Last updated: July 1, 2026

Privacy & data processing notice

This notice describes how Symbiosis LLC ("Symbiosis", "we") handles personal data and customer ESG data through Symbiosis ESG Compass (the "Service"). It is maintained by Symbiosis LLC and is subject to change; material changes will be announced in-product.

1. Roles

Personal data of end users (names, email addresses, authentication metadata): Symbiosis acts as the data controller.

Customer ESG data (frameworks, disclosures, metrics, evidence documents, emissions activities): Symbiosis acts as a data processor on behalf of the customer organization, which is the controller of that data.

2. Data we collect

  • Account data - email, name, hashed password or OAuth identifier, organization membership, role.
  • Workspace data - the ESG content you enter or upload: responses, evidence files, emission activities, readiness snapshots.
  • Billing data - Stripe customer ID and subscription state; card details are handled by Stripe, not stored by Symbiosis.
  • Operational logs - request logs and error traces used to keep the Service running and secure. Retained for up to 90 days.

3. How we use it

  • Provide the Service and secure your workspace.
  • Bill for subscriptions and manage entitlements.
  • Detect abuse, debug incidents, and improve reliability.
  • Send transactional messages (invitations, receipts, security alerts).

We do not sell personal or customer data, and we do not use customer ESG content to train third-party AI models.

4. Subprocessors

The Service relies on a small set of infrastructure subprocessors. Contact us for the current list with regions and DPAs:

  • Managed database, authentication, and file storage provider.
  • Cloud hosting for application and edge functions.
  • Stripe, Inc. - subscription billing.
  • Transactional email provider.

5. Data location & transfers

Production data is stored in facilities operated by our infrastructure provider. Where personal data is transferred out of the EEA/UK, we rely on Standard Contractual Clauses or equivalent safeguards. Customers with data-residency requirements should contact us before onboarding.

6. Retention

Customer workspace data is retained for the life of the subscription and for up to 30 days after termination, after which it is deleted unless a longer period is required by law. Backup copies are rotated within 35 days. Operational logs: up to 90 days.

7. Security

Data is encrypted in transit (TLS 1.2+) and at rest by our infrastructure provider. Access to production data is restricted, least-privilege, and audit-logged. Every customer workspace is isolated at the database layer via row-level security scoped to the organization.

8. Your rights

Depending on your jurisdiction, you may have the right to access, correct, export, or delete personal data we hold about you, and to object to or restrict certain processing. Requests can be sent to privacy@symbiosis-llc.com. For workspace data, contact your organization admin first.

9. Data processing agreement

A standard DPA is available on request for customers who require one to comply with GDPR, UK GDPR, or similar laws. See the Frameworks & compliance page for how to submit an attestation or DPA request.

10. Contact