Privacy Policy - Zensimu

Privacy Policy

Last updated: 2026-09-11

This policy explains what personal data Zensimu collects, why, who we share it with, and what your rights are. If anything is unclear, write to us at [email protected].

1. Who we are

Zensimu ApS, Vesterbrogade 26, Copenhagen, Denmark (CVR 44668033).

Mathias Le Scaon, founder, is responsible for privacy. Contact: [email protected]. We are not required to appoint a Data Protection Officer.

Zensimu ApS (“Zensimu”) is concerned about privacy issues and wants you to be familiar with how we collect, use and disclose information.

2. Our two roles

We are the controller for our own relationship with you: your instructor account, billing, support and marketing. This policy covers that data.

We are a processor for the data that instructors and participants enter into simulations for an organisation (a company, university or school). The organisation decides what is collected and why. We use this data only to provide the service, following the organisation's instructions and our Data Processing Agreement (DPA) with them. If you took part in a simulation through your organisation, its own privacy notice applies. If you contact us, we pass your request on to them and help them answer.

3. What we collect

Who

Data

Instructors

Name, email, organisation name and type, logo (if you add one). Your password is stored encrypted by Google; we never see it. For paid plans: billing name, company and address. Card details go directly to Stripe; we never see them.

Participants (players)

A display name or nickname, only if the player types one. Game decisions and scores. No account, no email, no password.

Contacts

What you send us by contact form, support request or email: name, email, company, message.

All users

Technical data: IP address, browser and device type, how the app is used, and error logs.

If you sign in with Google or Microsoft, we receive your name and email from them. If a colleague invites you to their team, they give us your email.

We do not collect sensitive data (such as health, religion or political opinions). Please do not enter any in the app.

4. Why we use it

Purpose

Legal basis

Create your account and run your sessions

Contract

Send service emails (account, security, changes to our terms)

Contract

Billing and accounting

Contract and legal obligation

Answer support requests

Contract or legitimate interest

Fix errors and keep the platform secure

Legitimate interest

Check that email addresses are valid

Legitimate interest

Send newsletters and product news

Legitimate interest. You can unsubscribe in one click.

Understand how the app is used, to improve it

Consent (cookie banner)

Measure the performance of our ads

Consent (cookie banner)

We do not sell your data. We do not use it for automated decisions that affect you.

5. How long we keep it

  • Instructor accounts: until you ask us to delete your account, or after 36 months without login. We email you before deleting an inactive account.

  • Session and player data: kept in the instructor's workspace and deleted with it, or earlier on request.

  • Enterprise customers: deleted within 30 days after the contract ends, on request.

  • Backups: deleted data is removed from all backups within 35 days.

  • Invoices and accounting records: 5 years, as required by Danish law.

  • Support and sales messages: as long as needed for the request or business relationship. We review this at least once a year.

  • Marketing emails: until you unsubscribe or your account is deleted (see retention period).

6. Who we share it with

We use the providers below (sub-processors) to run Zensimu. Each one has signed a data processing agreement with us and only receives the data it needs.

Application sub-processors:

They process data inside the Zensimu app, including customers' data.

Provider (legal entity)

Purpose

Data

Data location

Google Cloud / Firebase (Google Cloud EMEA Ltd, Ireland)

Hosting and database for the app

All app data

USA

Customer.io (Peaberry Software Inc., USA)

Service emails and newsletters

Name, email, app usage

USA

Mixpanel (Mixpanel, Inc., USA)

Analytics, to improve the app (only if you accept cookies)

App usage, device data

EU

PostHog (PostHog, Inc., USA)

Analytics (only if you accept cookies). Session logs, to investigate bugs

App usage, session logs, errors, device data

EU

Help Scout (Help Scout, USA)

Help desk and knowledge base

Name, email, support messages

USA

Featurebase (Featurebase OÜ, Estonia)

Feedback board, in-app surveys

Name, email, suggestion

EU

Emailable (Emailable LLC, USA)

Check that an email address is valid at sign-up

Email

USA

Billing

Provider (legal entity)

Purpose

Data

Data location

Stripe (Stripe, Inc., USA)

Card payments

Name, email, billing and card details

USA

e-conomic (Visma e-conomic A/S, Denmark)

Invoices and accounting

Name, company, billing details

EU

Internal tools

Provider (legal entity)

Purpose

Data

Data location

Google Workspace (Google LLC, USA)

Email and documents

Contact details, emails, documents

USA

Slack (Slack Technologies LLC, USA)

Internal communication

Names, emails, messages

USA

Marketing website

Provider (legal entity)

Purpose

Data

Data location

HubSpot (HubSpot, Inc., USA)

Website contact form

Name, email, company, message

EU

Google Analytics and Google Ads (Google LLC, USA)

Campaign performance statistics, only if you accept cookies

Browsing data, cookie IDs

USA

We update this page before a new provider starts processing personal data. For application sub-processors, enterprise customers with a DPA are told in advance and can object.

If a public authority asks for a enterprise customer's data, we inform the customer first, where the law allows.

7. Data outside the EU

Our app is hosted by Google Cloud in the United States, and some other providers are also in the US (see the table above). All of them are certified under the EU-US Data Privacy Framework, which the European Commission recognises as providing adequate protection (decision of 10 July 2023). We also have the EU Standard Contractual Clauses in place with them as an extra safeguard. You can ask us for a copy.

8. Cookies

Strictly necessary cookies and storage are used on the platform without consent: your login token, your current game session, and your language choice. Without them the application cannot work.

Analytics cookies and marketing cookies load only if you accept them in the cookie banner. The banner appears on both the marketing website and the platform. If you decline, these scripts are not loaded. You can change your choice at any time in the cookie settings.

9. Your rights

You can ask us to:

  • give you a copy of your data

  • correct it

  • delete it

  • limit how we use it, or object to it (you can always object to marketing)

  • send you your data in a common format, so you can take it elsewhere

  • withdraw any consent you gave

Write to [email protected]. We answer within one month. We may ask you to confirm who you are, for example by writing from your account's email address.

If your data was entered for an organisation (see section 2), we forward your request to them and help them answer.

You can also complain to the Danish Data Protection Agency (Datatilsynet, www.datatilsynet.dk) or to the authority in your country.

10. For enterprise customers

  • DPA: our Data Processing Agreement is available on request. We are also happy to review yours.

  • Data breaches: we inform you without undue delay, and within 24 hours of becoming aware of a breach affecting your data.

  • Sub-processors: we tell you before any change, and you can object.

  • Return of data: instructors can export sessions and results in Excel at any time. A full export is available on request.

  • Deletion: within 30 days after the contract ends. Written confirmation on request.

11. Changes to this policy

We may update this policy. We will change the date at the top, and tell account holders by email about important changes.