Legal
Privacy Policy and Data Processing Notice
Last updated: January 15, 2026
This page is maintained by Symbiosis Advisory LLC ("Symbiosis") to describe how the Symbiosis GRC Command Center ("the Service") handles data. It applies to customers, their authorized users, and visitors to this site. This document is not a certification and does not create any independent third-party attestation.
1. Who we are
Symbiosis Advisory LLC operates the Service at grc.symbiosis-llc.com. Contact: privacy@symbiosis-llc.com.
2. What data we collect
- Account data: name, work email, organization, and role.
- Compliance content you enter: control statuses, notes, evidence artifacts, system inventory, risk assessments, and reports.
- Uploaded files (evidence, logos): stored in isolated, per-organization storage buckets.
- Operational logs: sign-in events, error traces, and product usage metadata used to keep the Service reliable and secure.
- Billing data: handled by our payment processor (see subprocessors).
3. How we use your data
- Provide the Service, including cross-framework crosswalk and report generation.
- Authenticate users and enforce role-based access within your organization.
- Detect and mitigate abuse, fraud, and security incidents.
- Provide support and communicate service-related notices.
- Meet legal, tax, and regulatory obligations.
We do not sell your data. We do not use customer content to train third-party AI models. AI features (when enabled) operate on redacted content strictly to fulfill the requested task.
4. Legal bases (for EU/UK users)
- Performance of a contract: to deliver the Service you signed up for.
- Legitimate interests: security, fraud prevention, and product improvement.
- Consent: for optional communications and cookies where required.
- Legal obligation: to comply with applicable laws.
5. Subprocessors
Symbiosis relies on the following processors to operate the Service:
- Supabase (Amazon Web Services, US regions): managed database, authentication, and file storage.
- Cloudflare: application delivery, DDoS protection, and edge compute for the web application.
- Stripe: payment processing and subscription billing.
- Resend / Postmark class provider: transactional email delivery.
An up-to-date subprocessor list is available on request via privacy@symbiosis-llc.com.
6. International transfers
Customer data is primarily processed in the United States. Where personal data of EU/UK/Swiss data subjects is transferred, we rely on Standard Contractual Clauses (SCCs) with our subprocessors and apply supplementary technical measures including encryption in transit (TLS 1.2+) and at rest.
7. Retention
- Customer content and evidence: kept for the life of your subscription.
- After termination: exported on request within 30 days, then deleted within 60 days from live systems and within 90 days from backups.
- Billing records: retained for 7 years to meet tax and accounting obligations.
- Security logs: retained for 12 months.
8. Your rights
Depending on your jurisdiction (GDPR, UK GDPR, CCPA/CPRA and similar), you may have rights to access, correct, export, delete, restrict, or object to processing of your personal data. To exercise a right, contact privacy@symbiosis-llc.com. We will respond within 30 days.
9. Data processing addendum
Customers acting as data controllers can request a signed Data Processing Addendum (DPA) that incorporates the EU SCCs and UK IDTA. Request it from the Compliance page.
10. Security
Symbiosis applies role-based access control, per-organization data isolation via row-level security, encryption in transit and at rest, least-privilege service credentials, and continuous vulnerability scanning. Report suspected vulnerabilities to security@symbiosis-llc.com.
11. Changes to this notice
We will post material changes to this page and, where required, notify customers by email at least 15 days in advance.