Sim
GDPR evidence
The AI Workspace for Building and Managing AI Agents.
Sim and GDPR
Sim states it holds a data processing agreement. CertReports captured this on 17 Sep 2026 from its trust centre (Vanta); it is a vendor statement, not an independent confirmation.
Evidence
- Kind
- listing
- Issued or listed
- 3 Sep 2026
- Expires or valid through
- 3 Sep 2027
- Scope
- Sim Studio, Inc. operates Sim (sim.ai), a cloud platform on which business customers build, run, and monitor AI agents and automated workflows. Types of personal data covered: customer and client non-HR data and website visitor data. This includes account and contact details (name, email address, phone number, mailing address, profile picture, settings, and preferences); content and files that users upload to or connect with the platform; data accessed through integrations the user authorizes; usage and device data (IP address, browser type and version, pages visited, dates and times of access, device identifiers, and diagnostic data); cookie and analytics identifiers; and billing contact information. Human resources data is not covered by this certification. Purposes of processing: creating and administering accounts and authenticating users; providing, maintaining, and securing the platform; enabling user-authorized integrations with third-party services; providing customer support; processing payments and billing; product analytics and service improvement; detecting and preventing fraud, abuse, and security incidents; marketing and advertising measurement where the individual has consented; and complying with legal obligations. Types of third parties to which personal data may be disclosed, in each case for the purposes stated above: cloud hosting and infrastructure providers, authentication providers, database and storage providers, AI model providers, customer support providers, analytics and advertising providers, payment processors, integration providers selected by the user, professional advisers, public authorities where required by law, and parties to a merger, acquisition, or asset sale. Service providers acting on Sim's behalf process personal data only for limited and specified purposes, under written contract, and on Sim's documented instructions.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Sim: Active: EU-US Certification, SW-US Certification, UK Extension Certification | Live pagesha256 0caee73c8f |
- Kind
- listing
- Scope
- Our organization will receive donations for missionaries who are employees of our UK and Swiss offices. As a result of these transactions, we obtain human resource data to accurately account for the donations on behalf of these employees.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | SIM USA: Inactive | Live pagesha256 e3b63c2044 |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is Sim GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Change history
- 17 Sep 2026GDPR evidence addedA GDPR row entered the index with state Vendor-stated.
- 17 Sep 2026Subprocessor added: Amazon Web ServicesAmazon Web Services appeared on the subprocessor list.
- 17 Sep 2026Subprocessor added: GitHubGitHub appeared on the subprocessor list.
- 17 Sep 2026Subprocessor added: Google WorkspaceGoogle Workspace appeared on the subprocessor list.
- 17 Sep 2026Subprocessor added: GrafanaGrafana appeared on the subprocessor list.
- 17 Sep 2026Subprocessor added: SlackSlack appeared on the subprocessor list.
- 17 Sep 2026Subprocessor added: StripeStripe appeared on the subprocessor list.
- 17 Sep 2026Subprocessor added: Trigger.devTrigger.dev appeared on the subprocessor list.
Alternatives with GDPR evidence
Similar vendors (shared product tags or the AI infrastructure category) whose GDPR row is verified or vendor-stated, ranked by similarity.