Last updated July 2026
Privacy Policy
This Privacy Policy explains how Symphonee, a Luxembourg company, collects, uses, shares, and protects personal data when you visit our website, create an account, or use the Symphonee recruiting workspace.
Who is responsible
Symphonee is the controller for personal data we collect directly for our website, account administration, billing, security, support, and marketing. When a customer uploads or creates candidate, contact, client, job, message, note, CV, transcript, or similar workspace data, Symphonee processes that data as the customer's processor and follows the customer's lawful instructions.
What this policy covers
This policy covers symphonee.ai, the public site, the application workspace, the browser extension, API routes, support interactions, email and calendar integrations, billing, and operational logs. It does not cover third-party websites or services that you open from Symphonee, or the privacy practices of customers who decide what data to place in their workspaces.
Data we collect
We collect account data such as name, work email, role, organization, login credentials, workspace settings, language, and support messages. Customers may add recruiting data such as candidate and contact profiles, work history, skills, notes, pipeline stages, communications, CVs, transcripts, client accounts, jobs, feedback, billing records, and consent or deletion requests. We also collect operational data such as IP address, device and browser details, log events, product usage, security events, payment metadata, and email or calendar metadata needed to operate connected features.
Where data comes from
Data may come from you, your teammates, workspace administrators, candidates or clients who interact with shared links or self-service forms, connected Microsoft accounts, the Symphonee browser extension when a user chooses to capture information, imported files, public professional sources, and customer-authorized enrichment providers. Payment data is processed by Stripe and we receive only the transaction and subscription information needed to manage billing.
How we use data
We use personal data to provide and secure the service, authenticate users, maintain workspaces, run recruiting workflows, process imports and CVs, send notifications, support email and calendar integrations, prepare AI-assisted suggestions inside the customer's own workspace, process payments, provide support, prevent abuse, analyze reliability, enforce our terms, and comply with legal, tax, accounting, and security obligations.
Legal bases
For data where Symphonee is controller, we rely on contract performance, legitimate interests in operating and securing a business SaaS product, compliance with legal obligations, and consent where required, such as optional marketing or certain cookies. For customer-controlled workspace data, the customer determines the lawful basis for collection and use, and Symphonee processes the data as processor under the customer's instructions.
AI and automation
Symphonee uses AI to help recruiters summarize records, classify updates, draft outreach, evaluate role fit, and surface suggested next actions. Production AI requests are routed through vetted zero-retention inference infrastructure: prompts and outputs are not stored by the provider and are never used to train shared models. Symphonee does not use customer-controlled workspace data to train shared external models. AI output is assistive and customers remain responsible for human review, hiring decisions, outreach, and legal compliance.
How we share data
We share personal data only as needed to operate Symphonee: with service providers and subprocessors, with integrations enabled by the customer, with workspace users according to their permissions, with professional advisers, auditors, or authorities when required by law, and as part of a merger, acquisition, financing, or sale of assets if appropriate protections are in place. We do not sell personal data or use customer workspace data for cross-context behavioral advertising.
Subprocessors
Current subprocessors include DigitalOcean for EU cloud hosting in Frankfurt, managed MongoDB, managed Valkey, and serverless AI inference under zero-retention, no-training terms; Cloudflare for authoritative DNS, traffic proxying, TLS, and edge security; Resend for email delivery in the US; Coresignal for customer-authorized talent data enrichment in Lithuania; FullEnrich for customer-authorized contact enrichment in France; Stripe for payments in the US; and Microsoft for Outlook and calendar features inside the customer's own Microsoft tenant. We maintain a data map and subprocessor register and notify customers ahead of material changes where required.
International transfers
Symphonee is based in Luxembourg and its primary workspace compute and storage are hosted in DigitalOcean's Frankfurt, Germany region. Cloudflare manages authoritative DNS and proxies public application traffic at the edge. Some providers, including the separately described serverless inference service, may process data in the US or other countries listed in the subprocessor section; where required, we rely on data-processing agreements, standard contractual clauses, adequacy decisions, and provider security commitments.
Retention
We keep customer workspace data for as long as the workspace is active and for a short recovery period after cancellation or termination, unless a longer period is required by law or agreed with the customer. After that, data is deleted from production systems and backups age out on a rolling cycle. Security logs, billing records, audit trails, and aggregated non-identifying metrics may be kept longer where needed for security, accounting, dispute resolution, or legal compliance.
Your rights
Depending on where you live, including in the EU and UK, you may request access, correction, deletion, restriction, portability, objection to certain processing, or withdrawal of consent. Workspace users can update many account details directly. Candidates and contacts can use available self-service privacy flows or contact [email protected]. If your data was added by a Symphonee customer, we may need to refer the request to that customer because they control the workspace data. You may also lodge a complaint with the Luxembourg Commission nationale pour la protection des données, or your local data-protection authority.
Security
We use technical and organizational safeguards designed for a recruiting workspace, including role-based access, organization scoping, encryption in transit and at rest where supported by our infrastructure, session controls, audit trails, restricted production access, validation at system boundaries, and monitored subprocessors. No online service can be guaranteed perfectly secure, so customers should use strong passwords, manage seats carefully, and notify us promptly of suspected unauthorized access.
Cookies and marketing
We use necessary cookies and similar technologies to operate the site and application, remember settings, authenticate sessions, measure reliability, and protect against abuse. We may use optional analytics or marketing tools only where permitted by law and applicable consent settings. You can control cookies through your browser and any consent controls we provide.
Changes to this policy
We may update this Privacy Policy to reflect product, legal, or operational changes. When we do, we will update the date above and, where a change is material, provide additional notice through the website, application, email, or another reasonable channel.
Contact
Email [email protected] for privacy requests, security questions relating to personal data, or subprocessor information.