Privacy Policy
Last updated: 1 August 2026 · Applies to symbory.com and the Symbory platform
What applies today. symbory.com is currently a pre-launch waitlist. Until you have a
workspace, the only personal data we hold about you is the email address you submit to the waitlist, plus
analytics described in this policy. Everything below describes how the Platform handles candidate and
employee data, and applies from the moment your workspace is created.
1. Introduction
Symbory ("Symbory", "we", "us", "our") is operated by Ensetec B.V., registered at
Rijksweg 142c, 9870 Zulte, Belgium (VAT BE0897971758), and provides the People Relationship Management
(PRM) platform at symbory.com, together with any connected career pages,
applications, and services (collectively, the "Platform"). This Privacy Policy explains what personal data
we collect, why we collect it, how it is used, and the rights available to candidates, employees, and other
individuals whose data passes through the Platform.
Symbory is typically engaged by an employer, HR team, or recruiting organisation (the "Customer") to manage
relationships with their candidates and employees. In that relationship, the Customer is the data
controller for the personal data they submit to and manage within the Platform, and Symbory
acts as data processor, processing that data only on the Customer's documented instructions. Where
Symbory determines the purpose and means of processing — for example, for account administration, platform
security, or product analytics — Symbory acts as an independent controller for that limited
processing.
This Policy is written to comply with the EU General Data Protection Regulation (GDPR) and applicable national
implementing legislation, including Belgian data protection law. Where Symbory acts as processor, the Customer's
own privacy notice — not this Policy — governs how they collect and use personal data; this Policy describes
how Symbory itself handles that data on their behalf.
2. What is Symbory?
Symbory is a Human Relationship Memory platform — software that helps employers preserve the
complete, continuous context of a person's relationship with an organisation, from first application to final
day and beyond. Rather than scattering that context across disconnected recruiting, HR, and performance tools,
Symbory keeps it as one searchable timeline.
The Platform is used to support:
- Recruitment
- Onboarding
- Career development
- Performance conversations
- Learning
- Internal mobility
- Exit interviews
- Alumni relationships
The goal of this continuous record is simple: so that people don't have to repeat themselves, and so that
managers have the professional context they need to have better, more informed conversations.
3. What data do we collect?
Candidate data
- CV and application materials
- Motivation letters and application responses
- Application and pipeline history
- Interview notes
- Assessment and evaluation results
- Public professional profile information (e.g. a LinkedIn profile), where the employer's recruiter
chooses to import it for a candidate already in their pipeline. This is data we obtain from a source
other than the candidate; where it is imported, the Platform records on the candidate's timeline that it
came from a public profile, on what date, and which team member requested it — so the employer can tell
the candidate as GDPR requires.
Employee data
- Profile information
- Goals and career aspirations
- Meeting records (e.g. one-on-ones), including audio recordings and their transcripts where recording is
enabled
- Feedback
- Achievements and recognitions
- Learning activity
- Projects
- Internal mobility history
- Skills
AI-generated data
- Conversation and meeting summaries
- Suggested follow-up questions
- Extracted action items
- Derived insights and patterns
AI-generated content is a summary or suggestion, never a decision. AI does not make, and is never used to make,
employment decisions on its own. See
Section 5.
4. Why do we process data?
| Purpose | Legal basis |
| Recruitment | Consent |
| Candidate profile enrichment | Legitimate interest |
| Employment | Contract |
| Performance management | Legitimate interest |
| Learning | Legitimate interest |
| Compliance | Legal obligation |
| Platform security | Legitimate interest |
Where consent is the legal basis — most commonly for candidates during recruitment — that consent can be
withdrawn at any time, without affecting the lawfulness of processing carried out before withdrawal.
Candidate profile enrichment is the one recruitment activity that does not rest on consent, because the
information is not obtained from the candidate: where a recruiter imports a candidate's public professional
profile, the employer relies on their legitimate interest in assessing an applicant they are already
considering. That interest does not override the candidate's own rights, and it is bounded accordingly — the
import covers only a candidate already in the employer's pipeline, only a profile the person has published
publicly, and only when a recruiter asks for it. A candidate may object to this processing at any time under
Section 11.
5. AI Usage
AI is central to how Symbory works, and we take its responsible use seriously. Specifically:
- AI summarises conversations — interviews, one-on-ones, and other recorded interactions.
- AI extracts action items so commitments are not lost.
- AI proposes follow-up questions to help managers prepare for conversations.
What AI does not do, under any circumstance:
- AI never automatically hires a candidate.
- AI never automatically fires or dismisses an employee.
- AI never evaluates performance autonomously.
Every summary, suggestion, and extracted item is a draft for a human to review. A human — the hiring manager,
people manager, or HR professional — remains responsible for every decision that affects a candidate's or
employee's employment. This is a design principle, not a disclaimer: Symbory's role is to preserve context so
people can make better decisions, not to make decisions for them.
6. Data ownership
Data ownership on Symbory follows a clear split:
- The employer owns company data — the records, notes, and history created within their
workspace belong to them, not to Symbory.
- Employees and candidates retain their GDPR rights over their own personal data,
regardless of who owns the workspace it lives in (see Section 11).
- Employees may request an export of their personal data held in the Platform at any time,
through their employer or by contacting us directly.
- Employers decide retention for former employees' records after employment ends, subject
to applicable legal minimums and maximums (see Section 9).
7. Sharing data
We never sell personal data. Data is shared only with parties who process it on our behalf
under a data processing agreement, strictly to operate the Platform. These include:
- AI model provider (Anthropic) — where AI features such as summarisation are enabled, to
generate that output. We use Anthropic's European processing region, so prompts and generated output are
processed within the EU. No data is used by the provider to train their models.
- Hosting provider — to run and store the Platform's infrastructure and data.
- Email provider — to deliver transactional and account-related emails.
- Public profile enrichment provider — where a recruiter chooses to import
a candidate's public professional profile, we send that provider the web address of that profile so it can
retrieve the publicly visible page. Only the address is sent; no other candidate data leaves the Platform.
The retrieved profile is stored in the EU alongside the rest of the candidate's record. This provider is
used only for a profile a recruiter explicitly requests, one candidate at a time, for someone already in
their pipeline — it is never used to build, buy, or enrich lists of people who have not applied.
Transcription is not shared with anyone. Where recording is enabled, audio from interviews
and one-on-ones is transcribed on Symbory's own servers inside the European Union. The recording is not sent
to a third-party transcription service, and the audio is deleted once the transcript has been produced.
All subprocessors are bound by contractual confidentiality and data protection obligations at least as
strict as those in this Policy. A current list of subprocessors is available on request.
8. International transfers
The Platform is hosted in the European Union. Speech-to-text runs on our own servers in the same EU region,
so recordings never leave our infrastructure. AI summarisation runs in our provider's European processing
region. Where a subprocessor is nonetheless located outside the EEA, we rely on the European Commission's
Standard Contractual Clauses (SCCs), or another valid transfer mechanism recognised under GDPR, to ensure an
equivalent level of protection.
9. Retention
- Candidates: retained for the duration of the recruitment process, plus a limited period
afterward to defend against legal claims, unless the candidate withdraws consent sooner or is added to a
future-opportunities pool with separate consent.
- Employees: retained for the duration of employment, in line with the Customer's
record-keeping obligations.
- Former employees: retained after employment ends only as long as the employer's
configured retention period, or as required by applicable legal obligations, then deleted or anonymised.
- Deleted workspaces: data belonging to a closed or deleted Customer workspace is
permanently deleted within a defined grace period following termination of the agreement.
- Backups: deleted data may persist in encrypted backups for a limited period before being
purged as part of the normal backup rotation cycle.
10. Security
We protect personal data with layered technical and organisational measures, including:
- Encryption of data in transit and at rest
- Audit logs of access and changes to sensitive records
- Role-based permissions so people only see the data relevant to their role
- Regular backups to protect against data loss
- Multi-factor authentication (MFA) for account access
- Single sign-on (SSO) support for Customer-managed identity
11. Your rights
Under GDPR, candidates and employees have the following rights over their personal data. To exercise any of
these, contact us or your employer's HR team using the details in Section 12.
- Access — request a copy of the personal data we hold about you.
- Correction — request that inaccurate or incomplete data be corrected.
- Deletion — request erasure of your data, subject to legal retention obligations.
- Restriction — request that processing of your data be limited in certain circumstances.
- Export — receive your data in a structured, portable format.
- Complaint — lodge a complaint with your national data protection authority (in Belgium,
the Gegevensbeschermingsautoriteit / Autorité de protection des données)
if you believe your data has been mishandled.
Questions about this Policy, data protection requests, or how your data is handled can be sent to our data
protection contact at dpa@symbory.com, or to
hello@symbory.com. If you are a candidate or employee, you may also
contact your employer's HR team directly, as they act as data controller for your data on the Platform.
Symbory is operated by Ensetec B.V., Rijksweg 142c, 9870 Zulte, Belgium — VAT BE0897971758.