifications on Our Website.
13. CONTACT & COMPLAINT
13.1 If you wish to utilise Your rights of access, information, rectification, erasure, restriction, data portability or the right to object to the processing of personal data or if You have questions or requests regarding this privacy policy, Our processing or wish to file a complaint, please contact Us at: privacy@simplifai.ai. We will investigate all complaints and if a complaint is found justified, We will take all reasonable steps to resolve the issue.
13.2. You are also entitled to file a complaint to the Data Authority regarding Our processing of Your personal data. For information on how to contact the Data Authority, visit the Data Authority’s website.
13.4. To guard against fraudulent requests, We may require sufficient information to allow Us to confirm that the individual making the request is authorised to do so.