Legal

Privacy notice

Last updated 9 October 2026

This notice explains how SIMCON handles personal data in the Agentic Molding Toolkit portal at toolkit.simcon.ai: when you read its pages, request an account, sign in, manage a team, receive a licence or pay for a subscription.

It does not cover the Cadmould Cloud Services that the toolkit calls, which Annex A of the terms of service describes, or SIMCON's website at www.simcon.ai, which has its own privacy policy.

1. Who is responsible

SIMCON kunststofftechnische Software GmbH
Schumanstraße 18a, 52146 Würselen, Germany
Phone: +49 2405 64571-0
Email: product@simcon.com

Data protection officer: exkulpa GmbH, Waldfeuchter Str. 266, 52525 Heinsberg, Germany. Phone: +49 2452 99 33 11. Email: datenschutz@simcon.com.

2. SIMCON's role

SIMCON is the controller for the processing this notice describes, with one exception. Once your company holds a subscription, SIMCON processes the personal data of the people on its team on your company's behalf, under the data processing agreement. For that processing your company is the controller, and SIMCON follows its instructions. SIMCON stays the controller for what it does for its own purposes: security, licence enforcement, billing and the statistics in section 3.

3. What we process and why

Reading the portal

When you open a page, your browser sends your IP address and details of the request, such as the page, the time, your browser and the page you came from. Vercel, which hosts the portal, uses them to deliver the page and to protect the portal against attacks. Legal basis: Article 6(1)(f) GDPR, our legitimate interest in a secure and working website.

Requesting an account

On Request an account you give your email address, your name and, if you like, your company, and you accept the terms of service. We use them to set up your sign-in and to decide on your request. Auth0 holds your name and email address. The portal's database holds your name, your company, when you asked, and which version of the terms you accepted and when. SIMCON's Sales and accounting teams are told of your request by email, with your name, company and email address. Legal basis: Article 6(1)(b) GDPR, steps taken at your request before a contract.

Signing in

You sign in with a one-time code that Auth0 sends to your email address. Auth0 records each sign-in, including your IP address, to protect accounts against misuse. To limit misuse, the portal also counts sign-in attempts for each hour, by email address, kept only as a one-way hash, and by IP address. Legal basis: Article 6(1)(b) GDPR for the sign-in, and Article 6(1)(f) GDPR, our legitimate interest in preventing misuse, for the records and counters.

Your team

The owner of an account can add colleagues to its team by entering each colleague's name and email address. We tell each colleague by email that they have been added. If you were added by your company's account owner, that is where we received your data from. Legal basis: Article 6(1)(b) GDPR, the contract with your company, and Article 6(1)(f) GDPR, our legitimate interest in giving its team access.

Licences

Each person on a team receives a Cadmould licence in their own name. Their name and email address go to Thales Sentinel EMS, which issues the licence. SIMCON staff issue licences there, or a workflow on n8n does it for the portal. When you activate the licence on a computer, Sentinel EMS records an identifier of that device. When a person leaves a team or the subscription ends, their licence is taken back. Legal basis: Article 6(1)(b) GDPR.

Paying

A subscription paid by card is paid on Stripe's own checkout page. Your card details and billing address go to Stripe only, never to the portal. The portal keeps Stripe's identifiers for your company and its subscription, and the subscription's status. Stripe also uses payment data for its own fraud prevention and legal duties, as an independent controller under its own privacy policy. A subscription arranged with SIMCON's Sales team is invoiced by SIMCON's accounting. Legal basis: Article 6(1)(b) GDPR, and Article 6(1)(c) GDPR for the records that tax and commercial law require us to keep.

Emails from the portal

The portal sends emails about your account through Resend, from servers in Ireland: when you are added to a team, when a subscription becomes active or ends, and when the terms of service, the data processing agreement or the list of service providers changes. The emails contain no tracking pixels and no tracked links. The sign-in code is sent by Auth0. Legal basis: Article 6(1)(b) GDPR.

Statistics

To learn whether sign-up and licensing work, the portal's server records these steps in PostHog: a sign-in, the start of a payment, a paid subscription, a licence issued or failed, and a colleague added. Each record carries your Auth0 user identifier and a few facts about the step, such as the interval and amount of a subscription or the size of a team. It carries no email address, no name and no IP address of yours, and nothing about the pages you read or where you click. These records are made on the live portal only. Legal basis: Article 6(1)(f) GDPR, our legitimate interest in knowing that sign-up works. You can object at any time, see section 9.

Errors

When something fails on the portal's server, it records the error so that SIMCON can fix it. Error records are cleaned of email addresses before they are stored. Legal basis: Article 6(1)(f) GDPR, our legitimate interest in a working portal.

What SIMCON staff do

When SIMCON staff act on an account, for example to activate it or to remove a colleague, the portal records who did it, to which person and company, and when. Legal basis: Article 6(1)(f) GDPR, our legitimate interest in being able to account for what staff did.

4. Cookies

The portal sets only the cookies it needs to sign you in and to finish a form you started. Under § 25(2) no. 2 TDDDG these need no consent, which is why the portal shows no cookie banner. On the live portal each one is sent only over an encrypted connection and cannot be read by scripts on the page. The portal stores nothing else in your browser: no local storage and no session storage.

CookieWhat it is forHow long it lives
__sessionKeeps you signed in. It holds your sign-in, encrypted, and is split into numbered parts when it grows large.Ends after a day without use, and at the latest three days after you sign in, or when you log out.
__txn_Holds one sign-in in progress, so the portal can check the answer it gets back from the sign-in page.One hour, or until the sign-in is complete.
request_typedHolds the name, company and acceptance you entered on Request an account until the emailed code confirms your address. It is sent only to /auth/landed.15 minutes, or until it is used.
signin_refused_emailHolds the address of a sign-in that was refused, so the sign-in page can show it again. It is sent only to /login.60 seconds.

You may also see cookies the portal does not set:

  • The sign-in page. The page where you enter your code belongs to Auth0, which sets its own cookies there to run the sign-in safely.
  • Stripe's checkout. Stripe's checkout page sets its own cookies on Stripe's domain, for example to prevent fraud.
  • Cookies of www.simcon.ai. SIMCON's website may set cookies for the whole simcon.ai domain, for example for its consent tool, for HubSpot or for advertising. If you have visited that website, your browser also sends those cookies to the portal, because the portal is part of the same domain. The portal does not set, read or use them. You decide about them in the consent settings of www.simcon.ai, and its cookie policy describes them.

5. What the portal does not use

  • No analytics, tracking or advertising cookies.
  • No analytics or tracking scripts in your browser. The statistics in section 3 are sent from our server.
  • No fonts, scripts, maps or videos loaded from other companies. The fonts are part of the portal, and the office address in the footer only links to Google Maps.
  • No social media buttons or plugins.
  • No tracking pixels or tracked links in emails.
  • No email addresses in the portal's own database. People are referenced by their Auth0 user identifier.
  • No profiling, and no decisions about you made only by automated means (Article 22 GDPR).
  • No selling or renting of personal data.

6. Who receives data

SIMCON uses these service providers. Each processes personal data on SIMCON's instructions, under a data processing agreement. Stripe also uses payment data on its own account, for fraud prevention and its legal duties, as section 3 says.

ProviderWhat it doesWhat it receivesWhere
VercelHosts the portalIP address and request detailsFrankfurt, with files served from Vercel's network worldwide
NeonRuns the portal's databaseAccount, team, licence and acceptance records, with names and companyFrankfurt
Auth0 by OktaSigns people inName, email address, sign-in records with IP addressEU
StripeTakes card paymentsCard and billing details, email addressEU and USA
ResendSends the portal's emailsEmail address, name and the email's contentIreland
PostHogRecords the statistics in section 3Auth0 user identifier and the facts of each stepEU
n8nRuns the workflow that issues licencesName and email addressEU
Thales Sentinel EMSIssues Cadmould licences and activates them on devicesName, email address and device identifierEU
Amazon Web ServicesHosts the Cadmould Cloud ServicesSee Annex A of the terms of serviceEU
Grafana CloudMonitors the Cadmould Cloud ServicesSee Annex A of the terms of serviceEU

Some of these providers are based in the USA, or may give their staff there access for support. Where personal data leaves the European Union, it is protected by the EU-US Data Privacy Framework or by the EU Standard Contractual Clauses.

Within SIMCON, only the people who need your data for their work see it: Sales, accounting, support and the toolkit's product team. We disclose personal data to authorities only where the law requires it.

7. How long we keep it

  • Your account, its team, licences and the terms accepted: for as long as the account exists. When an account is closed, the portal takes back its licences, deletes the Stripe customer and deletes its own records. A request SIMCON declines is deleted.
  • A person who leaves a team: deleted from the portal once their licence has been taken back.
  • Your Auth0 sign-in: it stays after an account closes, because the same sign-in also opens other SIMCON products. Ask us and we delete it, see section 9.
  • Invoices and payment records: for as long as German commercial and tax law requires, up to ten years (§ 257 HGB, § 147 AO).
  • Records of staff actions: 365 days.
  • Error records: 30 days after the error last occurred.
  • Sign-in attempt counters: 1 hour. Counters for past hours are deleted with the next attempt.
  • Statistics: for as long as they help us see whether sign-up works.
  • Cookies: as in section 4.

8. Do you have to give us your data?

To receive an account you need to give your email address and your name, and you need an account to use the toolkit. Your company is optional. Without your email address and name we cannot set up an account.

9. Your rights

You have the right to access your personal data (Article 15 GDPR), to have it corrected (Article 16), to have it deleted (Article 17), to restrict its processing (Article 18) and to receive it in a portable format (Article 20).

Right to object (Article 21 GDPR). Where we process your data on the basis of our legitimate interests, Article 6(1)(f) GDPR, you can object at any time on grounds relating to your particular situation. We then stop, unless we can show compelling legitimate grounds that override your interests, or the processing serves to establish, exercise or defend legal claims.

To use any of these rights, write to datenschutz@simcon.com or to the address in section 1. Where your company is the controller (section 2), we pass your request to your company and help it answer.

You also have the right to lodge a complaint with a supervisory authority (Article 77 GDPR). The authority for SIMCON is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestraße 2-4, 40213 Düsseldorf, Germany.

10. Changes to this notice

We update this notice when the portal changes how it handles personal data. The date at the top says when it last changed.