Simplif-i Compliance Management Platform Privacy Policy

Effective date: 25 March 2026

Version: 1.0

Data Controller: Simplif-i Systems Ltd

Registered Address: 66 Paul Street, London, EC2A 4NA

Contact: privacy@simplif-i.com

1. Introduction

Simplif-i Systems Ltd ("we", "our", or "us"), registered at 66 Paul Street, London, EC2A 4NA, is committed to protecting your privacy and handling your personal data with care, transparency, and integrity. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you access or use the Simplif-i compliance management platform and any associated services, applications, or websites (collectively, the "Services").

This Privacy Policy explains how we process personal data and the legal bases we rely on under applicable data protection law (including the UK GDPR and EU/EEA GDPR, as applicable). Where we rely on consent (for example, for certain cookies or marketing communications), you may withdraw your consent at any time. For other processing, we rely on other lawful bases such as performance of a contract, compliance with legal obligations, and legitimate interests.

Role of the parties (controller/processor):

  • When we process personal data to administer our relationship with you (e.g., account creation, billing, support, security, and service communications), Simplif-i acts as an independent controller.
  • When our business customers upload or otherwise provide content to the Services (including compliance documents, evidence, assessments, and related personal data) and determine the purposes and means of that processing, Simplif-i acts as a processor on behalf of the customer. In those cases, our processing is governed by our Data Processing Agreement (DPA) and the customer's instructions.

Simplif-i is designed specifically for compliance-heavy organisations. We understand that the data you process through our platform may include sensitive business, regulatory, and audit information. Protecting that data is not just a legal obligation - it is central to what we do.

2. Information We Collect

2.1 Information You Provide

We collect information that you provide directly when creating an account, using our Services, or contacting us for support:

  • Account information: name, email address, job title, and company name
  • Payment information: billing details processed securely via Stripe; we do not store card data on our systems
  • Compliance documents and evidence: files, records, and supporting materials you upload to the platform
  • Questionnaire responses and assessment data: answers, scores, and structured data generated through compliance workflows
  • Communications: support enquiries, feedback, and any correspondence with our team
  • User preferences: notification settings, communication preferences, and platform configuration choices

2.2 Automatically Collected Information

When you access or use our Services, certain technical and usage data is collected automatically:

  • Device and browser information: operating system, browser type and version, screen resolution
  • Network data: IP address and approximate geographic location derived from it
  • Usage and interaction data: pages visited, features used, session duration, click patterns
  • Log data: server logs, error reports, and diagnostic information
  • Cookies and similar technologies: as described in Section 9 of this Policy

2.3 Sensitive Data

The Services are not intended to require the upload of special category data (e.g., health data) or criminal offence data. Where such data is included in customer content, we process it only on the customer's documented instructions and in accordance with our DPA and applicable law. Customers should avoid uploading such data unless necessary and legally permitted.

We use IP address-derived approximate location primarily for security purposes (e.g., detecting suspicious logins, preventing fraud and abuse) and to support basic service functionality (e.g., language/time zone defaults).

3. How We Use Your Information

We process your information only where we have a lawful basis to do so. Our purposes include:

  • Service delivery: providing, operating, maintaining, and improving the Simplif-i platform
  • Transaction processing: managing subscriptions, billing, and related notifications
  • Customer support: responding to enquiries, troubleshooting issues, and providing technical assistance
  • Platform communications: sending administrative updates, security alerts, and service-related notifications
  • Analytics and improvement: monitoring usage patterns to enhance user experience and platform performance
  • Security: detecting, investigating, and preventing fraudulent activity, unauthorised access, and technical vulnerabilities
  • Legal compliance: meeting our obligations under applicable law, regulation, and contractual requirements
  • Product development: using aggregated and de-identified information (for example, usage telemetry and feature adoption metrics) to guide feature development and improve the Services. We do not use customer content to build profiles about individuals or to identify specific customers, unless permitted by the customer and applicable law.

If we intend to process personal data for a new purpose that is not compatible with the purposes described in this Policy, we will provide an appropriate notice and, where required by applicable law, identify and rely on a valid lawful basis (including obtaining consent where necessary).

Legal bases (summary):

  • Contract (Art. 6(1)(b)): to provide the Services, manage accounts, and deliver support.
  • Legitimate interests (Art. 6(1)(f)): to secure and improve the Services, prevent fraud/abuse, and produce aggregated analytics (balanced against individuals' rights).
  • Legal obligation (Art. 6(1)(c)): to meet applicable legal, regulatory, and accounting obligations.
  • Consent (Art. 6(1)(a)): where required, such as for certain non-essential cookies and optional marketing communications.

4. Data Sharing and Disclosure

We do not sell your personal information to third parties. We may share your information in the following circumstances:

4.1 Service Providers

We engage carefully selected third-party vendors to support our operations - for example, hosting providers, payment processors, analytics platforms, and customer support tools. These providers access your data only to perform services on our behalf and are contractually bound to maintain appropriate data protection standards.

4.2 Legal Requirements

We may disclose your information where required by applicable law, regulation, court order, or formal request by a competent authority. Where legally permitted, we will notify you of such requests.

4.3 Business Transfers

In connection with a merger, acquisition, restructuring, or sale of assets, your information may be transferred as part of that transaction. We will take reasonable steps to ensure the receiving party honours this Privacy Policy or provides you with advance notice of any material changes.

4.4 With Your Consent

We may share your information with third parties where you have provided explicit, informed consent to do so.

4.5 Service providers (processors/sub-processors)

We use third-party service providers (including infrastructure/hosting, payment processing, analytics, and support tooling) that process personal data on our behalf. We require them to (a) process personal data only on our documented instructions, (b) apply appropriate security measures, and (c) enter into data protection terms consistent with UK GDPR/EU GDPR requirements. Where required, we provide a current list of sub-processors and will notify customers of material changes in accordance with our DPA.

Important: We never sell, rent, or trade your personal data to third parties for marketing or commercial purposes.

5. Data Security

We implement appropriate technical and organisational measures to protect your personal information from unauthorised access, disclosure, alteration, or destruction. Our security controls include:

  • TLS 1.3 encryption for all data in transit between your device and our servers
  • Encryption at rest for all stored personal and compliance data
  • Regular security assessments, vulnerability scanning, and penetration testing
  • Role-based access controls and multi-factor authentication mechanisms
  • Ongoing employee security training and awareness programmes
  • Incident response procedures and breach notification protocols

No method of transmission over the internet or electronic storage is 100% secure. While we take the protection of your data seriously, we cannot guarantee absolute security. If you have reason to believe your account has been compromised, please contact us immediately at privacy@simplif-i.com.

6. Data Retention

We retain your personal information for as long as necessary to fulfil the purposes outlined in this Policy, or as required or permitted by applicable law. Specifically:

  • Active account data is retained for the duration of your subscription and any applicable contractual period
  • When you close your account, we will delete or anonymise your personal data within 90 days, except where retention is required for legal, regulatory, or compliance purposes
  • Audit logs and compliance records may be retained for longer periods where this is required by law or requested by you as part of your own compliance obligations
  • Anonymised, aggregated data that cannot be used to identify you may be retained indefinitely for analytical and product improvement purposes

7. Your Rights

Depending on your location, you may have certain rights in relation to your personal data. These rights may include:

  • Access: request a copy of the personal data we hold about you
  • Rectification: request correction of inaccurate or incomplete data
  • Erasure: request deletion of your data (the "right to be forgotten"), subject to legal retention obligations
  • Portability: request transfer of your data in a structured, machine-readable format
  • Objection: object to processing of your data where we rely on legitimate interests as the lawful basis
  • Restriction: request that we limit the processing of your data in certain circumstances
  • Withdrawal of consent: where processing is based on consent, withdraw that consent at any time without affecting the lawfulness of prior processing

To exercise any of these rights, or to raise a question about our data practices, please contact us at privacy@simplif-i.com. We will respond within the timeframe required by applicable law (typically within 30 days). If you are located in the UK or European Economic Area and are not satisfied with our response, you have the right to lodge a complaint with the relevant supervisory authority - in the UK, this is the Information Commissioner's Office (ICO).

8. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence, including countries that may not provide the same level of data protection as your home jurisdiction. Where we transfer personal data outside the UK or the European Economic Area, we ensure appropriate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs) approved by the relevant supervisory authority
  • Transfers to countries with an adequacy decision from the UK or EU
  • Other lawful transfer mechanisms as required by applicable law

For more information about the specific safeguards in place for international transfers, please contact us at privacy@simplif-i.com.

9. Cookies and Tracking Technologies

We use cookies and similar technologies (such as web beacons and local storage) to enhance your experience on our platform, analyse usage, support security features, and, where applicable, assist with marketing efforts. The types of cookies we use include:

  • Strictly necessary cookies: essential for the platform to function; cannot be disabled
  • Performance and analytics cookies: help us understand how users interact with the platform
  • Functional cookies: remember your preferences and personalisation settings
  • Marketing cookies: used to deliver relevant content and measure campaign effectiveness (where applicable)

You can manage your cookie preferences through your browser settings or via any cookie consent tool we provide. Please note that disabling certain cookies may affect the functionality or performance of our Services.

10. Children's Privacy

Our Services are designed for business use and are not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have inadvertently collected personal data from a child under 18, we will take prompt steps to delete that information. If you believe we may have collected such data, please contact us immediately at privacy@simplif-i.com.

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. Where changes are material, we will notify you by posting the updated Policy on this page, updating the "Last updated" date, and, where appropriate, providing additional notice (such as by email or an in-platform notification). Your continued use of our Services following notification of material changes constitutes your acceptance of the updated Policy. We encourage you to review this Policy periodically.

12. Contact Us

If you have any questions, concerns, or requests relating to this Privacy Policy or our data practices, please get in touch:

Organisation: Simplif-i (a subsidiary of OpsLeadershipHub.com)

Email: privacy@simplif-i.com

Website: simplif-i.com

We take every privacy enquiry seriously and will do our best to respond promptly and helpfully.

Simplif-i is built for compliance teams who know that process matters. We hold ourselves to the same standard we help you achieve.

© 2026 Simplif-i. All rights reserved.

Install Simplif-i

Add to your home screen for quick access & offline viewing