UK GDPR (the UK's post-Brexit data protection regime) applies to UK residents. It parallels the EU GDPR with substantively the same rights, which are already enumerated in "Your Rights & Controls" above (access, rectification, erasure, restriction, objection, portability, complaint).
Data residency: Simplance stores user data in the United States (Supabase, AWS us-east-1). Transfers from the UK to the US rely on the UK Extension to the EU-US Data Privacy Framework and Standard Contractual Clauses where applicable. We do not transfer your data outside of these safeguards.
Supervisory authority: If you believe we're processing your personal data unlawfully, you have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk/make-a-complaint. We'd appreciate the chance to address your concern first via support@simplance.org.
Lawful basis for processing: we process your account and financial data under "contract" (we need it to provide the service you signed up for) and process analytics under "legitimate interest" (improving the product), which you can object to at any time. Marketing emails are sent only with your explicit consent and you can unsubscribe at any time.