Skip to main content
Platform Review
PricingSign in
← Sim assessment

Sim procurement policy evidence

Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.

Verified procurement policy findings for Sim
TopicPlan or tierRiskTheir wordsSource
DPA, audit rights & data residencyAll applicable tiersunknown“ Data subjects in the European Economic Area may contact the Representative on any matter relating to the processing of their Personal Data. We will respond to Your request within the timeframes stated in section 14 where those timeframes apply.”Captured 2026-09-25Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersunknown“ Technical and organizational measures described in section 5, including encryption in transit and at rest, access controls, and logging A copy of the applicable transfer clauses is available on request at privacy@sim.ai .”Captured 2026-09-25Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow“ Your information, including Personal Data, may be transferred to and maintained on computers outside Your state, province, country, or other governmental jurisdiction, where data protection laws may differ. If You are outside the United States and provide information to us, we transfer the data to the United States and process it there. Sim's primary hosting region is AWS us-east-1 in the United States. The current Service Provider list is maintained on the Sub-processors page. Providing Personal Data does not by itself constitute consent to an international transfer. Where Sim relies on consent, that consent will be freely given, specific, informed, unambiguous, obtained separately through a positive action, and recorded. International transfers from the European Economic Area or United Kingdom are made using applicable transfer safeguards, including: The European Commission's Standard Contractual Clauses adopted by Implementing Decision (EU) 2021/914 and, for transfers from the United Kingdom, the UK International Data Transfer Addendum Data Processing Addenda with each sub-processor that incorporate the applicable transfer clauses”Captured 2026-09-25Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersunknown“ If You are in the European Economic Area, You have the following data protection rights: Access: the right to obtain confirmation of whether we process Your Personal Data and to receive a copy of that data. Rectification: the right to correct inaccurate Personal Data and complete incomplete Personal Data. Erasure: the right to request deletion of Your Personal Data where the applicable conditions are met. Objection: the right to object to processing based on legitimate interests and to object at any time to processing for direct marketing. Restriction: the right to request restriction of processing where the applicable conditions are met. Data portability: the right to receive Personal Data You provided in a structured, commonly used, machine-readable format and to transmit it to another controller where applicable. Withdrawal of consent: the right to withdraw consent at any time where Sim relies on consent. Withdrawal does not affect the lawfulness of processing before withdrawal. You may submit a request at privacy@sim.ai , through in-app Account settings for access and deletion, or by using the postal address in section 17. We respond without undue delay and within one month after receiving a request. That period may be extended by up to two further months where necessary because of the complexity or number of requests. If an extension is required, we will tell You within the first month and explain the reason. ”Captured 2026-09-25Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersunknown“ Requests are handled free of charge. Where a request is manifestly unfounded, excessive, or repetitive, we may charge a reasonable fee based on the administrative cost or refuse to act. If we refuse or charge a fee, we will give reasons and explain the available complaint and judicial-remedy rights. We may request information needed to verify Your identity before acting on a request. Information collected for verification will be used only for that purpose. You have the right to lodge a complaint with the supervisory authority in the Member State of Your residence, place of work, or place of the alleged infringement, without prejudice to any other administrative or judicial remedy. The same rights are extended to data subjects in the United Kingdom under the UK GDPR.”Captured 2026-09-25Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersunknown“ You may request access to covered Personal Data and ask Sim to correct, amend, or delete it where it is inaccurate or has been processed in violation of the applicable DPF Principles. The methods for submitting a request are described in sections 14 and 17. Sim may be required to disclose Personal Data in response to lawful requests by public authorities, including to meet national-security or law-enforcement requirements.”Captured 2026-09-25Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersunknown“ Under Article 27 of the GDPR, Sim has appointed an EU Representative to act as its data protection agent: Instant EU GDPR Representative Ltd.”Captured 2026-09-25Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersunknown“ In compliance with the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF, Sim commits to resolve DPF Principles-related complaints about its collection and use of Personal Data. Individuals in the European Union, the United Kingdom and Gibraltar, and Switzerland with inquiries or complaints regarding Personal Data received in reliance on the applicable DPF program should first contact Sim using the information in section 17. Sim will respond to a DPF Principles-related complaint within 45 days. For unresolved complaints, Sim commits to cooperate with and comply with the advice of the panel established by the European Union data protection authorities, the United Kingdom Information Commissioner's Office and the Gibraltar Regulatory Authority, and the Swiss Federal Data Protection and Information Commissioner, as applicable. These independent recourse mechanisms are available at no cost to You. For more information about submitting a complaint, visit the DPF complaint guidance .”Captured 2026-09-25Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersunknown“ Sim Studio, Inc. complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce. Sim Studio, Inc. has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of Personal Data received from the European Union in reliance on the EU-U.S. DPF and from the United Kingdom and Gibraltar in reliance on the UK Extension to the EU-U.S. DPF. Sim Studio, Inc. has certified to the U.S. Department of Commerce that it adheres to the Swiss-U.S. Data Privacy Framework Principles (Swiss-U.S. DPF Principles) with regard to the processing of Personal Data received from Switzerland in reliance on the Swiss-U.S. DPF. If there is any conflict between this Privacy Policy and the applicable DPF Principles, the DPF Principles govern. To learn more about the DPF program and view our certification, visit the Data Privacy Framework website and Data Privacy Framework List . Sim subjects all Personal Data received from the European Union, the United Kingdom and Gibraltar, and Switzerland in reliance on the applicable part of the DPF program to the relevant DPF Principles. Sim Studio, Inc. has no other U.S. entities or U.S. subsidiaries covered by its certification. Sim's certification under the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF covers non-human-resources Personal Data only. Human-resources data is not covered by this certification.”Captured 2026-09-25Open source →Finding permalink →
Data retentionAll applicable tiersunknown“ Paid subscriptions automatically renew at the end of each billing period unless you cancel before the renewal date. You can cancel your subscription at any time through your account settings or by contacting us. Cancellations take effect at the end of the current billing period. You will retain access to paid features until that time. We do not provide refunds for partial billing periods. Upon cancellation or termination, you may export your data within 30 days. After 30 days, we may delete your data in accordance with our data retention policies.”Captured 2026-09-25Open source →Finding permalink →
Data retentionAll applicable tiersmedium“ We retain data only as long as necessary for the disclosed purposes:”Captured 2026-09-25Open source →Finding permalink →
Data retentionAll applicable tiersunknown“ When You revoke access, delete Your Account, or stop using a feature, we remove associated data within the timeframes above. You may request deletion through in-app settings or by contacting us.”Captured 2026-09-25Open source →Finding permalink →
Data retentionAll applicable tiersunknown“ Prompts and outputs are retained according to the data category and context in which they are processed. Account and workflow content follows the Account Data period in the retention table in section 10; Google Data, Usage Logs, and Transaction Records follow their respective periods in that table. Questions about AI processing may be sent to privacy@sim.ai .”Captured 2026-09-25Open source →Finding permalink →
Data retentionAll applicable tierslow“ Account Data During the active Account and for 30 days after a deletion request Google API Data During use of the enabled feature and for 7 days after revocation or Account deletion Usage Logs 90 days for analytics; up to 1 year for security investigations Transaction Records Up to 7 years for legal and tax compliance ”Captured 2026-09-25Open source →Finding permalink →
Data retentionAll applicable tiersunknown“ Sim limits covered Personal Data to information relevant for the purposes of processing and does not process it in a way that is incompatible with those purposes unless subsequently authorized by the individual or otherwise permitted by the applicable DPF Principles. To the extent necessary for those purposes, Sim takes reasonable steps to ensure that covered Personal Data is reliable for its intended use, accurate, complete, and current. Sim retains covered Personal Data only for as long as it serves a processing purpose, subject to the exceptions permitted by the applicable DPF Principles. Section 5 describes the safeguards Sim uses to protect Personal Data against loss, misuse, and unauthorized access, disclosure, alteration, or destruction.”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium“ Service Provider means a natural or legal person that processes data on behalf of the Company, including third parties engaged to facilitate, provide, support, or analyze the Service. For the purpose of the GDPR, Service Providers are Data Processors. Third-party Social Media Service means a website or social network through which a User can log in to or create an Account for the Service. Usage Data means data collected automatically, either generated through use of the Service or from the Service infrastructure itself. Website refers to Sim, accessible from sim.ai. You means the individual accessing or using the Service, or the company or other legal entity on whose behalf that individual accesses or uses the Service. Under the GDPR, You may be the Data Subject or User.”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium“ We may transfer Google Data, whether raw or derived, to third parties only under the following limited conditions and in line with user disclosures and consent: To provide or improve user-facing features, with the user's explicit consent”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium“ Sections 1 and 2 describe the types of Personal Data Sim collects and the purposes for which Sim collects and uses it. Sim may disclose Personal Data to cloud hosting and infrastructure providers, authentication providers, customer-support providers, analytics and advertising providers, payment processors, integration providers, AI model providers, professional advisers, public authorities, and parties involved in a corporate transaction, in each case for the purposes described in sections 4, 6, 8, 9, and 10A. Service Providers acting on Sim's behalf may process Personal Data only for limited and specified purposes consistent with Sim's instructions. Where the DPF Principles require choice, You may opt out of the disclosure of covered Personal Data to a third party that is not acting as Sim's agent or its use for a purpose materially different from the purpose for which it was originally collected or subsequently authorized. You may exercise this choice by contacting privacy@sim.ai . Sim obtains affirmative express consent before disclosing sensitive Personal Data to a third party or using it for a purpose other than the purpose for which it was originally collected or subsequently authorized, except where the DPF Principles allow otherwise. Sim also treats Personal Data as sensitive when a third party identifies and treats it as sensitive.”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium“ For onward transfers of covered Personal Data to a third party acting as a controller, Sim complies with the Notice and Choice Principles and requires the recipient by contract to process the data only for limited and specified purposes consistent with the consent provided and to provide the same level of protection as the applicable DPF Principles. For transfers to a third party acting as an agent, Sim transfers covered Personal Data only for limited and specified purposes, requires at least the same level of privacy protection as the applicable DPF Principles, takes reasonable and appropriate steps to ensure that the agent processes the data consistently with Sim's DPF obligations, and takes reasonable and appropriate steps to stop and remediate unauthorized processing upon notice. Sim remains liable under the applicable DPF Principles if an agent processes covered Personal Data in a manner inconsistent with the DPF Principles, unless Sim proves that it is not responsible for the event giving rise to the damage.”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown“ As part of a merger, acquisition, divestiture, or sale of assets, with explicit user consent”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslow“ We engage third-party companies and individuals to facilitate the Service, provide the Service on our behalf, perform Service-related services, or assist us in analyzing how the Service is used. These Service Providers may access Personal Data only to perform assigned tasks on our behalf and may not disclose or use it for another purpose. The legal basis for disclosing Personal Data to Service Providers depends on the service involved: Contractual necessity — Article 6(1)(b): providers required to deliver the Service, integrations, billing, or other features requested by You Legitimate interests — Article 6(1)(f): providers used for security, hosting, monitoring, and support tooling, where Sim's interests are to operate, protect, maintain, and support the Service Consent — Article 6(1)(a): analytics and advertising providers activated through non-essential Cookies or similar technologies Every Service Provider that processes Personal Data on Sim's behalf is engaged under a written data processing agreement that imposes confidentiality, purpose limitation, security, and sub-processor controls. Each provider is security-reviewed before onboarding and periodically thereafter and acts only on Sim's documented instructions. The current provider list is maintained on the Sub-processors page.”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown“ The Service may integrate with third-party services (such as Google Workspace, cloud storage providers, and AI model providers). Your use of third-party services is subject to their respective terms and privacy policies. We are not responsible for the availability, functionality, or actions of third-party services. Any issues with third-party integrations should be directed to the respective provider.”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown“ We may provide paid products or services within the Service and may use third-party payment processors. We do not store or collect Your payment card details. Those details are provided directly to the payment processor, whose use of Personal Data is governed by its privacy policy. Payment processors adhere to the PCI Data Security Standard managed by the PCI Security Standards Council. The payment processor we use is Stripe.”Captured 2026-09-25Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown“ If the Company is involved in a merger, acquisition, or asset sale, Your Personal Data may be transferred. We will provide notice before Your Personal Data is transferred and becomes subject to a different Privacy Policy.”Captured 2026-09-25Open source →Finding permalink →
Tier differencesAll applicable tiersmedium“ We offer Free, Pro, Max, and Enterprise subscription plans. Paid plans include a base subscription fee plus usage-based charges for inference and other services that exceed your plan's included limits. You agree to pay all fees associated with your account. Your base subscription fee is charged at the beginning of each billing cycle (monthly or annually). Inference overages are charged incrementally every $50 during your billing period, which may result in multiple invoices within a single billing cycle. Payment is due upon receipt of invoice. If payment fails, we may suspend or terminate your access to paid features. We reserve the right to change our pricing with 30 days' notice to paid subscribers. Price changes will take effect at your next renewal.”Captured 2026-09-25Open source →Finding permalink →

Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.

📢 POLICY UPDATES ALERT

AIRIN Brief

Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.