Platform4 min read

Privacy and Data Protection

How Symbi handles your data — consent, PII protection, GDPR rights, and where your information is stored.

Our Approach

Symbi is built as a privacy-first platform. We process data only when needed, encrypt everything at rest and in transit, and give you full control over what's stored, shared, and deleted.

This page summarizes the user-facing controls. For the full legal documents, see our Privacy Policy and DPA (Data Processing Agreement) linked in the footer.

What Data Symbi Handles

Symbi processes three broad types of data:

  • Account and workspace data — your email, company profile, settings, and usage
  • Content processed by agents — support tickets, emails, CRM records, and anything else your agents act on
  • AI interaction logs — prompts, responses, edits, and approval decisions used to improve agent performance

All of this is kept in your tenant, isolated from other customers.

PII Protection

Symbi applies company-level PII sanitization before content is sent to AI models. That means personal identifiers in the content — names, email addresses, phone numbers, account numbers, and similar — are replaced with placeholders before leaving our systems for third-party AI providers.

The sanitization is automatic and applies across all AI-powered paths: agent execution, Personal Assistant chats, knowledge base indexing, and review handling. You don't have to enable it manually.

Info

PII is sanitized on the way out to model providers and restored on the way back, so responses still contain the right names and details — AI providers never see raw PII.

First-time visitors see a consent banner that lets them opt in or out of non-essential cookies and analytics. You can update your preferences any time from the link in the footer.

Your team members' consent choices are stored per-user and respected across the platform.

GDPR Rights

If you're an EU resident, you have specific rights under GDPR. Symbi supports all of them:

  • Right to access — request a copy of all data we hold about you
  • Right to rectification — correct inaccurate personal data
  • Right to erasure — ask us to delete your account and associated personal data
  • Right to data portability — export your data in a machine-readable format
  • Right to object / restrict — limit how your data is processed

Submit any of these requests from Settings → Privacy → Data Rights, or email us at privacy@symbi.no.

Where Data Is Stored

Symbi is hosted in the EU (Frankfurt / Hetzner). All customer data — databases, file storage, logs — stays in EU data centers. We do not replicate customer data outside the EU.

Third-party subprocessors (such as AI model providers) may process requests in their respective regions. The current list of subprocessors is available in our DPA.

Encryption

  • In transit — all traffic uses HTTPS/TLS
  • At rest — databases and object storage are encrypted at the infrastructure layer
  • Sensitive fields — integration credentials, API keys, and OAuth tokens are encrypted with AES-256 before being written

Data Retention

  • Active workspace data — kept while your account is active
  • Activity logs — retained for 12 months by default (configurable per plan)
  • Deleted workspaces — purged permanently within 30 days of deletion
  • Backups — rolling 30-day retention

Your Personal Assistant's Data

Your Personal Assistant only sees data tied to you: your personal integrations, your chats, your skills. Other teammates' personal data is never visible to your assistant, and vice versa. Admins have aggregate visibility for usage and billing but cannot read the content of personal chats or activity.

Questions?

What's Next?