Simple Smooth Safe
Privacy

Privacy Policy

What we collect, why, and how to make it stop. This covers this website and our dealings with you as a prospect or customer contact — not the data inside your own Dataverse, which never reaches us and is covered by the Data Processing Agreement.

Version 1.0 Effective 10 August 2026

This is an archived version. It is published so that customers who ordered while it was in force can read the text that applied to them. It is not the current version — see the current documents.

Data controller

Simple Smooth Safe, Unipessoal Lda.
Rua Retiro dos Pacatos 50, Ed. Startup, Sala 9
2635-224 Rio de Mouro, Sintra, Portugal
NIF / VAT: PT518264742
info@simplesmoothsafe.com

We are a small company and are not required to appoint a Data Protection Officer. Privacy questions go to the address above and reach a person, not a queue.

The short version

1. What we collect, and why

1.1 Website analytics

We use Plausible Analytics to understand which pages are read and which links are used. Plausible is privacy-focused and EU-hosted: it sets no cookies, stores no personal data, does not fingerprint devices, and does not track visitors across sites or sessions.

It records aggregate page views, referrer, and coarse device and country information derived from the request and then discarded. No profile is built, and nothing collected identifies you.

FieldDetail
Legal basisLegitimate interest (Art. 6(1)(f) GDPR) — understanding whether our own website works. The balancing test is straightforward because no personal data is stored and no profiling occurs.
RetentionAggregate statistics only. No individual record exists to delete.
Consent needed?No. There is no cookie or device-storage access, so the ePrivacy consent requirement does not arise.

1.2 When you email us

If you contact us we hold your name, email address, whatever you chose to tell us about your organisation, and the correspondence itself.

FieldDetail
PurposeTo answer you, and to follow up on the specific thing you asked about.
Legal basisLegitimate interest (Art. 6(1)(f)) in responding to an enquiry you initiated, or steps prior to entering a contract (Art. 6(1)(b)) where you are asking to buy.
RetentionUp to 24 months after our last exchange, then deleted — unless you become a customer, in which case section 1.4 applies.

1.3 Early access and enquiry forms

Our forms are hosted on Microsoft Forms. They collect your name, work email, company, tenant or environment details, and whether you are a partner or an end client — behind a required consent question that is not pre-ticked, because a pre-ticked box is not consent.

FieldDetail
PurposeTo contact you about the product you asked about — early access, availability, or a demo. That is the only thing it is used for.
Legal basisConsent (Art. 6(1)(a)), given by ticking the box on the form.
RetentionUntil you withdraw consent, or until the programme you signed up for closes, whichever is first.
WithdrawingEmail us. No reason needed, no effect on anything else, and no retention "for our records".

1.4 Customer and supplier records

If your organisation becomes a customer we hold business-contact details for the people we deal with — name, role, work email, work phone — plus contracts, invoices and support correspondence.

FieldDetail
PurposePerforming the contract, supporting the products, and meeting our accounting and tax obligations.
Legal basisContract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)) for the accounting records.
RetentionFor the life of the relationship, then 10 years for anything that forms part of the accounting record, which is the retention period Portuguese tax law requires. Contact details not needed for that are deleted within 12 months of the relationship ending.

1.5 Support access to your systems

Resolving a support case occasionally requires us to look at your environment. When it does, we may see personal data belonging to your staff or your clients. In that situation you are the controller and we are your processor — the Data Processing Agreement governs it, not this policy. Access is on your invitation, for the case, and we do not take copies.

2. What we do not do

3. Who else sees it

Only the processors we need to run the business, each bound by a data-processing agreement:

ProcessorPurposeLocation
Microsoft Ireland Operations LtdEmail, file storage, Microsoft FormsEU
Plausible Insights OÜCookieless website analyticsEU (Estonia / Germany)
Our hosting providerServing this websiteEU
Our accountantStatutory accounting and tax filingPortugal

We will also disclose data where the law requires it. If we are ever compelled to, we will tell you unless we are legally prohibited from doing so.

The Data Processing Agreement carries the sub-processor list that applies when we process data on a customer's behalf, and the notice terms for changing it.

4. International transfers

Our processors are established in the EU and we ask them to keep data in the EU. Where a processor is part of a group that may access data from outside the EEA, transfers rely on the European Commission's Standard Contractual Clauses together with the supplementary measures the transfer requires. We do not transfer personal data to a country without an adequacy decision or appropriate safeguards.

5. Your rights

Under the GDPR you can ask us to:

Email info@simplesmoothsafe.com. We answer within 30 days, usually far sooner, and we do not charge for it. We may ask you to confirm your identity where the request concerns data whose disclosure to the wrong person would cause harm.

6. Complaints

If you think we have handled your data badly, tell us first — it is the fastest route to fixing it. You also have the right to complain to a supervisory authority. Ours is the Portuguese data protection authority:

Comissão Nacional de Proteção de Dados (CNPD)
Av. D. Carlos I, 134 — 1.º, 1200-651 Lisboa, Portugal
www.cnpd.pt

If you are in another EU member state you may complain to your own national authority instead.

7. Security

We apply measures appropriate to the risk: multi-factor authentication on every account, encryption in transit and at rest through our platform providers, least-privilege access, and no copies of customer data taken outside the systems above. The products themselves are designed so that your data stays in your tenant, which removes most of the risk rather than managing it.

If a breach affects your personal data and is likely to result in a risk to your rights, we will notify the CNPD within 72 hours and tell you without undue delay where the risk is high.

8. Children

Our products and this website are for business use. We do not knowingly collect data from anyone under 16, and there is no part of what we do that is directed at children.

9. Changes

If we change this policy we update the version and date at the top. Where a change materially affects how we use data we already hold, we will tell the people affected directly rather than relying on them re-reading this page.