Last updated: July 1, 2026
This notice describes how Symbiosis LLC ("Symbiosis", "we") handles personal data and customer ESG data through Symbiosis ESG Compass (the "Service"). It is maintained by Symbiosis LLC and is subject to change; material changes will be announced in-product.
Personal data of end users (names, email addresses, authentication metadata): Symbiosis acts as the data controller.
Customer ESG data (frameworks, disclosures, metrics, evidence documents, emissions activities): Symbiosis acts as a data processor on behalf of the customer organization, which is the controller of that data.
We do not sell personal or customer data, and we do not use customer ESG content to train third-party AI models.
The Service relies on a small set of infrastructure subprocessors. Contact us for the current list with regions and DPAs:
Production data is stored in facilities operated by our infrastructure provider. Where personal data is transferred out of the EEA/UK, we rely on Standard Contractual Clauses or equivalent safeguards. Customers with data-residency requirements should contact us before onboarding.
Customer workspace data is retained for the life of the subscription and for up to 30 days after termination, after which it is deleted unless a longer period is required by law. Backup copies are rotated within 35 days. Operational logs: up to 90 days.
Data is encrypted in transit (TLS 1.2+) and at rest by our infrastructure provider. Access to production data is restricted, least-privilege, and audit-logged. Every customer workspace is isolated at the database layer via row-level security scoped to the organization.
Depending on your jurisdiction, you may have the right to access, correct, export, or delete personal data we hold about you, and to object to or restrict certain processing. Requests can be sent to privacy@symbiosis-llc.com. For workspace data, contact your organization admin first.
A standard DPA is available on request for customers who require one to comply with GDPR, UK GDPR, or similar laws. See the Frameworks & compliance page for how to submit an attestation or DPA request.
Symbiosis LLC · privacy@symbiosis-llc.com · security@symbiosis-llc.com