Privacy Policy
Last updated: July 31, 2026. This policy may be updated from time to time — the version in effect is always the one published here.
1. Who is responsible for your data
Symbiotic Design Academy, established in Eindhoven, the Netherlands, is the controller responsible for the personal data described in this Privacy Policy, within the meaning of the General Data Protection Regulation (GDPR) and the Dutch GDPR Implementation Act (UAVG).
Chamber of Commerce (KVK) number: 96731222. VAT/BTW number: NL005228606B35.
Contact email: admin@symbioticdesignacademy.com. Contact phone: +31 6 29562311. We have not appointed a formal Data Protection Officer (DPO), as this is not currently required given the scale of our processing. Privacy questions should be sent to the contact email above.
2. What personal data we collect
We collect the following categories of personal data, depending on how you interact with the Website: account data (name, email address, and password, stored in hashed/encrypted form), if you create an account to sign in; contact and support form data (name, email address, and the content of your message), when you use the contact form, support form, or other forms on the Website; community submissions, meaning any content you voluntarily submit through community or feedback features, together with your account information; technical data (IP address and basic request metadata), used only for spam and abuse prevention on our forms and standard web server operation, not for tracking or profiling; and communications, meaning copies of emails we exchange with you, including transactional emails such as password resets and confirmations.
We do not currently collect payment or financial data, because the Website does not yet sell any products or services.
3. Cookies and similar technologies
At the time of writing, the Website does not run analytics scripts, advertising scripts, or a chat widget, and does not set any non-essential cookies. The only cookies in use are a strictly necessary session/authentication cookie, set when you sign in to an account, and a cookie that remembers your cookie-consent choice — both required for the site to function and neither requires consent under the ePrivacy rules.
If we activate analytics, a chat widget, or any other technology that sets non-essential cookies in the future, those cookies will only be set once you have given consent through the cookie banner shown on the Website.
4. Why we process your data and our legal basis
We process your data to provide the Website and respond to your enquiries (contact/support forms) — legal basis: performance of a contract or steps taken at your request prior to entering into a contract, or our legitimate interest in responding to enquiries; to create and manage your account — legal basis: performance of a contract; to prevent spam and abuse of our forms — legal basis: legitimate interest in keeping the Website secure and functional; to send you transactional emails — legal basis: performance of a contract; and to comply with legal obligations, such as tax and accounting record-keeping — legal basis: legal obligation.
5. Who we share your data with
We share personal data only with service providers (processors) who help us run the Website, under data processing agreements, and only to the extent necessary for the purposes described above. Our current processors include Vercel Inc. (hosting and delivery of the Website); Supabase Inc. (our database provider; the database itself is hosted in the EU, in Frankfurt, Germany); Resend, built on Amazon Web Services (SES), for delivery of transactional emails; and Google Workspace, for our business email. We do not sell your personal data, and we do not share it with third parties for their own marketing purposes.
6. International data transfers
Some of our service providers (such as Vercel and AWS, which underlies Resend) are US-based companies. Where personal data is transferred outside the European Economic Area, we rely on appropriate safeguards recognised under the GDPR, such as the EU Standard Contractual Clauses, or the provider’s participation in an approved data transfer framework. We aim to keep data such as our primary database within the EU, as is currently the case with our database, which is hosted in Germany.
7. How long we keep your data
We keep account data for as long as your account remains active, and for a limited period afterwards to allow you to recover your account, after which it is deleted or anonymised. Contact/support form submissions are kept for as long as reasonably necessary to handle your enquiry and for a limited period afterwards for record-keeping, unless a longer period is required by law. Data we are required to keep for tax or accounting purposes is retained for the statutory period under Dutch law, currently seven years.
8. Your rights
Under the GDPR, you have the right to access the personal data we hold about you; request correction of inaccurate or incomplete data; request erasure of your data, where applicable; request restriction of, or object to, our processing of your data; request a copy of your data in a portable format; and withdraw consent at any time, where processing is based on consent, without affecting the lawfulness of processing before withdrawal.
To exercise any of these rights, contact us at admin@symbioticdesignacademy.com. You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), autoriteitpersoonsgegevens.nl, or with the supervisory authority in your own EU country of residence.
9. Security
We take appropriate technical and organisational measures to protect your personal data, including encrypted connections (HTTPS), hashed account passwords, and restricted, role-based access to submitted form data within our systems. No method of transmission or storage is completely secure, but we work to protect your data using industry-standard practices.
10. Children
The Website is intended for adults and is not directed at anyone under the age of 18. We do not knowingly collect personal data from anyone under 18. If you believe someone under 18 has provided us with personal data, please contact us so we can delete it.
11. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements, such as the introduction of analytics, a chat widget, or paid products. We will post the updated version on this page with a revised effective date, and, for material changes, will take reasonable steps to bring them to your attention.
12. Contact
For any question about this Privacy Policy or how we handle your personal data, contact us at admin@symbioticdesignacademy.com or support@symbioticdesignacademy.com.