Who We Are
Salessims ("Salessims", "we", "us", or "our") is a product and trade name of Mantawise B.V.
Legal entity: Mantawise B.V.
Registered office: Rotterdam, The Netherlands
Chamber of Commerce (KvK): 96197749
Contact for privacy matters: support@salessims.ai
1. Our Two Roles: Controller and Processor
Salessims is a business-to-business platform deployed as a customized environment for organizations ("Customers"). It is important to understand which role we play for which data, because it determines who you should contact about your rights.
a) Personal data within a Customer deployment — we are the processor. When the platform processes personal data about a Customer's users (for example, trainees' account details, training-session recordings, and performance metrics), the Customer is the data controller and Mantawise B.V. is the data processor. We process this data only on the Customer's documented instructions, under a separate Data Processing Agreement (verwerkersovereenkomst). If you are a trainee or employee using Salessims through your employer, your employer determines how your data is used, and you should direct privacy requests to them. We will support our Customers in responding to such requests. As the controller, the Customer (employer) is responsible for establishing a lawful basis for processing its employees' personal data, for informing them, and for meeting any applicable employee-monitoring and works-council (ondernemingsraad) requirements.
b) Personal data we collect in our own right — we are the controller. For certain data we are the controller ourselves, and this policy applies directly. This includes data about administrators and business contacts, billing and invoicing details, support communications, prospective customers, and visitors to our website.
The sections below describe our practices in both roles, and indicate where the Customer's own privacy notice applies instead.
2. Information We Collect
Depending on your relationship with us, we may process:
• Account information: name, email address, job title, and organization. Where you sign in via single sign-on (SSO) with Google or Microsoft, we receive limited profile information (such as your name, email, and organization identifier) from your identity provider; we never receive or store your password.
• Usage data: how you interact with the platform, training-session recordings, and performance metrics (processed on behalf of the Customer).
• Communication data: messages you send us and our responses.
• Business and billing data: the contact and company details needed to manage the Customer relationship and to issue invoices. We bill exclusively by invoice; we do not operate a card-payment facility and do not collect or store payment-card numbers.
• Website and technical data: cookie and device information when you visit our website (see "Cookies" below).
3. How We Use Information and Legal Bases
Where we act as controller, we rely on the following legal bases under the GDPR:
• Performance of a contract — to provide, maintain, and support the Service and to manage the Customer relationship;
• Legitimate interests — to operate, secure, and improve our platform, and for limited business communications (balanced against your rights);
• Legal obligation — to comply with tax, accounting, and other legal requirements;
• Consent — where required, for example for certain non-essential cookies (you may withdraw consent at any time).
Where we act as processor, we use personal data only to provide the Service on the Customer's instructions and as set out in the Data Processing Agreement.
4. Artificial Intelligence and Automated Processing
Salessims uses AI to generate customer personas and to produce feedback and performance metrics. This AI-generated feedback is an indicative training aid and may contain inaccuracies. The platform does not make automated decisions that produce legal or similarly significant effects on individuals. Any evaluation of an employee based on training results is a decision made by the Customer (the employer), not automatically by the platform.
5. Information Sharing and Sub-Processors
We do not sell, rent, or trade personal information. We share data only with service providers ("sub-processors") that help us operate the platform, under appropriate contractual safeguards, and otherwise only when required by law, to protect our legal rights, in connection with a merger or acquisition (with prior notice), or with your consent.
To operate the platform we rely on sub-processors in the following categories:
• AI and language-model providers — for generating customer personas, conversation, and feedback;
• AI voice synthesis — for spoken interactions, where used;
• Authentication and database — for secure sign-in and data storage;
• Hosting and infrastructure — for running the platform;
• Email and workflow services — for service communications and automation.
The exact, up-to-date list of sub-processors used in a given Customer deployment — including their names and the locations of processing — is set out in that Customer's Data Processing Agreement (verwerkersovereenkomst) and is available on request. We provide at least 30 days' notice of new or replacement sub-processors, during which a Customer may object. Several of our sub-processors maintain recognized security certifications (such as SOC 2 or ISO 27001).
6. International Data Transfers
Some of our sub-processors are located outside the European Economic Area, including in the United States. Where personal data is transferred outside the EEA, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses and, where applicable, adequacy decisions, together with supplementary measures where necessary.
7. Zero Data Retention Option
For deployments with heightened confidentiality requirements, we can configure Zero Data Retention (ZDR) with supported AI providers. When enabled, conversation content sent to those providers is not retained by them and is not used to train their models. ZDR is configured per deployment as agreed with the Customer.
8. Data Security
We implement appropriate technical and organizational measures to protect personal data, including:
• Encryption of data in transit (TLS/SSL) and at rest (AES-256);
• Access controls restricting personal data to authorized personnel on a need-to-know basis;
• Contractual security commitments with our sub-processors, several of which hold independent certifications (such as SOC 2 or ISO 27001).
9. Data Retention
We retain personal data only as long as necessary:
• Account data: retained for the duration of the Customer relationship, then deleted (subject to legal retention obligations);
• Training-session recordings: kept no longer than necessary for the training purpose. Recordings are retained so that users and the Customer can review past sessions; they can be deleted by the Customer at any time, or by us on request. ZDR deployments may retain none;
• Billing and accounting records: retained for the period required by Dutch law (generally 7 years);
• Following a valid deletion request, data is removed within 30 days, unless we are legally required to retain it.
On termination of the Customer relationship, personal data is deleted within 30 days, unless a statutory retention obligation applies. The Customer may request a data export within that period.
For data processed on a Customer's behalf, retention and deletion follow the Customer's instructions and the Data Processing Agreement.
10. Your Rights
Depending on your location, you may have the right to:
• Access — request a copy of your personal data;
• Rectification — correct inaccurate or incomplete data;
• Erasure — request deletion of your personal data;
• Portability — receive your data in a machine-readable format;
• Object — opt out of certain processing;
• Restrict — limit how we use your data;
• Withdraw consent — where processing is based on consent.
If we are the controller, contact us at support@salessims.ai. If your data is processed through your employer's deployment (where we are the processor), please contact your employer, who is the controller; we will assist them as needed.
You also have the right to lodge a complaint with a supervisory authority. In the Netherlands this is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).
11. Cookies
We use only essential cookies that are strictly necessary for the platform and website to function (for example, to keep you signed in). We do not use advertising cookies, and we do not use non-essential analytics or tracking cookies, so no cookie-consent banner is required for these. You can control cookies through your browser settings; disabling essential cookies may affect functionality.
12. Children's Privacy
The Service is intended for business professionals and is not directed at children under 16. We do not knowingly collect personal data from children under 16. If you believe we have done so, contact us at support@salessims.ai and we will delete it promptly.
13. Changes to This Policy
We may update this policy from time to time. When we make significant changes, we will:
• Notify affected Customers via email at least 30 days before the changes take effect;
• Display a notice on our platform where appropriate; and
• Update the "Last updated" date at the top of this policy.