Privacy Policy

Version 2.0 · 17 June 2026

This English version is provided for convenience. The Italian version is the authoritative version of this Privacy Policy.

Preamble

SimpL S.r.l., with registered office in Gallarate (VA), Via Alessandro Manzoni 11, 21013, tax code and VAT number 03951480122, acting through its pro tempore legal representative as Data Controller, informs data subjects under Articles 13 and 14 of Regulation (EU) 2016/679 that personal data will be processed lawfully, fairly, transparently and proportionately. SimpL develops, produces and markets innovative, high-technology products and services, including a software ecosystem for businesses and end users that automates and improves the management of sales activities, customer relationships and business information. The ecosystem may include CRM functions, user-identification systems, proprietary algorithms, certification tools and separate credentials for each company and user. Regulation (EU) 2016/679 on personal-data protection (the “GDPR”) and Italian Legislative Decree no. 196 of 30 June 2003, as amended by Legislative Decree no. 101/2018 (the “Privacy Code”), recognise the right to personal-data protection and govern processing in respect of the data subject’s fundamental rights and freedoms, including confidentiality, personal identity and security.

Data Controller and Processors

The Data Controller is SimpL S.r.l., acting through its pro tempore legal representative, with registered office in Gallarate (VA), Via Alessandro Manzoni 11, 21013, tax code and VAT number 03951480122. An up-to-date list of all Data Processors appointed over time is available at the Controller’s registered office and will be provided upon written request in the forms required by law. For questions or requests concerning the processing of personal data, contact the Controller at privacy@simplsales.ai.

Categories of Personal Data Processed

Processing is limited to the data necessary for the stated purposes. SimpL may process: • identification and contact data, including name, surname, email address, telephone number, company contact data, account data, user identifiers, credentials, roles, authorisation profiles and information needed to manage digital identity in the software ecosystem; • business and management data, including data about customers, prospects, suppliers, contacts and commercial communications, CRM activities, HR processes, workflows, operational activities, administrative and documentary data, and information uploaded or processed by users while using the requested services; • technical, log and security data, including IP addresses, device identifiers, timestamps, access logs, authentication events, technical records of operations, and information concerning system security, correct operation, prevention of unauthorised access and business continuity; • data generated through use of the software, including reports, statements, indicators, summaries, certifications, checks or evidence produced by proprietary algorithms and information-control systems in the databases analysed; • data voluntarily supplied through forms, communications, support requests, emails, tickets, messages or other channels made available by SimpL; • data collected through third-party services or platforms, where actually used and within their respective purposes, under their privacy policies, applicable contracts and this documentation.

Whether Providing Data Is Mandatory or Optional

Some personal data processed for the purposes described are necessary to establish and perform a contractual relationship between SimpL and the data subject. If those data are not provided, the contractual relationship cannot be established and SimpL cannot meet its legal obligations. Where consent is required, it is collected through a free, specific, informed and unambiguous expression of intent. Without the required consent, the relevant processing will not take place.

Processing Methods and Security

Data are processed, including by automated means, for the time necessary to achieve the purposes for which they were collected and in compliance with personal-data protection requirements, in particular Article 32 GDPR and all measures needed to ensure confidentiality and security. Because SimpL uses advanced technologies and artificial intelligence, it follows a data-protection-by-design-and-by-default approach. Where technically possible and consistent with the processing purposes, personal data are stored off-chain or otherwise in controlled environments; only technical references, cryptographic hashes, integrity evidence or certifications that do not immediately identify an individual are recorded in exposed databases. Any use of distributed ledgers is assessed in advance for data minimisation, storage limitation, exercise of data-subject rights, reversibility or decoupling of identifiers, and the possible need for a data-protection impact assessment. Credentials and access profiles are configured with separation by customer company, user, role and function to reduce the risk of unauthorised access, commingling of environments, improper access to data belonging to different parties or processing beyond the stated purposes.

Data Retention

Data are processed only for the specific purposes pursued. Retention periods follow applicable legal limits, the data-minimisation principle and rational archive management. The Controller and appointed Processors, Designated Persons and Authorised Persons retain the data only for the period strictly necessary for the stated purposes, for the duration of the contractual relationship or use of the services and, afterwards, for the period required by law or necessary to protect the Controller’s or third parties’ rights. You may request information about retention periods or exercise your rights at any time by writing to privacy@simplsales.ai. When SimpL no longer needs personal data, it will remove them from its systems and/or records and take appropriate steps to anonymise them so that the user cannot be identified, unless retention is required by a specific legal obligation.

Disclosure and Sharing with Third Parties

Personal data provided by customers are used only to perform the requested service or activity and are disclosed to third parties only where necessary to perform it. The following may become aware of personal data: • employees and collaborators specifically appointed, designated and/or authorised to process data under Article 28 GDPR and Article 2-quaterdecies of the Privacy Code; • parties to whom SimpL entrusts outsourced activities, appointed as external Processors under Article 28 GDPR or as independent Controllers for the purposes identified in this Policy. These may include financial operators, internet providers, IT-service providers, couriers and legal or tax advisers. A specific list of the parties that may access personal data is available at the Controller’s registered office and may be consulted on request. Processing by third parties is duly authorised by the Controller and carried out in accordance with security and privacy law. Personal data are not publicly disclosed unless required by law, regulation or European law. In particular, data may be provided to law-enforcement, judicial or administrative authorities when required by law to establish or prosecute offences, prevent and protect against public-security threats, enable SimpL to exercise or defend its or third parties’ rights before the competent authorities, or otherwise protect others’ rights and freedoms.

International Transfers

For technical, organisational, software-development, security, hosting, cloud, repository, analytics, AI, automation, ticketing, document-management, CRM, communication and collaboration needs, the Controller may use third-party suppliers and services. They are selected according to their function, safeguards, data location, privacy role and declared technical and organisational measures. These may include: • hosting, cloud infrastructure, databases, storage, backup, cybersecurity and technical monitoring; • software-development tools, repositories, test environments, automation, deployment, logging, bug, task and project-management tools; • artificial-intelligence, language-processing, machine-learning, data-analysis, operational-automation and development-support services, where actually used; • CRM, customer-management, communications, ticketing, support, productivity, email and collaboration services; • blockchain technologies, certification tools, digital assets and services for verification, timestamping, tracking or validation of information, within the stated purposes and adopted technical configuration. If organisational or technical requirements make it necessary to use additional suppliers established outside the European Economic Area, personal-data transfers will take place only in accordance with Articles 44 et seq. GDPR, on the basis of a European Commission adequacy decision or appropriate safeguards such as standard contractual clauses or other mechanisms permitted by applicable law. Cloud-service providers are selected from providers offering appropriate safeguards under Article 46 GDPR. Before activating new suppliers or technological tools involving significant processing, third-country transfers, privileged access, artificial intelligence, blockchain or automated processing of personal data, SimpL carries out a prior compliance review, including, where necessary, an assessment of the supplier’s privacy role, Article 28 GDPR agreements, international transfers, supplementary measures and a data-protection impact assessment.

Data Subject Rights

Data subjects may exercise their rights against the Controller and the Data Processor at any time under Chapter III (Articles 12–22) GDPR. In particular, you have the right: • to access personal data held and processed by SimpL, including confirmation of whether they exist and, if so, their content and a copy; • to obtain rectification of inaccurate personal data without undue delay; • to have incomplete personal data completed, including by providing a supplementary statement; • to obtain erasure without undue delay where one of the grounds in Article 17(1) GDPR applies; • to obtain restriction of processing where one of the conditions in Article 18(1) GDPR applies; • to object at any time, on grounds relating to your particular situation, to processing based on Article 6(1)(e) or (f) GDPR, including profiling; • to lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali) at www.garanteprivacy.it; • to data portability within the limits and in the manner provided by Article 20 GDPR. To exercise these rights, write to privacy@simplsales.ai. Rights may also be exercised by a delegated person or by a person acting to protect the data subject where and to the extent provided by Article 2-terdecies of Italian Legislative Decree no. 196/2003.

Other Privacy Notices

To provide correct information to all categories of data subjects under Article 13 GDPR, SimpL has prepared additional privacy notices, including: • a notice for website users and visitors; • a cookie policy; • a notice for customers with a consent form; • a notice for employees with a consent form.