GDPR
SIMEZU was built in Europe, for European rules. This page sets out what the GDPR entitles you to and, more usefully, where in the product each of those rights actually lives — most of them are a button in your account rather than an email to us.
Access
You can see the personal data SIMEZU holds about you from your account: profile, connected apps, active sessions, subscriptions and invoices. If you want the whole record in one file, ask and we will send it in a machine-readable format within 30 days.
Portability
Your data is yours to take elsewhere. Export is delivered as structured JSON, covering the data you provided and the data generated by your use of the service.
Correction
Name, email and profile details are editable from your account and change everywhere at once — SIMEZU is the single identity behind every connected app, so there is nothing to correct app by app.
Erasure
You can delete your SIMEZU identity, which removes it across every app that relies on it. Two things survive, and they are the same two the law requires: invoices, which tax rules oblige us to keep for seven years, and the tamper-evident security log, which is retained on a rolling basis and then anonymised.
Restriction and objection
You can ask us to restrict processing while a dispute is resolved, and object to processing based on legitimate interest. Email privacy@simezu.com and we will act on it.
Consent
Where we rely on consent — optional communications, for instance — you can withdraw it at any time, and withdrawing it is as easy as giving it. Nothing essential to the service depends on consent, because consent is the wrong basis for something you cannot decline and still use the product.
Where your data lives
European infrastructure, EU region only. Sub-processors are listed in the data processing agreement, each bound by equivalent obligations.
For apps building on SIMEZU
If you run an app on SIMEZU you are the controller for your users and SIMEZU is your processor. The Article 28 terms are in the data processing agreement, and the admin API exposes the endpoints you need to serve access, export and erasure requests yourself.
Complaints
If you think we have handled your data wrongly, tell us first at privacy@simezu.com — we would rather fix it. You also have the right to complain to your national supervisory authority; in the Netherlands that is the Autoriteit Persoonsgegevens.