symbolflow logo

SymbolFlow Privacy Policy

Effective Date: July 21, 2026

SymbolFlow Team (Operating as Individual Provider) (collectively, "we," "us," or "our"), as the operator of the SymbolFlow website, applications, APIs, SDKs, and related services (collectively, the "Platform" or "Services"), values and respects your privacy. During the interim period before our European operating entity (an Estonian OÜ) is incorporated, SymbolFlow Team (Operating as Individual Provider) acts as the Data Controller for your personal data collected directly through the Platform.

This Privacy Policy explains how we collect, use, disclose, store, and safeguard your personal information when you visit, register, log in, or use the Platform, as well as your statutory rights under the European Union General Data Protection Regulation (GDPR) and other applicable data protection laws.

Please read this Privacy Policy carefully. By choosing to use the Platform, you acknowledge our processing of your personal data as described herein. Agreement to our Terms of Service is unbundled from your acknowledgment of this Privacy Policy, and any consent requested for specific data processing activities is entirely voluntary and may be withdrawn at any time.

Table of Contents

I. Data Controller Identity and Contact Details
II. Personal Information We Collect, Processing Purposes, and Legal Bases (GDPR Art. 6)
III. Developer Data and Roles under GDPR (Controller vs. Processor)
IV. Cookies and Similar Technologies
V. Storage and Retention of Personal Information
VI. Data Sharing, Sub-Processors, and Third-Party Integrations
VII. International Data Transfers and EU Standard Contractual Clauses (SCCs)
VIII. Data Security Measures
IX. Your GDPR Data Subject Rights and How to Exercise Them
X. Right to Lodge a Complaint with a Supervisory Authority (GDPR Art. 77)
XI. Minors and Children's Privacy (GDPR Art. 8)
XII. Revisions and Notifications
XIII. Scope of Application and Contact Us


I. Data Controller Identity and Contact Details

During the interim period prior to the incorporation of our Estonian operating entity (planned within 2–3 months), the Data Controller responsible for processing your personal data collected directly via the Platform is:

  • Data Controller: SymbolFlow Team (Operating as Individual Provider)
  • Geographic Location / Country of Origin: Guangzhou, People's Republic of China (Non-EEA jurisdiction)
  • Privacy & Support Email: [[email protected]]
  • Official Website: https://symbolflow.com

Note pursuant to GDPR Article 13(1)(a): As the Data Controller is currently located outside the European Economic Area (EEA), international data transfers from EEA/UK users to the Data Controller are executed subject to the EU Standard Contractual Clauses (SCCs) and technical safeguards detailed in Section VII. Upon the formal incorporation of our Estonian operating company (Estonian OÜ, an EU entity within the EEA), data controller operations for European and global users will transfer to the Estonian entity, and you will be notified of updated contact details in accordance with Section XII.


II. Personal Information We Collect, Processing Purposes, and Legal Bases (GDPR Art. 6)

We process personal data only when we have a valid legal basis under GDPR Article 6(1). Personal data refers to any information relating to an identified or identifiable natural person ("Data Subject").

1. Information We Collect Directly from You
  • Account Registration & Authentication

    • Types of Personal Data Collected: Email address, nickname, avatar, account ID, mobile number (if provided), authentication credentials.
    • Processing Purpose: Creating and managing your account, providing access to Platform services, verifying user identity.
    • Legal Basis under GDPR Art. 6(1): Performance of Contract (Art. 6(1)(b)).
  • Service Usage & AI Model Inputs

    • Types of Personal Data Collected: Text inputs, instructions, dataset uploads, workflow parameters, uploaded images/media.
    • Processing Purpose: Processing AI workflow requests, generating outputs, delivering platform features.
    • Legal Basis under GDPR Art. 6(1): Performance of Contract (Art. 6(1)(b)).
  • System Security & Operation

    • Types of Personal Data Collected: IP address, browser type and version, operating system, time zone, device model, system logs, crash logs.
    • Processing Purpose: Maintaining service security, detecting cyberattacks, troubleshooting system errors, ensuring operational stability.
    • Legal Basis under GDPR Art. 6(1): Legitimate Interests (Art. 6(1)(f)) (maintaining platform security and performance).
  • Customer Support & Consultation

    • Types of Personal Data Collected: Communication records, support tickets, feedback forms, user inquiry logs.
    • Processing Purpose: Responding to user inquiries, resolving technical issues, improving service quality.
    • Legal Basis under GDPR Art. 6(1): Performance of Contract (Art. 6(1)(b)) / Legitimate Interests (Art. 6(1)(f)).
  • Service Notifications & Communication

    • Types of Personal Data Collected: Email address, notification preferences.
    • Processing Purpose: Sending essential service updates, security alerts, and system notices.
    • Legal Basis under GDPR Art. 6(1): Performance of Contract (Art. 6(1)(b)).
  • Promotional & Marketing Messages

    • Types of Personal Data Collected: Email address.
    • Processing Purpose: Sending newsletters, feature updates, or product announcements (optional).
    • Legal Basis under GDPR Art. 6(1): Consent (Art. 6(1)(a)) (Can be withdrawn at any time via unsubscribe link).
  • Legal Compliance & Record Keeping

    • Types of Personal Data Collected: Transaction history, invoice details, consent records, legal correspondence.
    • Processing Purpose: Complying with statutory record-keeping, tax laws, and legal obligations.
    • Legal Basis under GDPR Art. 6(1): Compliance with Legal Obligation (Art. 6(1)(c)).
2. Information Received from Third Parties

When you log in or authenticate through third-party providers (e.g., OAuth providers such as GitHub or Google), we receive basic profile information (such as your email address, name, and profile picture) as authorized by you with that third party.

  • Legal Basis: Performance of Contract (Art. 6(1)(b)) or Consent (Art. 6(1)(a)).
3. Purpose Limitation

We do not process your personal data for purposes incompatible with those disclosed above. We do not use your proprietary workflow inputs, datasets, or personal data to train publicly accessible AI models without your explicit consent.


III. Developer Data and Roles under GDPR (Controller vs. Processor)

  1. Developer Data Defined. "Developer Data" refers to datasets, database configurations, plugin/API credentials, audio/video files, and End User data uploaded or processed by developers when building or operating intelligent workflows, applications, or static sites on the Platform.
  2. Customer as Controller. When you build applications or workflows on our Platform that collect or process personal data of third parties or your End Users, you act as the Data Controller and SymbolFlow Team acts as the Data Processor under GDPR Article 28.
  3. Data Processing Addendum (DPA). As a Data Processor, our processing of End User personal data on your behalf is governed strictly by the SymbolFlow Data Processing Addendum (DPA) attached as Annex B to our Terms of Service. We process such data solely on your documented instructions and implement appropriate technical and organizational security measures.
  4. Developer Responsibilities. As Data Controller, you are responsible for establishing a valid legal basis (such as consent or contract) with your End Users, providing them with your own privacy policy, and fulfilling Data Subject requests in accordance with GDPR.

IV. Cookies and Similar Technologies

We use Cookies, local storage, and similar technologies to ensure core service functionality and enhance your user experience.

  1. Strictly Necessary Cookies: Essential for platform navigation, user authentication, session security, and account login.
    • Legal Basis: Performance of Contract (GDPR Art. 6(1)(b)) / Legitimate Interests (Art. 6(1)(f)).
  2. Functional & Performance Cookies: Help us remember your preference settings (e.g., language preference, UI theme) and analyze aggregated platform performance.
    • Legal Basis: Consent (GDPR Art. 6(1)(a)).
  3. Managing Cookies: You can manage or disable Cookies through your web browser settings. Please note that disabling strictly necessary Cookies may impact your ability to log in or use core platform features.

V. Storage and Retention of Personal Information

  1. Retention Principles: We retain your personal data only for as long as necessary to fulfill the processing purposes outlined in Section II, including satisfying service delivery, security, legal, accounting, or reporting obligations.
  2. Retention Criteria:
    • Active Account Data: Retained for the duration of your active account subscription.
    • Security & Network Logs: Retained for a period of 90 days to 12 months for security auditing and threat detection.
    • Financial & Legal Records: Retained for the statutory period required by applicable tax and commercial laws.
  3. Deletion & Anonymization: Upon expiration of the applicable retention period, or upon a valid request for erasure under GDPR Article 17, we will securely delete or anonymize your personal data, ensuring it can no longer identify you.

VI. Data Sharing, Sub-Processors, and Third-Party Integrations

We do not sell your personal data to third parties. We share personal data only with trusted partners and service providers under strict data protection agreements in the following circumstances:

  1. Approved Sub-Processors & Service Providers:
    • Cloud Infrastructure & Storage: Amazon Web Services (AWS EU regions), Cloudflare, Inc. (Edge CDN, DDoS protection, security DNS).
    • Payment Processors: Third-party payment gateways (e.g., Stripe, PayPal) for processing subscription transactions securely.
    • Email Delivery: Transactional email service providers for sending account verification and system notifications.
  2. Legal & Regulatory Disclosures: We may disclose personal data to law enforcement, judicial authorities, or regulatory bodies if required by mandatory law, court order, or to protect the life, safety, or legal rights of SymbolFlow, our users, or the public.
  3. Corporate Reorganization: In the event of a merger, acquisition, corporate restructuring, or transfer of operating assets (such as transitioning operations to our Estonian OÜ entity), your personal data will be transferred under equivalent security standards, with prior notice provided to you.

VII. International Data Transfers and EU Standard Contractual Clauses (SCCs)

During the interim period where SymbolFlow Team operates as an Individual Provider, personal data of users in the European Economic Area (EEA), European Union (EU), or United Kingdom (UK) may be processed on secure servers located outside the EEA.

  1. Transfer Safeguards: Where personal data of EU/EEA residents is transferred to countries outside the EEA that do not possess an adequacy decision from the European Commission, we ensure appropriate data protection safeguards are implemented pursuant to GDPR Chapter V.
  2. Standard Contractual Clauses (SCCs): Transfers are executed in accordance with the EU Standard Contractual Clauses approved by European Commission Decision (EU) 2021/914 (Module 2 Controller-to-Processor and Module 3 Processor-to-Processor), incorporated directly into Annex B of our Terms of Service.
  3. Supplementary Technical Measures: International transfers are protected by strong technical encryption (TLS 1.3 in transit, AES-256 at rest) and strict access controls.

VIII. Data Security Measures

We implement comprehensive technical and organizational security measures to protect personal data against accidental loss, unauthorized access, alteration, or disclosure in accordance with GDPR Article 32:

  1. Encryption: End-to-end encryption for data in transit (TLS 1.3) and robust encryption for data at rest (AES-256).
  2. Access Controls: Strict role-based access controls (RBAC) ensuring only authorized personnel with a clear business need can access personal data under binding confidentiality obligations.
  3. System Audits & Incident Response: Continuous vulnerability scanning, logging, and an established Personal Data Breach notification procedure designed to notify affected users and supervisory authorities within 48 to 72 hours of breach confirmation where required by GDPR Article 33/34.

IX. Your GDPR Data Subject Rights and How to Exercise Them

Under the GDPR (Articles 15–22), if you reside in the EU/EEA or UK, you have the following statutory rights regarding your personal data:

  1. Right of Access (Art. 15): You have the right to request confirmation as to whether we process your personal data and to obtain a copy of your personal data held by us.
  2. Right to Rectification (Art. 16): You have the right to request the correction of inaccurate or incomplete personal data.
  3. Right to Erasure / "Right to be Forgotten" (Art. 17): You have the right to request the deletion of your personal data when it is no longer necessary for the purposes for which it was collected, or when you withdraw consent and no other legal basis applies.
  4. Right to Restriction of Processing (Art. 18): You have the right to restrict our processing of your personal data under certain conditions (e.g., while the accuracy of data is being contested).
  5. Right to Data Portability (Art. 20): You have the right to receive your personal data provided to us in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.
  6. Right to Object (Art. 21): You have the right to object to processing based on legitimate interests (Art. 6(1)(f)) or direct marketing at any time.
  7. Right to Withdraw Consent (Art. 7(3)): Where processing is based on consent, you have the right to withdraw your consent at any time without affecting the lawfulness of processing prior to withdrawal.
How to Exercise Your Rights

To exercise any of your GDPR rights, please submit your request to us at [[email protected]]. We may verify your identity before fulfilling your request. We will respond to your request without undue delay and within one month (30 days) of receipt, extending by up to two additional months only in complex cases with prior notice.


X. Right to Lodge a Complaint with a Supervisory Authority (GDPR Art. 77)

In accordance with GDPR Article 77, if you are located in the EU/EEA or UK and believe that our processing of your personal data infringes applicable data protection laws, you have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, place of work, or place of the alleged infringement.


XI. Minors and Children's Privacy (GDPR Art. 8)

The Platform and Services are intended for adults and business developers aged 18 and above (or 16 where permitted by local law). We do not knowingly collect or solicit personal data from children under 16 without verifiable parental/guardian consent. If we become aware that we have collected personal data from a child under 16 without proper consent, we will take immediate steps to delete such data from our servers.


XII. Revisions and Notifications

We may update this Privacy Policy from time to time to reflect changes in our services, legal requirements, or corporate structure (such as the incorporation of our Estonian operating company). We will notify you of any material changes by posting the updated Privacy Policy on the Platform, updating the "Effective Date" at the top, and providing prominent notice (via email or platform notification) prior to the changes taking effect.


XIII. Scope of Application and Contact Us

This Privacy Policy applies to the SymbolFlow Platform, websites, client tools, and related technical services. It does not apply to third-party websites or services linked from our Platform that maintain independent privacy policies.

If you have any questions, comments, or requests regarding this Privacy Policy or our data protection practices, please contact us at:

  • Entity: SymbolFlow Team (Operating as Individual Provider)
  • Privacy Email: [[email protected]]