This Privacy Policy explains how Symbionix SL (Sociedad Limitada), tax ID (CIF) B-22937023, registered office at Carrer de Pere IV 182, 08005 Barcelona, Spain ("AirStrings", "we", "us"), collects and processes personal data in connection with the AirStrings service and website (airstrings.com) (the "Service").
We are established in the European Union and process personal data in accordance with Regulation (EU) 2016/679 ("GDPR") and Spanish data-protection law (LOPDGDD, Ley Orgánica 3/2018). Our lead supervisory authority is the Agencia Española de Protección de Datos (AEPD).
1. Our two roles: controller and processor
AirStrings acts in two capacities:
- As a controller — for personal data about our customers and their users that we determine the purposes of: account, authentication, billing, support, security, and marketing data. This Privacy Policy covers that processing.
- As a processor — for personal data our customers choose to put into the Service as Customer Content (strings, locales, project data) or that flows through the Service on the customer's behalf. For that processing, the customer is the controller (or acts on behalf of its own controller), and our obligations are set out in our Data Processing Agreement, not in this Policy.
The Service is designed for application strings and localization data, not for personal data. We ask customers not to include personal data in Customer Content unless strictly necessary.
2. Personal data we process (as controller)
| Category | Examples | Source |
|---|---|---|
| Account & identity | Name, work email, organization name, password (hashed), role | You, at signup |
| Authentication & security | API key metadata (keys are stored hashed), session and refresh tokens, IP address, device/browser info, security logs, correlation IDs | Automatically, on use |
| Billing | Plan, billing contact, VAT/tax ID, country, transaction and invoice records; card data is handled by our payment processor and not stored by us | You / our payment processor |
| Usage & product analytics | Feature usage, request metadata, aggregated and where possible anonymized telemetry, error/diagnostic data | Automatically, on use |
| Support & communications | Emails and messages you send us, support-ticket content | You |
| Marketing | Email address and preferences for our newsletter/waitlist, marketing engagement | You (opt-in) |
We do not intentionally collect special categories of personal data (Art. 9 GDPR) as controller, and ask that you do not send them to us.
3. Why we process it and on what legal basis
We rely on the following legal bases under Article 6(1) GDPR:
| Purpose | Legal basis |
|---|---|
| Provide, operate, and secure the Service; manage your account and authenticate you | Contract — Art. 6(1)(b) |
| Process payments, invoicing, and collect fees | Contract — Art. 6(1)(b); legal obligation — Art. 6(1)(c) (tax/accounting) |
| Keep the Service secure, prevent fraud and abuse, maintain logs, ensure signed-bundle integrity | Legitimate interests — Art. 6(1)(f) (securing our and customers' systems) |
| Product analytics and improving the Service using aggregated/anonymized data | Legitimate interests — Art. 6(1)(f) |
| Comply with legal, tax, and accounting obligations and respond to lawful requests | Legal obligation — Art. 6(1)(c) |
| Send transactional/service emails (e.g. security, billing, account notices) | Contract — Art. 6(1)(b); legitimate interests — Art. 6(1)(f) |
| Send marketing emails and newsletters | Consent — Art. 6(1)(a); or legitimate interests for existing-customer soft opt-in where permitted |
| Establish, exercise, or defend legal claims | Legitimate interests — Art. 6(1)(f); legal obligation — Art. 6(1)(c) |
Where we rely on legitimate interests, you may object as described in Section 8. Where we rely on consent, you may withdraw it at any time without affecting prior processing.
4. How we use cookies and analytics
4.1 Application. The AirStrings dashboard and API use only strictly necessary cookies and local storage (for authentication, sessions, security, and preferences). These do not require consent.
4.2 Website analytics. We aim to use privacy-friendly, cookie-less analytics that do not track individuals across sites and do not build advertising profiles. We do not use advertising or third-party tracking cookies.
5. Who we share personal data with (subprocessors and recipients)
We share personal data with service providers ("subprocessors") who process it on our behalf under written contracts. These providers fall into a small number of categories: hosting and database providers, CDN and object-storage providers (for delivery of signed bundles), a payment processor, and a transactional-email provider. They are located in the European Union and the United States and process personal data under appropriate safeguards (EU Standard Contractual Clauses, or an adequacy decision where applicable). A current list of subprocessors, including the specific provider names, is available to business customers on request at support@airstrings.com.
We may also disclose personal data: to professional advisers (lawyers, accountants) under confidentiality; to authorities where legally required; and to a successor entity in a merger, acquisition, or asset sale (subject to this Policy). We do not sell personal data, and we do not use Customer Content to train AI models.
6. International transfers
We are established in the EU. Some of our subprocessors are located in the United States, so providing the Service may involve transfers of personal data outside the European Economic Area. For those transfers, we are the data exporter and rely on appropriate safeguards under Chapter V GDPR:
- Standard Contractual Clauses (SCCs) as the primary safeguard, incorporated into each subprocessor's data-processing terms; and
- where applicable, the subprocessor's certification under the EU–US Data Privacy Framework as an additional basis.
The specific transfer mechanism relied on for each subprocessor is part of the subprocessor list available to business customers on request. You can request more information about these safeguards at support@airstrings.com.
7. How long we keep personal data
We keep personal data only as long as necessary for the purposes above:
| Data | Retention |
|---|---|
| Account & profile data | For the life of your account; deleted within 30 days after account closure (see Terms §14.4), except where longer retention is legally required |
| Customer Content (as processor) | Per the DPA — available for export during a 30-day Retention Window after termination, then deleted from active systems and purged from backups on the normal backup cycle |
| Backups | Rotated on our normal backup-expiry cycle; deleted content is purged as backups expire |
| Billing & invoicing records | Retained as required by Spanish tax and commercial law (the Código de Comercio requires accounting records to be kept for 6 years — confirm exact figure with counsel) |
| Security & access logs | Typically up to 12 months (confirm), then deleted or anonymized |
| Marketing data | Until you unsubscribe or object, then suppressed as needed to honour your choice |
| Data needed for legal claims | Until the relevant limitation period expires |
8. Your rights
Under the GDPR, you have the right to: access your personal data; request rectification of inaccurate data; request erasure; restrict or object to processing; data portability; and, where processing is based on consent, to withdraw consent at any time. You will not be subject to solely automated decisions with legal or similarly significant effects.
To exercise any right, email support@airstrings.com (subject: "Privacy request"). We will respond within one month, as required by the GDPR (extendable by two further months for complex requests, with notice). We may need to verify your identity.
Where we act as processor (for Customer Content), please direct requests to the relevant customer (the controller); we will assist them as required by the DPA.
You also have the right to lodge a complaint with the Agencia Española de Protección de Datos (AEPD) — www.aepd.es — or with your local EU supervisory authority. We would appreciate the chance to address your concern first.
9. How we protect personal data
We implement technical and organizational measures appropriate to the risk, including encryption in transit (TLS) and at rest, hashed storage of passwords (bcrypt) and API keys, least-privilege access controls, structured security logging, and Ed25519 signing of delivered bundles. Our measures for personal data processed on behalf of customers are described in Annex II of the DPA. No system is perfectly secure, but we work to protect your data and to notify affected parties of incidents as required by law.
10. Children
The Service is a business tool not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us personal data, contact support@airstrings.com and we will delete it.
11. Data protection contact
We are not required to appoint a Data Protection Officer under Article 37 GDPR for our current activities, and we have not designated one. You can reach our privacy contact for any data-protection matter:
- Privacy contact: support@airstrings.com (subject: "Privacy")
- Postal: Symbionix SL, Carrer de Pere IV 182, 08005 Barcelona, Spain
If our activities change such that a DPO becomes mandatory, we will appoint one and update this Policy.
12. Changes to this Policy
We may update this Policy. We will post the updated version with a new effective date and, for material changes, notify you by email or in-product in advance. Continued use of the Service after the effective date constitutes acknowledgement of the updated Policy.