Data processing agreement
When an app uses SIMEZU for identity or payments, that app is the controller of its users' personal data and SIMEZU is the processor. These are the Article 28 terms that relationship runs on. They apply automatically to every connected app; no separate signature is required, though one can be issued on request.
Roles
The connected app decides why and how its users' data is processed and is therefore the controller. SIMEZU processes that data only to deliver identity, access and payment services, and only on the app's documented instructions — the API calls it makes and the settings it configures are those instructions.
Subject matter and duration
Processing lasts as long as the app remains connected. When an app is disconnected, its data is deleted or returned within 30 days, except where SIMEZU must retain records to meet its own legal obligations — invoices, most notably, which tax law requires us to keep.
Categories of data
Identity data (name, email, authentication factors), access data (sessions, devices, IP addresses, granted scopes), and payment data (a tokenised payment profile and transaction records). SIMEZU never stores full card numbers; those stay with the payment provider.
Confidentiality
Everyone at SIMEZU with access to personal data is bound by confidentiality obligations and works under access controls scoped to their role. Access is logged in a tamper-evident audit trail.
Security
Encryption in transit and at rest, hashed credentials, MFA, rate limiting, anomaly detection and an HMAC-chained audit log. Security measures are reviewed continuously; specifics are on the security page.
Sub-processors
SIMEZU uses a small number of sub-processors, each bound by equivalent obligations. We publish changes here before they take effect so a controller can object.
- Mollie B.V. (Netherlands) — payment processing.
- Stripe Payments Europe Ltd. (Ireland) — payment processing.
- PayPal (Europe) S.à r.l. (Luxembourg) — payment processing and payouts.
- European hosting infrastructure — application and database hosting, EU region only.
International transfers
Data stays in the European Union. Where a sub-processor is reached outside the EU, transfers rely on an adequacy decision or Standard Contractual Clauses with supplementary measures.
Assistance to the controller
SIMEZU assists the app in answering data subject requests, in carrying out impact assessments, and in notifying the supervisory authority where required. Most access, export and erasure requests can be served directly from the account and the admin API without contacting us.
Breach notification
SIMEZU notifies affected controllers without undue delay and in any case within 48 hours of becoming aware of a personal data breach, with the information needed for the controller to meet its own 72-hour obligation.
Audits
SIMEZU makes available the information needed to demonstrate compliance with Article 28 and allows for audits by the controller or an auditor it mandates, on reasonable notice and without disrupting other customers.
Deletion and return
On termination the controller chooses deletion or return of the data. Backups age out on their normal rotation; nothing is restored from them into live systems after a deletion request.