1. Who we are
Simpace is a brand and mobile application operated by an individual entrepreneur (sole proprietor) registered and established in Poland, not by a separate incorporated company.
Operator and data controller: Hanna Kapova-Savanova
Business name or brand: Simpace
NIP: 1122334455
Address for postal and legal notices: Poland, Warsaw, Divizjonu AK Bayt 5, 32
Privacy contact: legal@simpace.app
Support contact: support@simpace.app
In this Privacy Policy, “Simpace”, “we”, “us”, and “our” refer to the operator identified above.
This Privacy Policy applies to the Simpace mobile application, its related services, and the website pages that link to it (collectively, the “Services”). The Simpace website does not currently use advertising cookies or website analytics.
2. Our roles when processing data
Simpace acts as the data controller for account, authentication, subscription, support, security, service-communication, marketing, and product-analytics data that we determine how and why to process.
Practitioners may use Simpace to store information about their own clients, sessions, notes, documents, supervision materials, and finances. For that information, the practitioner or practice is normally the data controller and Simpace acts as a data processor. Simpace stores and transmits this information only to provide the Services on the practitioner’s instructions. Simpace does not contact the practitioner’s clients or use client records for its own advertising, profiling, recommendations, clinical analysis, or automated decision-making.
The practitioner is responsible for selecting an appropriate legal basis, providing any required privacy notice to clients and other individuals, and obtaining any permission required for dictation or other processing. Our Data Processing Addendum forms part of the Terms of Use automatically to the extent Simpace processes personal data on the user’s behalf.
3. Personal data we process
The data we process depends on the features you use and may include:
- Account and authentication data: email address, account or user ID, authentication-provider information, account status, IP address, and authentication and security logs when you sign in with email, Google, or Apple.
- Practitioner and settings data: language, time zone, currency, notification preferences, app-lock settings, and other settings you choose.
- Client and contact data: client aliases or names, contact details, country, focus area, status, and other information entered by a practitioner about a client.
- Practice records: session dates and times, time zones, duration, prices, payment status, notes, forms, documents, feedback, supervision materials, and other user-generated content. These fields may contain confidential information or special categories of personal data, including information concerning physical or mental health, depending on what the user enters.
- Financial and subscription data: prices, payments, refunds, expenses, currencies, balances, subscription status, purchase history, and entitlement information. Payment-card details are processed by the relevant app store and are not stored directly by Simpace.
- Voice and transcription data: when you start voice transcription, microphone audio is streamed directly from your device to Deepgram’s EU endpoint solely to generate a real-time transcript. The audio and transcript are excluded from Deepgram’s Model Improvement Program and are retained by Deepgram only for the time necessary to process the request. Simpace does not receive or store the audio. A transcript becomes part of your saved content only if you expressly select Save. The feature is intended for practitioners to dictate their own notes, not to record sessions or other people.
- Support and feedback data: messages, attachments, feedback, and other information you send to us.
- Technical and usage data: IP address, operating system, device and application information, diagnostics, security events, approximate timestamps, and interactions with the Services.
- Product-analytics data: a pseudonymous user ID and events such as interactions with application buttons. Simpace does not send the contents of screens, notes, documents, client records, or dictated transcripts to product analytics.
- Local device data: app settings and limited cached API responses may be stored locally on your device. Cached responses may remain for up to seven days. Settings may remain until you remove them, sign out, clear app data, or uninstall the application.
Please do not enter information that is not necessary for your professional work or use the Services as a general-purpose repository for unrelated sensitive data.
4. Purposes and legal bases
Where the GDPR applies, we process personal data on the following legal bases:
- Contract: we process account, authentication, settings, subscription, entitlement, and service data where necessary to create an account, enter into or perform our contract with you, provide requested features, synchronize content, respond to service requests, and manage purchases. The email address and authentication information required during registration must be provided so that we can create and secure an account. Without them, we cannot provide account-based Services.
- Legitimate interests: we process limited technical, security, fraud-prevention, support, and pseudonymous product-analytics data to protect the Services and users, diagnose failures, understand whether core features work, and improve reliability and usability. Our interests are operating a secure and effective service while minimizing the data used. You may object to this processing as described in section 10.
- Legal obligations: we process and retain information where necessary to comply with tax, accounting, consumer-protection, law-enforcement, and other legal obligations.
- Consent: we rely on consent where required for marketing communications, microphone access, or other optional processing. Consent can be withdrawn at any time for future processing without affecting processing carried out before withdrawal.
- Legal claims: where necessary, we process relevant information to establish, exercise, or defend legal claims.
For client records and other personal data that we process solely on a practitioner’s behalf, the practitioner determines the applicable legal basis, including any condition required by Article 9 GDPR for special-category data.
Simpace does not use personal data for profiling or decisions based solely on automated processing that produce legal or similarly significant effects.
5. Product analytics
We use PostHog Cloud EU to collect a pseudonymous user ID and limited interaction events, such as button presses. This helps us understand feature usage and identify usability and reliability problems. We do not send the content of screens, notes, client records, documents, or transcripts to PostHog, and session replay is disabled.
Where permitted, we rely on our legitimate interests for this limited analytics processing. You may object by contacting legal@simpace.app. Where consent is required by applicable law, we will request it before enabling the relevant analytics processing.
6. Marketing and service communications
We may send account confirmations, security notices, legal notices, subscription information, support responses, and other messages necessary to operate the Services. These are service communications and cannot always be opted out of while maintaining an account.
We send promotional offers, product announcements that constitute direct marketing, and other marketing emails only where permitted by law, including on the basis of consent where required. Marketing messages include a free and straightforward way to unsubscribe. You may also withdraw marketing consent by contacting legal@simpace.app. Withdrawing from marketing does not stop necessary service communications.
7. Providers and sharing
We do not sell personal data or share it for cross-context behavioral advertising. We share data only as necessary to provide the Services, comply with law, protect users, or complete a transaction you requested. Depending on the features you use, recipients may include:
- Hetzner, Germany: hosting of our API, database, application content, and backups in the European Union;
- Supabase, EU region: authentication, account management, IP addresses, and audit and security logs; application content is not stored in Supabase;
- Google: Google Sign-In, Google Play Services, and Google Play transactions where applicable;
- Apple: Sign in with Apple and App Store transactions where applicable;
- Deepgram, EU region: transient real-time speech-to-text processing when you use voice transcription;
- RevenueCat: subscription and entitlement management for in-app purchases;
- PostHog Cloud EU: limited pseudonymous product analytics;
- communications, security, professional, accounting, and legal service providers that process information under appropriate instructions; and
- public authorities, courts, regulators, or other parties where disclosure is required or permitted by law.
Where we act as a processor, subprocessors are governed by the Data Processing Addendum.
Provider information is available here:
- Hetzner Data Privacy
- Supabase Privacy Policy
- Google Privacy Policy
- Apple Privacy Policy
- Deepgram Privacy Policy
- RevenueCat Privacy Policy
- PostHog Privacy Policy
8. International transfers
Our primary application hosting, database infrastructure, product analytics, and speech-to-text processing are configured in the European Union. Some providers, including their support, security, corporate, or app-store operations, may process limited personal data outside the European Economic Area.
Where a transfer outside the EEA requires safeguards, we use an applicable transfer mechanism such as an adequacy decision, Standard Contractual Clauses, or another mechanism recognized by applicable data-protection law. You may contact us for information about safeguards relevant to a particular transfer.
9. Retention and deletion
We retain personal data only as long as necessary for the purposes described in this Privacy Policy or as required by law. In particular:
- account and active application data are retained while the account remains active;
- after an account-deletion request, the account enters a seven-day deletion period, after which its data is removed from active systems;
- backups are retained for up to 30 days and copies older than 30 days are automatically deleted, so final removal from active systems and backups may take up to 37 days after the initial request;
- audit, authentication, and security logs are retained for up to 90 days, unless a longer period is necessary to investigate abuse, a security incident, or a legal claim;
- support correspondence is retained for up to 24 months after the matter is closed, unless longer retention is necessary for a dispute or legal obligation;
- client records and professional content are retained while the account is active and then deleted according to the account-deletion process, subject to the practitioner’s instructions and applicable legal requirements;
- Deepgram retains opted-out audio and transcript data only for the duration necessary to process the transcription request;
- PostHog analytics data is retained according to the retention settings applicable to our PostHog Cloud EU service and is deleted or anonymized when no longer necessary for product analytics;
- subscription and transaction records may be retained for as long as necessary to manage entitlements, restore purchases, resolve disputes, prevent fraud, and comply with accounting, tax, app-store, or other legal requirements; and
- local cached responses may remain on a device for up to seven days, while local settings may remain until removed, the application data is cleared, or the application is uninstalled.
You can request deletion inside the application or through our Account Deletion page. You may also contact legal@simpace.app. We may need to verify your identity.
Deleting a Simpace account does not automatically cancel an App Store or Google Play subscription. You must cancel the subscription separately through the relevant store. Deletion does not require us to erase information that must be retained by law, is necessary to establish or defend legal claims, or has been irreversibly anonymized.
If you are a client whose information was entered by a practitioner, please normally direct your request to that practitioner. We will assist the practitioner where Simpace processes the information on the practitioner’s behalf.
10. Your rights
Depending on applicable law, you may have the right to:
- obtain access to your personal data;
- correct inaccurate or incomplete data;
- request deletion of your data;
- request restriction of processing;
- object to processing based on legitimate interests or to direct marketing;
- receive applicable data in a structured, commonly used, machine-readable format;
- withdraw consent where processing is based on consent; and
- lodge a complaint with the data-protection supervisory authority in your country of residence, place of work, or place of the alleged infringement.
In Poland, the supervisory authority is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO), uodo.gov.pl.
To exercise your rights, contact legal@simpace.app. We may verify your identity and will respond within the period required by law. Rights are not absolute, and we will explain any lawful reason why a request cannot be fully granted. Where we process client data solely as a processor, we will refer the request to, or assist, the relevant practitioner/controller.
11. California residents
If the California Consumer Privacy Act, as amended, applies to Simpace and to your information, you may have rights to know, access, correct, delete, and obtain information about the categories of personal information we collect, as well as the right to opt out of sale or sharing and the right not to receive discriminatory treatment for exercising your rights. Simpace does not sell personal information or share it for cross-context behavioral advertising. Contact legal@simpace.app to make a request.
12. Children
The Services are intended for people aged 18 or older. We do not knowingly offer accounts to or collect personal data directly from children under 18. Practitioners must comply with applicable law before entering information concerning a minor into professional records. If you believe a child has created an account or provided personal data directly to us, contact legal@simpace.app.
13. Security
We use appropriate technical and organizational measures designed to protect personal data, including authenticated access controls, secure credential handling, encryption in transit, restricted provider access, backups, and security logging and monitoring. No service can guarantee absolute security. Users are responsible for protecting their account credentials and devices.
14. Personal-data breaches
Where Simpace acts as controller and a personal-data breach requires notification, we will notify the competent authority and affected individuals within the legally required timeframe. Where Simpace acts as processor, we will notify and assist the relevant controller as described in the Data Processing Addendum.
15. Changes to this Privacy Policy
We may update this Privacy Policy when our Services, providers, or legal obligations change. We will publish the revised version with a new effective date and provide additional notice where required. If a change requires consent, we will request it before the relevant processing begins.
16. Contact us
For privacy questions, rights requests, or complaints, contact:
Hanna Kapova-Savanova
Operating under the Simpace brand
NIP: 1122334455
Poland, Warsaw, Divizjonu AK Bayt 5, 32
legal@simpace.app