Legal
Privacy Policy
Simba Health, Inc. sells healthcare-literacy training to employers. We are not a health plan, and we do not want your employees' health information. This policy explains what we do collect, why, and what you can ask us to do with it.
Which parts apply to you
Visiting this site or asking for a demo. All of it applies, and we are the ones deciding how your information is used.
Taking Simba training. Your employer makes those decisions and we follow their instructions. Section 9 is written for you.
Contacted by us out of the blue. We got your work contact details from a business contact database. Section 1 says exactly what we hold and where it came from; Section 8 is how you get it deleted.
Evaluating us as an employer or advisor. Sections 1, 4, 6 and 7 are the ones a security review will care about.
1. What we collect
We collect four narrow categories of information.
- Information you give us. When you request a demo or email us, we receive your name, work email, company, role, employee-count range, and anything you write in the message field. The demo form does not store submissions in a database — it forwards them to our email. If you become a customer, we also hold the business contact details we need to invoice you.
- Training records. What we receive depends on how the training reaches you.
Delivered as a SCORM package into your employer’s own learning system, we typically receive nothing at all. Their system holds the roster and records who completed what. We see it only if your employer chooses to send us a report.
Delivered on a learning platform we provide, we process the roster fields needed to assign and track training — name, work email, department, and location, plus employee ID where a customer asks us to carry it — along with which videos each learner started and completed, and how far they got. - Business contact information we obtain from a vendor. We use a third-party business contact database — currently Apollo.io — to identify people in HR, benefits, and advisory roles who may want to hear from us. From it we obtain workplace contact details: name, job title, employer, work email address, and sometimes a work phone number or a LinkedIn profile URL. You did not give us any of this, and you may never have heard of us before we wrote to you. Apollo compiles it from public and commercial sources; their own privacy notice describes how.
- Technical information. Our website host keeps standard server logs: IP address, browser type, pages requested, and timestamps. We do not run analytics software on this site.
Not all of this comes from you directly. If you are a learner, your employer supplies your details; you never hand them to us. We may also receive an employer’s contact information from a benefits advisor introducing us, or from a colleague at your organization.
That fourth category is the only personal information we obtain from a data vendor. We do not buy consumer or household data, information about anyone’s health, finances, or family, or anything about you outside your professional role. We do not enrich learner or customer records with purchased data, and we do not build behavioral profiles.
If you would rather we did not hold your contact details, say so and we will delete them and stop writing. Section 8 explains how.
2. What we don't collect
We do not collect protected health information, claims data, diagnoses, prescriptions, biometric data, or any record of the care anyone received. We do not ask which plan an employee enrolled in.
We are not a covered entity or a business associate under HIPAA, and our training does not create a HIPAA obligation for your organization.
We do not collect Social Security numbers, financial account details, precise geolocation, or the other categories that state privacy laws treat as sensitive personal information.
We do not collect payment card numbers. Customers pay by invoice and bank transfer, so no card information reaches us and none is stored.
3. How we use it
We use the information above to deliver and support the training, report completion to the employer that purchased it, respond to your inquiries, keep the service secure, meet our legal obligations, and improve the courses — for example, by seeing in aggregate where learners stop watching.
We use business contact details to introduce Simba to people whose work involves employee benefits — including people who have not contacted us first. Every message we send identifies us, and every message includes a way to unsubscribe. Unsubscribing has no effect on training you have been assigned.
We do not use purchased contact data for anything other than contacting that person about Simba.
We do not sell personal information, and we do not share it for cross-context behavioral advertising.
We do not use learner or customer information to train artificial intelligence models, and we do not send it to third-party AI services.
4. Who we share it with
We share information with the employer or benefits advisor that purchased the training, with the service providers that process data on our behalf under contract, and where required by law or to protect our rights. If we are ever involved in a merger or acquisition, information may transfer as part of that transaction.
Today those service providers are our website host, our business email provider, and the sales outreach platform we use to manage contacts and send those emails (currently Apollo.io, which is both the source of the contact data described in Section 1 and the tool we send from). Where we supply a learning platform to a customer who does not have their own, that platform vendor processes learner data on our behalf under contract. We do not use analytics vendors, advertising vendors, or a third-party video host.
Your information is processed and stored in the United States. We require United States data residency of any learning platform vendor we engage.
A current list of our subprocessors is available on request at info@simbahealth.com.
5. Cookies, tracking, and other sites
We use only the cookies necessary for this site to function. We do not run analytics software, we do not use advertising or tracking cookies, and we do not embed third-party media players.
Because we neither sell nor share personal information, there is nothing a Global Privacy Control or similar browser signal would opt you out of. Some browsers also send a Do Not Track signal. We do not do the kind of tracking that signal was built to stop, so there is nothing for us to change in response to it.
Where we supply a learning platform, that platform sets its own cookies to keep learners signed in and to record progress. Those are necessary for it to work.
This site may link to pages we do not operate. Those sites have their own privacy practices and we are not responsible for them.
6. How long we keep it
- Completion records. We keep them for the term of the customer’s agreement plus three years, or for whatever period the customer directs, so employers can evidence that training was delivered. Where training runs inside a customer’s own learning system, retention is governed by that system and their policy rather than ours.
- Demo and inquiry correspondence. We keep it while we are in contact with you about your inquiry and for a reasonable period afterward. We delete it sooner if you ask.
- End of an agreement. When a customer’s agreement ends, we delete or return learner data within 30 days of a request, and in any event within 90 days.
7. Security
We serve this site over HTTPS, and the data we hold is encrypted at rest by our hosting provider. Access to personal information is limited to the people who need it for their work, which today is a very short list.
We do not maintain a learner database of our own. Training records live either in the customer’s own learning system or, where we supply the platform, with that platform vendor under contract.
No system is perfectly secure, and we cannot guarantee absolute security.
8. Your rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of the personal information we hold about you, to opt out of certain processing, and to appeal a decision we make about your request. The exact rights vary by state. We will not discriminate against you for exercising them.
Some state laws also give you the right to limit how a business uses sensitive personal information. We do not collect any, as Section 2 explains, so there is nothing here to limit.
This section covers information we hold in our own right — chiefly site visitors and people who contact us. If you are a learner taking Simba training, Section 9 applies to you instead.
To make a request, email info@simbahealth.com. Because we operate entirely online, email is our designated method for these requests. We may need to verify your identity before acting, and we will respond within the time the law allows. You may use an authorized agent, and we may ask that agent for proof of authority. We may decline a request that is excessive, repetitive, or manifestly unfounded, and if we do we will tell you why.
You can unsubscribe from our email using the link in any message, or by replying and asking. If we obtained your details from a business contact database rather than from you, the same request works: tell us and we will delete your record.
One honest caveat. To make sure a deleted contact is not re-imported the next time we pull a list, we keep the minimum needed to suppress you — normally your email address alone, on a do-not-contact list used for nothing else. If you would rather we kept nothing at all, tell us and we will remove that too, though we cannot then guarantee you will not reappear in a future list.
9. Employees and employers
If you are taking Simba training through your employer, your employer decides what training to assign and who may see your completion records. Where we hold that data at all, we process it on their instructions — in the language of California’s privacy law, as their service provider, rather than as a business acting for our own purposes.
In many cases we hold nothing about you. When training runs inside your employer’s own learning system, your records stay there and never reach us.
Requests about your training records are best directed to your HR or benefits team. If you come to us first, tell us which organization you took the training through so we can route your request, and we will let them know you asked.
Your employer’s own privacy and security practices are their own, and may differ from what this policy describes. We are not responsible for them.
10. Minors
Our training is made for people at work, and the only learner records we hold are the ones an employer gives us about its own workforce. We do not market to children, and we do not knowingly collect personal information from members of the public who are minors.
Employers do sometimes employ people under 18. Where a customer’s roster includes them, we process those records on the employer’s instruction on exactly the same terms as any other employee record, and we collect nothing additional because of a learner’s age. We do not ask anyone for a date of birth.
11. Changes to this policy
If we make a material change, we will update the date at the top of this page and, for customers, give notice at least 30 days before it takes effect.