Privacy Policy

Simplifi Solutions Limited · Last updated 4 May 2026

This Privacy Policy explains how Simplifi Solutions Limited collects, uses, stores and shares personal data when you visit our website, contact us, use our software or services, or otherwise interact with us.

Please read this policy carefully. It is intended to help you understand what personal data we collect, why we use it, the lawful bases we rely on, who we share it with, how long we keep it, and the rights you have.

1. Who we are

Simplifi Solutions Limited, also referred to in this policy as “Simplifi Solutions”, “we”, “us” or “our”, is a company registered in England and Wales.

Registered office: Simplifi Solutions Ltd, Suite 2.2, My Buro, 20 Market Street, Altrincham, Cheshire, WA14 1PF

Company number: 06625819

For the purposes of the UK General Data Protection Regulation, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003, Simplifi Solutions Limited is the controller of the personal data described in this policy, except where we process personal data on behalf of our customers as a processor. More information about this is set out below.

2. How to contact us

If you have any questions about this policy, how we use your personal data, or how to exercise your data protection rights, you can contact us using the details below:

Email: hello@simplifisolutions.co.uk

Postal address: Simplifi Solutions Ltd, Suite 2.2, My Buro, 20 Market Street, Altrincham, Cheshire, WA14 1PF

Privacy contact: hello@simplifisolutions.co.uk

3. Controller and processor roles

We act as a controller when we decide why and how personal data is used. This includes personal data relating to website visitors, business contacts, customers, account users, prospects, suppliers, and people who contact us directly.

We may act as a processor when our customers use our software or services to upload, manage or process personal data about their own employees, contractors, suppliers, clients, site visitors or other individuals. In those circumstances, our customer is usually the controller and we process the personal data on the customer’s instructions under our customer contract and data processing terms.

If your personal data has been uploaded to or managed within our software by one of our customers, you should usually contact that customer first to exercise your data protection rights. We will support our customers in responding to valid data protection requests where we are required to do so.

This policy explains how we use personal data when we act as controller. Our processing of customer-controlled data is governed by our customer contract and data processing agreement.

4. Personal data we collect

The personal data we collect depends on how you interact with us.

4.1 Information you provide to us

You may provide personal data to us when you:

— visit or use our website

— complete a website form

— request a demonstration, quote or proposal

— create or use an account

— use our software or services

— use the Simplifi A Register service

— subscribe to updates or marketing communications

— contact us by email, telephone, post, online form, social media or another channel

— provide feedback, survey responses or support requests

— attend a meeting, webinar, event or training session with us; or

— enter into a contract with us

This may include:

— Identity information, such as your name, job title, employer or organisation

— Contact information, such as your business address, email address and telephone number

— Account information, such as username, account settings, user role, login records and password-related credentials. We do not store passwords in plain text

— Commercial information, such as products or services you have purchased or enquired about, contract details, billing information and payment status

— Communications information, such as emails, messages, call notes, support tickets, form submissions, feedback and survey responses

— Marketing preference information, such as whether you have opted in or opted out of marketing communications

— Event or training information, such as attendance records, booking details and dietary or accessibility requirements where relevant

— Any other information you choose to provide to us

We do not intentionally collect more personal data than we need. Please do not provide special category data, such as health information, unless we specifically ask for it and explain why it is needed.

4.2 Information we collect automatically

When you visit our website or use our software, we may automatically collect technical and usage information, including:

— IP address

— browser type and version

— operating system and device type

— approximate location derived from your IP address

— pages visited and links clicked

— date and time of visits

— referring website or source

— login activity

— usage logs

— error logs and diagnostic data; and

— cookie and similar technology identifiers

We use this information to operate, secure, troubleshoot and improve our website, software and services. Where cookies or similar technologies are used, please see the cookie section below.

4.3 Information from third parties and public sources

We may receive personal data from third parties and public sources, including:

— your employer or organisation

— our customers, where they create accounts for users or provide contact details for service delivery

— payment processors and accounting providers

— CRM, sales, marketing, analytics and customer support tools

— professional advisers

— Companies House and other public registers

— business websites, LinkedIn and other professional or publicly available sources; and

— event partners, referral partners or other organisations where you have asked them to share your information with us or where the sharing is otherwise lawful

Where we receive personal data from third parties, we will use it only where we have a lawful basis to do so.

5. Special category data

Special category data includes information about health, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data used for identification, sex life or sexual orientation.

We do not usually collect special category data through our website or for our own general business purposes.

However, our software and services may be used by customers to manage environmental, health and safety, compliance, training, incident, audit or register information. Depending on how a customer uses the software, customer-controlled data may include special category data, such as health information relating to incidents, accidents, occupational health, reasonable adjustments or safety records.

Where we process that information on behalf of a customer, we do so as a processor under the customer’s instructions and the relevant data processing agreement. The customer is responsible for identifying the lawful basis and any special category condition that applies to its own use of that data.

If we ever need to collect special category data for our own purposes, we will explain why we need it and the lawful basis and special category condition we rely on, unless the law allows or requires us not to do so.

6. How we use personal data and our lawful bases

We only use personal data where we have a lawful basis under data protection law. The main lawful bases we rely on are:

— Contract: where processing is necessary to enter into or perform a contract with you or your organisation

— Legal obligation: where processing is necessary to comply with a legal obligation

— Legitimate interests: where processing is necessary for our legitimate business interests or those of a third party, provided your interests and fundamental rights do not override those interests

— Consent: where you have given clear consent for a specific purpose, such as some marketing or non-essential cookies

— Vital interests: where processing is necessary to protect someone’s life. This is unlikely to apply in most day-to-day circumstances

The list below explains the main ways we use personal data.

Responding to enquiries

Examples of data used: name, contact details, organisation and enquiry details.

Lawful basis: legitimate interests, or contract where the enquiry relates to a proposed contract.

Legitimate interest: responding to business enquiries and providing information about our services.

Providing our software and services

Examples of data used: account details, user details, contact details, service usage, support records and contract information.

Lawful basis: contract and legitimate interests.

Legitimate interest: delivering, managing and improving our services.

Creating and managing accounts

Examples of data used: name, email address, job title, organisation, username, user role and login records.

Lawful basis: contract and legitimate interests.

Legitimate interest: providing secure account access and user administration.

Providing Simplifi A Register and related services

Examples of data used: contact details, account details, service records and communications.

Lawful basis: contract and legitimate interests.

Legitimate interest: delivering the requested service and supporting customer compliance workflows.

Customer support and service communications

Examples of data used: contact details, account details, support tickets, call notes, emails and usage information.

Lawful basis: contract and legitimate interests.

Legitimate interest: resolving issues and maintaining customer relationships.

Billing, payment administration and accounting

Examples of data used: contact details, billing details, invoice records and payment status.

Lawful basis: contract, legal obligation and legitimate interests.

Legitimate interest: managing payments, debt recovery and financial records.

Business administration and record keeping

Examples of data used: contact details, communications, contract records and audit records.

Lawful basis: legal obligation and legitimate interests.

Legitimate interest: operating our business and maintaining appropriate records.

Improving our website, software and services

Examples of data used: usage data, feedback, survey responses, diagnostic logs and analytics data.

Lawful basis: legitimate interests, or consent where required for cookies or analytics.

Legitimate interest: improving performance, security, usability and customer experience.

Security, fraud prevention and misuse detection

Examples of data used: login records, IP address, device data, usage logs and account activity.

Lawful basis: legitimate interests and legal obligation.

Legitimate interest: protecting our systems, users, customers and business.

Marketing to existing customers and business contacts

Examples of data used: name, business email address, organisation, marketing preferences and service history.

Lawful basis: consent, legitimate interests where permitted, and the PECR soft opt-in where applicable.

Legitimate interest: promoting relevant similar products and services.

Sending newsletters or updates

Examples of data used: name, email address and preferences.

Lawful basis: consent, unless another lawful basis clearly applies.

Legitimate interest: keeping subscribers informed about relevant developments.

Market research and feedback

Examples of data used: contact details, feedback and survey responses.

Lawful basis: consent and legitimate interests.

Legitimate interest: understanding customer needs and improving our services.

Legal claims and compliance

Examples of data used: relevant records, communications, contracts and account information.

Lawful basis: legal obligation and legitimate interests.

Legitimate interest: establishing, exercising or defending legal rights.

Business sale, merger or restructuring

Examples of data used: contact details, contract records, customer records and supplier records.

Lawful basis: legitimate interests and legal obligation where applicable.

Legitimate interest: managing corporate transactions and business continuity.

We do not sell your personal data.

7. Marketing communications

We may use your personal data to send you information about our products, services, updates, events, guidance or other content that may be relevant to you.

We will only send electronic marketing where we are allowed to do so under data protection law and the Privacy and Electronic Communications Regulations. This may be where:

— you have consented to receive marketing communications

— you are an existing customer and the communication relates to similar products or services, provided you were given a clear opportunity to opt out when your details were collected and in every subsequent message; or

— the communication is otherwise permitted by law, for example certain business-to-business communications

You can opt out of marketing at any time by:

— using the unsubscribe link in our emails

— following the opt-out instructions in the message; or

— contacting us using the details in this policy

If you opt out of marketing, we may still send you service messages, legal notices, security alerts, account updates and other non-marketing communications relating to your use of our services.

8. Cookies and similar technologies

Our website and software may use cookies and similar technologies. Cookies are small text files placed on your device. Similar technologies may include pixels, tags, local storage, scripts and device identifiers.

We use cookies and similar technologies for purposes such as:

— making our website and software work

— keeping you logged in

— remembering your preferences

— protecting security

— measuring website performance

— understanding how visitors use our website

— improving our website and services; and

— delivering or measuring marketing, where applicable

Some cookies are strictly necessary for the website or software to function. We do not need your consent to use strictly necessary cookies.

For non-essential cookies, such as analytics, advertising or certain third-party cookies, we will ask for your consent before setting them, unless the law allows otherwise.

You can also control cookies through your browser settings. However, blocking some cookies may affect how our website or software works.

Our usual cookie categories are:

— Strictly necessary cookies

— Cookie preference cookies

— Analytics and performance cookies

— Functionality cookies

— Marketing and advertising cookies

— Third-party embedded content cookies

We will keep our cookie list under review and update it when the cookies, tools or providers we use change.

9. Who we share personal data with

We may share personal data with trusted third parties where necessary for the purposes described in this policy. These may include:

— hosting and cloud infrastructure providers

— software, IT and security providers

— CRM and customer relationship management providers

— email, newsletter and marketing platform providers

— analytics providers

— payment processors, banks and accounting providers

— customer support and helpdesk providers

— professional advisers, including lawyers, accountants, auditors and insurers

— consultants, contractors and service providers who help us provide our services

— regulators, public authorities, courts, law enforcement agencies or other bodies where required by law

— prospective buyers, sellers, investors or advisers in connection with a merger, acquisition, sale, restructuring or similar corporate transaction; and

— any other third party where you have asked us to share your information or where we are legally permitted or required to do so

Where service providers process personal data on our behalf, we require them to protect it and use it only in accordance with our instructions, unless they are acting as independent controllers.

We do not sell personal data.

10. Where we store personal data and international transfers

We store personal data on secure servers located within the United Kingdom.

If we ever need to transfer personal data outside the UK, or use a supplier that stores or accesses personal data outside the UK, we will take steps designed to ensure that the personal data receives an appropriate level of protection. This may include relying on:

— an adequacy regulation made by the UK government

— the UK International Data Transfer Agreement

— the UK Addendum to the EU Standard Contractual Clauses

— another lawful transfer mechanism; or

— another safeguard permitted by data protection law

You can contact us if you would like more information about storage locations or international transfer safeguards.

11. How long we keep personal data

We keep personal data only for as long as necessary for the purposes for which it was collected, including for legal, regulatory, accounting, reporting, security and legitimate business purposes.

The exact retention period depends on the type of personal data, the reason we use it, and whether we need it to comply with legal obligations or protect legal rights.

Our usual retention periods are:

When we no longer need personal data, we will delete it, anonymise it, or securely archive it where appropriate.

12. How we protect personal data

We use appropriate technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration or disclosure.

These measures may include, where appropriate:

— access controls

— authentication and password protection

— encryption in transit

— secure hosting arrangements

— data backup and recovery measures

— staff confidentiality obligations

— staff training

— system monitoring and logging

— vulnerability management

— contractual controls with service providers; and

— incident response procedures

No website, software system or transmission over the internet is completely secure. However, we take reasonable steps to protect personal data and to respond appropriately if a security incident occurs.

13. Your rights

Under data protection law, you have rights in relation to your personal data. These rights may include:

— the right to be informed about how we use your personal data

— the right to access your personal data

— the right to ask us to correct inaccurate or incomplete personal data

— the right to ask us to delete personal data in certain circumstances

— the right to ask us to restrict processing in certain circumstances

— the right to data portability, meaning the right to receive certain personal data you have provided to us, or ask us to transfer it to another organisation, in certain circumstances

— the right to object to certain processing, including direct marketing

— the right to withdraw consent where we rely on consent; and

— the right to complain to the Information Commissioner’s Office

You can exercise your rights by contacting us using the details in this policy.

We may need to verify your identity before responding to a request. We will respond within the time limits required by law. In most cases, this means within one month of receiving your request, although this may be extended where permitted by law.

Some rights are not absolute and may only apply in certain circumstances. We may also need to keep certain information where required by law or where we have a legitimate reason to do so.

14. Automated decision-making and profiling

We do not use personal data to make solely automated decisions that have a legal or similarly significant effect on individuals.

We may use limited profiling or segmentation for purposes such as understanding customer interests, tailoring communications, improving services or showing relevant information. You can object to direct marketing at any time.

15. Links to other websites

Our website may contain links to third-party websites, platforms or services. This policy does not apply to those third-party sites. We are not responsible for their content, security or privacy practices. You should read the privacy policies of any third-party websites you visit.

16. Children

Our website, software and services are intended for business users and are not directed at children.

We do not knowingly collect personal data from children through our website.

If you believe a child has provided personal data to us, please contact us so that we can take appropriate action.

17. Changes to this policy

We may update this policy from time to time to reflect changes in our business, services, systems, legal obligations or data protection practices.

When we make changes, we will update the “Last updated” date at the top of this policy. Where changes are significant, we may take additional steps to notify you, such as by placing a notice on our website or contacting you directly.

18. Complaints

If you have concerns about how we use your personal data, please contact us first so that we can try to resolve the issue.

You also have the right to lodge a complaint with the Information Commissioner’s Office, the UK regulator for data protection matters.

Information Commissioner’s Office

Website: https://ico.org.uk/

Telephone: 0303 123 1113