Privacy Policy
On this page
- Information We Collect and How We Use It
- Sources of Personal Information
- USE OF PERSONAL INFORMATION
- Your Privacy Controls
- How We Share Information
- Keeping Your Information Secure
- Your Privacy Rights
- U.S. State Privacy Rights
- Your European Privacy Rights
- Cookies
- Compliance & Cooperation with Regulators
- Exercising your Rights.
- Changes to This Policy.
- Contact Us
Last Updated October, 2025
At Simulacrum Inc. (“Simulacrum,” “we,” “our,” or “us”), we are committed to protecting your privacy and handling your personal information with transparency, integrity, and care. This Privacy Policy outlines how we collect, use, disclose, and safeguard the information you provide when interacting with our products, services, websites, and platforms.
Our goal is to help you understand what data we collect, why we collect it, how it is used, and the choices you have regarding your information. We also explain how we comply with applicable data protection laws and how we work to ensure your information remains secure.
This Privacy Policy applies to our online and offline practices regarding the processing of personal information of customers, suppliers, business contacts, visitors, employees, contractors and job applicants by us as the data controller, including on the https://www.smlcrm.com website, the https://app.smlcrm.com app, the API, SDK, our released softwares, tools, and documentation (collectively “Services”). Processing by other affiliated entities or third parties may be governed by separate privacy policies, and we recommend that you review the privacy policies of those websites.
Please note that by using our Services, you may be transferring your personal information to the United States, which may not have the same data protection laws as your home country.
1. Information We Collect and How We Use It
“Personal information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to, directly or indirectly, a particular consumer or household. We collect various types of personal information depending on how you use our Services. We may also record calls made to us for quality and training purposes and to prevent and detect crime. The following are categories (with non-exhaustive examples) of personal information we may collect about you and for each category the purpose for which it may be used:
| Categories | Examples | Purpose of Processing |
|---|---|---|
| A. Individual Identifiers and Demographic Information | A real name, company name alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, address, telephone number, account name, Social Security number, driver’s license number, passport number, credit card information, your areas of interest or other similar identifiers. | Processing orders (including collecting payment and sending invoices). Delivering products/services. Responding to inquiries. Authenticating your account. Processing API requests. Delivering accurate forecasts. Managing usage quotas. Fulfilling contractual obligations. Sending important administrative messages, such as updates about your account, security notifications, or changes to our policies. Processing job applications and Human Resources Data for purposes of administration and communication, and to comply with labor law requirements. |
| B. Protected Classifications | Protected classifications under applicable law, including gender, age and citizenship. | Processing job applications and employee data, and to comply with labor law requirements. |
| C. Commercial Information | Records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies. | Processing orders (including collecting payment and sending invoices). Delivering products/services. Responding to inquiries. Management of customer purchases and accounts, compiling details of user engagement. |
| D. Device, System, Interaction and Diagnostic Data | Information about the device and software you use to access our Services, such as device type, browser settings, language, operating system, API client version, and mobile network information. Server logs that include your IP address, timestamps, error reports, system activity, usage data, and referrer URLs. Interaction with our Services, including API calls made, time spent, and feature usage patterns. Time-series input. | Optimization of our tools to better serve our users. To maintain the reliability, security, and performance of our platform. Network and IT security purposes. To ensure our systems are working as intended, detect bugs or performance issues, and improve model accuracy, stability, and efficiency. Aggregate insights from time-series usage patterns may help us refine our forecasting algorithms or better scale infrastructure during peak demand. |
| E. Professional or Employment-Related Information | Employee names, addresses, phone numbers, and possible other contact details (including emergency contact), current or past job history, performance evaluations, and other professional, economic, and employment details, IT and systems use, grievance, disciplinary and performance information, family leave, vacation, banking details, benefits information, health and disability information, references, experience, information provided by recruitment agencies, from social media, regulators, membership of any professional bodies and details of any pre-employment assessments and interview notes. | Processing job applications and employee data for purposes of administration and communication, to instigate, manage and end employment relationship, workforce management, respond to and defend legal claims and to comply with labor law requirements. |
| F. Education Information | Education records directly related to a student maintained by an educational institution or party acting on its behalf, such as grades, transcripts, class lists, student schedules, student identification codes, student financial information, or student disciplinary records. | Processing job applications and employee data for purposes of administration and communication, and to comply with labor law requirements. |
| G. Preferences, characteristics, abilities | Preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, and abilities. | Processing job applications and employee data for purposes of administration and communication, to comply with labor law requirements, and to provide accommodations. |
| H. Location Information | IP address-based geolocation. Inferred location based on time zone or activity. Other device-derived signals. | Tailoring the Services to individual customer needs. |
| H. Sensitive Personal Information | Social Security Number, driver’s license, state identification card, or passport number; health and medical information, Account log-in financial account, debit card, or credit card number in combination with any required security access code, password, or credentials allowing access to the account; Precise geolocation; Racial or ethnic origin, religious or philosophical beliefs, or union membership, sex life, contents of mail, email or text messages unless Company is intended recipient of the communication; or Genetic Information and criminal records. | Processing job applications and employee data for purposes of administration and communication, to comply with labor law requirements, and to provide accommodations. Monitor sick leave, assess working capacity, administer sickness and insurance benefits, take decisions as to an employee’s working capacity and for occupational health purposes. Information about racial/ethnic origin, sexual orientation or religion or belief, is done for the purposes of equal opportunities monitoring. We may process sensitive data relating to your criminal record (and driving offences) where the nature of is necessary to comply with a legal or statutory obligations or under an employment contract (e.g. for vehicle insurance) or where you have consented (e.g. background check). |
| Additional note | We do not make automated decisions about you using your personal data. |
Personal information does not include:
Deidentified or aggregate information – “Deidentified Information” means information that cannot reasonably identify, relate to, describe, be capable of being associated with, or be linked, directly or indirectly, to a particular individual, and for which Simulacrum has implemented technical safeguards and business processes that prohibit reidentification of the individual. “Aggregate Information” means information that relates to a group or category of individuals, from which individual identities have been removed, that is not linked or reasonably linkable to any individual or household, including via a device.
Excluded information – Certain laws require separate privacy notices or are exempt from general personal information privacy policy disclosure requirements. Such laws include health or medical information covered by the Health Insurance Portability and Accountability Act of 1996 (HIPAA); and data covered under the Fair Credit Reporting Act (FCRA).
2. Sources of Personal Information
We obtain the categories of personal information listed above from the following categories of sources:
Personal information you provide – Simulacrum collects personal information when you voluntarily submit it to us. For example, we may collect or receive personal information from forms you complete or products and services you purchase, reviews you post, any requests you submit to our customer service team, any interactions you have with our social media pages, or otherwise from any interactions you have with us through the Services. If you inquire about a career at Simulacrum through our website’s careers page, you will be asked to provide information about yourself, including your resume.
Publicly available - available information from government or other sources (e.g. credit rating agency).
Automatically collected personal information – Simulacrum indirectly collects other information from you automatically through the Services. For example, we receive personal information from you when you visit and navigate our Services on any device. Simulacrum collects some personal information automatically using cookies or other online tracking technologies as described below in this Privacy Policy.
Personal information obtained from third parties – Simulacrum may obtain or receive personal information about you from other third party sources. For example, we receive personal information from our business partners or other third party companies. We may merge or combine such personal information with the personal information we collect from you directly or automatically.
3. USE OF PERSONAL INFORMATION
We process personal information for the following purposes:
Purpose of Processing Legal Basis Processing orders (including collecting payment and sending invoices) Performance of our agreement with you Delivering products/services Performance of our agreement with you Responding to inquiries Our legitimate interest, which is the proper functioning of our commercial activity Management of customer purchases and accounts, compiling details of user engagement Our legitimate interest, which is the proper functioning of our commercial activity To evaluate consumer trends and usage related to our Services and allows us to improve our Services content and offerings accordingly Our legitimate interest, which is the proper functioning of our commercial activity Processing job applications and Human Resources Data for purposes of administration and communication, and to comply with labor law requirements Our legitimate interest or legal obligation or performance of our agreement with you We believe the risk to your data protection rights in connection with personal information that we process on the basis of our legitimate interests is not excessive or overly intrusive. We have also put in place protections for your rights by ensuring proper retention periods and security controls.
If you choose not to give us personal information, we may not be able to provide you with any services you may request or require, or enter into a contract with you.
4. Your Privacy Controls
At Simulacrum, we believe in transparency and giving you meaningful choices about your personal data. You have the right to access, manage, and control how your information is collected, used, and retained when using our Services.
Managing and Updating Your Information
You can review and update the personal information associated with your account, including your contact details, payment preferences, and content shared through our Services. Account settings allow you to manage these details directly.
Signed-Out Controls
Even if you are not signed into an account, you still have the ability to manage certain privacy settings. You can configure your browser to limit or block cookies and other tracking technologies that may collect data during your visits. Additionally, your device settings allow you to control access permissions for features such as location services, camera, and microphone. These controls help you maintain a degree of privacy when using our Services without an account.
Data Use for Service Improvement
As described in our Terms of Use, we may use data submitted through our API to improve and develop our models and services. However, you may choose to opt out of this data use at any time via your account settings. Once your opt-out request is processed, any content you submit moving forward will no longer be used for model training or service improvement purposes.
Data Deletion
You may request the deletion of your Simulacrum account and associated data at any time. Once we receive and verify your request, we will initiate the process to remove your personal data from our active systems. Because of the nature of distributed storage and backup systems, complete deletion may take time. During this period, access to the data is restricted, and it is no longer used for operational purposes. We follow a secure deletion process to ensure information is removed from active databases and, where feasible, from backup systems. Residual copies may persist temporarily but are securely stored and isolated from any further processing.
Data Retention
We retain personal information for varying durations depending on the nature of the data and the reasons for its collection:
User-Controlled Data: Certain information—such as uploaded files or account activity—can be deleted manually by you at any time, or set to auto-delete after a selected retention period.
Operational Data: Aggregated, anonymized, or system-critical data may be retained to support product functionality, analytics, and service improvement.
Legal and Business Obligations: We may retain information for extended periods to comply with legal obligations (e.g., tax, financial, or audit requirements), enforce our Terms of Use, detect and prevent fraud, ensure safety, or resolve disputes.
We retain your personal information only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, comply with legal obligations, resolve disputes, and enforce our agreements.
Children's Privacy
Our Services are not intended for children under the age of 13, and we do not knowingly collect personal information from children. If we become aware that we have collected personal data from a child without appropriate parental consent, we will take steps to delete that information in accordance with applicable laws.
Communication Preferences
You may choose how you receive communications from us, including product updates, promotional messages, and support notices. You can modify these preferences in your account or unsubscribe by following instructions in our emails.
5. How We Share Information
We value your trust and do not sell your personal information. We share your information only in limited, clearly defined circumstances outlined below:
With Your Consent
We may share personal information with third parties when you provide explicit consent. For example, if you authorize an integration or third-party app to connect with Simulacrum, we will share only the information necessary for that purpose. You have control over these permissions and may revoke access at any time through your account settings.
With Service Providers and Affiliates
We may share your personal data with trusted third-party service providers and affiliates who assist in operating our business. These partners perform services such as hosting, data storage, analytics, customer support, and infrastructure operations. All such providers are required to handle your information in compliance with this Privacy Policy and under strict confidentiality and security obligations.
For Legal Obligations
We may disclose your personal information when required to comply with applicable laws, legal proceedings, or enforceable governmental requests. This may include, but is not limited to, complying with court orders, responding to law enforcement inquiries, or fulfilling tax or regulatory reporting duties. In such cases, we will limit disclosure to the minimum required and, where appropriate, notify you unless prohibited by law.
For Security and Protection
We may share information when we believe it is necessary to detect, prevent, or address fraud, abuse, security risks, or technical issues, or to protect the rights, property, or safety of Simulacrum, our users, or the public. This includes enforcing our Terms of Use or investigating potential violations.
In Business Transfers
If Simulacrum is involved in a merger, acquisition, restructuring, sale of assets, or bankruptcy, your information may be transferred as part of that transaction. In such cases, we will ensure appropriate safeguards are in place and notify you before any material changes to how your personal data is handled.
With Aggregated or De-Identified Data
We may share non-personally identifiable information in aggregate or anonymized form for analytics, research, or business purposes. For example, we may publish insights on time-series data usage trends or model performance, provided such information does not identify you individually.
Third-Party Links and Services
Our Services may include links to or integrations with third-party websites, applications, or services that are not operated or controlled by Simulacrum. We are not responsible for the privacy practices or content of those third parties.
6. Keeping Your Information Secure
At Simulacrum, we prioritize the security of your personal information and integrate robust protections into the design of our services. Our infrastructure is built with advanced security features to continuously monitor, detect, and block threats before they can compromise your data.
We take the following measures to help protect your information from unauthorized access, alteration, disclosure, or destruction:
Encryption in Transit: We encrypt data as it moves between your device and our systems to protect it from interception.
Security Controls: We apply a range of industry-standard safeguards, such as multi-factor authentication and internal access controls.
Operational Reviews: We regularly assess our data collection, storage, and processing procedures—including physical and technical safeguards—to minimize risks.
Access Restrictions: Access to personal data is limited to Simulacrum employees, contractors, and authorized agents who require it to perform their duties. These individuals are bound by strict confidentiality obligations and may face disciplinary action, including termination, for violations.
We are committed to continuous improvement and maintaining safeguards that reflect best practices aligned with frameworks such as the National Institute of Standards and Technology (NIST) Cybersecurity Framework, and to complying with applicable U.S. laws, including the Federal Trade Commission (FTC) guidance and relevant state privacy regulations.
7. Your Privacy Rights
This section is subject to specific disclosures on privacy rights set below in Sections 9 and 10. We are committed to facilitate the exercise of your rights granted by the laws of your jurisdiction, which may include the right to access, correct, modify or delete of your personal information, and the right to opt out of the sale or sharing of your personal information (as applicable). We will do our best to honor your requests pursuant to applicable law, subject to any legal and contractual obligations.
Subject to local law, you may have additional rights under the laws of your jurisdiction regarding your personal data, such as the right to complain to your local data protection authority and the right to appeal our decision regarding a data rights request.
8. U.S. State Privacy Rights
This Notice at Collection and Supplemental Notice is for residents of U.S. states that have adopted comprehensive privacy legislation and others that may come into effect from time to time, including, but not limited to, California, Connecticut, Colorado, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nevada, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia, (to the extent applicable to the processing of residents’ personal information, “Applicable State Laws”).
The following table describes the categories of personal information we collect and whether we disclose that personal information for a business purpose (e.g., to a service provider) or for certain advertising purposes to a third-party. Note that we may not collect all categories of personal information, or all types of personal information in any category, about you. See also Section I of this policy for more information on categories of personal information we process.
Residents of certain states have the right to opt out of the “sale” or “sharing” of their personal information. A “sale” is defined broadly and includes the transfer of personal information by a business to a third party for valuable consideration (even if there is no exchange of money). “Sharing” means disclosure to a third party for purposes of cross-context behavioural advertising.
Simulacrum may “sell” or “share” personal information. The categories of personal information we have “sold” and the categories of third parties we have “sold” or “shared” personal information to in the preceding twelve months are listed below:
Category of Personal Information Collected by Simulacrum Category of Third Parties to which Personal Information is Disclosed for a Business Purpose Category of Third Parties to which Personal Information is Sold or Shared for advertising Purposes Identifiers. A real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, Social Security number, or other similar identifiers. Service providers Business partners Affiliates Other users or third parties you share or interact with Government entities Operating systems and platforms N/A Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)) A name, signature, Social Security number, physical characteristics or description, address, telephone number, passport number, driver's license or state identification card number, insurance policy number, education, employment, employment history, bank account number, credit card number, debit card number, or any other financial information, medical information, or health insurance information. Personal Information does not include publicly available information that is lawfully made available to the general public from federal, state, or local government records. Note: Some personal information included in this category may overlap with other categories. Service providers Business partners Affiliates Other users or third parties you share or interact with Government entities N/A Protected classification characteristics under California or federal law Age (40 years or older), race, color, ancestry, national origin, citizenship, religion or creed, marital status, medical condition, physical or mental disability, sex (including gender, gender identity, gender expression, pregnancy or childbirth and related medical conditions), sexual orientation, veteran or military status, genetic information (including familial genetic information). Service providers Business partners Affiliates Other users or third parties you share or interact with Government entities N/A Commercial information Records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies. Service providers Business partners Affiliates Other users or third parties you share or interact with Government entities Operating systems and platforms N/A Device, System, Interaction and Diagnostic Data Information about the device and software used to access Services, such as device type, browser settings, language, operating system, API client version, and mobile network information. Server logs that include IP address, timestamps, error reports, system activity, usage data, and referrer URLs. Interaction with the Services, including API calls made, time spent, and feature usage patterns, when Services are used.. Service providers Business partners Affiliates Government entities Operating systems and platforms N/A Geolocation data Physical location or movements. Service providers Business partners Affiliates Government entities Operating systems and platforms N/A Professional or employment-related information Current or past job history or performance evaluations. Service providers Business partners Affiliates Other users or third parties you share or interact with Government entities N/A Non-public education information (per the Family Educational Rights and Privacy Act (20 U.S.C. Sec. 1232g, 34 C.F.R. Part 99)) Education records directly related to a student maintained by an educational institution or party acting on its behalf, such as grades, transcripts, class lists, student schedules, student identification codes, student financial information, or student disciplinary records. N/A N/A Sensitive Personal Information. Social Security Number, driver’s license, state identification card, or passport number; Account log-in financial account, debit card, or credit card number in combination with any required security access code, password, or credentials allowing access to the account; Precise geolocation; Racial or ethnic origin, religious or philosophical beliefs, or union membership; Contents of mail, email or text messages unless Company is intended recipient of the communication; or Genetic Information. Service providers Business partners Affiliates Other users or third parties you share or interact with Government entities N/A
Opt-out of "Sales" and "Sharing"
You have the right to opt-out of the sale or sharing of certain personal information to third parties who intend to license or sell that personal information. You can exercise this right by contacting us as set forth in Contact Us section at the end of this policy, and providing us with your name, email address, and phone number. If you submit a data subject request, we will ask for your name, email address and phone number, and we will endeavor to authenticate your account by using the IP address associated with your submission. We may also require that you submit your request via the Services' standard authentication procedures (i.e., log on with username and password to submit a request) to ensure you are the person you say you are. If this information or these processes are insufficient to verify your identity and assess your privacy request, we may need to ask for additional information. If you have any questions, please contact us as set forth in Contact Us section at the end of this policy.
Additional Privacy Rights for Residents of Certain States
Subject to Applicable Law, if you are a resident of certain states, you may have the rights described herein, which may include the following rights:
Access to and Portability of Your Personal Information, including: (i) confirming whether we are processing your personal information; (ii) obtaining access to or a copy of your personal information; and (iii) receiving an electronic copy of personal information that you have provided to us, or asking us to send that information to another company in a structured, commonly used, and machine readable format (also known as the “right of data portability”);
Request Correction of your personal information where it is inaccurate or incomplete. In some cases, we may provide self-service tools that enable you to update your personal information;
Request Deletion of your personal information;
Request Restriction of or Object to our processing of your personal information where the processing of your personal information: (i) is based on our legitimate interest for direct marketing purposes; (ii) involves processing or sharing of your sensitive personal information for certain non-essential purposes, or in contexts that require your consent; and (iii) is based solely on automated decision making or for profiling in furtherance of decisions that produce legal or similarly significant effects concerning you;
Opt-out of Sale, Sharing for Cross-Contextual Advertising, or Targeted Advertising involving your personal information. Although we do not “sell” your personal information as the term “sale” is typically understood, we may share your information with analytics providers to understand how visitors use our website. You may opt-out of this “sharing” by adjusting your privacy choices as described.
Withdraw your Consent to our processing of your personal information. Please note that your withdrawal will only take effect for future processing and will not affect the lawfulness of processing before the withdrawal.
Non-Discrimination. We will not discriminate against you, in terms of price or services that we offer, if you exercise any of the rights listed above.
Sources of Personal Information We Collect
As more fully described in Section I titled Information We Collect and How We Use It, the sources from which we collect personal information include directly from you when you interact with us, automatically from you when you use our sites and services (for example through cookies and other online technologies), from third parties (for example, from providers of government contractor contact information) and through referrals from others.
Purposes for which We May Use the Information We Collect
The business purposes for which we collect personal information are described in more detail in section I titled Information We Collect and How We Use It, and include:
To provide our Services to you;
For our Administrative purposes (including security, fraud detection and protection, and improve our Services);
To process your requests, orders, and transactions (including provide customer service to you); and,
To comply with law and enforce our rights and the rights of others.
Retention of Personal Information
We store the personal information we collect as described in this Privacy Policy for as long as you use our Services, or as necessary to fulfill the purpose(s) for which it was collected, provide our Services, resolve disputes, establish legal defenses, conduct audits, pursue legitimate business purposes, enforce our agreements, and comply with applicable laws, or based upon other criteria, including, but not limited to, the sensitivity and volume of such data. Additionally, we endeavor to retain all such personal information in accordance with legal requirements.
Processing Sensitive Information
Under applicable laws, you may have the right to limit the processing of sensitive personal information for certain purposes such as profiling or inferring characteristics about you. We will only process your sensitive personal information where permitted by Applicable State Law and as required by the California Consumer Privacy Act (CCPA), we will not use or disclose sensitive personal information subject to the CCPA for purposes other than the following:
To perform the services or provide the goods reasonably expected by an average consumer who requests those goods or services.
To prevent, detect, and investigate security incidents that compromise the availability, authenticity, integrity, or confidentiality of stored or transmitted personal information,
To resist malicious, deceptive, fraudulent, or illegal actions directed at the business and to prosecute those responsible for those actions. To ensure the physical safety of natural persons. For short-term, transient use, including, but not limited to, non-personalized advertising shown as part of a consumer’s current interaction with the business, provided that the personal information is not disclosed to another third party and is not used to build a profile about the consumer or otherwise alter the consumer’s experience outside the current interaction with the business. To perform services on behalf of the business. To verify or maintain the quality or safety of a product, service, or device that is owned, manufactured, manufactured for, or controlled by the business, and to improve, upgrade, or enhance the service or device that is owned, manufactured by, manufactured for, or controlled by the business. To collect or process Sensitive Personal Information where such collection or processing is not for the purpose of inferring characteristics about a consumer.
Authorized Agent
Depending on where you live, you may have the right to use an authorized agent on your behalf to exercise a privacy right discussed above. If you are an authorized agent acting on behalf of a user to communicate with us or to exercise a privacy right discussed above, you must be able to demonstrate that you have the requisite authorization to act on behalf of the user, and have sufficient access to that user's laptop, desktop, or mobile device to exercise that user's right digitally. If you are an authorized agent trying to exercise rights on behalf of one of our users, then you can make a request on the user's behalf by contacting us as set forth below in the Contact Us section: Such requests must include the following information: (1) a written authorization from the consumer that includes the consumer's full name, address, telephone number and valid email address used by the consumer to interact with us, that is signed by the consumer and clearly bestows upon the agent the proper authority; and (2) a certificate of good standing with your state of organization. Alternatively, an acting agent can provide a valid power of attorney signed by the consumer on the agent's behalf and a valid email address used by the consumer to interact with us. The email address of the consumer will be used to separately verify the agent's authority with the consumer.
Appeal
You may have the right to appeal our decision or response to your request. To exercise your right to appeal, you can submit an appeal request using the same method used to submit your original request, including by contacting us as set forth in Contact Us section at the end of this policy.
De-Identified Information
If we create or receive de-identified information, we will not attempt to reidentify such information, except to comply with Applicable Law or in accordance with our Privacy Policy.
Make a request
Our contact information is listed at the bottom of this policy. To exercise your rights as described in this Privacy Policy, please contact us as set forth in Contact Us section at the end of this policy. If you submit a data subject request, we will ask for your name, email address and phone number, and we will endeavor to authenticate your account by using the IP address associated with your submission. We may also require that you submit your request via the Services' standard authentication procedures (i.e., log on with username and password to submit a request) to ensure you are the person you say you are. If this information or these processes are insufficient to verify your identity and assess your privacy request, we may need to ask for additional information.
California "Shine the Light" Information-Sharing Disclosure
Under California Civil Code sections 1798.83-1798.84, California residents who have an established business relationship with Simulacrum are entitled to ask us for a notice describing what categories of personal information we share with third parties for their direct marketing purposes. This notice will identify the categories of information shared with and will include a list of the third parties with which it is shared, along with their names and addresses. If you are a California resident and would like a copy of this notice, please submit a written request to us at the contact information listed below with "California Shine the Light Rights" in the subject line.
Do Not Track Disclosure
We use commercially reasonable efforts to respond to Do Not Track browser settings and Global Privacy Control signals.
9. Your European Privacy Rights
If you are located in the European Union, the European Economic Area, the United Kingdom, Switzerland or another jurisdiction that has adopted laws substantially similar to the General Data Protection Regulation (GDPR), the following section explains your rights that you may exercise. The various rights are not absolute, and each is subject to certain exceptions, or may be provided to you as required by applicable law.
The right of access – You may have the right to obtain from us confirmation as to whether or not your personal information is being processed by us, and about certain other information (similar to that provided in this Privacy Policy) about how it is used. You may also have the right to access your personal information, by requesting a copy of the personal information concerning you. This is so you are aware and can check that we are using your personal information in accordance with data protection law. We can refuse to provide information where to do so may reveal personal data about another person or would otherwise negatively impact another person's rights.
The right to rectification – You can ask us to take measures to correct your personal information if it is inaccurate or incomplete (e.g., if we have the wrong name or address for you).
The right to erasure – You may request the deletion or removal of your personal information where, for example, there is no compelling reason for us to keep using it or its use is unlawful. This is however not a general right to erasure and there are some exceptions, e.g., where we need to use the information to fulfil a request you have made, in defense of a legal claim, or to be able to comply with a legal obligation.
The right to restrict processing – You may have the right to 'block' or suppress the further use of your personal information when we are assessing a request for rectification or as an alternative to erasure. When processing is restricted, we can still store your personal information, but may not use it further.
The right to data portability – You may have the right to obtain and reuse certain personal information for your own purposes across different organizations (being separate data controllers). This only applies to your personal information that you have provided to us that we are processing with your consent and for the purposes of contract fulfillment, which is being processed by automated means. In such a case we will provide you with a copy of your data in a structured, commonly used and machine-readable format or (where technically feasible) we may transmit your data directly to a separate data controller.
The right to object – You may have the right to object to certain types of processing, on grounds relating to your particular situation, at any time insofar as that processing takes place for the purposes of our legitimate interests. We will be allowed to continue to process the personal information if we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or we need this for the establishment, exercise, or defense of legal claims. If you object to the processing of your personal information for direct marketing purposes, we will no longer process your personal information for such purposes.
The right to withdraw consent – Where we process your personal information on the basis of your consent, you have the right to withdraw your consent at any time. However, such withdrawal does not affect the lawfulness of the processing that occurred prior to such withdrawal.
The right to provide us with directives regarding the use of your personal information after your death – In certain cases, you have the right to provide us with instructions on the management (e.g., retention, erasure, and disclosure) of your personal information after your death. You can change or revoke your instructions at any time.
The right to lodge a complaint – If you believe that we do not comply with applicable data protection laws, you have the right to lodge a complaint before any competent data protection authority or government agency. To exercise these rights you may contact us as set forth in Contact Us section at the end of this policy.
For any complaints regarding GDPR rights you may contact the EU supervisory authority in your country and for the UK the Information Commissioners Office https://ico.org.uk/concerns/ although we would appreciate the opportunity to deal with any complaint you may have ourselves first.
10. Cookies
When you visit or interact with our Services, we (or our third-party providers) may use "cookies" or other similar technologies to personalize and enhance your experience. A “cookie” is a small piece of information sent to a visitor’s computer or other Internet-connected devices to uniquely identify the visitor’s browser or to store information or settings in the browser. Cookies are used to make our Services work, or work more efficiently, as well as to provide data to the Services owners. Our Services use required cookies, functional cookies, and analytics and performance cookies.
Except for technical cookies, in some cases the storing of cookies on the device of a visitor requires consent. Except where otherwise required by applicable law, by continuing browsing the Services after having seen the cookies banner displayed on the home page of the Services, the visitor consents to the storing of cookies on his/her device. Where such consent is required, this consent is valid for a period of 13 months.
Required cookies enable you to move from page to page and to use features on our Services while your browser remains open. For example, required cookies allow you to add products to your shopping cart and carry the contents of your cart to checkout.
Functional cookies last from visit to visit. For example, functional cookies may be used to recognize you as a previous user to provide a more personalized experience. They are stored in your computer, device, or browser until you choose to delete them.
Analytics and performance cookies allow us to collect data concerning the Services, including the number of visitors, where the visitors have come from, and the length of time visitors spend on the Services, which allows us or third-party providers to analyze how our Services are used and how our Services are performing.
The majority of web browsers accept cookies and similar files, but you can usually change your browser settings to prevent this. If for any reason you decide that you do not like our use of certain cookies, you can simply change your settings. However, if you do so, some functionality of our Services may be lost.
If you have any specific questions about the use of cookies on our Services, please feel free to contact us at any time as described below, with a subject line “Cookie Request.”
11. Compliance & Cooperation with Regulators
Simulacrum is committed to aligning its data practices with all applicable laws and regulatory requirements. We regularly review our Privacy Policy and data handling procedures to uphold transparency and ensure legal compliance across the jurisdictions in which we operate.
International Data Transfers
While Simulacrum is headquartered in New York City, U.S., our infrastructure may involve the processing of personal information on servers located in other countries. Since data protection laws vary by jurisdiction, we apply the safeguards outlined in this Privacy Policy regardless of where data is processed. We also comply with applicable international data transfer frameworks to ensure lawful and secure handling of personal information.
Engagement with Regulators
We take privacy concerns seriously. If we receive a formal privacy complaint, we will respond directly to the complainant and, if necessary, cooperate with the appropriate data protection authorities or regulatory bodies to reach a resolution.
12. Exercising your Rights
When exercising the rights or options described in this Privacy Policy, the following guidelines apply:
No fee usually required – You will not have to pay a fee to access your personal information (or to exercise any of the other rights). However, we may charge a reasonable fee or decline to comply with your request if your request is clearly unfounded, repetitive, or excessive.
What we may need from you – When exercising your rights or otherwise assisting you, we may need to request specific information from you to help us confirm your identity. This is a security measure to ensure we do not disclose personal information to any person who is not entitled to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response. Please note that your exercise of these rights is subject to certain exemptions to safeguard the public interest (e.g., the prevention or detection of crime) and our interests (e.g., the maintenance of legal privilege). If we are unable to process your request via you authenticating yourself on the Services, we may verify your request by asking for information sufficient to confirm your identity, based on the information we have on file. Requests to exercise these rights may be granted in whole, in part, or not at all, depending on the scope and nature of the request and as permitted by applicable law. Where required by applicable law, we will notify you if we reject your request, and notify you of the reasons we are unable to honor your request.
Time to respond – We will respond to all legitimate requests within any statutorily required timeframes. We may need to request additional time to respond, for instance if your request is particularly complex or you have made a number of requests. In this case, we will notify you of the delay, and may continue to update you regarding the progress of our response.
13. Changes to This Policy
We may revise this Privacy Policy from time to time to reflect updates in our business practices, applicable legal requirements, or technological developments. When material changes occur, we will provide clear and timely notice—such as through email communication or in-product notifications—where required by law or as deemed appropriate. Simulacrum is committed to transparency, and previous versions of this policy will be made available upon request for your reference.
14. Contact Us
Simulacrum welcomes feedback and questions on this Privacy Policy. If for any reason you wish to contact us, or exercise your rights as described in this Privacy Policy our contact information is: support@smlcrm.com