Privacy notice
SYMBOT LTD · LEGAL
Privacy, precisely scoped.
A clear account of the limited personal data SYMBOT LTD handles through sym.bot and its business relationships.
- Status
- Current
- Applies to
- The sym.bot website, enquiries, business contacts, support and enterprise evaluation relationships. Each SYM.BOT product has its own privacy notice.
- Updated
- 27 July 2026
This notice explains how SYMBOT LTD processes personal data as controller under UK data-protection law. It is deliberately scoped: it does not replace the privacy notice for a consumer application or a customer's own responsibilities when deploying software.
Product privacy
1. Controller and contact
The controller is SYMBOT LTD, trading as SYM.BOT, registered in Scotland under company number SC856218.
Contact: [email protected].
2. What we do — and do not — process
Customer data boundary
SYMBOT LTD does not collect or store customer operational data through sym.bot or merely because someone uses our open-source software. This includes prompts, agent conversations, mesh traffic, model state, credentials, source files, customer datasets and business-system records.
Current position · 27 July 2026
SYMBOT LTD has not received a customer email, support request, customer account record or customer product data. It therefore holds none of those categories.
The table distinguishes routine website infrastructure data from administrative information we would process only if someone later contacts us:
A person's name or work email address is personal data in law, but it is not customer operational data.
| Data and source | Purpose | Lawful basis |
|---|---|---|
| Technical and security data generated when you visit sym.bot, such as IP address, browser, request time and error or security events | Deliver, secure, diagnose and maintain the website | Legitimate interests in operating a secure public website |
| If you contact us: name, work contact details, organisation, role and message you provide in an enquiry or business conversation | Respond, assess fit, arrange discussions and manage relationships | Steps at your request before a contract; legitimate interests in developing and managing our business |
| If submitted: support, vulnerability, IP or legal correspondence and related records | Resolve reports, protect systems and rights, and meet legal duties | Contract, legal obligation, and legitimate interests in security and legal administration |
| If an evaluation or contract begins: business contact details and administration records | Administer an evaluation or commercial relationship | Contract and legitimate interests in delivering and securing it |
If we ask for consent for a specific optional purpose, consent will be the lawful basis for that purpose and you may withdraw it at any time.
Our standard enterprise model keeps work inside a customer-controlled environment and does not require customer operational data to be transferred to or stored by SYMBOT LTD. Do not send customer datasets, credentials, production records or confidential source files by email. Use synthetic or redacted material for discussions and evaluations.
3. Who receives personal data
We disclose personal data only as needed to organisations that help us operate: website hosting and content-delivery providers, email and collaboration providers, professional advisers, and security or support providers. They may act as processors under contract or as independent controllers for their own services.
We do not provide customer operational data to these providers because SYMBOT LTD does not collect or store that data.
This website currently requests font resources from Google Fonts and jsDelivr. Those providers may receive ordinary request data such as your IP address and browser information. Links to other websites are governed by their own privacy notices.
We may also disclose data where required by law, to protect rights or security, or in connection with a genuine corporate transaction. We do not sell personal data.
4. International transfers
Some providers may process data outside the United Kingdom. Where UK law requires a transfer safeguard, we use an applicable adequacy regulation, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or another lawful safeguard. Contact us for information about the safeguard relevant to your data.
5. Retention
We keep personal data only for as long as needed for its purpose, taking account of relationship status, security needs, legal duties and limitation periods.
- If received, business enquiries are normally kept for up to 24 months after the last substantive contact, unless a relationship continues or a legal need requires longer.
- If created, contract, security, IP and legal records are kept for the period needed to perform the relationship, establish or defend claims, and meet legal obligations.
- Technical logs are kept for the shortest period configured as reasonably necessary for security, diagnostics and reliable operation.
We delete or anonymise data when it is no longer needed, unless the law requires retention.
Customer operational data is not subject to a SYMBOT LTD retention period because we do not collect or store it.
6. Your rights
Depending on the circumstances, you may have the right to ask us for access to your personal data, correction, erasure, restriction, data portability, or to object to processing. Where processing relies on consent, you may withdraw consent without affecting earlier lawful processing.
To exercise a right, email [email protected]. We may need to verify your identity. You may complain to the UK Information Commissioner's Office, and may also have a right to complain to another local supervisory authority.
7. Automated decisions
SYMBOT LTD does not use personal data collected through sym.bot to make solely automated decisions that produce legal or similarly significant effects about you.
8. Cookies and local storage
sym.bot does not currently use advertising or behavioural-analytics cookies. Hosting infrastructure may use strictly necessary technologies for security, routing or reliable delivery. If we introduce non-essential cookies or similar storage, we will provide the information and consent controls required by law before using them.
9. Open-source mesh software
Using SYM.BOT open-source software does not, by itself, send personal data to SYMBOT LTD. Data roles and flows depend on how an organisation or individual deploys and configures the software. The deployer must identify its own responsibilities and provide any required privacy information.
A customer deployment remains under the customer's operational control. SYMBOT LTD does not receive or retain its prompts, agent exchanges, model state, credentials, files or business-system content.
10. Children
sym.bot is a company website and is not directed to children. A consumer product's own notice explains any age restrictions and child-specific processing relevant to that product.
11. Security and changes
We use technical and organisational measures appropriate to the nature and risk of the data. No system is completely secure.
We may update this notice as our operations or legal obligations change. The date above identifies the current version. Material changes will be highlighted where appropriate.