Privacy Policy
Last updated: 1 September 2026
1. Data controller
Symbionix, S.L.
Tax ID (CIF): B22937023
Carrer de Pere IV, 18 — Barcelona, Spain
Contact: info@symbionix.io
2. Scope
This policy covers the website symbionix.io and the applications and browser extensions developed and maintained by Symbionix, including the Chrome extension Whatsapp Replies.
3. Data we process
3.1 Website
Browsing data and whatever you give us voluntarily when you contact us (name, email address and the content of your message).
3.2 Whatsapp Replies extension
The extension is a working tool for customer support teams. It processes:
From the agent using it: their licence key and their name.
From the customer being served: the name WhatsApp displays and their phone number. These are used to locate afterwards the conversation each reply belongs to.
From the interaction: which predefined reply was sent, which category it belongs to, in which language, how long the reply took, and the date and time.
Important: the log stores the reply the agent sends, which is a template written beforehand by the company. The content of the messages customers write is not stored.
3.3 AI suggestion feature
When the agent presses the suggestion button, the text of the last message received in that conversation is sent to our AI providers to generate a proposed reply.
That transmission is anonymous. The providers receive only the text: they are not given the customer's name, their phone number, the agent's identity, or any identifier that would reveal which conversation it came from. The agent's licence stops at our intermediate server and never travels to the provider.
That content is not stored at any point, neither by Symbionix nor by them: it is transmitted, processed and discarded.
The feature is optional and only activates when the agent explicitly requests it. If it is not used, no message leaves the browser.
4. Purpose and legal basis
Extension data is processed to provide the service, to allow quality control of customer support, and to locate specific conversations when they need reviewing. The legal basis is the legitimate interest of the client company in supervising the quality of its own support service.
It is not used for advertising, profiling or automated decision-making, nor sold or transferred to third parties for commercial purposes.
5. Roles
When a client company uses the extension, that company is the data controller — it decides what data is collected and why — and Symbionix acts as data processor, limited to providing and maintaining the tool according to its instructions. The relationship is governed by the corresponding data processing agreement.
6. Recipients
| Provider | Function | Location |
|---|---|---|
| Google (Firebase / Firestore) | Data storage | EU / USA |
| Cloudflare (Workers) | Intermediation and licence validation | Global network |
| Groq, Inc. | AI suggestion generation (anonymous text) | USA |
| Google (Gemini API) | Suggestion generation and semantic analysis (anonymous text) | USA |
International transfers: Groq and Google process in the United States the anonymous text described in section 3.3, covered by the EU-US Data Privacy Framework or by Standard Contractual Clauses.
7. Retention
Usage data is kept for 12 months, after which it is deleted.
The text sent to AI providers is not retained: it is processed on the spot and discarded.
8. Your rights
Anyone may request access, rectification, erasure, restriction, portability or objection to the processing of their data by writing to info@symbionix.io.
If the data is processed on behalf of a client company, we will forward the request to that company as controller, or handle it following their instructions.
You may also lodge a complaint with the Spanish Data Protection Agency (aepd.es).
9. Security
Access to data is restricted through individual licences. Only accounts with administration permissions can consult usage logs. Provider keys are not included in the extension: they live on an intermediate server controlled by Symbionix.
10. Changes
We will publish any change on this page, updating the date in the header.