Privacy Policy
Last updated: 2026-09-11
This policy explains what personal data Zensimu collects, why, who we share it with, and what your rights are. If anything is unclear, write to us at [email protected].
1. Who we are
Zensimu ApS, Vesterbrogade 26, Copenhagen, Denmark (CVR 44668033).
Mathias Le Scaon, founder, is responsible for privacy. Contact: [email protected]. We are not required to appoint a Data Protection Officer.
Zensimu ApS (“Zensimu”) is concerned about privacy issues and wants you to be familiar with how we collect, use and disclose information.
2. Our two roles
We are the controller for our own relationship with you: your instructor account, billing, support and marketing. This policy covers that data.
We are a processor for the data that instructors and participants enter into simulations for an organisation (a company, university or school). The organisation decides what is collected and why. We use this data only to provide the service, following the organisation's instructions and our Data Processing Agreement (DPA) with them. If you took part in a simulation through your organisation, its own privacy notice applies. If you contact us, we pass your request on to them and help them answer.
3. What we collect
Who | Data |
|---|---|
Instructors | Name, email, organisation name and type, logo (if you add one). Your password is stored encrypted by Google; we never see it. For paid plans: billing name, company and address. Card details go directly to Stripe; we never see them. |
Participants (players) | A display name or nickname, only if the player types one. Game decisions and scores. No account, no email, no password. |
Contacts | What you send us by contact form, support request or email: name, email, company, message. |
All users | Technical data: IP address, browser and device type, how the app is used, and error logs. |
If you sign in with Google or Microsoft, we receive your name and email from them. If a colleague invites you to their team, they give us your email.
We do not collect sensitive data (such as health, religion or political opinions). Please do not enter any in the app.
4. Why we use it
Purpose | Legal basis |
|---|---|
Create your account and run your sessions | Contract |
Send service emails (account, security, changes to our terms) | Contract |
Billing and accounting | Contract and legal obligation |
Answer support requests | Contract or legitimate interest |
Fix errors and keep the platform secure | Legitimate interest |
Check that email addresses are valid | Legitimate interest |
Send newsletters and product news | Legitimate interest. You can unsubscribe in one click. |
Understand how the app is used, to improve it | Consent (cookie banner) |
Measure the performance of our ads | Consent (cookie banner) |
We do not sell your data. We do not use it for automated decisions that affect you.
5. How long we keep it
Instructor accounts: until you ask us to delete your account, or after 36 months without login. We email you before deleting an inactive account.
Session and player data: kept in the instructor's workspace and deleted with it, or earlier on request.
Enterprise customers: deleted within 30 days after the contract ends, on request.
Backups: deleted data is removed from all backups within 35 days.
Invoices and accounting records: 5 years, as required by Danish law.
Support and sales messages: as long as needed for the request or business relationship. We review this at least once a year.
Marketing emails: until you unsubscribe or your account is deleted (see retention period).
6. Who we share it with
We use the providers below (sub-processors) to run Zensimu. Each one has signed a data processing agreement with us and only receives the data it needs.
Application sub-processors:
They process data inside the Zensimu app, including customers' data.
Provider (legal entity) | Purpose | Data | Data location |
|---|---|---|---|
Google Cloud / Firebase (Google Cloud EMEA Ltd, Ireland) | Hosting and database for the app | All app data | USA |
Customer.io (Peaberry Software Inc., USA) | Service emails and newsletters | Name, email, app usage | USA |
Mixpanel (Mixpanel, Inc., USA) | Analytics, to improve the app (only if you accept cookies) | App usage, device data | EU |
PostHog (PostHog, Inc., USA) | Analytics (only if you accept cookies). Session logs, to investigate bugs | App usage, session logs, errors, device data | EU |
Help Scout (Help Scout, USA) | Help desk and knowledge base | Name, email, support messages | USA |
Featurebase (Featurebase OÜ, Estonia) | Feedback board, in-app surveys | Name, email, suggestion | EU |
Emailable (Emailable LLC, USA) | Check that an email address is valid at sign-up | USA |
Billing
Provider (legal entity) | Purpose | Data | Data location |
|---|---|---|---|
Stripe (Stripe, Inc., USA) | Card payments | Name, email, billing and card details | USA |
e-conomic (Visma e-conomic A/S, Denmark) | Invoices and accounting | Name, company, billing details | EU |
Internal tools
Provider (legal entity) | Purpose | Data | Data location |
|---|---|---|---|
Google Workspace (Google LLC, USA) | Email and documents | Contact details, emails, documents | USA |
Slack (Slack Technologies LLC, USA) | Internal communication | Names, emails, messages | USA |
Marketing website
Provider (legal entity) | Purpose | Data | Data location |
|---|---|---|---|
HubSpot (HubSpot, Inc., USA) | Website contact form | Name, email, company, message | EU |
Google Analytics and Google Ads (Google LLC, USA) | Campaign performance statistics, only if you accept cookies | Browsing data, cookie IDs | USA |
We update this page before a new provider starts processing personal data. For application sub-processors, enterprise customers with a DPA are told in advance and can object.
If a public authority asks for a enterprise customer's data, we inform the customer first, where the law allows.
7. Data outside the EU
Our app is hosted by Google Cloud in the United States, and some other providers are also in the US (see the table above). All of them are certified under the EU-US Data Privacy Framework, which the European Commission recognises as providing adequate protection (decision of 10 July 2023). We also have the EU Standard Contractual Clauses in place with them as an extra safeguard. You can ask us for a copy.
8. Cookies
Strictly necessary cookies and storage are used on the platform without consent: your login token, your current game session, and your language choice. Without them the application cannot work.
Analytics cookies and marketing cookies load only if you accept them in the cookie banner. The banner appears on both the marketing website and the platform. If you decline, these scripts are not loaded. You can change your choice at any time in the cookie settings.
9. Your rights
You can ask us to:
give you a copy of your data
correct it
delete it
limit how we use it, or object to it (you can always object to marketing)
send you your data in a common format, so you can take it elsewhere
withdraw any consent you gave
Write to [email protected]. We answer within one month. We may ask you to confirm who you are, for example by writing from your account's email address.
If your data was entered for an organisation (see section 2), we forward your request to them and help them answer.
You can also complain to the Danish Data Protection Agency (Datatilsynet, www.datatilsynet.dk) or to the authority in your country.
10. For enterprise customers
DPA: our Data Processing Agreement is available on request. We are also happy to review yours.
Data breaches: we inform you without undue delay, and within 24 hours of becoming aware of a breach affecting your data.
Sub-processors: we tell you before any change, and you can object.
Return of data: instructors can export sessions and results in Excel at any time. A full export is available on request.
Deletion: within 30 days after the contract ends. Written confirmation on request.
11. Changes to this policy
We may update this policy. We will change the date at the top, and tell account holders by email about important changes.