SIMBIM
Company policy

Privacy Policy

This Privacy Policy explains how SIMBIM collects, uses, stores and protects personal data through its website, the My SIMBIM client portal, software licensing, consulting, training and support services.

Last reviewed: 18 August 2026

Who we are

This Privacy Policy explains how Simulación y Modelado de Información para la Edificación S.L.U. ("SIMBIM", "we", "us" or "our") collects, uses, stores and protects personal data through our website, the My SIMBIM client portal, contact forms, software licensing processes, consulting services, training activities, support channels and related business communications.

  • Data controller: Simulación y Modelado de Información para la Edificación S.L.U.
  • Trading name: SIMBIM
  • Tax ID: ESB66148818
  • Registered office: Av. Diagonal 640, P6 (SIMBIM), 08017, Barcelona, Spain
  • Canonical website: https://simbim.eu
  • Privacy contact: gdpr@simbim.eu
  • General support contact: support@simbim.eu

During SIMBIM's domain and mailbox transition period from .es to .eu, the website may operate under simbim.eu while privacy and support communications continue to use monitored simbim.es parallel to simbim.eu email addresses. These contact addresses will remain valid until SIMBIM publishes updated contact details and a change notification.

Services contracted with SIMBIM INC. (Toronto, Canada) may be subject to separate contractual terms; the controller for personal data processed through this website and the My SIMBIM portal is the Spanish company identified above.

SIMBIM has not appointed a Data Protection Officer. Privacy matters and data-protection rights requests are handled through the privacy contact listed above. If SIMBIM appoints a Data Protection Officer in the future, this Privacy Policy will be updated with the relevant contact details.

Scope of this policy

This policy applies to personal data processed when you:

  • visit SIMBIM websites;
  • use the My SIMBIM client portal;
  • contact us through forms, email, telephone, chat or social media;
  • request information about software, consulting, training or support;
  • create or use a customer account;
  • request a proposal, quotation, renewal, licence, subscription or support service;
  • purchase products or services from SIMBIM;
  • subscribe to newsletters or marketing communications;
  • attend training, webinars, events or certification-related activities;
  • interact with SIMBIM customer support or implementation teams;
  • use portals, payment links or third-party platforms connected to SIMBIM services.

This policy does not replace the privacy notices of third-party software vendors, payment providers, learning platforms, cloud service providers or other independent controllers. Where those third parties process your data for their own purposes, their own privacy policies apply.

Personal data we collect directly from you

Depending on your relationship with SIMBIM, we may collect the following categories of personal data directly from you.

Identification and contact data. Name, surname, company name, job title, professional role, email address, telephone number, billing address, delivery address and country.

Account and customer data. Login details, customer profile information, account status, language preference, order history, invoices, subscriptions, licences, renewals, support records, billing references and service history.

Commercial and enquiry data. Information submitted through forms, emails, calls, proposal requests, software enquiries, training requests, event registrations and consultation requests.

Software licensing and support data. Licence holder details, organisation details, software product, subscription or maintenance information, renewal status, technical support tickets, implementation notes, support correspondence and vendor-related licence fulfilment data.

Training and event data. Course registration details, attendance information, certification-related records where applicable, training preferences and communication history.

Payment and billing data. Billing details, transaction references, payment status, invoices and accounting records. Where card or bank payments are handled by external payment providers, SIMBIM does not intentionally store full payment card details unless explicitly required and lawfully processed.

Marketing and communication data. Newsletter preferences, marketing consent records, communication history, product interests, event interests and unsubscribe records.

Technical and website data. IP address, device information, browser type, operating system, website usage data, cookies, analytics identifiers, log data and similar technical information.

Support interaction data. Messages, contact details and metadata generated when you use support, helpdesk or customer-service tools.

Portal activity data. When you use the My SIMBIM portal, SIMBIM records account and status events (for example: account created, account approved, request submitted, status changed) together with the acting user, timestamp and affected record, for security, traceability and audit purposes.

Compliance and security data. Records needed to protect our systems, prevent fraud, manage legal claims, respond to rights requests, keep audit trails and comply with legal obligations.

Personal data we may receive from third parties

SIMBIM may also receive personal data indirectly from third parties. This may include:

  • contact details of a customer's employees, consultants or authorised representatives provided by that customer;
  • licence-holder or subscription-administrator details provided by a customer organisation;
  • software licence, renewal or entitlement data provided by software vendors, distributors or technology partners;
  • training registration details provided by an employer, organisation or event coordinator;
  • billing or payment confirmation data provided by payment or accounting providers;
  • support or implementation information provided by software vendors or customer systems;
  • professional contact data from public business sources or previous business interactions.

Where SIMBIM receives personal data indirectly, we process it only for the purposes described in this policy and according to the applicable legal basis. Where required by law, SIMBIM will provide the relevant privacy information to the individual or ensure that the organisation providing the data has a lawful basis to share it.

Why we process personal data and legal basis

We process personal data only where there is a lawful basis under applicable data-protection law.

Responding to enquiries and contact requests. Contact details, enquiry content and communication history. Legal basis: legitimate interest in responding to business enquiries. Where the enquiry relates to a possible contract, the legal basis may be pre-contractual steps requested by the individual.

Preparing proposals and quotations. Contact details, company details, requested products/services, project or licence information. Legal basis: pre-contractual steps or legitimate interest in managing commercial opportunities, understanding customer requirements and preparing relevant commercial responses.

Managing software licences, subscriptions, renewals and support. Customer details, licence details, vendor-related fulfilment data, support records. Legal basis: contract performance. Additional basis may apply where processing is necessary to comply with legal obligations or to protect SIMBIM's legitimate interest in maintaining service continuity and support history.

Delivering consulting, implementation, training and professional services. Contact details, project information, training data, support records and service history. Legal basis: contract performance. Legitimate interest may apply where SIMBIM processes business contact data to coordinate delivery with a customer organisation.

Managing customer accounts, orders, invoices and payments. Account details, billing details, order records, invoices and transaction references. Legal basis: contract performance. Legal obligation applies to accounting, invoicing and tax record keeping.

Operating the My SIMBIM portal, including account approval and audit logging. Account data, organisation linkage, status events and access logs. Legal basis: contract performance (providing the portal service you or your organisation requested); legitimate interest in security, traceability and abuse prevention. Where you self-register and your account awaits approval, the legal basis is pre-contractual steps taken at your request.

Sending service and transactional emails (invitations, password resets, request confirmations, notifications). Contact details, message content and delivery outcomes. Legal basis: contract performance and legitimate interest in reliable service communication. See "Service providers we use" for the sending provider.

Sending newsletters and marketing communications. Contact details, consent records, preferences, product interests and unsubscribe records. Legal basis: consent, where required. Where permitted by law for existing customer relationships and similar services, SIMBIM may rely on legitimate interest, subject to the right to object and the right to unsubscribe at any time.

Communicating with customers about licences, renewals, updates or services. Contact details, licence/subscription details and communication history. Legal basis: contract performance where the communication relates to the service or licence. Legitimate interest may apply to service continuity, renewal reminders and customer relationship management.

Sharing information with software vendors or technology partners. Relevant contact, licence, organisation, order or support details, when needed for licensing, support or implementation. Legal basis: contract performance where sharing is necessary to issue, renew, manage or support licences or services. Legitimate interest may apply where sharing is necessary to coordinate technical support, implementation or vendor fulfilment.

Website operation, application security and basic technical functionality. Technical data, session data, security logs and necessary cookies/storage. Legal basis: legitimate interest in operating a secure and functional website and web application. Where cookies or storage are strictly necessary to provide a service requested by the user, consent is not required.

Analytics, non-essential cookies and marketing tracking. Technical data, cookies, usage data and analytics identifiers. Legal basis: consent. SIMBIM does not currently use third-party analytics, advertising, remarketing or pixel-tracking technologies on the website unless this is later added and consented through the cookie banner.

Compliance, claims and legal obligations. Relevant records, invoices, contracts, communications and audit logs. Legal basis: legal obligation where SIMBIM must comply with accounting, tax, regulatory or data-protection obligations. Legitimate interest may apply where processing is necessary to establish, exercise or defend legal claims.

Where SIMBIM relies on legitimate interest, we assess whether the processing is necessary, proportionate and balanced against the rights and freedoms of the individuals concerned. You may object to processing based on legitimate interest in the circumstances described in the data-protection rights section.

The My SIMBIM client portal

The My SIMBIM portal at simbim.eu/portal is an account-based environment where SIMBIM clients manage their commercial relationship with SIMBIM.

Accounts. Accounts are created by SIMBIM invitation or by self-registration. Self-registered accounts remain pending until reviewed and approved by SIMBIM staff; until approval, the account has no access to any client data. SIMBIM staff link approved accounts to the correct client organisation.

What you can see. Portal users see only records belonging to their own organisation: subscriptions, contracts, proposals, invoices, licence-delivery information, support requests and documents shared with the organisation. Access is enforced at the database level per organisation.

Documents. Contracts, invoices and related documents shown in the portal are stored in SIMBIM's backend platform (see "Service providers we use") and served through short-lived, access-controlled links.

Activity and audit logging. For security and traceability, the portal keeps an append-only record of account and status events (who changed what, and when). These records support service integrity, dispute resolution and compliance, and are retained per the Data retention section.

Emails from the portal. The portal sends invitations, password resets, confirmations and notifications from notifications@m.simbim.eu with reply routing to support@simbim.eu. These messages are delivered through Resend, Inc. (see "Service providers we use" and "International transfers"). Service and transactional emails sent by the portal do not contain open-tracking pixels or rewritten tracking links; SIMBIM processes only delivery outcomes (sent, delivered, failed) to verify service reliability.

Marketing communications

SIMBIM may send information about software, renewals, training, consulting, support, events, offers or related BIM and AECO services where we have a lawful basis to do so.

Where required, we will ask for your consent before sending marketing communications. You can withdraw consent or unsubscribe at any time using the unsubscribe link in our messages or by contacting us at gdpr@simbim.eu.

Where marketing communications involve software vendors or technology partners, SIMBIM will only share or use your data for that purpose where there is a lawful basis and where the communication is relevant to your request, relationship or consent.

We do not sell personal data.

Software vendors, partners and third-party recipients

SIMBIM works with software vendors, distributors, technology partners, certification bodies, payment processors, cloud providers, communication platforms, CRM systems, learning platforms, accounting tools and professional advisers.

We may share personal data with third parties where necessary to:

  • issue, renew or manage software licences;
  • process orders, payments and invoices;
  • provide support or implementation services;
  • manage training or certification-related activities;
  • communicate with customers;
  • operate the website, web application and customer systems;
  • comply with legal, tax or accounting obligations;
  • protect SIMBIM's rights, systems and customers.

Third parties may act as processors on behalf of SIMBIM or as independent controllers depending on the circumstances. Where a third party acts as a processor, SIMBIM requires appropriate contractual safeguards. Where a third party acts as an independent controller, that party's own privacy policy applies.

Service providers we use

SIMBIM uses the following service providers as processors or sub-processors for the website and the My SIMBIM portal. This list is reviewed when providers change; material changes are reflected in this policy before activation.

ProviderRoleCompany locationData location and transfer safeguards
Lovable Labs ABApplication platform: development, hosting and managed backend for the website and portalSweden (EU)Processor under Lovable's data processing agreement; the backend is operated on Supabase (below)
Supabase Inc. (sub-processor engaged via the application platform)Database, authentication and file storage for the portalUSA; infrastructure on AWSSafeguarded under the applicable data processing agreements (EU–U.S. Data Privacy Framework and/or Standard Contractual Clauses)
Resend, Inc.Transactional email delivery (invitations, resets, notifications) — open and click tracking disabledUSA (emails dispatched from EU infrastructure, Ireland)Emails are dispatched from EU (Ireland) infrastructure; account data, delivery logs and message metadata are stored in the USA. EU–U.S. Data Privacy Framework certification and Standard Contractual Clauses under the provider's data processing agreement
MailerLiteNewsletter deliveryLithuania (EU)EU processing under the provider's data processing agreement
Capsule CRM (Zestia Ltd)Customer relationship managementUnited KingdomEuropean Commission adequacy decision for the United Kingdom
ZendeskCustomer support ticketing, help centre and live chat (messaging widget)USAEU–U.S. Data Privacy Framework and/or Standard Contractual Clauses under the provider's data processing agreement
Better ProposalsProposal preparation and electronic signatureUnited KingdomEuropean Commission adequacy decision for the United Kingdom
FreeAgentInvoicing and accounting (until planned replacement, end-2026)United KingdomEuropean Commission adequacy decision for the United Kingdom
Microsoft 365Corporate email and productivityUSA / IrelandMicrosoft's data processing agreement, including EU Data Boundary commitments; EU–U.S. Data Privacy Framework and/or Standard Contractual Clauses
DonDominioDomain registration and DNSSpain (EU)EU processing

Providers act under data-processing agreements with appropriate safeguards. Payment processing, workflow automation and further electronic-signature tooling are planned integrations: they are not active at the date of this policy and will be added to this list, with any required transfer safeguards, before activation.

International transfers

Some of the providers listed above process personal data outside the European Economic Area:

United States: Resend (transactional email; messages are dispatched from EU infrastructure in Ireland, while account data and delivery logs are stored in the USA), Zendesk (support), Microsoft (corporate email and productivity), and Supabase Inc. as sub-processor of the application platform. Transfers rely on the EU–U.S. Data Privacy Framework where the provider is certified, and otherwise on Standard Contractual Clauses annexed to the provider's data-processing agreement, together with technical and organisational safeguards.

United Kingdom: Capsule CRM, Better Proposals and FreeAgent. Transfers rely on the European Commission's adequacy decision for the United Kingdom.

You may request further information about the safeguards used, including copies where applicable, by contacting gdpr@simbim.eu.

Cookies and similar technologies

SIMBIM websites may use cookies or similar technologies for necessary website operation, consent management, session continuity, preferences, security and portal functionality.

At the time of this policy, SIMBIM does not currently use third-party analytics, advertising, remarketing, pixel tracking, third-party live chat, third-party embedded-content cookies or third-party marketing cookies on the website unless later added and disclosed in the Cookie Policy.

Necessary cookies or storage may be used to operate the website, maintain sessions, remember cookie choices, protect the site and provide requested services.

Non-essential cookies, including analytics, marketing or third-party tracking cookies, will only be used where valid consent has been obtained through the cookie banner or cookie settings panel.

Users must be able to accept, reject or configure non-essential cookies in a clear and accessible way.

For detailed information about cookies, providers, purposes, duration and how to change your choices, users should consult SIMBIM's Cookie Policy or cookie settings panel when available.

Forms, portals and communication tools

When you contact SIMBIM through contact forms, email, telephone or similar tools, we process the information you provide so that we can respond to your request, manage support, follow up on opportunities, prepare proposals, resolve incidents or maintain customer records.

Basic anti-abuse measures (such as submission-timing checks) protect the forms; the legal basis is SIMBIM's legitimate interest in security.

The website offers an optional live chat operated by Zendesk. The chat widget and its cookies load only when you choose to start a chat; until then, no Zendesk script runs on your device. Chat conversations are processed by Zendesk as described in "Service providers we use" and "International transfers".

If SIMBIM later adds third-party live chat, helpdesk, analytics, scheduling or embedded-content tools, the relevant provider and processing details must be reflected in the Privacy Policy and Cookie Policy before publication or activation.

Customer accounts, orders and payments

If you create an account or place an order, SIMBIM may process personal data needed to manage your account, process the transaction, issue invoices, manage renewals, provide support and comply with accounting and tax obligations.

This may include identity data, contact data, billing data, order history, licence details, support records and payment status.

Payment information may be processed by external payment providers. SIMBIM does not intentionally store full payment-card data where payments are handled directly by those providers.

Data retention

SIMBIM keeps personal data only for as long as necessary for the purposes for which it was collected, including legal, accounting, contractual, tax, support, audit and dispute-resolution requirements.

General retention criteria:

  • Enquiry and contact records: kept while the enquiry is active and for a reasonable follow-up period afterwards, unless a longer period is needed for legal claims or business continuity.
  • Customer, order, licence and invoice records: kept for the duration of the customer relationship and for statutory accounting and tax periods.
  • Accounting, commercial and business records: generally retained for six years from the last relevant accounting entry, in line with Spanish commercial record-keeping obligations, unless a longer period applies.
  • Tax-related records: generally retained for at least four years, subject to the applicable tax limitation periods and any interruptions or special rules.
  • Contract and proposal records: kept for the duration of the relationship and for the applicable limitation periods for legal claims.
  • Support records: kept as needed to provide service continuity, evidence support history, improve quality and protect SIMBIM's legitimate interests.
  • Marketing records: kept until consent is withdrawn, the user unsubscribes, the user objects, or the data is no longer needed.
  • Cookie consent records: kept according to the cookie tool's retention settings and applicable guidance.
  • Portal activity and audit logs: retained for the duration of the client relationship plus six years, aligned with commercial-record retention, to support security, dispute resolution and compliance.
  • Email delivery logs: send outcomes and related metadata retained for twelve months, then deleted or anonymised.
  • Legal/compliance records: kept as long as necessary to comply with law or defend legal claims.

When data is no longer needed, it will be deleted, anonymised or securely archived according to SIMBIM's retention procedures.

Minors

SIMBIM services are intended for professional and business users, not children. We do not knowingly collect personal data from minors through the website for commercial services.

Under Spanish data-protection law, minors aged 14 or over may give valid consent for the processing of their personal data in the circumstances permitted by law. For children under 14, consent must be given by the holder of parental responsibility or legal guardianship where consent is the relevant legal basis.

If a training, event or educational activity involves minors, SIMBIM will apply additional safeguards and obtain any required authorisations where applicable.

Your data-protection rights

You may exercise the following rights under applicable data-protection law:

  • Right of access: to know whether SIMBIM processes your personal data and obtain a copy.
  • Right to rectification: to correct inaccurate or incomplete data.
  • Right to erasure: to request deletion where legally applicable.
  • Right to restriction: to request limitation of processing in certain cases.
  • Right to object: to object to processing based on legitimate interests or direct marketing.
  • Right to portability: to receive certain data in a structured, commonly used and machine-readable format.
  • Right to withdraw consent: to withdraw consent at any time where processing is based on consent.
  • Right not to be subject to automated decisions producing legal or similarly significant effects, where applicable.

To exercise your rights, contact SIMBIM at gdpr@simbim.eu. We may need to verify your identity before responding. We will respond within the legally required period.

If you object to processing based on legitimate interest, SIMBIM will stop the processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or unless the processing is necessary for legal claims.

You also have the right to lodge a complaint with the Spanish Data Protection Agency: Agencia Española de Protección de Datos (AEPD), https://www.aepd.es.

Automated decision-making and profiling

SIMBIM does not make decisions based solely on automated processing that produce legal effects or similarly significant effects on individuals. Portal status changes and account approvals are performed by SIMBIM staff.

SIMBIM may use basic segmentation or preference information to understand customer interests, manage communications or improve services, but this does not involve legally significant automated decision-making.

If SIMBIM introduces automated decision-making in the future, this policy will be updated and affected individuals will be informed as required by law.

Security measures

SIMBIM applies technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration or disclosure. These measures may include:

  • access control;
  • role-based permissions;
  • per-organisation database access enforcement;
  • secure authentication;
  • controlled records;
  • backups;
  • provider due diligence;
  • confidentiality obligations;
  • audit and review procedures;
  • secure communication and storage practices;
  • staff awareness and internal governance.

No system can be guaranteed completely secure, but SIMBIM works to maintain protection proportionate to the nature of the data and the risks involved.

Confidentiality

SIMBIM personnel, collaborators and service providers who access personal data must handle it confidentially and only for authorised purposes.

Confidentiality applies to customer data, project data, commercial information, support records, licence data, training records and any personal data processed through SIMBIM systems.

Changes to this Privacy Policy

SIMBIM may update this Privacy Policy to reflect legal, technical, organisational or service changes.

The latest version will be published on the website with the applicable "Last reviewed" or "Last updated" date.

Material changes may be communicated through the website or by direct notice where appropriate.

Contact

For privacy-related questions, data-protection rights requests or concerns about personal data processing, contact:

  • SIMBIM — Simulación y Modelado de Información para la Edificación S.L.U.
  • Av. Diagonal 640, P6 (SIMBIM), 08017, Barcelona, Spain
  • Privacy email: gdpr@simbim.eu
  • General support: support@simbim.eu
  • Website: https://simbim.eu

During SIMBIM's transition from the older simbim.es environment to the new simbim.eu website, the simbim.es email addresses listed in this policy remain the monitored contact channels for privacy and support matters.

Barcelona, 2026

SIMBIM's Management