Legal
Privacy notice
Last updated .
The short version
We hold what is needed to know who has a licence and which machines it is activated on, plus the ordinary records of running a business. Your simulation work never reaches us — no geometry, no meshes, no results, no reports and no file names. The application can report anonymous usage data if you agree to it when it first runs, and that is about how it is used rather than what you model (section 4). We use no advertising networks and no cross-site tracking, and the site sets no analytics cookies, which is why you are not being asked to dismiss a cookie banner.
1. Who is responsible
The data controller is SHD Systems Ltd, company number 17003359, registered office 13 Old Hall Road, Norwich, NR13 5FA, United Kingdom. We are registered with the Information Commissioner’s Office as a data protection fee payer under reference ZC177326, which you can check on the ICO’s public register.
For anything in this notice, contact privacy@shd-sim.com.
2. What we collect, why, and on what lawful basis
Under UK GDPR every use of personal data needs a lawful basis. Ours are set out against each purpose rather than listed vaguely at the end.
| Data | Purpose | Lawful basis |
|---|---|---|
| Email address, name, organisation | Creating and running your account; sending licence keys and service email | Performance of a contract |
| Password hash, session records, two-factor secret | Authenticating you and keeping the account secure | Performance of a contract; legitimate interests (security) |
| Subscription and licence state — tier, seats, renewal date | Providing what you paid for and knowing what you are entitled to | Performance of a contract |
| Device activations — hashed machine fingerprint, label, last check-in | Enforcing seat counts and letting you manage your own devices | Performance of a contract; legitimate interests (preventing licence abuse) |
| Billing records and invoices | Tax and accounting records | Legal obligation |
| IP address and user agent at sign-in | Rate limiting, fraud prevention, showing you your own active sessions | Legitimate interests (security) |
| Audit log of staff actions on your account | Accountability for support actions taken on your behalf | Legitimate interests (accountability); legal obligation |
| Education verification evidence | Confirming eligibility for an academic price | Performance of a contract |
| Contact form — your name, email address and the message you write | Answering you, and being able to find the exchange again if you follow up | Legitimate interests (responding to an enquiry you sent us) |
| Module interest — your email address, which module, and the page you asked from | Emailing you once when that module is released, and counting demand to decide what to build next | Consent — withdrawable at any time |
| Marketing email, if you opt in | Product announcements | Consent — withdrawable at any time |
| Business contact details — name, work email, job title and employer, where we approached you first | Introducing this software to organisations whose work it suits | Legitimate interests — you may object at any time, and for direct marketing that objection is absolute. See section 6 |
The two forms on this site, in plain terms. The contact form sends your message to the address shown next to whatever you picked, and stores a copy so a lost email does not mean a lost enquiry. It does not add you to anything.
The tell me when this ships form sends you a confirmation link and stores nothing usable until you press it — that press is the consent, and without it the record is deleted unused. For a module, what follows is one email, on the day it is released.
The prompt on the download page is the same mechanism with a different promise: it is an ongoing list, and what follows is an email when a version ships and when a new validation case is published. Alongside it there is a second, separate tick box for occasional product and pricing email. It is optional, it is off unless you tick it, and leaving it alone still gets you the release notes. The two are held as separate permissions and you can hold one without the other.
There is no sequence and no sharing of the address with anybody. Every message carries a one-click unsubscribe that takes effect immediately and covers everything we hold for that address — not just the list the message came from. You can also email privacy@shd-sim.com and we will remove it by hand.
Email we send to those lists records whether you opened it and whether you clicked a link. That is done with a small image in the message and by routing links through our sending provider, and we use it only to judge whether what we send is worth sending. Transactional email — your licence key, a password reset, a reply to a support ticket — carries no such tracking, because you did not ask for those and did not consent to being measured on them.
3. Website analytics
We use Umami, which we host ourselves on our own server at analytics.shd-systems.co.uk — a different domain, but the same company: it is run by SHD Systems Ltd, who publish this site, and is shared across our sites so that one instance serves all of them. It is not a third-party analytics service: the data does not leave our infrastructure and is not shared with anybody.
It sets no cookies, assigns no persistent identifier, and does not track you between sites or between days. It records aggregate page views, referrer, country, browser and device type. Because it neither identifies you nor stores anything on your device, it does not require consent under the Privacy and Electronic Communications Regulations, which is why this site has no cookie banner. Lawful basis: legitimate interests (understanding which pages are useful).
4. Usage data from the application
The Software can report anonymously that it is being used. You are asked when you first run it, before anything is sent, and you can change the answer at any time in Settings → Privacy.
If you agree, it sends: a random identifier generated on first run, the version, your operating system and its version, the processor architecture, the number of cores and how much memory the machine has, your language (the language only, never the region), which licence tier is in use, when the application is opened and for how long, when a tier limit refuses something and which limit it was, and summary facts about solver runs — which solver, which analysis type, and whether it finished. Mesh sizes and run times are grouped into wide bands before they are sent, and the exact figures are never stored.
The identifier is not the licence fingerprint. The fingerprint used for activation is derived from your machine and is linked to your account; this one is random, is not derived from anything about the machine, and is deliberately not linked to your account, your licence or your email. Nothing sends both. Turning the setting off deletes the record and everything collected under it; turning it on again generates a new identifier rather than resuming the old one.
Your IP address reaches our server, as it must for any request. We convert it to a two-letter country code and do not store the address.
Lawful basis: consent, because the identifier is stored on your device. Withdrawable at any time, from inside the application or by emailing privacy@shd-sim.com with the identifier shown in Settings → Privacy. An administrator can switch it off for every user on a machine by placing a file named no-telemetry in the installation folder, or by setting SIMCFD_TELEMETRY=0 in the environment.
Separately, the installer reports once that an install or an uninstall completed, carrying only the product, version, release channel and operating system. It contains no identifier of any kind and stores nothing on your machine, so it cannot be linked to you, to a session, or to any other install, and it is not affected by the setting above. Lawful basis: legitimate interests (knowing how many copies are installed). Because there is no identifier, a reinstall is counted as a second install.
5. Download counting
When you download an installer we record the file, version, the country from the request, and a salted hash combining your IP address, browser string and the current date. We do not store the IP address or the browser string themselves.
Because the date is inside the hash, today’s value cannot be matched against yesterday’s. It lets us count one person downloading twice in a day as one download, and it cannot be used to identify anybody or to build a history. Lawful basis: legitimate interests (knowing how much the software is used).
6. Business contacts we approach
We sometimes write to engineers and engineering organisations who have not contacted us, to introduce this software. If you received such a message, this section explains what we hold about you and where it came from — you are entitled to be told, because you did not give us the information yourself.
What we hold: your name, your work email address, your job title, your employer, and a short note on why we thought this software was relevant to your work. Nothing else, and nothing about you personally.
Where it came from: your employer’s own website, your public professional profile, or published technical material such as a paper or a conference presentation. We do not buy lists, we do not scrape addresses in bulk, and we do not use data brokers.
Lawful basis: legitimate interests — ours in finding the engineers a simulation tool is genuinely useful to, and yours in hearing about tools relevant to your work. We have carried out and documented a balancing assessment weighing that against your rights, and will provide a copy on request to privacy@shd-sim.com. We rely on consent rather than legitimate interests where the law requires it, which includes individual subscribers such as sole traders and partnerships, and jurisdictions whose rules on unsolicited business email are stricter than the United Kingdom’s.
You can stop it at any time, and we will not ask why. Reply to the message, or email privacy@shd-sim.com. Objecting to direct marketing is an absolute right: there is no balancing test and we must stop. We keep a record of your address for the sole purpose of not contacting you again, which is the only way to honour the objection.
How long: deleted within six months if you do not reply, and on request at any time. An unanswered introduction is not a relationship and we do not keep it as though it were.
7. What we never collect
No case files, no geometry, no meshes, no results and no reports. No file names and no folder paths. No advertising identifiers, no third-party trackers, no data brokers. We do not sell personal data, and we never will.
Section 4 is the limit of what the application reports, and it is deliberately about the shape of a run rather than its content: that a steady incompressible case of somewhere between 250,000 and a million cells completed, never what was modelled, what it was called, or what the answer was.
8. Who processes data for us
These are our processors. Each handles data only on our instructions and under a contract requiring appropriate safeguards.
| Processor | What for | Where |
|---|---|---|
| Paddle.com Market Ltd | Payments, invoicing and tax, as merchant of record | UK / EU |
| Hetzner Online GmbH | Hosting of the application, database and analytics | Germany (EU) |
| Cloudflare, Inc. | DNS and CDN | Global network; EU/US |
| ZeptoMail (Zoho Corporation) | Sending transactional email — licence keys, receipts, password resets | EU |
| Zoho Mail (Zoho Corporation) | Our own mailboxes — receiving and sending the mail you send us | United States |
| Zoho Campaigns (Zoho Corporation) | Sending the release-notes and product email you opted in to, and holding the subscriber list for that purpose | United States |
Card details are handled entirely by Paddle and never reach our systems.
9. International transfers
Our application, database and analytics are hosted in the EU, and transactional email is sent from within the EU. Two things sit outside it: Cloudflare’s global network, and our Zoho Mail and Zoho Campaigns accounts, which are on Zoho’s United States region. That means the mail you send us, and the address you give us for the release-notes list, are processed in the US.
Those transfers rely on UK International Data Transfer Agreements, the EU Standard Contractual Clauses, or an adequacy decision, as applicable.
10. How long we keep it
| Record | Retention |
|---|---|
| Account and licence records | While the account is open, then anonymised on erasure request |
| Billing and tax records | Six years after the end of the accounting period (HMRC requirement) |
| Sessions | Expire automatically; 30 days for customers, 12 hours absolute for staff |
| IP addresses in security logs | Kept briefly for rate limiting and audit, then discarded |
| Audit log | Retained for accountability; append-only and not editable by staff |
| Analytics and download counts | Aggregate and non-identifying; retained indefinitely |
| Application usage data (section 4) | Individual events for 90 days, then only daily totals, which are aggregate and non-identifying. An installation that has not reported for a year is deleted outright, as is one that turns the setting off |
| Contact form messages | Two years from the last message in the exchange, then deleted — long enough to make sense of a follow-up, short enough not to be a filing cabinet |
| Module interest registrations | Unconfirmed requests are deleted after 30 days; confirmed ones until the module ships and you have been told, or until you unsubscribe |
| Business contacts we approached (section 6) | Deleted within six months if you do not reply, or on request. Where you have asked not to be contacted, your address alone is kept so that the request can be honoured |
11. Your rights
Under UK GDPR you have the right to:
- Be told what we hold about you, and get a copy (access).
- Have inaccurate data corrected (rectification).
- Have your data deleted (erasure), subject to records we must keep by law.
- Restrict or object to processing, including processing based on legitimate interests.
- Receive your data in a portable format.
- Withdraw consent at any time, where consent is the basis.
Email privacy@shd-sim.com. We will respond within one month.
A note on how erasure works. We anonymise rather than delete rows. The effect is the same — nothing identifying you remains — but it keeps billing and audit history internally consistent, which matters because a deleted customer with a live subscription is unrecoverable for both of us. Records we are legally required to retain, principally invoices, survive an erasure request until their retention period expires.
12. Complaints
If you are unhappy with how we have handled your data, tell us first and we will try to put it right. You also have the right to complain to the Information Commissioner’s Office, the UK supervisory authority, at ico.org.uk or on 0303 123 1113.
13. Cookies
We set only strictly necessary cookies: a session cookie when you sign in, and a security token to prevent cross-site request forgery. These are exempt from the consent requirement because the service cannot work without them. We set no analytics, advertising or tracking cookies of any kind.
14. Children
The service is intended for professional and academic users and is not directed at children under 13. We do not knowingly collect their data.
15. Changes
We will publish changes here with a new date, and email account holders about material changes.
Questions about any of this: legal@shd-sim.com