Privacy Policy
Last updated: July 14, 2026
Versiunea în română1. Who we are
This policy explains how MP RIVERSIDE GROUP SRL (Romanian tax ID 34152763, Str. Efta Botoca nr. 1, Timișoara, România), referred to as “Symbai”, “we” or “us”, processes personal data under Regulation (EU) 2016/679 (“GDPR”) and applicable Romanian law, including Law 190/2018.
It covers symbai.app and the Symbai POS, Symbai Staff and Symbai Portal applications. Privacy questions may be sent to hello@symbai.app.
2. Our roles as controller and processor
- Controller: for information collected directly by us, such as website enquiries, commercial communication, subscription administration and our own billing.
- Processor: for operational data entered by a business using Symbai, such as your employer or a merchant. That business is the controller; we process the data under its instructions and a data processing agreement.
You may contact the relevant business or us to exercise your rights. When necessary, we forward the request to the controller.
3. Data we process and why
3.1 Website
Contact and demo forms may collect your name, company, phone number, email address and message. We use them to respond and prepare an offer. The legal bases are pre-contractual steps requested by you and our legitimate interest in answering enquiries. The website uses only technologies necessary for operation and security.
3.2 Symbai POS
On behalf of the employer or business using Symbai, the professional POS application may process:
- account data: user or employee ID, name, email, phone number, PIN, role and work location;
- customer or business tax and billing details entered for requested records, such as address, Romanian personal or company tax identifiers and other required invoice identifiers;
- operational data: shifts, attendance, work notes, processed orders, purchase history and cash or card transactions;
- technical and security data: IP address, app-generated device identifier, device type and activity logs.
The camera is used when requested for product, operational or room-code scanning and, when the user chooses, for chat photos or HACCP evidence. The photo library is accessed only after the user selects a photo. Local network access connects the app to the venue’s edge server.
3.3 Symbai Staff
For field, delivery and production workflows, the application may additionally process:
- precise foreground location for sales-visit check-ins, attendance records, nearby-customer suggestions and delivery-route operations;
- precise background location only during an active delivery shift or route, so authorized dispatchers can follow route progress and stops. Background tracking begins only after permission is granted and stops when the active route or shift ends;
- images or videos you select for work conversations, plus photos you capture or select, notes and signatures you provide as delivery, receiving or work evidence;
- when the employer enables attendance identity verification, the attendance selfie and profile photo are compared once to create biometric data: a similarity result and score. In AI mode, the images are securely sent to our AI provider, OpenAI, only for that comparison. Unclear or mismatched results are reviewed by a manager and do not by themselves produce a decision with a significant legal effect;
- customer, order and physical delivery-address data required for assigned work, plus sales or CRM activity entered by you;
- operational financial information required for assigned work, such as cash collected or handed over, fuel expenses and B2B balances or debts;
- an app-generated device identifier used to associate an authorized device with shifts and operational sync and, when configured, weights received through Bluetooth from a compatible scale.
You can revoke camera, photo, Bluetooth or location access in device settings. Some corresponding functions will then be unavailable.
3.4 Symbai Portal
On behalf of the merchant, the customer application may process:
- name, email, phone number, preferences and privacy settings;
- orders, bookings, loyalty points, reviews, chat messages and badges;
- a notification token required for push notifications;
- optional family information entered by a parent or guardian who confirms they have authority to provide it.
Marketing messages are sent only when the applicable consent has been given and can be disabled at any time.
4. Legal bases
- contract performance and pre-contractual steps — providing accounts, services, orders and requested offers;
- legal obligation — tax, accounting and record-keeping requirements;
- legitimate interests — security, fraud prevention, operational organization and product improvement;
- consent — where required for marketing, notifications or device permissions. Consent can be withdrawn without affecting prior lawful processing.
- biometric attendance verification — disabled by default; if enabled, the employer as controller must identify and communicate the applicable bases under GDPR Articles 6 and 9 and employment law. Symbai performs the comparison only under that controller’s instructions.
5. Recipients
We do not sell personal data. We may disclose it only as needed to:
- the business using Symbai, which controls its operational data;
- independent payment processors such as Viva.com for card transactions;
- OpenAI as a processor for the one-time selfie/profile-photo comparison, only when the business enables AI attendance verification;
- hosting and IT infrastructure providers that protect and process data on our behalf;
- public authorities when disclosure is legally required.
6. Storage and international transfers
Symbai customer instances are logically isolated and hosted in the European Union. Some specialized services, including the optional AI provider used for attendance verification, may temporarily process data outside the European Economic Area. We use GDPR safeguards for these transfers, including data processing agreements and Standard Contractual Clauses.
7. Retention
- account and operational data — while the Customer uses the Service and as instructed by that controller;
- tax and accounting records — for the statutory period, generally up to ten years;
- website enquiry data — generally 24 months after the last interaction unless a contractual relationship begins;
- field location data — only as long as reasonably necessary for delivery evidence and operational analysis.
- attendance selfies and comparison results — with the corresponding attendance record for the period set by the employer and applicable law; images sent through the OpenAI API may be retained by that provider for up to 30 days under its standard configuration and are then deleted unless law requires otherwise.
When retention ends, data is securely deleted or anonymized.
8. Children
Our business applications are not directed to children. In Symbai Portal, a parent or guardian may add information about their own children through an optional family feature and confirms that they have the necessary authority.
9. Cookies and tracking
symbai.app uses only technologies necessary for operation and security. We do not use advertising cookies on the website. The mobile applications do not use advertising identifiers to track you across other companies’ apps or websites.
10. Your GDPR rights
You may have the right to:
- access your data and obtain processing information;
- correct inaccurate data;
- request deletion or restriction;
- receive portable data in a structured format;
- object to processing based on legitimate interests;
- withdraw consent at any time;
- not be subject to solely automated decisions producing significant effects, where the GDPR applies.
Use the privacy or Legal & GDPR section in the application, visit our account and data deletion page, or email hello@symbai.app. We normally respond within 30 days. If another business is the controller, we will coordinate with it.
11. Security
We use measures such as HTTPS/TLS, authentication, role-based access, restricted database access, isolated customer instances and activity monitoring. Data sent through the AI provider’s API is not used for model training by default. Face verification supports manager review; the AI result is not the sole basis of a decision producing a significant effect.
12. Supervisory authority
You may lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), www.dataprotection.ro, or your competent EU supervisory authority.
13. Changes
We may update this policy. We publish the current version and date here and communicate material changes where required.
Data controller / provider
MP RIVERSIDE GROUP SRL · CUI 34152763
Str. Efta Botoca nr. 1, Timișoara, jud. Timiș, România
Contact: hello@symbai.app