1. Scope and parties
This Data Processing Addendum (“DPA”) forms part of the Simpace Terms of Use between the user accepting those Terms (“Controller”) and Hanna Kapova-Savanova, an individual entrepreneur operating under the Simpace brand (“Processor”).
This DPA applies automatically to the extent Processor processes personal data on behalf of Controller in connection with the Services. It does not apply to personal data for which Simpace independently determines the purposes and means of processing; that data is governed by the Privacy Policy.
If Controller processes personal data on behalf of another controller, Controller confirms that it is authorized to appoint Processor and give instructions under this DPA.
2. Definitions
“Applicable Data Protection Law” means the GDPR and other data-protection law applicable to the processing.
“Controller”, “data subject”, “personal data”, “personal-data breach”, “processing”, “processor”, and “supervisory authority” have the meanings given in Applicable Data Protection Law.
“GDPR” means Regulation (EU) 2016/679.
“Subprocessor” means another processor engaged by Processor to process personal data covered by this DPA.
3. Processing details
The subject matter, nature, purpose, and duration of processing, as well as the categories of data and data subjects, are described in Annex 1.
Processor will:
- process personal data only on Controller’s documented instructions, including instructions given through use and configuration of the Services, unless processing is required by law;
- inform Controller before processing required by law unless the law prohibits that notice;
- immediately inform Controller if, in Processor’s opinion, an instruction infringes Applicable Data Protection Law; and
- process personal data only for the duration and purposes specified in this DPA.
Controller instructs Processor to process personal data as necessary to provide, secure, maintain, back up, support, and delete the Services and to engage the Subprocessors listed in Annex 3.
4. Controller responsibilities
Controller is responsible for:
- the lawfulness, fairness, accuracy, and transparency of its processing;
- providing required notices to data subjects;
- having an applicable Article 6 legal basis and, where relevant, an Article 9 condition for special-category data;
- limiting personal data to what is necessary;
- ensuring its instructions comply with law; and
- responding to data subjects, regulators, and other third parties as controller.
5. Confidentiality
Processor ensures that persons authorized to process personal data are bound by confidentiality obligations and receive access only where necessary for their duties.
6. Security
Processor will implement and maintain appropriate technical and organizational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Current measures are described in Annex 2.
Controller is responsible for using available security features appropriately, protecting account credentials and devices, and considering whether the Services and available measures are suitable for its processing risks.
7. Subprocessors
Controller gives Processor general written authorization to engage the Subprocessors listed in Annex 3. Processor will impose data-protection obligations on each Subprocessor that are no less protective than the relevant obligations in this DPA, to the extent applicable to the services provided.
Processor may add or replace Subprocessors. Processor will give Controller reasonable advance notice of an intended material change by email or another durable electronic method, allowing Controller to object on reasonable data-protection grounds. If the parties cannot resolve a valid objection, Controller may stop using the affected feature or terminate the affected Services before the new Subprocessor begins processing.
Processor remains responsible for each Subprocessor’s performance of its data-protection obligations to the extent required by Applicable Data Protection Law.
8. Data-subject requests
Taking into account the nature of processing, Processor will provide reasonable assistance through appropriate technical and organizational measures so Controller can respond to requests concerning access, rectification, erasure, restriction, objection, and portability.
If Processor receives a request concerning personal data processed solely for Controller, Processor will not respond substantively except on Controller’s instructions or as required by law. Processor may direct the data subject to Controller and will notify Controller where reasonably identifiable and legally permitted.
9. Personal-data breaches
Processor will notify Controller without undue delay after becoming aware of a personal-data breach affecting personal data covered by this DPA. The notice will provide information reasonably available to Processor that Controller needs to meet its notification obligations, including where available:
- the nature of the breach;
- affected categories of data and data subjects;
- likely consequences;
- measures taken or proposed; and
- a contact for further information.
Processor may provide information in phases as it becomes available. Notification is not an admission of fault or liability.
10. Assistance and compliance information
Taking into account the nature of processing and information available to Processor, Processor will reasonably assist Controller with security, breach notification, data-protection impact assessments, and prior consultation obligations.
Processor will make available information reasonably necessary to demonstrate compliance with Article 28 GDPR. On reasonable written notice, Controller may request relevant compliance information. If that information is insufficient, Controller may conduct or commission an audit no more than once annually, unless a personal-data breach or regulator requires more frequent review. Audits must protect other customers, confidentiality, security, and system availability and must not involve access to other users’ data.
11. International transfers
Processor’s primary application hosting and database infrastructure are located in the European Union. Processor will not transfer personal data covered by this DPA outside the EEA unless the transfer complies with Applicable Data Protection Law through an adequacy decision, Standard Contractual Clauses, or another valid mechanism.
Where legally required, the then-current European Commission Standard Contractual Clauses are incorporated by reference and apply to the relevant restricted transfer. The parties will complete or interpret their modules and annexes according to their respective roles and the processing described in this DPA.
12. Return and deletion
During an active account, Controller may access personal data through the available functionality of the Services. Simpace does not currently provide a self-service bulk-export feature, but Processor will reasonably assist with legally required access or portability requests.
On account deletion or termination, Processor will delete personal data from active systems after the seven-day deletion period unless law requires retention. Backups are retained for up to 30 days, so final removal from active systems and backups may take up to 37 days from the initial request. During backup retention, personal data remains protected and is not restored except where necessary for disaster recovery or legal compliance.
Processor may retain data that has been irreversibly anonymized or that it must retain by law, provided it remains protected and is used only for the applicable lawful purpose.
13. Liability and precedence
Liability under this DPA is subject to the limitations in the Terms to the extent permitted by Applicable Data Protection Law. Nothing limits data-subject rights or regulatory powers.
If this DPA conflicts with the Terms regarding processing covered by this DPA, this DPA prevails. If valid Standard Contractual Clauses conflict with this DPA, the Standard Contractual Clauses prevail.
14. Contact
Notices and requests concerning this DPA should be sent to legal@simpace.app.
Processor: Hanna Kapova-Savanova
Operating under the Simpace brand
NIP: 1122334455
Poland, Warsaw, Divizjonu AK Bayt 5, 32
Annex 1 — Processing description
Subject matter: provision of Simpace’s practice-management, note, document, calendar, financial-record, synchronization, backup, and related features.
Duration: for the term of the account and the deletion and backup periods described in section 12, unless Controller instructs earlier deletion or law requires retention.
Nature and purpose: collection, transmission, organization, storage, retrieval, display, synchronization, backup, support, security, and deletion of personal data solely to provide and protect the Services on Controller’s instructions.
Data subjects may include: Controller’s clients and prospective clients; practitioners; supervisors and supervisees; professional contacts; employees, contractors, and representatives; and other individuals whose information Controller lawfully enters.
Categories of personal data may include: names, aliases, contact details, country, identifiers, professional relationships, calendar and session information, prices and payment status, notes, forms, documents, feedback, supervision materials, and other content selected by Controller.
Special categories may include: information concerning physical or mental health and other special-category information that Controller chooses to enter. Controller must not enter such data unless it has an applicable Article 9 GDPR condition and has assessed that the Services are appropriate for the processing.
Processing frequency: continuous or as initiated by Controller through use of the Services.
Annex 2 — Technical and organizational measures
Processor maintains measures appropriate to the risk, including:
- authenticated user accounts and access controls;
- secure credential handling;
- encryption in transit using current transport-security protocols;
- hosting of primary application systems and backups in the European Union;
- restricted administrative and provider access based on operational need;
- audit and security logging;
- monitoring and procedures for security incidents;
- backup retention of up to 30 days;
- data-minimization measures for product analytics;
- direct transmission of dictated audio from the user’s device to Deepgram’s EU endpoint;
- exclusion of Deepgram requests from its Model Improvement Program; and
- confidentiality obligations for authorized personnel.
Measures may evolve to address changes in risk, technology, and the Services, provided overall protection is not materially reduced.
Annex 3 — Authorized Subprocessors
| Subprocessor | Location or processing region | Purpose | Data involved |
|---|---|---|---|
| Hetzner | Germany / EU | API, database, User Content, file and backup hosting | User Content, client records, account identifiers, service data |
| Supabase | EU | Authentication, account management, audit and security logging | Email, user ID, authentication data, IP address, security logs |
| Deepgram | EU endpoint | Transient real-time speech-to-text processing | Dictated audio and transient transcript |
PostHog is used by Simpace for its own limited product analytics and is not intended to receive client records or other personal data processed on Controller’s behalf. RevenueCat, Apple, and Google process subscription, entitlement, authentication, or app-store data under the roles applicable to those services and do not receive client records through Simpace’s processor services.