Legal

Version 1.0 · Last updated: July 20, 2026

Privacy Policy

Symbioen is committed to protecting personal data. This policy explains what we collect, how we use it, and your rights under the General Data Protection Regulation (GDPR) and applicable data protection laws.

1. Who we are

The data controller is SIA symbioen, a Latvian limited liability company registered under unified registration number 40203754396. Symbioen provides independent EV charging infrastructure data intelligence, benchmarking, and audit services in European markets. For questions about this policy or our use of personal data, contact us at hello@symbioen.com.


2. Infrastructure data and personal data

Most data analysed by Symbioen relates to EV charging infrastructure, locations, operators, availability, status, utilization indicators, session-success signals, and performance metrics. This is generally not personal data.

We do not intentionally collect personal driver data, vehicle-side data, or individual EV user behaviour for the current Service. If that changes, we will update this policy before using that data in a materially different way.


3. Personal data we collect

We collect the following categories of personal data:

  • Contact details - name, email address, company, role, and similar business contact information.
  • Requests and communications - demo requests, report requests, audit inquiries, support messages, and other information you send to us.
  • Account and login data - email address, authentication identifiers, account settings, and access permissions if you use a dashboard or protected service.
  • Monitoring preferences - stations, operators, regions, reports, notification settings, and subscription choices you configure.
  • Billing and business records - invoice details, purchase history, order forms, and payment status where you buy reports, audits, subscriptions, or data access.
  • Usage and analytics data - pages visited, features used, device/browser information, approximate location from IP address, and interaction events collected through analytics and performance tools.
  • Marketing preferences - newsletter, event, outreach, or product-update preferences if you opt in or interact with our business communications.

We do not intentionally collect sensitive personal data such as health, biometric, precise location, or special-category data.


4. How we use personal data

We use your data to:

  • Respond to inquiries, demo requests, report requests, and support messages.
  • Provide, maintain, and improve the website, dashboard, monitoring, reports, audits, and data services.
  • Manage accounts, access permissions, subscriptions, notifications, and transactional emails.
  • Prepare proposals, order forms, invoices, customer records, and audit or report deliveries.
  • Send newsletters, product updates, or B2B outreach where permitted by law.
  • Understand website and product usage, improve performance, and measure marketing effectiveness.
  • Protect the security, integrity, and availability of the Service and prevent abuse.
  • Comply with legal, tax, accounting, and regulatory obligations.

We do not sell your personal data to third parties. We do not use your data for automated decision-making or profiling that produces legal effects.


5. Legal basis for processing

We process your data on the following legal grounds under GDPR Article 6:

  • Contract - to provide paid reports, audits, dashboard access, monitoring, data access, or other services you sign up for.
  • Pre-contractual steps - to respond to demo, audit, proposal, or report requests before a contract is signed.
  • Legitimate interests - B2B outreach, responding to business inquiries, website analytics, product improvement, security, fraud prevention, and internal administration, provided your rights do not override those interests.
  • Consent - for optional communications and marketing emails, which you can withdraw at any time.
  • Legal obligation - tax, accounting, compliance, and other records where required by applicable law.

6. Data retention

We retain personal data only as long as necessary for the purposes described in this policy, including providing services, handling inquiries, maintaining business records, complying with legal obligations, and resolving disputes.

  • Inquiry and contact data is normally retained for up to 24 months after the last interaction.
  • Account and customer data is retained while the account or customer relationship is active.
  • Monitoring preferences are deleted or anonymized within a reasonable period after unsubscribe or account closure unless we need them for records or security.
  • Accounting, invoice, tax, and contract records are retained for the period required by applicable law.
  • Analytics data is retained according to the settings of the analytics provider and our internal retention configuration.

You may request deletion of your data at any time, subject to legal retention requirements and other permitted grounds for continued processing.


7. Service providers and subprocessors

We share personal data with service providers that help us operate the Service. These may include hosting, cloud database, authentication, analytics, performance, email, CRM/form, payment, accounting, security, and customer-support providers.

Current core and user-facing providers include:

  • Supabase - authentication and database storage (EU region).
  • Vercel - hosting, edge infrastructure, analytics, and performance insights.
  • Resend - transactional email delivery.
  • Web3Forms - processing website contact and report-request forms.
  • Google - optional Google account sign-in when you choose that method.
  • OpenStreetMap and CARTO - map tiles and basemap content; these providers may receive IP address, device, and request information when a map loads.

Where personal data is transferred outside the EEA, we use appropriate safeguards where required, such as adequacy decisions, standard contractual clauses, or other lawful transfer mechanisms. You may contact us at hello@symbioen.com for information about the safeguards relevant to your data and how to obtain a copy.


8. Your rights

Under GDPR you have the right to:

  • Access the personal data we hold about you.
  • Rectification of inaccurate or incomplete data.
  • Erasure ("right to be forgotten") of your data.
  • Restriction of processing in certain circumstances.
  • Data portability in a structured, machine-readable format.
  • Object to processing based on legitimate interests.
  • Withdraw consent at any time without affecting prior processing.

To exercise any of these rights, email us at hello@symbioen.com. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection supervisory authority. In Latvia, this is the Data State Inspectorate at dvi.gov.lv.


9. Cookies and analytics

We may use cookies and similar technologies for website functionality, authentication, security, analytics, performance measurement, and service improvement. Maps and other externally hosted resources may also transmit your IP address and request information to their providers when loaded. You can disable non-essential cookies in your browser settings. If we introduce marketing or tracking cookies that require consent in your jurisdiction, we will request consent before using them.


10. Changes to this policy

We may update this policy from time to time. Material changes will be communicated by email or by a prominent notice on the platform. The date at the top of this page reflects the most recent revision.