Last Updated: January 2022
Please ensure you read the privacy notice in full.
Capsim (“Capsim”, “we”, “us”, or “our”) believes in creating engaging, real-world experience that teaches and measures specific skills of students and employees. Capsim cares about the security and privacy of the personal data that is entrusted to us.
This privacy notice sets out how Capsim collects and uses information about you when you use our products and services (“services”) and why we collect certain personal data. This notice also explains the choices that you can make about the way that we use your information.
Your privacy protection is important to us. This is why we have adopted the following pivotal legislation: EU’s General Data Protection Regulation 2016/679 (“GDPR”), UK General Data Protection Regulation (“UK GDPR”) and the California Consumer Privacy Act 2018 (“CCPA”). This privacy notice relates to all personal data we process and addresses the legislation mentioned.
‘Personal data’, in this privacy notice, means any information relating to an identified or identifiable natural person (‘data subject’). An identifiable natural person is someone who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
Capsim Management Simulations Inc.
2640 White Oak Cir, Suite C
Aurora, IL 60502 USA
Our EU representative under the GDPR is Kimura Limited d/b/a Apex Privacy - Main Street, Portarlington, Co. Laois, Ireland. In regards to the processing of your data, Capsim will act as its Processor.
For all data privacy matters, please contact our Data Protection Officer (DPO), at Privacy@Capsim.com.
Capsim’s Privacy Policy applies to all visitors to this website and to anyone who uses Capsim’s products or services through this website (“you” and “your”). This Privacy Policy applies to Capsim’s collection, use, storage, processing, transmission, and transfer of your information, as well as creation of information pertaining to you, whether online and offline. Capsim may update, revise, modify or amend this Privacy Policy at any time. You should check this page periodically for updates, revisions, modifications, or amendments. The last change to this Privacy Policy was on the date that appears on the top of this Privacy Policy.
‘GDPR’ means either or both of the EU GDPR and UK GDPR. We will use this when there is little or no difference in the wording of the relevant law for the context.
‘Personal data’ means any information relating to an identified or identifiable natural person, namely one who can be identified, directly or indirectly from that information alone or in conjunction with other information ‘in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person’.
“Financial Information” means Personal Information of a financial nature, such as your credit card number.
“Other Business Parties” means parties other than you that contract with Capsim either to provide products and services to Capsim in connection with products or services that Capsim provides to you or that engage Capsim to assist in its provision of products or services to you (e.g., your university or your employer). Other Business Parties may include your fellow students or employees.
“Personal Information” means information about you that Capsim collects about you that may be used, alone or in combination with other information, to identify you as a specific individual.
“Unrelated Parties” means persons or entities other than you, Capsim, or Other Business Parties.
“Unrelated Parties” means persons or entities other than you, Capsim, or Other Business Parties.
In order for us to provide you with our services or for correspondence purposes we need to collect your personal data. We ensure that the information we collect and use is confined to this purpose. We always process your personal data for specific purposes, with the nature of the data collected depending on your interaction with us. We are committed to transparency in this.
Our legal bases for controlling or processing personal data are:
Where we rely on a specific basis for processing your information and you wish to object to that processing, you must be aware that it might not be possible for you to continue using our services.
Capsim collects information from you whenever you visit or use the website, some of which you provide voluntarily and some of which is collected automatically. In addition, Capsim may receive information about you from Other Business Parties. This can be information that you provide through our websites, over the phone, through email, including when you:
We may need to pass your personal data on to third-party service providers contracted to Capsim in the course of providing you services. We do this because there are services, such as our videos and chat features, which will not work unless we are able to make these transfers. Any third parties we share your data with are obliged to keep your personal data secure and use it only for necessary service delivery.
https://www.capsim.com/ may use your information for the following purposes:
Your Financial Information will be used to provide requested products and services, to analyze operational and business results, to analyze risk, and to conclude a transaction between you and either Capsim or an Other Business Party. It will not be sold, rented, or otherwise transferred to anyone for any other purpose. Capsim uses the services of a third-party service provider to process credit card payments. Therefore, Capsim itself will not have access to you credit card information. In addition, the third-party service provider has agreed that it only uses your [personally identifiable] credit card information to process your payments.
If you are using Capsim products or services in your capacity as a student of an Other Business Party that is subject to the U.S. federal Family Educational Rights and Privacy Act (FERPA) (“Covered Educational Institution”), to the extent that your Personal Information is an “education record” under FERPA, it will be subject to FERPA. If you want to assert your rights under FERPA, you should contact your Covered Educational Institution.
Capsim will share your information only with your explicit consent. Your information may be shared to a third-party for reasons including:
Any third party we share your information with must disclose the purpose for which they intend to use your information. They must retain your information only for the duration disclosed when requesting or receiving said information. The third-party service provider must not further collect, sell, or use your personal information except as necessary to perform the specified purpose. We seek to enter into Data Processing Agreements with our third party service providers to ensure they only process your data as instructed by us. If you obtain products or services directly from us on behalf of others we will ensure those third party service providers have a Data Processing Agreement (DPA) with us.
If you choose to provide such information during registration or otherwise, you are giving Capsim permission to use, share, and store that information in a manner consistent with this Privacy Policy.
Your information may be disclosed for additional legal reasons, including:
We will process (collect, store and use) the information you provide in a manner compatible with GDPR. We maintain physical, organizational and technical safeguards for all personal data we hold. We will endeavor to keep your information accurate and up to date, and not keep it for longer than is necessary. We are required to retain certain information in accordance with the law, such as information needed for income tax and audit purposes. How long certain kinds of personal data should be kept are governed by specific business sector requirements and agreed practices. Personal data can be held in addition to these periods depending on individual business needs.
We will process different forms of personal data for as long as it is necessary and proportionate for the purpose for which it has been supplied and we will store the personal data for the shortest amount of time possible, taking into account legal and service requirements.
All data is stored on servers that are located in the US. Production servers and data are hosted in Amazon Web Services (AWS) Cloud. Capsim products are web application platforms, therefore all the data is separated logically, rather than physically. Retained data can be deleted upon client’s request. At the 7-year mark, data will be either deleted or archived. All stored passwords and email addresses are encrypted. Please note that user passwords are not provided during LTI integration.
Authorization of data is done via SSL protocol with validated private keys and secrets. Data is accessed by authorized personnel only: Capsim Employees and Third-Party certified secure AWS contractors have all signed Privacy and Non-Disclosure Agreements.
The personal information which is accessed is First Name, Last Name, Student ID, Student Email. This information is stored for the convenience of the Professor and Students for teamwork and grading. Upon request, this information can be made anonymous by using randomly generated placeholder info. Students can only see their own personal information and grading data. Professors can see data for all students and courses which they are teaching.
All stored personal information is used only for the purpose of the client/user. Capsim does not sell, rent, or lease any personal information.
Amazon Web Services (AWS) Cloud
As mentioned, all production servers and data are hosted in Amazon Web Services (AWS) Cloud. The IT infrastructure that AWS provides is in alignment with security best practices and IT security standards, including: SOC 1/SSAE 16/ISAE 3402 (formerly SAS 70), SOC 2, SOC 3, FISMA, DIACAP, and FedRAMP, DOD CSM Levels 1-5, PCI DSS Level 1, ISO 9001 / ISO 27001 / ISO 27017 / ISO 27018, ITAR, FIPS 140-2, MTCS Level 3
As well as several industry-specific standards, including:
AWS Physical Security
All physical access to AWS facilities is strictly controlled both at the perimeter and at building ingress points by professional security staff utilizing video surveillance, intrusion detection systems, and other electronic means.
Authorized staff must pass two-factor authentication a minimum of two times to access data center floors. All visitors are required to present identification and are signed in and continually escorted by authorized staff.
All physical access to data centers by AWS employees is logged and audited routinely.
We have no interest in collecting any data beyond that needed to ensure our services work for you. If you are going to be contacted by us for marketing purposes, we will not rely solely on this privacy notice. We will endeavour to seek your consent appropriately. Capsim does not sell data, and has no intentions in doing so in the future.
All marketing activities must comply with our Privacy & Marketing Policy, its related procedure, and all applicable laws at all times.
At Capsim we understand the importance of protecting the personal data of children under the age of 16. It is not our intention to collect personal data from a child. If you believe that a child has disclosed personal data or that we hold personal information about a child, please email us at privacy@capsim.com.
At any point while we are in possession of or we process your personal data, you have the following rights:
To exercise your data protection rights please contact our DPO at Privacy@Capsim.com.
We will comply with your request to the extent required by applicable law. We will not be able to respond to a request if we no longer hold your Personal Data. If you feel that you have not received a satisfactory response from us, you may have the right under applicable laws to consult with the data protection authority in your country.
For your protection, we may need to verify your identity before responding to your request, such as verifying that the email address from which you send the request matches the email address that we have on file. If we no longer need to process Personal Data about you in order to provide our Services or our Sites, we will not maintain, acquire or process additional information in order to identify you for the purpose of responding to your request.
Cookies are defined as ‘small text files that are placed on your computer by websites that you visit. They are widely used in order to make websites work, or work more efficiently, as well as to provide information to the owners of the site.’ You can find out all about cookies, how to manage them and delete them, and how to manage your browser settings, at the UK ICO and www.aboutcookies.org.
You can change or withdraw your consent to the cookies we use at any time contacting the Privacy Team at Privacy@Capsim.com You can also opt out of being tracked by Google Analytics across all websites.
Please note that if you manage your consent or your browser and third party settings to block cookies, some or all of the Website and Services may not have full functionality and your user experience may be impacted.
If we provide social media links or interactions on our website, such as like or share buttons, and you interact with them, the social media organization may drop cookies and they will be covered by the Privacy Policy of that organization. We typically do not receive any personal data collected as a result of such interaction, although we may receive aggregated reports.
Your information’s security is important to us.
Capsim utilizes a range of security measures to prevent the misuse, loss, or alteration of the information you have given us. However, because no security can ever be 100% guaranteed, Capsim cannot guarantee you against the loss, misuse, or alteration of your Personal Information and you must access our service at your own risk.
Capsim is additionally strongly committed to security and privacy of the personal data that is entrusted to us. Data at rest and in transit is encrypted using Advanced AES 256 Encryption. User data is only used for the necessary purposes of the simulation.
Capsim does not sell, rent, or lease any Personal Information. Our EU representative under the GDPR is Kimura Limited d/b/a Apex Privacy - Main Street, Portarlington, Co. Laois, Ireland. All production servers and data are hosted in Amazon Web Services (AWS) Cloud within the US.
Capsim is not responsible for the performance of websites operated by third parties or your interactions with them. When you leave this website, we recommend you review the privacy practices of other websites you interact with and determine the adequacy of those practices.
Our servers are being continuously monitored for uptime with immediate escalation to the authorized system administrators for any downtime. In the event that a security incident is suspected to have resulted in a breach of personal information, notification of the affected entities will occur within 48 hours of the breach. Upon discovering a possible security breach, system administrators focus on investigating and containing the breach as well as addressing appropriate gaps to prevent the incident from reoccurring. Client will be continuously updated on the status of the investigation, containment, and follow-up actions.
Public Status Page: https://status.capsim.com/
When developing any software through our agile methodology, the project is divided into iterations. Our secure design standards are applied to each iteration which will be implemented as part of the product requirements.
Our secure design strategy focuses on three main areas for every iteration. Confidentiality - data is protected from unauthorized individuals/systems. Integrity - data remains complete and uncorrupted. Availability - data is accessible only by authorized users without interference. Additionally, we incorporate server-side session checks prior to allowing access to software updates in order to verify the authenticity of the user. Finally, we also verify security guards that are in place combined with automated testing and version control prior to any release.
Capsim’s website may contain links to other websites. Some of them may collect your Personal Information and may apply their own policies on how your Personal Information is used. Please read all applicable policies of all websites you visit. Capsim is not responsible for the privacy practices of anyone else’s website(s).
Personal Data may be stored and processed in any country where we do business, or our service providers do business. We may transfer your Personal Data to countries other than your own country, including to the United States. These countries may have data protection rules that are different from your country. When transferring data accross borders, we take measure to comply with applicable data protections law related to such transfer. Official (such as law enforcement or security authorities in those countries may be entitled to access your Personal Data.
We comply with laws on the transfer of personal data between countries to help ensure your data is protected, wherever it may be.
Capsim’s international transfer of personal data collected in the European Economic Area, the United Kingdom, and Switzerland is governed by Standard Contractual Clauses.
Capsim updates our privacy notice when necessary or in response to:
If you have any questions about our privacy policy, please contact us by email at privacy@capsim.com