Legal

Privacy Policy

Last updated

Last edited on: 01-10-2026

1. About this policy

SimplyAi B.V. provides SimplyOS and this website. We are at De Nieuwe Erven 12, 5431 NT Cuijk, the Netherlands (KvK 89521811). Contact info@simplyrecruit.ai about privacy.

We are the controller for our website, enquiries, commercial relationships, billing and marketing. For customer recruitment records, communications and workspace logs, we act as processor on the customer’s instructions under the Data Processing Agreement (DPA). The recruiting organisation’s notice explains its purposes, legal grounds and retention. Contact it about its records; we help route requests and assist it. Separate information covers Simply’s own employment and recruitment.

2. Information we collect and why

For our own activities, we collect contact and company details, demo and booking information, correspondence, account-administration and billing records. Website visits generate IP addresses, device information, logs and, with consent, identifiers and interaction data. Information comes from you, your device, your organisation or referrals. For indirect collection, we explain the source by first contact or disclosure, or otherwise within one month where required.

Purpose Legal basis
Respond to enquiries and arrange, prepare for and follow up on requested demos Legitimate interest in responding to business requests
Manage customer relationships, accounts and essential service communications Legitimate interest in serving your organisation
Protect our website, prevent abuse and handle legal claims Legitimate interests in security, preventing misuse and protecting legal rights
Keep required tax records and fulfil privacy obligations Legal obligation
Send optional promotions; use optional analytics and advertising tools Consent

Where you personally request or enter a contract, necessary pre-contract and service administration rely on contractual necessity instead. We assess legitimate interests against your rights. Required fields are needed to handle the request; without them we may be unable to do so. Optional tracking is not required to browse or request a demo. Using Simply is not blanket consent.

3. Customer data and AI

We process CVs, professional and contact details, applications, assessments, documents, communications, recordings and generated results for customer-configured transcription, search, drafting, matching and automation. Sources include customers, candidates, imports, connected accounts and external enrichment providers.

Matching uses customer-selected criteria such as skills, experience and qualifications; scores can affect who recruiters review. Customers can inspect and override results and must provide required human review and decision information. Simply does not make hiring decisions for customers or solely automated decisions with legal or similarly significant effects for its own business activities.

We and our subprocessors do not use customer data to train or fine-tune AI models, or use it for advertising. We do not sell it or build a shared candidate database.

4. Connected accounts

With your permission, connections such as Google and Microsoft provide identity, contacts, email, attachments, calendars and access tokens for enabled synchronisation, communication, scheduling and AI features. Connection screens explain access and uses. Authorised workspace users and necessary service providers receive data subject to these restrictions.

Simply’s use and transfer of Google API data comply with the Google API Services User Data Policy, including Limited Use, and the Google Workspace policy. This includes derived data: no advertising, sale, credit assessment or AI training. Staff reading requires the relevant Google user’s affirmative agreement to the specific content, unless a Google-policy exception applies. General support authorisation is insufficient; business-sale transfers require explicit prior user consent. These restrictions prevail over general sharing permissions.

Disconnect in Simply or revoke permissions through your Google or Microsoft account. This stops future access. Contact the customer or us about deleting retained copies, which follow lawful customer instructions, the DPA and any stricter provider requirements.

5. Cookies and marketing

Necessary storage supports functions such as security and language preferences. With your prior consent, we use Google Tag Manager to manage tags, Google Analytics for usage measurement, Meta Pixel and LinkedIn Insight Tag for conversions and retargeting, Factors.ai for company identification and attribution, and Contentsquare for experience analysis and session visualisations. These involve technical identifiers and activity data; company-level reporting does not make collection anonymous. Form inputs and sensitive content are excluded or masked. Customer workspace content and submitted contact details are not used for these tools.

Cookie settings identifies technologies, providers, purposes and durations and lets you reject optional tracking or withdraw consent. Embedded booking and video services may also receive technical data; their optional tracking requires consent.

For relevant Pixel collection and transmission, Simply and Meta share responsibilities under the Meta Controller Addendum: Simply handles its implementation, notice and consent; Meta handles its processing and associated safeguards. Rights may be exercised against either. Meta’s further uses and LinkedIn’s independent-controller processing follow their Meta and LinkedIn notices.

You can stop direct marketing and related profiling at any time, using unsubscribe, Cookie settings or our email address. A demo request does not subscribe you to promotions. Essential service messages may continue.

6. Who receives information

Access is limited to authorised staff and suppliers supporting hosting, security, communications, support, billing and the website. Our demo form uses Formspark; bookings use TidyCal. Other website providers appear in section 5. Processors act under processing agreements; providers acting independently have their own notices. Customer-data subprocessors appear in the DPA’s register.

Necessary, protected disclosures to advisers, authorities or business successors require legal justification. Customer-selected integrations follow their own terms. Customer-data and Google restrictions still apply.

7. Where data is processed

The platform, primary databases and stored customer files are hosted in the Netherlands. Simply-managed AI, backups, support and logs containing customer data remain in the EU. Customer-selected integrations or AI provider keys can direct specified data elsewhere, subject to lawful transfer safeguards.

Website and business providers have a separate processing chain, including US processing by TidyCal and Factors.ai and international processing by analytics and advertising providers. Transfers outside the EEA use applicable adequacy decisions or appropriate safeguards, normally EU standard contractual clauses with necessary assessments and supplementary measures. Ask us for destination details and copies of the relevant safeguards.

8. Retention and security

For information we control, our usual maximum periods are:

  • Enquiries and unsuccessful demos: 12 months after substantive contact; ordinary account administration: the relationship plus 12 months; administrative support correspondence: 24 months after closure.
  • Routine website security logs: 90 days; identifiable analytics events: 14 months; session visualisations: 30 days; company-identification and attribution records: 12 months; retargeting audience membership: 90 days after the last qualifying event.
  • Marketing contacts: until withdrawal or objection, with an inactivity review after 24 months. We keep minimal suppression records to honour objections.
  • Required tax records: normally seven years. Necessary consent, contract and claim evidence: the applicable limitation period and ongoing proceedings, subject to periodic necessity review.

We delete earlier when no longer needed or legally required. Specific records may be kept longer for a legal duty, an identified incident or a live dispute. These limits include our processors’ copies; independent providers explain their separate retention. Customer records follow customer instructions and the DPA’s deletion, backup and exit provisions.

Our service’s ISO 27001-certified information-security management system includes encryption, access controls, confidentiality, monitoring and incident response. See our Security page.

9. Your rights and policy updates

Under the GDPR, you may request access, correction, deletion, restriction and, where applicable, portability. You may object to legitimate-interest processing based on your circumstances; we stop unless a GDPR exception applies. Direct-marketing objections are unconditional. You may withdraw consent without affecting earlier lawful processing and exercise applicable rights concerning significant automated decisions, including human intervention and contesting a decision.

Email info@simplyrecruit.ai. Requests are normally free; we may proportionately verify identity. We respond within one month, explaining any justified extension of up to two further months within that first month. You may complain directly to the Autoriteit Persoonsgegevens or another competent supervisory authority and seek a judicial remedy.

We date updates and notify material changes as required. New purposes are explained before use, with fresh consent where needed. Updates do not reduce existing contractual data-protection commitments.