Legal
Privacy Policy
This policy explains what data we collect, what we use it for, who we share it with, and what you can do about it. It is written to be understood; if anything is unclear, contact us.
1. Data controller
- Controller
- Guillermo González — Simulador de Negocios
- Tax ID (CUIT)
- 20-16655164-2
- Registered address
- 9 de Julio 280, Córdoba, Argentina
- Country
- Argentina
- Privacy contact
- https://simuladordenegocios.com/en/contact
2. What we collect
- Account data: email, name and, if you sign in with Google, that account's identifier and profile picture. We never see your Google password. If you use email and password, we store a hash of the password, not the password.
- Business data: your role, industry, trading name and location, as you give them to us at sign-up.
- Simulation data: everything you write during a simulation — including your business's numbers — and the assessments generated from it.
- Technical data: IP address, approximate country, browser type and access logs, for security and abuse prevention.
- Payment data: the status, amount and identifier of each order. We do not store card details; the payment provider does.
- Free-trial data, before an account exists: the business profile you fill in and the conversation of those first replies are stored with no account attached, identified only by a cookie in your browser. If you sign in afterwards, that conversation becomes yours; if you do not, it is deleted on its own within the period in section 7.
We use no advertising cookies. The cookies we set are the ones needed to run the site: your session, your language preference, your currency preference and, if you started a trial, a random identifier that tells us the conversation is yours.
To protect the free trial from automated use we rely on Cloudflare Turnstile, which may store its own cookies in your browser during that check. They are not used for advertising or to track you across sites.
3. Why we use it, and on what legal basis
- To provide the service — keeping your history and your company memory between simulations: performance of a contract.
- To take payment and keep the credit ledger: performance of a contract and legal obligation.
- To send essential emails — verification, sign-in, password reset and receipts: performance of a contract.
- To prevent abuse, fraud and security incidents: legitimate interest.
- To comply with lawful requests from a competent authority: legal obligation.
We do not sell your data, we do not share it with third parties for their own purposes, and we do not use it for advertising. We do not train models on the content of your simulations.
4. When our team can read a conversation
This section matters, so it is written concretely.
Conversations contain sensitive information about your business. Our team can access the content of a conversation only in these cases:
- when you flag it for review or ask for support about it;
- when the system flags it automatically because of a technical failure, an anomalous cost or a forced close;
- when it is strictly necessary to investigate abuse, fraud or a security incident;
- when required by a competent authority.
Every access to a conversation is logged with the identity of whoever opened it, the date, and a written reason. That audit log cannot be edited or deleted — the database does not grant the application permission to do so. The admin panel shows metadata by default, not content.
5. Language models
To generate responses we send the content of the conversation to a large language model provider. We do so with provider-side retention turned off: the provider does not keep the conversation and does not use it to train its models. Your history lives in our database, not theirs.
6. Who we share data with
Only with those needed to run the service, and only with the data they need:
- Mercado Pago — processes payments and receives the data needed to charge you (Argentina).
- PayPal — processes payments and receives the data needed to charge you (Estados Unidos / USA).
- OpenAI — generates the simulator responses, with retention disabled (Estados Unidos / USA).
- Cloudflare — delivers the site and protects it from attacks (Estados Unidos / USA).
- Contabo GmbH — hosts the server running the application and the database (Alemania / Germany).
- Google — lets you sign in with your Google account, if you choose that route (Estados Unidos / USA).
- Adobe — serves the site typeface, and therefore sees your IP when a page loads (Estados Unidos / USA).
Some of these providers are outside Argentina, so international transfers of data take place. They are made under each provider's contractual clauses and limited to what is necessary to run the service.
7. How long we keep it
- Simulations and assessments: for as long as your account is active — they are your history.
- Trial conversations never attached to an account: 30 days, after which they are deleted entirely. There is no owner to ask or to notify, so they go on their own.
- Technical logs: 90 days.
- Accounting and payment records: for the period the law requires (10 years), even after account deletion, in anonymised form.
- The access audit log: never deleted. That is what makes section 4 verifiable.
8. Your rights
You can request access, rectification, updating, portability or erasure of your data through the contact form, using your account email. You can also object to processing based on legitimate interest, and withdraw consent where we rely on it.
Deleting your account removes your personal data and the content of your simulations; the anonymised accounting record is kept, because the law requires it.
We are established in Argentina and our primary data protection regulator is the Agencia de Acceso a la Información Pública, the supervisory authority under Argentine Law 25.326. If you are in the EEA or the UK, you may also lodge a complaint with your local supervisory authority.
9. Security
- All traffic is encrypted (HTTPS enforced, with HSTS).
- Passwords are stored with a resistant hashing algorithm, never in plain text.
- Sessions are revocable, and admin panel access requires a second factor.
- Backups are encrypted.
- The server exposes no public port other than key-based administration.
- Database permissions are separated: not even the application can alter the credit ledger or delete the audit log.
If we detect a security incident affecting your data, we notify you by email and notify the relevant supervisory authority where required.
10. Children
The service is not directed at anyone under 18 and we do not knowingly collect data from minors. If we find a minor's account, we close it and delete the data.
11. Changes
If we change this policy materially, we notify you by email before it takes effect and update the date above.
12. Contact
Contact form. We reply within 5 business days. You can also write to [email protected].
