Information under Articles 13 and 14 GDPR

Privacy policy

This policy tells you what happens to your data when you visit simosphereai.com or write to us. It describes only processing that actually takes place on this website.

It stands on its own and replaces, for this site, any policy that applies to other SIMO GmbH websites. The scope here is different: simosphereai.com serves businesses and consumers.

Ordering through this website is on hold. You cannot open an account here and you cannot place an order. What happens once the shop opens is set out in sections 5, 6, 10 and 11 and marked as such there. As long as no checkout is reachable on simosphereai.com, none of that processing takes place.

1. Who the controller is

The controller within the meaning of Article 4 (7) GDPR is:
SIMO GmbH
Würzburger Str. 152
63743 Aschaffenburg, Germany
Commercial register: HRB 15769, Aschaffenburg Local Court
Phone: +49 6021 327 45 50
Email: [email protected]

For anything concerning your data, write to [email protected] or use the postal address above, marked "Data protection".

2. When you open this site

Every request leaves an entry in the server log. We record the truncated IP address, the date and time, the address requested, the referrer, the browser and the operating system.

Purpose
Delivering the site, keeping it available, detecting and investigating attacks.
Legal basis
Article 6 (1) (f) GDPR. Our legitimate interest is a site that stays up and does not get abused.
Storage period
7 days, then deleted automatically.
Recipients
Our hosting provider as a processor under Article 28 GDPR. Servers are located in Germany.

Cloudflare's content delivery network sits in front of our servers (Cloudflare Germany GmbH, Rosental 7, 80331 Munich, Germany). It serves images and fonts from a data center near you and absorbs denial-of-service attacks. Your IP address is processed briefly in the process. The legal basis is Article 6 (1) (f) GDPR.

The typefaces used are stored on our own server. No connection to Google Fonts is made.

3. Consent, storage on your device, and withdrawal

We ask for your consent before any access to your device that is not strictly necessary (section 25 (1) TDDDG, the German implementation of the ePrivacy Directive). Until you agree, nothing that requires consent loads, not even a preconnect to a third party.

Strictly necessary, therefore no consent required

  • Your consent decision itself. We keep it in your browser's local storage so we do not have to ask again on every visit. We record the purposes you chose, the moment you chose them and the version of the consent text. Article 7 (1) GDPR requires us to be able to demonstrate consent. The entry never leaves your device.
  • Language choice. Remembers which language you read in. Nothing else is stored.

Only with your consent

Nothing, at present. No service on this website currently requires consent. The two purposes payment and analytics were dropped on August 9, 2026: without a checkout we embed no payment service, and no audience measurement takes place. Should a service that needs consent be added, we will ask you first, and the cookie declaration will name it.

You may withdraw your consent at any time, and it takes no more effort than giving it did. The entry point sits permanently in the footer of every page under "Change consent". Withdrawal takes effect going forward; it does not affect the lawfulness of processing carried out beforehand (Article 7 (3) GDPR).

The cookie declaration lists every purpose, what each one does and how long the entries remain.

4. When you write to us

When you email us or book an introductory call, we process what you tell us: usually your name, email address, company and the content of your message.

Purpose
Answering your inquiry and keeping a record of how it was handled.
Legal basis
Article 6 (1) (b) GDPR where your inquiry aims at a contract. Otherwise Article 6 (1) (f) GDPR, our interest in answering the people who write to us.
Storage period
Until the matter is settled. We then delete unless commercial or tax law requires us to keep the record.
Recipients
None. Your message stays with us.

5. Customer account

Applies once the shop opens. As long as no checkout is reachable on simosphereai.com there are no customer accounts, and the processing described below does not take place.

If you open an account, we store your email address, your name, your billing address and, where applicable, your delivery address, together with your orders. The account gives you access to invoices, contract terms and cancellation.

Legal basis
Article 6 (1) (b) GDPR. Without this data there is no contract and no account.
Storage period
Until you delete the account. Contract and invoice data are unaffected because section 257 of the German Commercial Code and section 147 of the Fiscal Code require us to retain them.
Recipients
None.

6. Orders, invoices and payment

Applies once the shop opens. The processing set out below takes place from the moment you can order and do order. While ordering is on hold, none of it happens. Anyone who only reads is unaffected in any case.

Order and delivery

We process your name, address, email address, the items ordered and the price. The legal basis is Article 6 (1) (b) GDPR. Where hardware is shipped, we pass your name and delivery address to the carrier we instruct. Without that, nothing can be delivered.

Invoicing and tax

We process invoice data because section 14 of the German VAT Act obliges us to (Article 6 (1) (c) GDPR). The recipients are our tax advisors and their data center. Retention: 10 years under section 147 of the Fiscal Code.

If you provide a VAT identification number, we verify it with the Federal Central Tax Office through the European VAT Information Exchange System. The legal basis is Article 6 (1) (c) GDPR.

Payment

You enter your payment details (card number, bank details, PayPal credentials) directly with the payment provider. We never see them; all we receive is confirmation of whether the payment went through.

Stripe
Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Dublin 2, Ireland. Stripe passes data to Stripe, Inc. in the United States and acts as its own controller for fraud prevention.
PayPal
PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, 2449 Luxembourg. PayPal acts as its own controller and may run its own credit check.

The legal basis is Article 6 (1) (b) GDPR. Where these providers process data under their own responsibility, their own privacy notices apply.

7. Withdrawal and cancellation

When you withdraw from a contract or cancel a subscription, we process what you tell us in order to act on the declaration and confirm that it reached us. The legal basis is Article 6 (1) (b) and (c) GDPR. Section 312k (3) of the German Civil Code expressly requires a confirmation stating the date and time. We keep the declaration for three years, as long as claims arising from it can still be brought.

8. No audience measurement

We do not measure the audience of this website. Nobody counts which pages are opened, neither on someone else's servers nor on our own. No entry sits on your device for it, and there is no analysis.

We run no advertising networks on this site. There is no Google Tag Manager, no Google Analytics and no cross-site recognition.

What a page view leaves in the server log is described in section 2. That is not audience measurement but operational security, and it is deleted after seven days.

9. The AI chat on this site

Where this site offers an AI chat, the following applies: your input and a pseudonymous session identifier are logged briefly so that we can detect abuse and check answer quality. Your IP address is turned into a SHA-256 value before it is stored. Requests run through our own gateway on a server in Germany, using language models operated inside the European Union.

Legal basis
Article 6 (1) (f) GDPR, our interest in a service that works and cannot be abused.
Storage period
24 hours.
Note
You are talking to a system, not to a person. We say so because Article 50 of Regulation (EU) 2024/1689 requires it.

Please do not enter special categories of personal data under Article 9 GDPR into the chat, health data for instance. For advice on such matters, use the post or the telephone.

10. Who receives your data

We share data only where one of the sections above says so. We do not sell data and we do not pass it on for advertising.

  • Processors under Article 28 GDPR: our hosting provider, Cloudflare, our tax advisors and their data center. A data processing agreement is in place with each of them.
  • Separate controllers: Stripe and PayPal, each for fraud prevention and their own payment processing. This applies once the shop opens; at present neither of them receives any data from us.
  • Public authorities and courts, where the law obliges us to disclose (Article 6 (1) (c) GDPR).

11. Transfers to third countries

This website is operated in Germany. At present no data is transferred to a third country. Once the shop opens, a third-country transfer arises in one place only, namely payment: Stripe Payments Europe Ltd. passes data to Stripe, Inc. in the United States.

That transfer rests on the standard contractual clauses of the European Commission under Article 46 (2) (c) GDPR, unless an adequacy decision under Article 45 GDPR covers the recipient. We will tell you on request which basis applies in a given case; we review the position regularly, because it can change.

You can choose a payment method that involves no third-country transfer at all. The checkout tells you which ones those are.

12. How long we keep things

Server logs
7 days
Chat logs
24 hours, IP address stored as a hash
Consent decision
12 months, after which we ask again
Enquiries without a contract
until the matter is settled
Customer account
until you delete it
Contract and invoice data
6 years under section 257 (4) of the German Commercial Code, 10 years under section 147 (3) of the Fiscal Code
Withdrawal and cancellation
3 years

When a period runs out, we delete. Where a retention obligation stands in the way, we apply restriction of processing instead of deletion. The data is then held for the purpose of retention and nothing else.

13. Your rights

You have the following rights against us. Exercising them costs you nothing, and we answer within one month.

Right of access (Article 15 GDPR)
You can find out whether and what data we process about you, and ask for a copy.
Right to rectification (Article 16 GDPR)
If something is wrong or incomplete, we correct or complete it.
Right to erasure (Article 17 GDPR)
We erase as soon as the purpose has fallen away and no retention obligation stands in the way.
Right to restriction of processing (Article 18 GDPR)
Instead of erasing, we can limit processing to mere storage, while the accuracy of the data is in dispute, for example.
Right to data portability (Article 20 GDPR)
What you gave us on the basis of consent or a contract, we hand back in a structured, machine-readable format.
Right to object (Article 21 GDPR)
You can object to processing based on our legitimate interests on grounds relating to your particular situation.
Right to withdraw consent (Article 7 (3) GDPR)
At any time, as easily as you gave it, with effect for the future.

You also have the right to lodge a complaint with a supervisory authority (Article 77 GDPR). The authority responsible for us is the Bavarian Data Protection Authority (Bayerisches Landesamt für Datenschutzaufsicht), Promenade 27, 91522 Ansbach, Germany. You may equally approach the authority where you live.

14. Whether you have to provide data

You do not have to provide any data to read this site. For a contract we need what it takes to perform it: name, address, email address and a means of payment. Without those we cannot enter into the contract. Everything beyond that is voluntary and marked "optional".

15. No automated decision-making, no profiling

We take no decisions about you that are based solely on automated processing and produce legal effects concerning you (Article 22 GDPR). We do not profile you for advertising.

Where a payment provider checks your creditworthiness under its own responsibility, that happens at their end and under their notices, not at ours.

16. Security

Traffic is encrypted end to end with TLS; your browser shows the padlock. Access to personal data is limited to the people who need it for their work. Please report security issues to [email protected].

17. Changes to this policy

If what we process changes, this policy changes with it. The version in force is always the one on this page; the date at the bottom tells you which that is. Where a change concerns processing you consented to, we ask you again.

Version of August 9, 2026