1. Who we are (controller)
CImple provides CImple as a software-as-a-service (SaaS) biopharma intelligence portal. Our public website is https://gocimple.com.
For the personal data described in this Policy that we decide the purposes and means of processing (for example account administration, Service analytics, security, and product improvement), CImple is the data controller (or equivalent under applicable law).
Technology development and engineering of the Service are provided by Niya Tech Labs (ABN 26 698 379 145) as CImple’s technology developer / implementation partner. Where information security management or related technical certifications apply to how the Service is built and operated (for example ISO/IEC 27001), those certifications are attributable to Niya Tech Labs (ABN 26 698 379 145) in its capacity as technology partner — not as a substitute for CImple as the product controller or commercial provider. This disclosure is for transparency and compliance attribution only.
Where your employer or contracting organisation determines who may access CImple and how staff may use it, that organisation may also be a controller for workplace access decisions. In some enterprise arrangements we act as a processor for specific processing instructed in writing; if a data processing agreement (DPA) is signed, that DPA prevails for the processing it covers.
Privacy and data-subject requests: solutions@gocimple.com. Operational support: solutions@gocimple.com. Website: https://gocimple.com.
2. Scope and data subjects
This Policy covers personal data of authorised portal users (User, Team, and Admin roles) and registration applicants for the Service.
It does not cover unrelated third-party websites linked from the Service, or commercial terms that appear only in a separate order form or master agreement with CImple.
CImple is a professional research and intelligence tool. It is not intended for submitting patient-identifying clinical records. Do not enter names, medical record numbers, or other direct identifiers of individual patients into Ask CImple or support forms.
3. Categories of personal data we collect
We process the following categories when you or your organisation use the Service:
- Identity and account data — name, work email, organisation, role, subscription tier, entitled therapeutic areas, account status, last login, and password credentials stored as one-way hashes (not plain text).
- Registration data — information in access requests (including requested therapeutic areas).
- Usage and telemetry data — logins, navigation, filters applied, alert reads/bookmarks, watchlist saves, and similar events logged for operations and analytics.
- Query and chat content — Ask CImple questions and messages, chat metadata (therapeutic area, timestamps, run status), and generated answers needed to provide the feature.
- Support data — Issues and Support submissions (category, details, contact consent) and related email.
- Technical data — security and delivery logs from hosting providers (which may include IP address and similar connection metadata), browser/device signals required to run the Service, API timing logs, and AI-model usage metrics.
- Account preference data — watchlist selections (companies, trials, categories, and update types per therapeutic area) stored on our servers with your account so they sync across devices.
- Local device data — certain UI preferences (for example table/layout preferences or sidebar state) may be stored in your browser’s local storage and are not always copied to our servers.
4. Payments and payment cards
CImple does not ask for, collect, or store credit card, debit card, or other payment-card details in the portal. Fees and invoicing are handled outside the Service under your commercial arrangement with CImple (see gocimple.com / solutions@gocimple.com).
5. Purposes of processing
We process personal data to:
- Authenticate users, apply entitlements (tier and therapeutic areas), and administer accounts.
- Provide Ask CImple, Alerts, Intel, Help, and Issues and Support.
- Allow authorised CImple administrators to review usage and query activity for analytics, quality assurance, abuse prevention, capacity planning, and system improvement.
- Send account, security, and subscription-related communications.
- Meet legal obligations and enforce our Terms & Conditions.
6. Usage tracking, queries, and analytics
Authorised CImple administrators may access activity and usage records tied to subscriber accounts, including search and Ask CImple query text and related metadata, for analytics, reliability, content/model quality improvement, and operational reporting.
We retain user query and related activity records for at least 365 days. We may retain longer when required by law, contract, dispute, or security investigation. After the retention window, records may be deleted, anonymised, or aggregated (including via administrative tools such as Purge Logs, Retention jobs, or scheduled jobs when enabled).
7. Lawful bases under GDPR / UK GDPR
Where the EU GDPR or UK GDPR applies to our processing of your personal data, we rely on specific Article 6 lawful bases mapped to purposes as follows:
- Article 6(1)(b) contract — creating and operating your (or your organisation’s) subscribed access: authentication, entitlements, delivering portal features you request, and related support.
- Article 6(1)(f) legitimate interests — securing the Service; detecting abuse; measuring and improving product quality and performance; reviewing query/usage analytics as described in Section 6; and maintaining business records. We balance these interests against your rights and expect professional use of a B2B research tool.
- Article 6(1)(a) consent — only where we ask for it expressly (for example contact consent on an Issues and Support report). You may withdraw consent for future processing based on that consent by emailing us; withdrawal does not affect prior lawful processing.
- Article 6(1)(c) legal obligation — where we must retain or disclose information to comply with applicable law.
7.1 Special category / sensitive data
We do not seek to collect special-category data about identifiable patients (GDPR Article 9). Clinical content in the Service is curated professional intelligence (for example trial and regimen information), not your patients’ medical records.
If you choose to paste health-related text about identifiable individuals into the Service, that is outside the intended use. We may still process such text as part of query logs under Sections 5–6 until deleted under retention rules or a valid erasure request.
8. Australian Privacy Act and other laws
Where the Australian Privacy Act 1988 (Cth) and Australian Privacy Principles (APPs) apply, CImple handles personal information in ways consistent with this Policy, including collection for stated purposes, reasonable security steps, and access/correction pathways described in Section 12.
Other national or sector privacy laws may also apply depending on where you or your organisation are established. If they grant you stronger mandatory rights, we will honour those rights to the extent required.
If your organisation has a signed DPA or similar schedule with us, that document controls for the processing it covers where it conflicts with this Policy.
9. Storage, processors, and sub-processors
Personal data for the Service is stored in managed cloud systems used to operate the portal (database, authentication, and application hosting). Access is limited by role-based controls; traffic is protected with HTTPS in transit.
We use processors (sub-processors) strictly as needed to deliver the Service. Current sub-processors include:
- Niya Tech Labs (ABN 26 698 379 145) — technology developer / implementation partner for engineering, hosting configuration, and operational support of the Service (may access personal data solely as needed to build, secure, and support the Service under CImple instruction).
- Supabase — cloud database and authentication for accounts, chats, activity logs, content state, and related Service data.
- Vercel — application hosting and associated operational/platform logs.
- Anthropic — AI model inference for Ask CImple (prompts, conversation context, and necessary retrieved clinical context).
- OpenAI — embedding generation used for clinical retrieval supporting Ask CImple.
- Google (Gmail SMTP) and/or Resend — transactional email for registration, password reset, welcome messages, and Issues and Support notifications.
9.1 International transfers
Processors may be located outside your country (including outside the EEA/UK or Australia). Where GDPR/UK GDPR transfer rules apply, we use appropriate safeguards such as the European Commission’s Standard Contractual Clauses (or UK equivalent addenda) and vendor due diligence, unless another lawful transfer mechanism applies.
A maintained sub-processor list is available on request from solutions@gocimple.com and may also be provided under a customer data processing agreement (DPA).
10.1 US state privacy notices (including CCPA/CPRA)
Where the California Consumer Privacy Act (CCPA) as amended by the CPRA, or similar US state privacy laws, apply to personal information we process about you in connection with the Service, this section supplements the rest of this Policy.
CImple is a B2B professional SaaS provider. We process personal information of authorised business users to provide the Service to your organisation. We do not sell personal information, and we do not “share” personal information for cross-context behavioural advertising as those terms are defined under the CCPA/CPRA.
Categories of personal information we may collect are described in Section 3 (for example identifiers such as name and work email; professional information; internet or electronic activity such as usage and query logs; and inferences limited to Service administration). We collect them from you, your organisation, and automatically from use of the Service, for the business purposes in Section 5.
Subject to legal exceptions, California residents may have rights to: know/access personal information we hold about them; correct inaccurate personal information; delete personal information; obtain a portable copy of certain information; and not be discriminated against for exercising privacy rights. Because we do not sell or share personal information for cross-context behavioural advertising, a “Do Not Sell or Share” opt-out is not applicable to our current processing; if that changes we will update this Policy and provide a required opt-out mechanism.
To exercise applicable rights, email solutions@gocimple.com from your account email (or ask your organisation’s administrator to contact us). We may need to verify your identity. Authorised agents may submit requests where permitted by law, with proof of authority. We aim to respond within the timeframes required by applicable US state law.
Sensitive personal information: we do not seek to collect sensitive personal information for the purpose of inferring characteristics about consumers. Do not submit patient-identifying health information into the Service.
11. Retention
Account data is kept for the subscription relationship and a reasonable period afterward for security, offline billing reconciliation, disputes, and legal compliance.
Ask CImple queries, chat content, and detailed usage/activity logs are retained for at least 365 days for analytics, improvement, support, and auditability, and longer when Section 6 exceptions apply.
After erasure from live systems, residual copies may remain in encrypted backups until those backups are rotated under normal cycles.
12. Your rights and how to exercise them
Depending on applicable law (including GDPR/UK GDPR and the Australian Privacy Act), you may have rights to:
- Access a copy of personal data we hold about you.
- Correct inaccurate personal data.
- Erase personal data in certain circumstances.
- Restrict or object to certain processing (including objection to processing based on legitimate interests).
- Data portability for data you provided where processing is based on contract or consent and is automated.
- Withdraw consent where processing is based on consent.
- Lodge a complaint with a supervisory authority (for example an EU/UK data protection authority, or the Office of the Australian Information Commissioner (OAIC) in Australia).
12.1 Response process
Email solutions@gocimple.com from your account email address (or ask your organisation’s administrator to contact us). We may verify identity before acting.
Where GDPR/UK GDPR applies, we aim to respond within one month of a validated request (extendable by up to two further months for complex requests, with notice). Where the Australian Privacy Act applies, we will respond within a reasonable period.
Some requests may be limited where we must retain data for security, legal claims, or shared-controller responsibilities with your organisation.
13. Security
We use administrative, technical, and organisational measures appropriate to a SaaS B2B product (access control, encrypted transport, hashed passwords, and operational monitoring). Engineering and information-security practices for the Service are delivered with Niya Tech Labs (ABN 26 698 379 145) as technology partner; where ISO/IEC 27001 or similar certifications apply to that engineering ISMS, they are held by Niya Tech Labs (ABN 26 698 379 145), not by CImple. No system is perfectly secure; protect your credentials and report suspected unauthorised access promptly to solutions@gocimple.com or solutions@gocimple.com.
14. Children
The Service is for professional adult users authorised by a subscribing organisation. It is not directed to children.
15. Changes to this Policy
We may update this Policy from time to time. The effective date will change when we do. Updated versions may be posted in the Service and/or on gocimple.com. Material changes may also be notified by email. Continued use after the effective date constitutes acknowledgment where permitted by law.
16. Contact
Controller: CImple · Website: https://gocimple.com
Technology partner: Niya Tech Labs (ABN 26 698 379 145)
Privacy: solutions@gocimple.com · Support: solutions@gocimple.com
Effective date: 9 August 2026.
