Legal

Data processing agreement

In force since 9 October 2026

Data Processing Agreement

Agentic Molding Toolkit and Cadmould Cloud Services

This Data Processing Agreement (this “DPA”) is concluded between the company that holds a subscription to the Agentic Molding Toolkit (the “Customer”) and SIMCON kunststofftechnische Software GmbH, Schumanstraße 18a, 52146 Würselen, Germany (“SIMCON”). It sets out the terms that Article 28(3) of Regulation (EU) 2016/679 (the “GDPR”) requires for the personal data SIMCON processes on the Customer’s behalf. It forms part of the agreement under which SIMCON provides the subscription, including the Operational Usage Terms (together, the “Agreement”).

1. Subject matter and roles

1.1 SIMCON processes personal data on the Customer’s behalf in providing the subscription: the self-service portal where the Customer’s account owner signs in and manages a team, the Cadmould licence issued to each person on that team, the software development kit, and the Cadmould Cloud Services those people use (together, the “Services”).

1.2 For that personal data the Customer is the controller and SIMCON is the processor. This DPA does not apply to personal data SIMCON processes as a controller for its own purposes, such as service security, licence enforcement and billing under Section 8 of the Operational Usage Terms.

1.3 If this DPA conflicts with the Agreement on the protection of personal data, this DPA prevails.

2. Duration

This DPA applies for as long as SIMCON processes personal data on the Customer’s behalf: from the Customer’s first use of the Services until that personal data is deleted or returned under Section 11.

3. Nature and purpose of the processing

SIMCON processes the personal data only to provide the Services: storing account, team, subscription and licence records; signing people in; issuing and withdrawing Cadmould licences; running the simulations people request; sending the emails the Services send; and support.

4. Data subjects and personal data

4.1 Data subjects: the Customer’s account owner and the colleagues the owner adds to the team, as a rule the Customer’s employees and contractors.

4.2 Personal data: name, business email address, company, sign-in identifier, team role, licence and acceptance records, IP address and request metadata, and the device identifier used to activate a licence.

4.3 Simulation data (geometries, meshes, material and process parameters, results) is not intended to contain personal data, and the Customer shall not submit any (Section 9.3 of the Operational Usage Terms). Personal data it contains nonetheless is processed under this DPA. No special categories of personal data under Article 9 GDPR are processed.

5. Instructions

5.1 SIMCON processes the personal data only on the Customer’s documented instructions, including with regard to transfers to a third country or an international organisation, unless Union or Member State law to which SIMCON is subject requires it to do otherwise. In that case SIMCON informs the Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.

5.2 The Agreement, this DPA and the Customer’s use of the functions of the Services, such as adding or removing a colleague, are the Customer’s documented instructions. Further instructions are given in text form.

5.3 SIMCON informs the Customer immediately if, in its opinion, an instruction infringes the GDPR or other Union or Member State data protection provisions.

6. Confidentiality

SIMCON ensures that the persons it authorises to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

7. Security of processing

SIMCON takes all measures required under Article 32 GDPR. Annex 1 describes them. SIMCON may adapt them to technical progress, provided the level of protection does not fall below the level described there.

8. Sub-processors

8.1 The Customer gives SIMCON general written authorisation to engage the sub-processors listed under Sub-processors on the current page of this DPA, toolkit.simcon.ai/legal/dpa.

8.2 SIMCON informs the Customer’s account owner by email of any intended addition or replacement of a sub-processor at least 15 days before it starts processing the Customer’s personal data. The Customer may object to the change within that period.

8.3 SIMCON imposes on each sub-processor, by contract, the same data protection obligations as this DPA sets out, in particular sufficient guarantees to implement appropriate technical and organisational measures so that the processing meets the requirements of the GDPR. Where a sub-processor fails to fulfil those obligations, SIMCON remains fully liable to the Customer for the performance of that sub-processor’s obligations.

9. Transfers outside the European Economic Area

SIMCON transfers personal data to a country outside the European Economic Area, or allows a sub-processor to do so, only where the conditions of Chapter V GDPR are met, such as an adequacy decision, including the EU-US Data Privacy Framework, or the EU Standard Contractual Clauses.

10. Assistance

10.1 Taking into account the nature of the processing, SIMCON assists the Customer by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Customer’s obligation to respond to requests from data subjects exercising their rights under Chapter III GDPR. SIMCON forwards to the Customer without undue delay any such request it receives directly.

10.2 Taking into account the nature of the processing and the information available to it, SIMCON assists the Customer in ensuring compliance with its obligations under Articles 32 to 36 GDPR. In particular, SIMCON notifies the Customer without undue delay after becoming aware of a personal data breach affecting the Customer’s personal data, with the information Article 33(3) GDPR requires as far as it is available.

11. Deletion and return

11.1 When the Services end, SIMCON deletes the personal data it processes on the Customer’s behalf or, at the Customer’s choice made before they end, returns it to the Customer, and deletes existing copies, unless Union or Member State law requires storage of the personal data.

11.2 Closing the Customer’s account deletes its team, subscription and licence records from the portal and withdraws its licences. Each person’s sign-in identity is shared with other SIMCON products and is not deleted by the close. A person may ask SIMCON to delete it. SIMCON’s own record of the actions its staff took on the account keeps the person’s name and sign-in identifier, and is deleted after one year.

12. Information and audits

SIMCON makes available to the Customer all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR, and allows for and contributes to audits, including inspections, conducted by the Customer or another auditor mandated by the Customer. The Customer gives reasonable notice of an audit, which takes place during business hours without disrupting operations, and any auditor is bound to confidentiality.

13. Records and contact

SIMCON keeps a record of the processing activities it carries out on behalf of its customers under Article 30(2) GDPR. Data Protection Officer: exkulpa GmbH, Waldfeuchter Str. 266, 52525 Heinsberg, Germany. Email: datenschutz@simcon.com.

Annex 1

Technical and organisational measures

These measures cover the self-service portal. The Cadmould Cloud Services run in the EU on Amazon Web Services, where partners are separated logically through access controls (Annex A.5 of the Operational Usage Terms).

  • Location. The portal’s database and server functions run in Frankfurt, Germany.
  • Encryption. Data is encrypted in transit with TLS, and at rest by the hosting and database providers.
  • Sign-in for customers. People sign in with a one-time code sent to their email address. No passwords are kept.
  • Access within an account. An account owner manages only their own team. A colleague sees their own details and a read-only view of the team.
  • Access for SIMCON staff. Staff sign in through SIMCON’s Microsoft single sign-on. They act on the edge of a customer’s account, never inside it, and cannot sign in as a customer. Every action they take is recorded with who took it.
  • Data minimisation. The portal’s database stores no email addresses and refers to people by their sign-in identifier. Error records are kept free of email addresses and are deleted after 30 days.
  • Separation of environments. Production runs on its own database, apart from test environments, so the credentials of one cannot open the other.
  • Least privilege. The keys the portal holds for other services are limited to the permissions it needs.
  • Abuse protection. Sign-ins and account requests are rate-limited.
  • Recovery. The database provider offers point-in-time restore.

Sub-processors

CompanyWhat it does
VercelHosts the portal
NeonStores account and team records
Auth0 by OktaSigns people in, and holds their names and email addresses
StripeTakes payments, and holds billing details
ResendSends the portal's mails
n8nRuns the workflow that issues Cadmould licences
PostHogCounts sign-up and payment steps against a pseudonymous id
Amazon Web ServicesHosts the Cadmould Cloud Services and the data submitted to them
Thales Sentinel EMSIssues Cadmould licences and activates the devices they run on
Grafana CloudMonitors the Cadmould Cloud Services