← Back to home

Privacy Policy

Last updated: 28 August 2026

This Privacy Policy explains how Simson Softwares Private Limited ("Simson", "we", "us", or "our") collects, uses, stores and protects personal data when you use SimsonDesk — our multi-tenant work platform (helpdesk / TicketFlow, CRM, HR, projects, assets and compliance) — and SimDesk, our standalone remote-support desktop application available on the Microsoft Store. We do not sell your personal data.

Using Simson Desk Email Client? That is a separate product with a different shape — it has no backend and your mail never reaches us — so it has its own policy: Email Client privacy policy.

1. Who we are

The data controller is Simson Softwares Private Limited, 1723, Simson House, JLPL Industrial Area, Sector 82, Mohali-140306, Punjab, India. For workspace (tenant) data that our customers upload, the customer is the controller and Simson acts as a data processor on their instructions.

2. Personal data we process

  • Account & profile: name, username, work email, phone, role and profile photo.
  • Employee / HR data (workspace staff only): identifiers such as government IDs and tax numbers, date of birth, address, bank details, emergency contacts, nominees, qualifications, attendance and onboarding/KYC documents.
  • Customer / CRM data: names, emails, phone numbers, addresses and company details of your customers, leads and contacts.
  • Visitor data (where a workspace uses the visitor book): the visitor's name, mobile number and email address, who they are visiting and why, the organisation they come from, and their arrival and departure times. Where the workspace has configured it, we also record a photo taken at check-in, an identity document where entry to a sensitive area such as a server room is requested, the IP address the check-in came from, and the device's location coordinates — used only to confirm the visitor is physically at the premises, and never to track anyone afterwards. What is collected is shown on the check-in form itself.
  • Vendor & third-party due-diligence data (where a workspace uses vendor KYC): the vendor's legal and trading details, addresses, tax registrations such as GSTIN, the goods or services supplied, named contacts, and shareholders or beneficial owners together with their shareholding percentage, plus the documents the vendor uploads to evidence these. A vendor completes this themselves through a private link, confirms their identity with a one-time code sent to their email address or WhatsApp number, and their agreement is recorded with a timestamp.
  • Notification delivery data: if you switch on browser or desktop notifications, the push endpoint your browser issues together with the keys needed to deliver to it and your browser's user-agent string, or a device token for our desktop notifier. These let us deliver a notification to that one browser or device and do nothing else. Turning notifications off, or removing the device, deletes the record.
  • Support data: ticket content, email correspondence and, where a SimDesk remote-support session is run with your consent, session metadata and optional screen recordings.
  • SimDesk licensing & activation data: the name and email address you give us to receive a licence key or start a free trial (including the IP address the request came from and how many times you downloaded the app), and, for each computer you activate, a machine fingerprint (an irreversible hash of hardware and operating-system installation identifiers), the computer's hostname, the operating-system user name, and first/last-seen timestamps. We also keep a record of each activation attempt — whether it succeeds or fails — including the outcome (for example an unknown, expired or seat-limited key), the machine fingerprint and the originating IP address. We use this activation data to issue keys, enforce the number of seats a licence allows, let you revoke a machine you no longer control, provide support, prevent licence abuse, and understand how SimDesk is being adopted — never to advertise to you and never to sell your data.
  • Billing data: plan, subscription status and invoices. Card details are handled directly by our payment processors — we do not store full card numbers.
  • Technical data: IP address, device and browser information, and security/audit logs.

3. Why we process it (lawful bases)

  • Contract — to provide the platform, manage subscriptions and deliver support.
  • Legal obligation — tax, statutory HR/payroll and record-keeping duties.
  • Legitimate interests — securing the platform, preventing abuse and running our business, balanced against your rights.
  • Consent — where specifically requested, for example before a SimDesk remote-control session or before a session is recorded.

4. SimDesk remote-support privacy

SimDesk lets an authorised technician assist you on your device. Privacy controls are built in:

  • A technician can request to view your screen, and can control it only after you click the on-screen "Allow" prompt. You can End the session at any time.
  • A technician can view your screen only by presenting a signed, time-limited authorisation token issued by our backend. A 6-digit session code on its own — guessed, overheard or forwarded — does not let anyone view or control your device.
  • Sessions are recorded only with your consent. Recordings are encrypted (AES-256) at rest, access-restricted to authorised administrators, retained for 90 days and then deleted.
  • During an active, consented session the app accesses your screen contents, and — only when you grant control — keyboard and mouse input. File transfer works only when you enable it.
  • Files you receive are never written anywhere until you accept them. Each incoming file is shown with its name, size and the exact folder it will be saved to, and you can accept it, choose a different folder, or discard it. You can see every transfer in the session, in both directions, with its progress and final location.
  • File browsing is a separate permission you are asked for explicitly. A technician can request to see the folders and files on your computer — like an FTP client, with your machine on one side and theirs on the other — so they can copy files to or from it during support. You are prompted the first time they ask, you can refuse and still send files yourself, and the permission lasts only for that session. Until you allow it, the technician cannot list your files and cannot choose where files they send are saved. We do not receive or store any listing of your files; it is sent only between the two computers.
  • Voice is off unless you switch it on. If you enable "Talk to support", your microphone is used for the duration of that session so you can speak to the technician. Audio is streamed live between the two computers only — it is not recorded, not stored, and is not included in session recordings, which capture the screen alone. The microphone is released the moment the session ends, and you can mute at any time.
  • Clipboard sharing is shown as a tick box you can clear before the session starts. It is pre-selected because copying text between the two computers is needed in most support sessions, and it appears on the same screen as the connect button, so no session can begin without you seeing it. When it is on, text you copy during the session is shared with the technician so it can be pasted at either end, and text they send is placed on your clipboard. It is text only, capped in size, and stops the moment the session ends. Clipboard contents are relayed between the two computers and are not stored by us or included in session recordings.
  • Unattended access is opt-in and uses a customer-held secret key stored encrypted on the device — Windows DPAPI on Windows, and the desktop keyring (GNOME Keyring / KWallet) on Linux, falling back to a file only your own account can read. The key is never written to disk in the clear. SimDesk ships no kernel driver.
  • SimDesk has no third-party advertising, analytics or behavioural-tracking SDKs, and sets no advertising cookies. We keep only our own first-party records: licensing and activation data (described above) and a simple count of which of our own download and buy buttons were clicked on our website (with the page, an optional campaign tag and the originating IP) so we can measure our own marketing — never shared with or sold to anyone. The installed app additionally reports a few anonymous milestones — that it was opened, that the activation screen was reached, and that a licence key was requested — each carrying only a random identifier generated on your device, the app version and whether you are on Windows or Linux. That identifier is not linked to you, your name, your email, your hostname or your machine fingerprint, and it exists solely so we can tell how many people who install SimDesk actually get it running. SimDesk does not log your keystrokes, read your files, or capture your screen outside an active session you have allowed.
  • SimDesk collects only what is needed to run a session (session metadata and any consented recording) and to validate your licence, and does not sell your data.

If you asked us to email you a licence key or start a free trial, we keep your name and email address as described in section 2 and use them to send you the key, to support you and — where permitted — to tell you about SimDesk. You can opt out of the latter at any time, and you can ask us to delete the record entirely using the contact details in section 13.

5. Sharing & sub-processors

We share personal data only with vetted service providers ("sub-processors") acting on our instructions under a data-processing agreement. Our current sub-processors are:

  • Microsoft Azure / Microsoft Graph & SharePoint — cloud infrastructure, document storage and email.
  • Backblaze B2 — encrypted automated backups and encrypted session recordings.
  • Stripe — global card payment processing.
  • Razorpay — payment processing for India.
  • Meta / WhatsApp Cloud API — transactional notifications.

Each sub-processor receives only the data necessary for its function and is contractually barred from using it for any other purpose.

6. Where your data is hosted

Operational personal data is hosted in India. Some sub-processors may process limited data (for example payment or notification metadata) in other regions; where that occurs, appropriate contractual safeguards are applied.

7. Security (SOC 2 Trust Services Criteria)

Our controls are designed around the AICPA Trust Services Criteria of Security, Availability, Confidentiality and Privacy, and include encryption in transit (TLS 1.2+) and at rest (AES-256 field-level for sensitive PII), database-per-tenant isolation, role-based access control, MFA/2FA, least-privilege access, audit logging, encrypted automated backups, vendor management and a defined incident-response process. See our Security page for detail. Simson's information-security management is independently assessed / certified by TÜV-SÜD South Asia Limited and aligned with ISO 27001, ISO 27701, the OWASP Top 10 and SOC 2 Type II readiness.

8. Retention

We keep personal data only as long as necessary for the purposes above or as required by law, then delete or anonymise it. Concrete periods (for example tickets 3 years, KYC documents 90 days after conversion, session recordings 90 days, audit logs 2 years) are set out in our Data Retention Policy. You can delete your account and data as described in our Data Deletion Policy.

9. Your rights

Subject to applicable law you may request access, rectification, erasure, restriction, objection and portability, and may withdraw consent at any time. To exercise these rights contact our privacy team at compliance@simsononline.com. We respond to verified requests within the timeframes required by law.

10. Cookies

The SimsonDesk web app uses only essential cookies and local storage needed to sign you in and keep your session secure. We do not use advertising or cross-site tracking cookies. See our Cookie Policy.

11. Children

SimsonDesk and SimDesk are intended for business use by people aged 18 or over. We do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will delete it.

12. Changes

We may update this policy. Material changes will be notified in-app or by email and the "Last updated" date above will change.

13. Contact

Simson Softwares Private Limited

1723, Simson House, JLPL Industrial Area, Sector 82, Mohali-140306, Punjab, India

Privacy / DPO: compliance@simsononline.com

General / support: support@simsononline.com · +91 73411 00734