Skip to main content
Sim logo

Sim

GDPR evidence

The AI Workspace for Building and Managing AI Agents.

sim.aiAI infrastructureLast verified 17 Sep 2026
GDPR mark, CertReports state Vendor-stated as of 17 Sep 2026Vendor-stated

Sim and GDPR

Sim states it holds a data processing agreement. CertReports captured this on 17 Sep 2026 from its trust centre (Vanta); it is a vendor statement, not an independent confirmation.

Evidence

Vendor-statedVendor states GDPR on its trust centre
as of 17 Sep 2026 · confidence 90%
SourceCapturedQuoteLinks
Sim trust centre (Vanta)
Vendor trust centre · HTTP 200
17 Sep 2026GDPR
Live page Snapshotsha256 621fbcf86d
VerifiedActive: EU-US Certification, SW-US Certification, UK Extension Certification
as of 17 Sep 2026 · confidence 100%
Kind
listing
Issued or listed
3 Sep 2026
Expires or valid through
3 Sep 2027
Scope
Sim Studio, Inc. operates Sim (sim.ai), a cloud platform on which business customers build, run, and monitor AI agents and automated workflows. Types of personal data covered: customer and client non-HR data and website visitor data. This includes account and contact details (name, email address, phone number, mailing address, profile picture, settings, and preferences); content and files that users upload to or connect with the platform; data accessed through integrations the user authorizes; usage and device data (IP address, browser type and version, pages visited, dates and times of access, device identifiers, and diagnostic data); cookie and analytics identifiers; and billing contact information. Human resources data is not covered by this certification. Purposes of processing: creating and administering accounts and authenticating users; providing, maintaining, and securing the platform; enabling user-authorized integrations with third-party services; providing customer support; processing payments and billing; product analytics and service improvement; detecting and preventing fraud, abuse, and security incidents; marketing and advertising measurement where the individual has consented; and complying with legal obligations. Types of third parties to which personal data may be disclosed, in each case for the purposes stated above: cloud hosting and infrastructure providers, authentication providers, database and storage providers, AI model providers, customer support providers, analytics and advertising providers, payment processors, integration providers selected by the user, professional advisers, public authorities where required by law, and parties to a merger, acquisition, or asset sale. Service providers acting on Sim's behalf process personal data only for limited and specified purposes, under written contract, and on Sim's documented instructions.
SourceCapturedQuoteLinks
Data Privacy Framework list
Official registry · HTTP 200
17 Sep 2026Sim: Active: EU-US Certification, SW-US Certification, UK Extension Certification
Live pagesha256 0caee73c8f
ExpiredInactive
as of 17 Sep 2026 · confidence 85%
Kind
listing
Scope
Our organization will receive donations for missionaries who are employees of our UK and Swiss offices. As a result of these transactions, we obtain human resource data to accurately account for the donations on behalf of these employees.
SourceCapturedQuoteLinks
Data Privacy Framework list
Official registry · HTTP 200
17 Sep 2026SIM USA: Inactive
Live pagesha256 e3b63c2044
What GDPR means, and what it does not

"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.

Read the GDPR guide and browse all vendors with evidence

Questions buyers ask

Is Sim GDPR compliant?

There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.

How does CertReports verify this?

Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.

Change history

  1. 17 Sep 2026GDPR evidence addedA GDPR row entered the index with state Vendor-stated.
  2. 17 Sep 2026Subprocessor added: Amazon Web ServicesAmazon Web Services appeared on the subprocessor list.
  3. 17 Sep 2026Subprocessor added: GitHubGitHub appeared on the subprocessor list.
  4. 17 Sep 2026Subprocessor added: Google WorkspaceGoogle Workspace appeared on the subprocessor list.
  5. 17 Sep 2026Subprocessor added: GrafanaGrafana appeared on the subprocessor list.
  6. 17 Sep 2026Subprocessor added: SlackSlack appeared on the subprocessor list.
  7. 17 Sep 2026Subprocessor added: StripeStripe appeared on the subprocessor list.
  8. 17 Sep 2026Subprocessor added: Trigger.devTrigger.dev appeared on the subprocessor list.

Alternatives with GDPR evidence

Similar vendors (shared product tags or the AI infrastructure category) whose GDPR row is verified or vendor-stated, ranked by similarity.