Privacy Policy

Last updated: 6 July 2026

This policy describes how SimLab processes personal data when you use our training simulator. We have tried to describe our practices as concretely and honestly as possible.

1. Data controller

SimLab is the data controller for personal data processed in the service. Questions about this policy or our processing of personal data can be directed to support@simlab.no.

If you use SimLab through your employer, your employer will in many cases be the data controller for the training data, and SimLab then acts as a data processor on behalf of the organization.

2. What data we process

  • Account information: name, email address, and profile information from our sign-in provider (Clerk).
  • Organization data: which organization you belong to, your role, and team affiliation.
  • Conversation data: text transcripts of your training conversations and evaluations with scores and feedback. These are stored in SimLab's database.
  • Speech during the session: when you talk to the AI character, the audio is streamed in real time to our AI provider (see section 5) so that the character can respond. We never store this audio — only the text transcript of the conversation.
  • Documents you upload: administrators can build scenarios from an incident report or a procedure. The document is never stored: it is read in memory, automatically scrubbed of email addresses, national identity numbers and phone numbers, and the text is then sent to our AI provider (see section 5) to draft the scenario. Do not upload documents containing patient or service-user data.
  • Demo and pilot enquiries: if you submit the form at simlab.no/demo, we store your name, organisation, email and, where provided, phone number, role, sector, size and message — solely in order to reply to you. The information is not shared with anyone else and is deleted once the enquiry is closed, or earlier on request.

3. Purposes of the processing

We process the data in order to:

  • Deliver the training simulator, including real-time conversations with AI characters.
  • Generate evaluations and feedback after each session.
  • Show you your own history, progress, and certifications.
  • Give administrators in your organization aggregated training statistics.
  • Operate, troubleshoot, and secure the service.

4. Legal bases for processing

  • Contract (GDPR Art. 6(1)(b)): processing that is necessary to deliver the service you or your employer have contracted for — your account, the training conversations, and the evaluations.
  • Consent (point (a)): analysis of your word choice for self-regulation only takes place when you actively enable it in the settings. You can turn the feature off again at any time. We never analyse your tone of voice: inferring emotions from voice is biometric processing, which the EU AI Act (Article 5) prohibits in the workplace.
  • Legitimate interest (point (f)): operation, security, and improvement of the service, as well as aggregated statistics for the organization's administrators.

5. Subprocessors and transfers to third countries

We use the following subprocessors (data processors) to deliver the service:

ProviderLocationWhat it is used for
ClerkUSAAuthentication and account management (name, email, sign-in).
OpenAIUSAReal-time speech processing: the audio from the training conversation is streamed to the OpenAI Realtime API so that the AI character can listen and respond with voice.
AnthropicUSALanguage model that may be used to evaluate the text transcript of the session and generate feedback.
GroqUSALanguage model that may be used to evaluate the text transcript of the session and generate feedback.
SimliStreaming of audio to generate a lip-synced video avatar. Used only when the video avatar is enabled for the scenario.
ResendUSASending transactional email: invitations, notifications, and enquiries submitted through our contact form.
HetznerGermany (EEA)Operation of servers and database. This is where text transcripts, evaluations, and account data, among other things, are stored.

Several of the providers process data in the USA. Transfers to countries outside the EEA take place on the basis of the European Commission's Standard Contractual Clauses (SCC) with the individual provider.

6. Retention period

Account information, text transcripts, and evaluations are stored for as long as your account is active. If you delete your account (see section 7), all of this data is permanently deleted. We never store audio recordings of the sessions.

7. Your rights

Under data protection law — the GDPR and the Norwegian Personal Data Act (personopplysningsloven) — you have the right to access the data we process about you, and the right to rectification, erasure, data portability, restriction of processing, and to object to processing based on legitimate interest. Where processing is based on consent, you can withdraw your consent at any time.

Access and erasure are self-service: under Settings in the app you can at any time download a complete copy of your data (JSON) and permanently delete your account, including all training sessions, evaluations, and certifications. Other requests — for example rectification or restriction — can be sent to support@simlab.no, and we will respond without undue delay and at the latest within one month.

8. Right to complain

If you believe we process personal data in breach of the rules, we would appreciate you contacting us first so that we can put things right. You always have the right to lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet) — see datatilsynet.no.

9. Changes to this policy

We update this policy as needed, for example when the service or the regulations change. Material changes will be announced in the service. The date at the top shows when the policy was last changed.

10. Contact

Questions about privacy in SimLab? Contact us at support@simlab.no. See also the terms of use for the terms that govern your use of the service.