Last updated: August 4, 2026 · Version 3.0
GDPR Compliance
This page provides information about how SOCSimulator LLC complies with the General Data Protection Regulation (GDPR) and your rights as a European Union resident.
Table of Contents
1. GDPR Overview
The General Data Protection Regulation (GDPR) is a European Union regulation that provides comprehensive data protection rights to individuals within the EU and EEA. SOCSimulator LLC is committed to protecting the privacy and security of your personal data in compliance with GDPR.
This page supplements our Privacy Policy with additional information specific to GDPR compliance.
2. Data Controller
SOCSimulator LLC is the data controller for personal data collected through SOCSimulator. This means we determine the purposes and means of processing your personal data.
Contact Information:
- Company: SOCSimulator LLC
- Address: 30 N Gould St Ste N, Sheridan, WY 82801
- Email: support@socsimulator.com
Send data protection enquiries to that address — whether you are exercising a right as an individual in the EEA or the UK, or writing on behalf of a supervisory authority. We route every enquiry internally to the people responsible for data protection and respond within the time limits the GDPR sets. Where a request is lawful and applies to us, we act on it.
3. Lawful Basis for Processing
Under GDPR, we must have a valid legal basis for processing your personal data. We rely on the following lawful bases:
| Processing Activity | Lawful Basis | GDPR Article |
|---|---|---|
| Account creation and management | Contract performance | Art. 6(1)(b) |
| Processing payments | Contract performance | Art. 6(1)(b) |
| Sending transactional emails | Contract performance | Art. 6(1)(b) |
| Analytics, incl. sampled session replay & heatmaps (service improvement) | Legitimate interest | Art. 6(1)(f) |
| Marketing communications | Consent | Art. 6(1)(a) |
| Security and fraud prevention | Legitimate interest | Art. 6(1)(f) |
| Account restrictions, recovery, and review | Contract performance and legitimate interest | Art. 6(1)(b), Art. 6(1)(f) |
| Legal compliance | Legal obligation | Art. 6(1)(c) |
4. Your Rights Under GDPR
As an EU/EEA resident, you have the following rights regarding your personal data:
Right of Access (Art. 15)
You have the right to request a copy of the personal data we hold about you, along with information about how we process it.
Right to Rectification (Art. 16)
You have the right to request correction of inaccurate personal data or completion of incomplete data.
Right to Erasure (Art. 17)
Also known as the "right to be forgotten," you can request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for its original purpose.
Right to Restriction of Processing (Art. 18)
You can request that we limit how we use your data in certain circumstances, such as while we verify its accuracy.
Right to Data Portability (Art. 20)
You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller.
Right to Object (Art. 21)
You can object to processing based on legitimate interests, including profiling. You can also object to direct marketing at any time.
Right to Withdraw Consent (Art. 7)
Where we rely on consent, you can withdraw it at any time. This does not affect the lawfulness of processing before withdrawal.
Rights Related to Automated Decision-Making (Art. 22)
You have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects. Security automation may flag an account or apply a temporary, remediable access restriction, but we do not treat an automated signal as conclusive evidence for a permanent ban. We provide the general reason, a recovery path where available, and a way to request human review from a person authorized to restore access. We do not currently use solely automated decisions that we expect to produce legal or similarly significant effects.
How to Exercise Your Rights
To exercise any of these rights, please contact us at support@socsimulator.com. We will respond to your request within 30 days. In some cases, we may need to verify your identity before processing your request.
5. Data Processing Activities
We process personal data for the following purposes:
| Category | Data Types | Retention Period |
|---|---|---|
| Account Data | Email, display name, password hash | Until account deletion + 30 days |
| Profile Data | Job title, organization, avatar | Until account deletion |
| Usage Data | Scenarios completed, time spent, progress | Until account deletion |
| Payment Data | Billing address, transaction history | 7 years (legal requirement) |
| Log Data | IP address, browser, device info | 90 days |
| Communication Data | Support tickets, emails | 3 years |
| Account Restriction Data | Reason code, status, recovery steps, evidence, review log | Until account deletion, subject to legal holds |
6. International Data Transfers
SOCSimulator LLC is based in the United States. When you use SOCSimulator, your personal data may be transferred to and processed in the United States.
We ensure appropriate safeguards for international transfers through:
- Standard Contractual Clauses (SCCs): We use EU-approved SCCs with our service providers
- Data Processing Agreements: Contracts with sub-processors that ensure GDPR-compliant data handling
- EU-Based Processing: Where possible, we use service providers with EU data centers (e.g., Supabase EU region)
7. Data Protection Measures
We implement technical and organizational measures to protect your data:
Technical Measures
- Encryption in transit (TLS) and at rest, provided by our infrastructure providers (Supabase, Vercel)
- Authentication and password storage managed by our identity provider (Supabase Auth)
- Automated dependency-vulnerability monitoring on our codebase
- Encrypted, access-controlled database backups (managed by Supabase)
Organizational Measures
- Least-privilege access to production data, limited to the company principal
- Sub-processors selected for recognized security certifications (e.g., SOC 2) and bound by data-processing terms
- A documented incident-response process, including breach notification
- Risk assessments for new processing, including a legitimate-interest assessment for product analytics
8. Data Breach Notification
In the event of a personal data breach, we will:
- Notify the relevant supervisory authority within 72 hours (where required)
- Notify affected individuals without undue delay if the breach poses high risk to their rights and freedoms
- Document all breaches, including their effects and remedial actions taken
9. Complaints
If you are unhappy with how we handle your personal data, you have the right to lodge a complaint with a supervisory authority. You can contact:
- The supervisory authority in your EU/EEA country of residence
- The supervisory authority where the alleged infringement occurred
However, we encourage you to contact us first at support@socsimulator.com so we can try to resolve your concerns directly.
A list of EU/EEA supervisory authorities is available at: European Data Protection Board - Members
10. Contact Us About Data Protection
For any GDPR-related inquiries or to exercise your data subject rights, please contact:
- Email: support@socsimulator.com
- Subject Line: Please include "GDPR Request" in your subject line
- Response Time: We will respond within 30 days
For general privacy inquiries, see our Privacy Policy or contact support@socsimulator.com.