Legal

Privacy Policy

Version 1.0 · Effective 8 September 2025 · Last updated 8 September 2025

This Privacy Policy explains how Symbionix SL (Sociedad Limitada), tax ID (CIF) B-22937023, registered office at Carrer de Pere IV 182, 08005 Barcelona, Spain ("AirStrings", "we", "us"), collects and processes personal data in connection with the AirStrings service and website (airstrings.com) (the "Service").

We are established in the European Union and process personal data in accordance with Regulation (EU) 2016/679 ("GDPR") and Spanish data-protection law (LOPDGDD, Ley Orgánica 3/2018). Our lead supervisory authority is the Agencia Española de Protección de Datos (AEPD).


1. Our two roles: controller and processor

AirStrings acts in two capacities:

  • As a controller — for personal data about our customers and their users that we determine the purposes of: account, authentication, billing, support, security, and marketing data. This Privacy Policy covers that processing.
  • As a processor — for personal data our customers choose to put into the Service as Customer Content (strings, locales, project data) or that flows through the Service on the customer's behalf. For that processing, the customer is the controller (or acts on behalf of its own controller), and our obligations are set out in our Data Processing Agreement, not in this Policy.

The Service is designed for application strings and localization data, not for personal data. We ask customers not to include personal data in Customer Content unless strictly necessary.


2. Personal data we process (as controller)

CategoryExamplesSource
Account & identityName, work email, organization name, password (hashed), roleYou, at signup
Authentication & securityAPI key metadata (keys are stored hashed), session and refresh tokens, IP address, device/browser info, security logs, correlation IDsAutomatically, on use
BillingPlan, billing contact, VAT/tax ID, country, transaction and invoice records; card data is handled by our payment processor and not stored by usYou / our payment processor
Usage & product analyticsFeature usage, request metadata, aggregated and where possible anonymized telemetry, error/diagnostic dataAutomatically, on use
Support & communicationsEmails and messages you send us, support-ticket contentYou
MarketingEmail address and preferences for our newsletter/waitlist, marketing engagementYou (opt-in)

We do not intentionally collect special categories of personal data (Art. 9 GDPR) as controller, and ask that you do not send them to us.


3. Why we process it and on what legal basis

We rely on the following legal bases under Article 6(1) GDPR:

PurposeLegal basis
Provide, operate, and secure the Service; manage your account and authenticate youContract — Art. 6(1)(b)
Process payments, invoicing, and collect feesContract — Art. 6(1)(b); legal obligation — Art. 6(1)(c) (tax/accounting)
Keep the Service secure, prevent fraud and abuse, maintain logs, ensure signed-bundle integrityLegitimate interests — Art. 6(1)(f) (securing our and customers' systems)
Product analytics and improving the Service using aggregated/anonymized dataLegitimate interests — Art. 6(1)(f)
Comply with legal, tax, and accounting obligations and respond to lawful requestsLegal obligation — Art. 6(1)(c)
Send transactional/service emails (e.g. security, billing, account notices)Contract — Art. 6(1)(b); legitimate interests — Art. 6(1)(f)
Send marketing emails and newslettersConsent — Art. 6(1)(a); or legitimate interests for existing-customer soft opt-in where permitted
Establish, exercise, or defend legal claimsLegitimate interests — Art. 6(1)(f); legal obligation — Art. 6(1)(c)

Where we rely on legitimate interests, you may object as described in Section 8. Where we rely on consent, you may withdraw it at any time without affecting prior processing.


4. How we use cookies and analytics

4.1 Application. The AirStrings dashboard and API use only strictly necessary cookies and local storage (for authentication, sessions, security, and preferences). These do not require consent.

4.2 Website analytics. We aim to use privacy-friendly, cookie-less analytics that do not track individuals across sites and do not build advertising profiles. We do not use advertising or third-party tracking cookies.


5. Who we share personal data with (subprocessors and recipients)

We share personal data with service providers ("subprocessors") who process it on our behalf under written contracts. These providers fall into a small number of categories: hosting and database providers, CDN and object-storage providers (for delivery of signed bundles), a payment processor, and a transactional-email provider. They are located in the European Union and the United States and process personal data under appropriate safeguards (EU Standard Contractual Clauses, or an adequacy decision where applicable). A current list of subprocessors, including the specific provider names, is available to business customers on request at support@airstrings.com.

We may also disclose personal data: to professional advisers (lawyers, accountants) under confidentiality; to authorities where legally required; and to a successor entity in a merger, acquisition, or asset sale (subject to this Policy). We do not sell personal data, and we do not use Customer Content to train AI models.


6. International transfers

We are established in the EU. Some of our subprocessors are located in the United States, so providing the Service may involve transfers of personal data outside the European Economic Area. For those transfers, we are the data exporter and rely on appropriate safeguards under Chapter V GDPR:

  • Standard Contractual Clauses (SCCs) as the primary safeguard, incorporated into each subprocessor's data-processing terms; and
  • where applicable, the subprocessor's certification under the EU–US Data Privacy Framework as an additional basis.

The specific transfer mechanism relied on for each subprocessor is part of the subprocessor list available to business customers on request. You can request more information about these safeguards at support@airstrings.com.


7. How long we keep personal data

We keep personal data only as long as necessary for the purposes above:

DataRetention
Account & profile dataFor the life of your account; deleted within 30 days after account closure (see Terms §14.4), except where longer retention is legally required
Customer Content (as processor)Per the DPA — available for export during a 30-day Retention Window after termination, then deleted from active systems and purged from backups on the normal backup cycle
BackupsRotated on our normal backup-expiry cycle; deleted content is purged as backups expire
Billing & invoicing recordsRetained as required by Spanish tax and commercial law (the Código de Comercio requires accounting records to be kept for 6 years — confirm exact figure with counsel)
Security & access logsTypically up to 12 months (confirm), then deleted or anonymized
Marketing dataUntil you unsubscribe or object, then suppressed as needed to honour your choice
Data needed for legal claimsUntil the relevant limitation period expires

8. Your rights

Under the GDPR, you have the right to: access your personal data; request rectification of inaccurate data; request erasure; restrict or object to processing; data portability; and, where processing is based on consent, to withdraw consent at any time. You will not be subject to solely automated decisions with legal or similarly significant effects.

To exercise any right, email support@airstrings.com (subject: "Privacy request"). We will respond within one month, as required by the GDPR (extendable by two further months for complex requests, with notice). We may need to verify your identity.

Where we act as processor (for Customer Content), please direct requests to the relevant customer (the controller); we will assist them as required by the DPA.

You also have the right to lodge a complaint with the Agencia Española de Protección de Datos (AEPD) — www.aepd.es — or with your local EU supervisory authority. We would appreciate the chance to address your concern first.


9. How we protect personal data

We implement technical and organizational measures appropriate to the risk, including encryption in transit (TLS) and at rest, hashed storage of passwords (bcrypt) and API keys, least-privilege access controls, structured security logging, and Ed25519 signing of delivered bundles. Our measures for personal data processed on behalf of customers are described in Annex II of the DPA. No system is perfectly secure, but we work to protect your data and to notify affected parties of incidents as required by law.


10. Children

The Service is a business tool not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us personal data, contact support@airstrings.com and we will delete it.


11. Data protection contact

We are not required to appoint a Data Protection Officer under Article 37 GDPR for our current activities, and we have not designated one. You can reach our privacy contact for any data-protection matter:

  • Privacy contact: support@airstrings.com (subject: "Privacy")
  • Postal: Symbionix SL, Carrer de Pere IV 182, 08005 Barcelona, Spain

If our activities change such that a DPO becomes mandatory, we will appoint one and update this Policy.


12. Changes to this Policy

We may update this Policy. We will post the updated version with a new effective date and, for material changes, notify you by email or in-product in advance. Continued use of the Service after the effective date constitutes acknowledgement of the updated Policy.