Privacy Policy
Symplio respects your privacy and is committed to protecting your personal data. This policy explains what data we process when you use the Symplio platform or visit symplio.eu, and how we comply with the EU General Data Protection Regulation (GDPR).
1. Who we are
Symplio, established in Portugal, with tax and VAT number (NIPC): PT519140672, is the controller for personal data of website visitors and the contact persons of customer organizations. For employee data processed inside the Symplio platform, the customer organization is the controller and Symplio acts as processor under our Data Processing Agreement.
2. Data we collect
- Account & profile: name, email, role, language, avatar (optional).
- Workforce data: working hours, attendance, schedules, leave/absence records, entitlement balances.
- Technical data: login records, IP address, device/browser info, security logs.
- Communications: contact form submissions, support emails.
Symplio does not intentionally process special categories of personal data (Art. 9 GDPR).
3. Purposes & legal basis
- Providing and securing the Symplio service — performance of contract.
- Authentication, fraud and abuse prevention — legitimate interest.
- Transactional notifications (clocking and absence requests, decisions, password reset) — performance of contract. Employees can disable email notifications in their profile.
- Compliance with legal obligations (e.g. payroll record retention requested by the customer).
4. Sharing & sub-processors
We use carefully selected sub-processors to operate the platform. The current list is available on the sub-processors page. We do not sell personal data and do not use customer data for advertising.
5. International transfers
Symplio hosts customer data in the European Economic Area. Where data is transferred outside the EEA, we rely on adequacy decisions or EU Standard Contractual Clauses.
6. Retention
Personal data is retained for the duration of the customer's subscription plus the period required by applicable law. On termination, customers can export their data; after that data is deleted from active systems and removed from backups according to our infrastructure retention schedule.
7. Your rights
You have the right to access, rectify, erase, restrict or port your personal data, and to object to processing. For employee data, please contact your employer (the controller) first — they can act through the Symplio admin panel. For all other requests, email support@symplio.eu. You also have the right to lodge a complaint with your supervisory authority.
8. Security
We apply TLS in transit, encryption at rest at the infrastructure level, role-based access control, tenant isolation through row-level security, and continuous access monitoring. Access to customer data is limited to authorized Symplio personnel and only as necessary to operate the service.
9. Cookies
symplio.eu uses only strictly necessary cookies (authentication session, language preference). We do not use third-party tracking or advertising cookies.
10. Contact
Privacy questions: support@symplio.eu