This Privacy Policy explains how Simple Works LTD ("we") collects, uses and protects personal data when you use SimpleAMS at https://simpleams.co.uk. We are established in Bulgaria and comply with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and the Bulgarian Personal Data Protection Act (Закон за защита на личните данни).
1. Who we are
Simple Works LTD is the data controller for personal data about visitors and account owners. Address: . Contact: privacy@simpleams.co.uk.
For personal data inside a customer Workspace (e.g. an employee's name on an asset record), the customer is the controller and we act as their processor - see our Data Processing Addendum.
2. What we collect
- Account data: name, work email, password (hashed), company name.
- Billing data: plan, subscription status (payment details are handled by our payment processor, not stored by us).
- Usage data: log entries, IP address, device/browser information.
- Cookies: see our Cookie Policy.
3. Why we use it (lawful bases)
- To provide and secure the Service (contract).
- To bill and prevent fraud (contract / legitimate interests).
- To improve the product via aggregated analytics (consent / legitimate interests).
- To send service and, where you opt in, marketing communications (consent).
- To meet legal obligations (legal obligation).
4. Sharing
We share data only with processors who help us run the Service (hosting, email, analytics, payments), all bound by data-protection terms. We do not sell personal data. We may disclose data where required by law.
5. International transfers
Where data is transferred outside the European Economic Area (EEA), we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (SCCs) and, where relevant, supplementary measures.
6. Retention
We keep personal data only as long as needed for the purposes above and to meet legal requirements, then delete or anonymise it.
7. Your rights
You have the right to access, rectify, erase, restrict, port and object to processing of your personal data, and to withdraw consent at any time. To exercise these rights contact privacy@simpleams.co.uk. You may also lodge a complaint with the Bulgarian Commission for Personal Data Protection (CPDP / Комисия за защита на личните данни, www.cpdp.bg) or with the supervisory authority in your EU country of residence.
Automated decision-making
We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects.
Children
The Service is a business tool and is not directed at children under 16. We do not knowingly collect their personal data.
8. Security
We use encryption in transit, hashed passwords, per-tenant database isolation, access controls and other measures appropriate to the risk.
9. Changes
We will post updates here and, where material, notify you.
10. Contact
privacy@simpleams.co.uk.