← Syntrofi

Privacy Policy

Who processes your data in Syntrofi, for what, where it comes from, and your rights.

This notice covers the Syntrofi app (`syntrofi.com`) and explains what happens to your personal data when you sign in, become a member of an event, or mark something.

Who is the controller

The controller is Digital Symbio spol. s r.o., Karpatské námestie 7770/10A, 831 06 Bratislava – Rača, Slovakia, company ID (IČO) 51 224 968, VAT ID SK2120641875, registered with the Bratislava III District Court, section Sro, insert no. 182899/B, e-mail info@digitalsymbio.com (below, "we" or "Digital Symbio").

We are always the controller for sign-in and your global account (your identity across events). For one event (a trip or a party, for example), the event's organiser may also be a controller — in that case we act as a processor under GDPR Art. 28, under a written contract with them. The event's settings name its organiser; this page does not change who controls sign-in.

What we use your data for

  • Sign-in and account. So we can recognise you when you come back and match you to your

events.

  • Event membership. So the app knows who may see which event and what you marked in it.
  • "Who's going" and picks. So other members of the event can see who from the group is

going to the same thing, and so the app can warn about time clashes.

  • The board. Where an event uses it, to exchange messages between members.
  • Location and camp — only when you turn it on yourself. Never on its own.
  • Gallery — only on events where it is on, and only for photos you upload yourself or

confirm your consent for.

We never use any of this for advertising, profiling, or selling to third parties.

Legal basis

  • Sign-in, membership, "who's going", picks and the board: GDPR Art. 6(1)(b) — needed

to carry out your joining and your participation in an event.

  • Location, camp, gallery and anything else you turn on yourself: **GDPR Art. 6(1)(a) —

consent.** You can withdraw consent at any time by turning the same switch off.

Where the data comes from

When you sign in with Google, we receive your Google ID (sub), e-mail, name and profile picture from it. We read nothing else from your Google account and write nothing back to it.

When you enter an event as a guest (no Google account) or with a username and password, you type your own name and we only verify the password — we never store it in readable form.

Who sees what

Other members of the same event see your name, and if you signed in with Google, your profile picture too. Your phone number, location and camp show up only if you turned sharing on yourself. Members of a different event cannot see you unless you are in that one too.

How long we keep data

  • Sign-in (session cookie) lasts 60 days from your last visit.
  • Event data (who's going, picks, board) stays for as long as the event exists. We

delete it once the organiser closes the event or on your request.

  • Global profile (name, e-mail, Google picture) stays for as long as you have at least

one event, or until you ask for deletion.

Who we share data with

  • WebSupport, s. r. o. (Slovakia) — hosting for the app.
  • Google LLC — only to verify your identity when you sign in with Google; beyond what

you enter on the sign-in screen yourself, the app sends it nothing else.

  • If an event uses the gallery, photos go through our own tool, mediahub — a server we

run ourselves within our hosting, not a third party.

  • If the organiser of an event switches on Kairos (AI help with the event settings), the

text the organiser writes and the event settings (title, dates, meeting point, route, gear, links) are processed by our tool goabot (a Digital Symbio server) and by a language model of Anthropic, PBC (USA). This transfers the data to the USA. Kairos gets nothing about participants — no names, e-mails, location, picks, board posts, tickets or payments. goabot stores neither the text nor the proposal; it keeps them in memory only until the organiser collects the proposal. Nothing is written to the app until the organiser checks it and saves it.

We send data nowhere outside this list, and we never sell it.

Cookies

The app uses only strictly necessary cookies — no analytics, no third-party script:

  • `spolus` — sign-in (session), lasts until you close the app or 60 days with "remember me".
  • `koine_remember` — restores your sign-in without going through Google again.
  • `koine_dev` — tells your browser apart when you enter an event as a guest, no account.
  • `koine_lang` — remembers whether you want the app in Slovak or in English.

Since none of these is optional or advertising-related, we do not ask for consent through a cookie banner.

Your rights

You have the right to access your data (Art. 15), to have it corrected (Art. 16), erased (Art. 17), to restrict processing (Art. 18), to portability (Art. 20), and to object (Art. 21). Write to info@digitalsymbio.com and we will handle it.

If you believe we handle your data incorrectly, you have the right to lodge a complaint with the Slovak Data Protection Authority (Úrad na ochranu osobných údajov SR, dataprotection.gov.sk).

Minors

The app is for people aged 16 and over.

Changes

We may update this notice from time to time — for example, when the app gains a new feature. The current version is always at this address.

Controller: Digital Symbio spol. s r.o., Karpatské námestie 7770/10A, 831 06 Bratislava – Rača, Slovakia, company ID (IČO) 51 224 968, Bratislava III District Court, section Sro, insert no. 182899/B · info@digitalsymbio.com