Privacy Policy
Version 2.0 · 17 June 2026
This English version is provided for convenience. The Italian version is the authoritative version of this Privacy Policy.
Preamble
SimpL S.r.l., with registered office in Gallarate (VA), Via Alessandro Manzoni 11, 21013, tax code and VAT number 03951480122, acting through its pro tempore legal representative as Data Controller, informs data subjects under Articles 13 and 14 of Regulation (EU) 2016/679 that personal data will be processed lawfully, fairly, transparently and proportionately.
SimpL develops, produces and markets innovative, high-technology products and services, including a software ecosystem for businesses and end users that automates and improves the management of sales activities, customer relationships and business information. The ecosystem may include CRM functions, user-identification systems, proprietary algorithms, certification tools and separate credentials for each company and user.
Regulation (EU) 2016/679 on personal-data protection (the “GDPR”) and Italian Legislative Decree no. 196 of 30 June 2003, as amended by Legislative Decree no. 101/2018 (the “Privacy Code”), recognise the right to personal-data protection and govern processing in respect of the data subject’s fundamental rights and freedoms, including confidentiality, personal identity and security.
Data Controller and Processors
The Data Controller is SimpL S.r.l., acting through its pro tempore legal representative, with registered office in Gallarate (VA), Via Alessandro Manzoni 11, 21013, tax code and VAT number 03951480122.
An up-to-date list of all Data Processors appointed over time is available at the Controller’s registered office and will be provided upon written request in the forms required by law.
For questions or requests concerning the processing of personal data, contact the Controller at privacy@simplsales.ai.
Purposes and Legal Bases for Processing
Personal data are processed in accordance with the principles of lawfulness, fairness, transparency, data minimisation, accuracy, storage limitation, integrity and confidentiality, and with the rights recognised by applicable law.
Personal data may be processed:
• to develop, produce, market, provide, maintain and improve innovative, high-technology products and services, including software ecosystems for businesses and users;
• to operate software functions for human resources, business workflows, customer and prospect relationship management, CRM, user authentication, separate credentials, authorisation profiles and access control;
• to process business data and data provided by users through proprietary algorithms in order to generate statements, reports, summaries, operating indicators, checks and certifications relating to information in the databases analysed, within the contractual purposes and the instructions given by customer Controllers;
• to ensure user identity, traceability of operations, information integrity and appropriate security standards, including through blockchain technologies, certification systems, timestamps, technical logs, logical segregation measures and access-control tools;
• to manage relationships with customers, suppliers, partners, users, company contacts and other data subjects, including administration, accounting, invoicing, assistance, technical support, contract management and any disputes;
• to carry out statistical, technical, aggregate or anonymised analyses, where possible, to improve services, system security, abuse prevention, performance verification and business continuity;
• to comply with legal, regulatory, European, authority, tax, accounting, administrative, corporate and information-security obligations.
Personal data are not used for promotional or marketing purposes, newsletters, commercial communications or advertising material about SimpL services unless the data subject gives specific consent through the consent form.
SimpL may use automated systems, proprietary algorithms, artificial-intelligence algorithms and data-analysis tools for technical, organisational, security, reporting, certification and operational-support purposes. Such processing is not normally intended to make decisions based solely on automated processing that produce legal effects or similarly significantly affect the data subject under Article 22 GDPR. If a specific software function involves relevant profiling or automated decision-making, SimpL will provide specific information, identify an appropriate legal basis, implement appropriate safeguards including meaningful human intervention and, where necessary, carry out a data-protection impact assessment.
Depending on the circumstances, the legal basis is performance of pre-contractual or contractual measures requested by the data subject, compliance with legal obligations, the Controller’s legitimate interests within the limits allowed by law, or, where necessary, freely given consent under Article 6 GDPR.
Categories of Personal Data Processed
Processing is limited to the data necessary for the stated purposes. SimpL may process:
• identification and contact data, including name, surname, email address, telephone number, company contact data, account data, user identifiers, credentials, roles, authorisation profiles and information needed to manage digital identity in the software ecosystem;
• business and management data, including data about customers, prospects, suppliers, contacts and commercial communications, CRM activities, HR processes, workflows, operational activities, administrative and documentary data, and information uploaded or processed by users while using the requested services;
• technical, log and security data, including IP addresses, device identifiers, timestamps, access logs, authentication events, technical records of operations, and information concerning system security, correct operation, prevention of unauthorised access and business continuity;
• data generated through use of the software, including reports, statements, indicators, summaries, certifications, checks or evidence produced by proprietary algorithms and information-control systems in the databases analysed;
• data voluntarily supplied through forms, communications, support requests, emails, tickets, messages or other channels made available by SimpL;
• data collected through third-party services or platforms, where actually used and within their respective purposes, under their privacy policies, applicable contracts and this documentation.
Whether Providing Data Is Mandatory or Optional
Some personal data processed for the purposes described are necessary to establish and perform a contractual relationship between SimpL and the data subject. If those data are not provided, the contractual relationship cannot be established and SimpL cannot meet its legal obligations.
Where consent is required, it is collected through a free, specific, informed and unambiguous expression of intent. Without the required consent, the relevant processing will not take place.
Processing Methods and Security
Data are processed, including by automated means, for the time necessary to achieve the purposes for which they were collected and in compliance with personal-data protection requirements, in particular Article 32 GDPR and all measures needed to ensure confidentiality and security.
Because SimpL uses advanced technologies and artificial intelligence, it follows a data-protection-by-design-and-by-default approach. Where technically possible and consistent with the processing purposes, personal data are stored off-chain or otherwise in controlled environments; only technical references, cryptographic hashes, integrity evidence or certifications that do not immediately identify an individual are recorded in exposed databases. Any use of distributed ledgers is assessed in advance for data minimisation, storage limitation, exercise of data-subject rights, reversibility or decoupling of identifiers, and the possible need for a data-protection impact assessment.
Credentials and access profiles are configured with separation by customer company, user, role and function to reduce the risk of unauthorised access, commingling of environments, improper access to data belonging to different parties or processing beyond the stated purposes.
Data Retention
Data are processed only for the specific purposes pursued. Retention periods follow applicable legal limits, the data-minimisation principle and rational archive management.
The Controller and appointed Processors, Designated Persons and Authorised Persons retain the data only for the period strictly necessary for the stated purposes, for the duration of the contractual relationship or use of the services and, afterwards, for the period required by law or necessary to protect the Controller’s or third parties’ rights.
You may request information about retention periods or exercise your rights at any time by writing to privacy@simplsales.ai.
When SimpL no longer needs personal data, it will remove them from its systems and/or records and take appropriate steps to anonymise them so that the user cannot be identified, unless retention is required by a specific legal obligation.
International Transfers
For technical, organisational, software-development, security, hosting, cloud, repository, analytics, AI, automation, ticketing, document-management, CRM, communication and collaboration needs, the Controller may use third-party suppliers and services. They are selected according to their function, safeguards, data location, privacy role and declared technical and organisational measures. These may include:
• hosting, cloud infrastructure, databases, storage, backup, cybersecurity and technical monitoring;
• software-development tools, repositories, test environments, automation, deployment, logging, bug, task and project-management tools;
• artificial-intelligence, language-processing, machine-learning, data-analysis, operational-automation and development-support services, where actually used;
• CRM, customer-management, communications, ticketing, support, productivity, email and collaboration services;
• blockchain technologies, certification tools, digital assets and services for verification, timestamping, tracking or validation of information, within the stated purposes and adopted technical configuration.
If organisational or technical requirements make it necessary to use additional suppliers established outside the European Economic Area, personal-data transfers will take place only in accordance with Articles 44 et seq. GDPR, on the basis of a European Commission adequacy decision or appropriate safeguards such as standard contractual clauses or other mechanisms permitted by applicable law.
Cloud-service providers are selected from providers offering appropriate safeguards under Article 46 GDPR. Before activating new suppliers or technological tools involving significant processing, third-country transfers, privileged access, artificial intelligence, blockchain or automated processing of personal data, SimpL carries out a prior compliance review, including, where necessary, an assessment of the supplier’s privacy role, Article 28 GDPR agreements, international transfers, supplementary measures and a data-protection impact assessment.
Data Subject Rights
Data subjects may exercise their rights against the Controller and the Data Processor at any time under Chapter III (Articles 12–22) GDPR. In particular, you have the right:
• to access personal data held and processed by SimpL, including confirmation of whether they exist and, if so, their content and a copy;
• to obtain rectification of inaccurate personal data without undue delay;
• to have incomplete personal data completed, including by providing a supplementary statement;
• to obtain erasure without undue delay where one of the grounds in Article 17(1) GDPR applies;
• to obtain restriction of processing where one of the conditions in Article 18(1) GDPR applies;
• to object at any time, on grounds relating to your particular situation, to processing based on Article 6(1)(e) or (f) GDPR, including profiling;
• to lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali) at www.garanteprivacy.it;
• to data portability within the limits and in the manner provided by Article 20 GDPR.
To exercise these rights, write to privacy@simplsales.ai. Rights may also be exercised by a delegated person or by a person acting to protect the data subject where and to the extent provided by Article 2-terdecies of Italian Legislative Decree no. 196/2003.
Other Privacy Notices
To provide correct information to all categories of data subjects under Article 13 GDPR, SimpL has prepared additional privacy notices, including:
• a notice for website users and visitors;
• a cookie policy;
• a notice for customers with a consent form;
• a notice for employees with a consent form.