Privacy Policy
Last updated: September 7, 2026
Versiunea în română1. Who we are
This policy explains how MP RIVERSIDE GROUP SRL (Romanian tax ID 34152763, Str. Efta Botoca nr. 1, Timișoara, România), referred to as “Symbai”, “we” or “us”, processes personal data under Regulation (EU) 2016/679 (“GDPR”) and applicable Romanian law, including Law 190/2018.
It covers symbai.app and the Symbai POS, Symbai Staff, Symbai Portal and Symbai Connect applications. Privacy questions may be sent to hello@symbai.app.
2. Our roles as controller and processor
- Controller: for information collected directly by us, such as website enquiries, commercial communication, subscription administration and our own billing.
- Processor: for operational data entered by a business using Symbai, such as your employer or a merchant. That business is the controller; we process the data under its instructions and a data processing agreement.
You may contact the relevant business or us to exercise your rights. When necessary, we forward the request to the controller.
3. Data we process and why
3.1 Website
Contact and demo forms may collect your name, company, phone number, email address and message. We use them to respond and prepare an offer. The legal bases are pre-contractual steps requested by you and our legitimate interest in answering enquiries.
We also measure website traffic: for each page viewed we keep the IP address, the page, the time, the approximate duration of the visit, the referring page, the country (derived from the IP address) and the browser type. So that we can tell visits by the same person apart from other people's (an IP address is often shared by many people), your browser stores a random identifier that belongs to symbai.app only and contains no information about you; you can delete it at any time from your browser's site data. We use this data internally only, to understand which pages are read and for how long — with no advertising profiles, no tracking on other websites and no transfer to third parties; it is kept for at most 12 months. Legal basis: our legitimate interest in improving the website and our materials (Art. 6(1)(f) GDPR).
3.2 Symbai POS
On behalf of the employer or business using Symbai, the professional POS application may process:
- account data: user or employee ID, name, email, phone number, PIN, role and work location;
- customer or business tax and billing details entered for requested records, such as address, Romanian personal or company tax identifiers and other required invoice identifiers;
- operational data: shifts, attendance, work notes, processed orders, purchase history and cash or card transactions;
- technical and security data: IP address, app-generated device identifier, device type and activity logs.
The camera is used when requested for product, operational or room-code scanning and, when the user chooses, for chat photos or HACCP evidence. The photo library is accessed only after the user selects a photo. Local network access connects the app to the venue’s edge server.
3.3 Symbai Staff
For field, delivery and production workflows, the application may additionally process:
- precise foreground location for sales-visit check-ins, attendance records, nearby-customer suggestions and delivery-route operations;
- precise background location only during an active delivery shift or route, so authorized dispatchers can follow route progress and stops. Background tracking begins only after permission is granted and stops when the active route or shift ends;
- images or videos you select for work conversations, plus photos you capture or select, notes and signatures you provide as delivery, receiving or work evidence;
- when the employer enables attendance identity verification, the attendance selfie and profile photo are compared once to create biometric data: a similarity result and score. In AI mode, the images are securely sent to our AI provider, OpenAI, only for that comparison. Unclear or mismatched results are reviewed by a manager and do not by themselves produce a decision with a significant legal effect;
- customer, order and physical delivery-address data required for assigned work, plus sales or CRM activity entered by you;
- operational financial information required for assigned work, such as cash collected or handed over, fuel expenses and B2B balances or debts;
- an app-generated device identifier used to associate an authorized device with shifts and operational sync and, when configured, weights received through Bluetooth from a compatible scale.
You can revoke camera, photo, Bluetooth or location access in device settings. Some corresponding functions will then be unavailable.
3.4 Symbai Portal
On behalf of the merchant, the customer application may process:
- name, email, phone number, preferences and privacy settings;
- orders, bookings, loyalty points, reviews, chat messages and badges;
- a notification token required for push notifications;
- optional family information entered by a parent or guardian who confirms they have authority to provide it.
Marketing messages are sent only when the applicable consent has been given and can be disabled at any time.
3.5 Symbai Connect: Google accounts and assistants
Symbai Connect connects a Google account you select to supported assistants and, through a separate cloud authorization, to a selected Symbai business. You grant access on Google's own consent page; Symbai does not ask for or store your Google password. We process your Google account identifier, name, email address, granted permissions and authorization tokens to identify and maintain your connection.
- Gmail on your computer: optional read access searches and retrieves the messages and attachments needed for your requests. Optional draft access creates drafts; Google includes sending in that permission, while Connect separately controls whether sending is enabled. Sending requires the corresponding permission and your requested action.
- Drive on your computer: you can choose read access across your Drive for searching and reading existing documents, or access to selected files. Optional writing is limited to files selected for or created with the application.
- Gmail in your business: the cloud sending authorization grants permission to send email, without requesting inbox or Drive reading. You select the business and separately enable approved supplier orders, operational emails or assistant-requested messages. Outgoing recipients, content and attachments are passed to Google for delivery. This connection can operate while your computer is off.
Desktop authorization tokens are stored encrypted on your computer; cloud authorization tokens are stored encrypted in the selected business's server environment. Tokens are not supplied to the assistants. When you allow Claude Code or Codex to use the desktop connection, requested email and document content is returned to that assistant and may be transmitted to Anthropic or OpenAI respectively. This transfer enables the task you request. The provider's account settings and terms govern storage of the resulting conversation; review them before granting access. Business users can use the cloud sender only within their Symbai permissions and the uses you enabled.
Symbai uses Google API data to provide the user-facing functions described here, not to sell data, target advertising or train generalized AI models. Use and transfer of Google API data is subject to the Google API Services User Data Policy, including its Limited Use requirements. Connecting an assistant does not authorize unrelated reuse of your data.
Connection credentials remain until the connection is removed, subject to Google's expiration or revocation. Connect does not create a background archive of your inbox or Drive. The cloud keeps sender identity, delivery status, message identifiers and deduplication records with business records; this delivery log does not store email bodies or attachments. Existing orders and other business documents follow the retention rules in section 7. Removing a connection removes its stored credentials and requests Google revocation; it does not erase email already delivered, business records or assistant conversations. Revocation at Google may affect other authorizations of the same application. For complete withdrawal, review your Google third-party connections and both your desktop and business settings. For retained Symbai records, use the deletion procedure in section 10; manage assistant history with the respective provider.
3.6 TikTok integration
Connecting TikTok is optional and authorized on TikTok's official page. Symbai does not request or store your TikTok password. We process the selected account's identifier, display name, profile picture, permissions and authorization tokens, stored encrypted on the server of the business using Symbai. We retrieve creator information needed for publishing, including available privacy and interaction options and limits reported by TikTok.
When publishing, we send TikTok your selected video or photos, text and confirmed options. We retain the content, settings, identifiers and processing results to manage posts and prevent duplicate publication. For eligible public videos, we may retrieve available aggregate view, like, comment and share counts; these do not identify individual viewers. Access follows your granted TikTok permissions and your permissions in the selected business. Post records remain for the duration of the service and according to the business's instructions, as explained in sections 2 and 7. TikTok processes the content and data it receives under its own terms and privacy policy.
You can remove the connection in Symbai and withdraw the app's access in TikTok settings. Removing the connection deletes tokens stored by Symbai and stops their use; it does not automatically request revocation from TikTok. Account identity and history may remain in the business's records, including to check in-progress posts after reconnection. Disconnecting does not delete posts on TikTok. For data retained in Symbai, follow our deletion procedure or contact hello@symbai.app.
3.7 Facebook, Instagram and Meta Ads
Connecting an account is optional. When using the Symbai application connection, you authorize access on Meta's official page, then select the Facebook Page, linked Instagram account or advertising account for your brand in Symbai. We do not request or store your Facebook password or authentication codes. Availability depends on Meta approvals.
Within the permissions you grant, we process authorized account identifiers and names, access tokens, posts and media, comments, messages and sender information, available insights, and campaign settings, budgets and results. We use this information for the features you select: publishing, managing interactions and inboxes, reporting and managing advertising. Connecting alone does not start advertisements. If you enable an assistant for these features, the necessary content may also be processed by the AI providers described in this policy.
Tokens for the Symbai application connection are encrypted at rest. Access follows permissions in the selected business and brand. We send Meta the content, replies and settings you submit or authorize through Symbai features. Meta processes this information under its own terms and privacy policy. Imported data and resulting records are retained for the duration of the service and under the business's instructions, as explained in sections 2 and 7.
You can disconnect an account in Symbai or withdraw application access in Meta settings. Disconnection stops use of the connection; it does not automatically delete published Meta posts or every copy and record in Symbai. Follow our data deletion procedure to request deletion. Requests received through Meta receive a confirmation code and a status page. Completion is confirmed after connection data is processed and the relevant CRM copies, materials and exports have been reviewed. We may retain a minimal record of the request and access withdrawal to document resolution and prevent a revoked authorization from being reactivated.
4. Legal bases
- contract performance and pre-contractual steps — providing accounts, services, orders and requested offers;
- legal obligation — tax, accounting and record-keeping requirements;
- legitimate interests — security, fraud prevention, operational organization and product improvement;
- consent — where required for marketing, notifications or device permissions. Consent can be withdrawn without affecting prior lawful processing.
- biometric attendance verification — disabled by default; if enabled, the employer as controller must identify and communicate the applicable bases under GDPR Articles 6 and 9 and employment law. Symbai performs the comparison only under that controller’s instructions.
5. Recipients
TikTok receives data and content for the features you authorize, as explained in section 3.6.
We do not sell personal data. We may disclose it only as needed to:
- the business using Symbai, which controls its operational data;
- independent payment processors such as Viva.com for card transactions;
- OpenAI as a processor for the one-time selfie/profile-photo comparison, only when the business enables AI attendance verification;
- Google for the Google account functions you authorize, and Anthropic or OpenAI when you choose the corresponding assistant, as explained in section 3.5;
- hosting and IT infrastructure providers that protect and process data on our behalf;
- public authorities when disclosure is legally required.
6. Storage and international transfers
Symbai customer instances are logically isolated and hosted in the European Union. Some specialized services, including the optional AI provider used for attendance verification, may temporarily process data outside the European Economic Area. We use GDPR safeguards for these transfers, including data processing agreements and Standard Contractual Clauses.
7. Retention
- account and operational data — while the Customer uses the Service and as instructed by that controller;
- tax and accounting records — for the statutory period, generally up to ten years;
- website enquiry data — generally 24 months after the last interaction unless a contractual relationship begins;
- field location data — only as long as reasonably necessary for delivery evidence and operational analysis.
- attendance selfies and comparison results — with the corresponding attendance record for the period set by the employer and applicable law; images sent through the OpenAI API may be retained by that provider for up to 30 days under its standard configuration and are then deleted unless law requires otherwise.
When retention ends, data is securely deleted or anonymized.
8. Children
Our business applications are not directed to children. In Symbai Portal, a parent or guardian may add information about their own children through an optional family feature and confirms that they have the necessary authority.
9. Cookies and tracking
symbai.app uses technologies necessary for operation and security, plus a single first-party random identifier stored in your browser for the traffic measurement described in section 3.1 — with no personal data, no third parties and no tracking on other websites. We do not use advertising cookies on the website. The mobile applications do not use advertising identifiers to track you across other companies’ apps or websites.
10. Your GDPR rights
You may have the right to:
- access your data and obtain processing information;
- correct inaccurate data;
- request deletion or restriction;
- receive portable data in a structured format;
- object to processing based on legitimate interests;
- withdraw consent at any time;
- not be subject to solely automated decisions producing significant effects, where the GDPR applies.
Use the privacy or Legal & GDPR section in the application, visit our account and data deletion page, or email hello@symbai.app. We normally respond within 30 days. If another business is the controller, we will coordinate with it.
11. Security
We use measures such as HTTPS/TLS, authentication, role-based access, restricted database access, isolated customer instances and activity monitoring. Data sent through the AI provider’s API is not used for model training by default. Face verification supports manager review; the AI result is not the sole basis of a decision producing a significant effect.
12. Supervisory authority
You may lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), www.dataprotection.ro, or your competent EU supervisory authority.
13. Changes
We may update this policy. We publish the current version and date here and communicate material changes where required.
Data controller / provider
MP RIVERSIDE GROUP SRL · CUI 34152763
Str. Efta Botoca nr. 1, Timișoara, jud. Timiș, România
Contact: hello@symbai.app