This notice explains how SIMCON handles personal data in the Agentic Molding Toolkit portal at toolkit.simcon.ai: when you read its pages, request an account, sign in, manage a team, receive a licence or pay for a subscription.
It does not cover the Cadmould Cloud Services that the toolkit calls, which Annex A of the terms of service describes, or SIMCON's website at www.simcon.ai, which has its own privacy policy.
1. Who is responsible
SIMCON kunststofftechnische Software GmbH
Schumanstraße 18a, 52146 Würselen, Germany
Phone: +49 2405 64571-0
Email: product@simcon.com
Data protection officer: exkulpa GmbH, Waldfeuchter Str. 266, 52525 Heinsberg, Germany. Phone: +49 2452 99 33 11. Email: datenschutz@simcon.com.
2. SIMCON's role
SIMCON is the controller for the processing this notice describes, with one exception. Once your company holds a subscription, SIMCON processes the personal data of the people on its team on your company's behalf, under the data processing agreement. For that processing your company is the controller, and SIMCON follows its instructions. SIMCON stays the controller for what it does for its own purposes: security, licence enforcement, billing and the statistics in section 3.
3. What we process and why
Reading the portal
When you open a page, your browser sends your IP address and details of the request, such as the page, the time, your browser and the page you came from. Vercel, which hosts the portal, uses them to deliver the page and to protect the portal against attacks. Legal basis: Article 6(1)(f) GDPR, our legitimate interest in a secure and working website.
Requesting an account
On Request an account you give your email address, your name and, if you like, your company, and you accept the terms of service. We use them to set up your sign-in and to decide on your request. Auth0 holds your name and email address. The portal's database holds your name, your company, when you asked, and which version of the terms you accepted and when. SIMCON's Sales and accounting teams are told of your request by email, with your name, company and email address. Legal basis: Article 6(1)(b) GDPR, steps taken at your request before a contract.
Signing in
You sign in with a one-time code that Auth0 sends to your email address. Auth0 records each sign-in, including your IP address, to protect accounts against misuse. To limit misuse, the portal also counts sign-in attempts for each hour, by email address, kept only as a one-way hash, and by IP address. Legal basis: Article 6(1)(b) GDPR for the sign-in, and Article 6(1)(f) GDPR, our legitimate interest in preventing misuse, for the records and counters.
Your team
The owner of an account can add colleagues to its team by entering each colleague's name and email address. We tell each colleague by email that they have been added. If you were added by your company's account owner, that is where we received your data from. Legal basis: Article 6(1)(b) GDPR, the contract with your company, and Article 6(1)(f) GDPR, our legitimate interest in giving its team access.
Licences
Each person on a team receives a Cadmould licence in their own name. Their name and email address go to Thales Sentinel EMS, which issues the licence. SIMCON staff issue licences there, or a workflow on n8n does it for the portal. When you activate the licence on a computer, Sentinel EMS records an identifier of that device. When a person leaves a team or the subscription ends, their licence is taken back. Legal basis: Article 6(1)(b) GDPR.
Paying
A subscription paid by card is paid on Stripe's own checkout page. Your card details and billing address go to Stripe only, never to the portal. The portal keeps Stripe's identifiers for your company and its subscription, and the subscription's status. Stripe also uses payment data for its own fraud prevention and legal duties, as an independent controller under its own privacy policy. A subscription arranged with SIMCON's Sales team is invoiced by SIMCON's accounting. Legal basis: Article 6(1)(b) GDPR, and Article 6(1)(c) GDPR for the records that tax and commercial law require us to keep.
Emails from the portal
The portal sends emails about your account through Resend, from servers in Ireland: when you are added to a team, when a subscription becomes active or ends, and when the terms of service, the data processing agreement or the list of service providers changes. The emails contain no tracking pixels and no tracked links. The sign-in code is sent by Auth0. Legal basis: Article 6(1)(b) GDPR.
Statistics
To learn whether sign-up and licensing work, the portal's server records these steps in PostHog: a sign-in, the start of a payment, a paid subscription, a licence issued or failed, and a colleague added. Each record carries your Auth0 user identifier and a few facts about the step, such as the interval and amount of a subscription or the size of a team. It carries no email address, no name and no IP address of yours, and nothing about the pages you read or where you click. These records are made on the live portal only. Legal basis: Article 6(1)(f) GDPR, our legitimate interest in knowing that sign-up works. You can object at any time, see section 9.
Errors
When something fails on the portal's server, it records the error so that SIMCON can fix it. Error records are cleaned of email addresses before they are stored. Legal basis: Article 6(1)(f) GDPR, our legitimate interest in a working portal.
What SIMCON staff do
When SIMCON staff act on an account, for example to activate it or to remove a colleague, the portal records who did it, to which person and company, and when. Legal basis: Article 6(1)(f) GDPR, our legitimate interest in being able to account for what staff did.
4. Cookies
The portal sets only the cookies it needs to sign you in and to finish a form you started. Under § 25(2) no. 2 TDDDG these need no consent, which is why the portal shows no cookie banner. On the live portal each one is sent only over an encrypted connection and cannot be read by scripts on the page. The portal stores nothing else in your browser: no local storage and no session storage.
| Cookie | What it is for | How long it lives |
|---|---|---|
__session | Keeps you signed in. It holds your sign-in, encrypted, and is split into numbered parts when it grows large. | Ends after a day without use, and at the latest three days after you sign in, or when you log out. |
__txn_ | Holds one sign-in in progress, so the portal can check the answer it gets back from the sign-in page. | One hour, or until the sign-in is complete. |
request_typed | Holds the name, company and acceptance you entered on Request an account until the emailed code confirms your address. It is sent only to /auth/landed. | 15 minutes, or until it is used. |
signin_refused_email | Holds the address of a sign-in that was refused, so the sign-in page can show it again. It is sent only to /login. | 60 seconds. |
You may also see cookies the portal does not set:
- The sign-in page. The page where you enter your code belongs to Auth0, which sets its own cookies there to run the sign-in safely.
- Stripe's checkout. Stripe's checkout page sets its own cookies on Stripe's domain, for example to prevent fraud.
- Cookies of www.simcon.ai. SIMCON's website may set cookies for the whole simcon.ai domain, for example for its consent tool, for HubSpot or for advertising. If you have visited that website, your browser also sends those cookies to the portal, because the portal is part of the same domain. The portal does not set, read or use them. You decide about them in the consent settings of www.simcon.ai, and its cookie policy describes them.
5. What the portal does not use
- No analytics, tracking or advertising cookies.
- No analytics or tracking scripts in your browser. The statistics in section 3 are sent from our server.
- No fonts, scripts, maps or videos loaded from other companies. The fonts are part of the portal, and the office address in the footer only links to Google Maps.
- No social media buttons or plugins.
- No tracking pixels or tracked links in emails.
- No email addresses in the portal's own database. People are referenced by their Auth0 user identifier.
- No profiling, and no decisions about you made only by automated means (Article 22 GDPR).
- No selling or renting of personal data.
6. Who receives data
SIMCON uses these service providers. Each processes personal data on SIMCON's instructions, under a data processing agreement. Stripe also uses payment data on its own account, for fraud prevention and its legal duties, as section 3 says.
| Provider | What it does | What it receives | Where |
|---|---|---|---|
| Vercel | Hosts the portal | IP address and request details | Frankfurt, with files served from Vercel's network worldwide |
| Neon | Runs the portal's database | Account, team, licence and acceptance records, with names and company | Frankfurt |
| Auth0 by Okta | Signs people in | Name, email address, sign-in records with IP address | EU |
| Stripe | Takes card payments | Card and billing details, email address | EU and USA |
| Resend | Sends the portal's emails | Email address, name and the email's content | Ireland |
| PostHog | Records the statistics in section 3 | Auth0 user identifier and the facts of each step | EU |
| n8n | Runs the workflow that issues licences | Name and email address | EU |
| Thales Sentinel EMS | Issues Cadmould licences and activates them on devices | Name, email address and device identifier | EU |
| Amazon Web Services | Hosts the Cadmould Cloud Services | See Annex A of the terms of service | EU |
| Grafana Cloud | Monitors the Cadmould Cloud Services | See Annex A of the terms of service | EU |
Some of these providers are based in the USA, or may give their staff there access for support. Where personal data leaves the European Union, it is protected by the EU-US Data Privacy Framework or by the EU Standard Contractual Clauses.
Within SIMCON, only the people who need your data for their work see it: Sales, accounting, support and the toolkit's product team. We disclose personal data to authorities only where the law requires it.
7. How long we keep it
- Your account, its team, licences and the terms accepted: for as long as the account exists. When an account is closed, the portal takes back its licences, deletes the Stripe customer and deletes its own records. A request SIMCON declines is deleted.
- A person who leaves a team: deleted from the portal once their licence has been taken back.
- Your Auth0 sign-in: it stays after an account closes, because the same sign-in also opens other SIMCON products. Ask us and we delete it, see section 9.
- Invoices and payment records: for as long as German commercial and tax law requires, up to ten years (§ 257 HGB, § 147 AO).
- Records of staff actions: 365 days.
- Error records: 30 days after the error last occurred.
- Sign-in attempt counters: 1 hour. Counters for past hours are deleted with the next attempt.
- Statistics: for as long as they help us see whether sign-up works.
- Cookies: as in section 4.
8. Do you have to give us your data?
To receive an account you need to give your email address and your name, and you need an account to use the toolkit. Your company is optional. Without your email address and name we cannot set up an account.
9. Your rights
You have the right to access your personal data (Article 15 GDPR), to have it corrected (Article 16), to have it deleted (Article 17), to restrict its processing (Article 18) and to receive it in a portable format (Article 20).
Right to object (Article 21 GDPR). Where we process your data on the basis of our legitimate interests, Article 6(1)(f) GDPR, you can object at any time on grounds relating to your particular situation. We then stop, unless we can show compelling legitimate grounds that override your interests, or the processing serves to establish, exercise or defend legal claims.
To use any of these rights, write to datenschutz@simcon.com or to the address in section 1. Where your company is the controller (section 2), we pass your request to your company and help it answer.
You also have the right to lodge a complaint with a supervisory authority (Article 77 GDPR). The authority for SIMCON is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestraße 2-4, 40213 Düsseldorf, Germany.
10. Changes to this notice
We update this notice when the portal changes how it handles personal data. The date at the top says when it last changed.