Legal
Privacy Policy
Last updated: June 2026
1. Introduction
SimsekLabs ("we", "our", "us") operates Iodibase, a multi-tenant IoT infrastructure platform. We are committed to protecting your personal data in compliance with the General Data Protection Regulation (GDPR) and applicable Norwegian data protection laws.
This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our services.
2. Data Controller
The data controller for your personal data is:
SimsekLabs
Norway
Email: privacy@iodibase.com
3. Data We Collect
We collect the following categories of personal data:
3.1 Account Information
- Name and email address
- Organization name and job title
- Authentication credentials (encrypted)
3.2 Usage Data
- API requests and response logs
- Device connection metrics
- Message throughput and storage usage
- Console interaction logs
3.3 IoT Telemetry Data
Iodibase processes IoT telemetry data on behalf of our customers. This data is owned by the customer and is processed strictly as a data processor under GDPR Article 28. We do not access, analyze, or share customer telemetry data without explicit authorization.
3.4 Technical Data
- IP addresses and device identifiers
- Browser type and version
- System logs and error reports
4. Legal Basis for Processing
We process your personal data based on the following legal grounds:
- Contract performance — to provide and maintain our services (Article 6(1)(b))
- Legitimate interests — to ensure platform security, prevent abuse, and improve our services (Article 6(1)(f))
- Legal obligation — to comply with applicable laws and regulations (Article 6(1)(c))
- Consent — for marketing communications and optional features (Article 6(1)(a))
5. Data Storage and Location
All personal data and IoT telemetry data is stored exclusively within the European Union. Our primary infrastructure is hosted in Germany and Finland through our partners at Hetzner Online GmbH. We also do have our own infrastructure in Norway. We do not transfer personal data outside the EEA.
Data is encrypted at rest using AES-256 and in transit using TLS 1.3.
6. Data Retention
We retain your personal data for the following periods:
- Account data — for the duration of your account plus 30 days after deletion
- IoT telemetry data — according to your plan's retention period (7 days to 1 year)
- API logs — 90 days for operational purposes
- Billing records — 5 years as required by Norwegian tax law
7. Your Rights Under GDPR
You have the following rights regarding your personal data:
- Right of access — request a copy of your personal data
- Right to rectification — correct inaccurate data
- Right to erasure — request deletion of your data ("right to be forgotten")
- Right to restrict processing — limit how we use your data
- Right to data portability — receive your data in a machine-readable format
- Right to object — object to processing based on legitimate interests
- Right to withdraw consent — withdraw consent at any time
To exercise any of these rights, contact us at privacy@iodibase.com. We will respond within 30 days.
8. Third-Party Services
We use the following third-party service providers, all based in the EU/EEA:
- Hetzner Online GmbH — infrastructure hosting (Germany)
- Stripe — payment processing (Ireland)
- Resend — email delivery (EU infrastructure)
All processors are bound by Data Processing Agreements (DPAs) compliant with GDPR Article 28.
9. Security Measures
We implement appropriate technical and organizational measures to protect your data:
- End-to-end encryption for all data in transit and at rest
- Regular security audits and penetration testing
- Role-based access control with principle of least privilege
- Multi-factor authentication for administrative access
- Automated vulnerability scanning and patch management
- Incident response procedures compliant with GDPR Article 33
10. Children's Privacy
Iodibase is a B2B platform and is not intended for individuals under 16. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child, we will take steps to delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices or applicable law. We will notify you of material changes by posting notice on our website or sending you an email. Continued use of our services after such notice constitutes acceptance of the updated policy.
12. Contact and Supervisory Authority
If you have questions about this Privacy Policy or our data practices, contact us at:
Email: privacy@iodibase.com
Address: SimsekLabs, Norway
You also have the right to lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet) at datatilsynet.no.