Legal

GDPR Privacy Notice for symbiontek.com

How SymBionTek handles your personal data: scope, retention, your rights.

1. Controller

Controller within the meaning of GDPR:
SymBionTek · Dipl.-Math. (FH) Andreas O. Schwan
Godelsberg 11a, 63739 Aschaffenburg
[email protected]

2. Server log files

Our hosting provider (webgo GmbH) automatically collects technical access data: IP address, browser type, operating system, referrer URL, time of request. Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in stable and secure operation). Data is deleted after a maximum of 7 days.

3. Contact form

When you contact us via the form, the data you provide (name, company, email, subject, message) is processed solely to handle your request. Legal basis: Art. 6 (1) (a) and (b) GDPR. Data is deleted as soon as the request has been finally resolved, unless statutory retention periods apply.

4. Cloudflare

This site uses Cloudflare (Cloudflare Inc., 101 Townsend St, San Francisco, CA 94107, USA) as a reverse proxy and CDN. Cloudflare processes connection metadata for security and performance. Standard contractual clauses are in place. More: cloudflare.com/privacypolicy.

5. Web fonts (Google)

For typographic display, this site loads web fonts from Google Fonts (Google Ireland Ltd.). Your browser establishes a connection to Google servers, transmitting your IP address. Legal basis: Art. 6 (1) (f) GDPR.

6. Hub login + Stripe payments

The SymBionTek Hub uses passwordless email magic-link login (Symfony Security entity provider). Your email address is stored to match purchases to your account; the login token expires after 30 minutes. Payments run via Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Dublin, Ireland. SymBionTek does not see your card data; Stripe transmits a transaction reference and the line items. Legal basis: Art. 6 (1) (b) GDPR (contract performance). Retention: per German tax law (HGB §257), invoice-relevant data is kept for 10 years.

7. Live AI tools (OpenAI, Anthropic)

When you run a Hub live tool (EU AI Act Classifier, MaRisk Gap Analyzer, Data Quality Scanner, LLM Comparison) or use the AI Battle Arena or Andreas-Bot, the input you submit is sent to either OpenAI Ireland Ltd. or Anthropic PBC for inference. The providers process the request transiently and, per their published policies, do not use API inputs for model training. SymBionTek does not store the inputs beyond the immediate response cycle. Do not paste real production banking data; use synthetic samples. Legal basis: Art. 6 (1) (b) and (f) GDPR.

8. Cookies + session storage

symbiontek.com sets only one technically necessary session cookie (PHPSESSID) used for CSRF protection, login state, and per-session rate limiting on the Battle and Bot APIs. No analytics, no tracking, no third-party advertising cookies. Legal basis: Art. 6 (1) (f) GDPR and § 25 (2) (2) TTDSG (strictly necessary).

9. Your rights

You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), objection (Art. 21) and the right to lodge a complaint with a supervisory authority. The competent authority for SymBionTek is the Bayerisches Landesamt für Datenschutzaufsicht (Promenade 18, 91522 Ansbach).

10. Contact for data protection requests

For all data protection inquiries, write to [email protected]. Replies within 30 days, usually faster.

Last updated: 04.08.2026