Effective date: 20 March 2026
1. Data Controller
Symphonix Health ("we", "us", "our") is the data controller responsible for your personal data. We are incorporated in Ireland and operate under the laws of the European Union.
Data Controller: Symphonix Health
Location: Dublin, Ireland
Contact: privacy@symphonix-health.com
Important: We do not process protected health information (patient data) through our website. Patient data processing occurs only within deployed BulletTrain instances under separate data processing agreements.
2. What Data We Collect
We collect personal data that you provide directly and data collected automatically when you use our website.
2.1 Data You Provide
- Contact information: name, email address, phone number, organisation name, and job title when you submit forms, request evaluations, or contact us.
- Communication data: the content of emails, messages, and enquiries you send to us.
- Account data: credentials and profile information if you register for developer access or documentation portals.
2.2 Data Collected Automatically
- Usage data: pages visited, time spent on pages, navigation paths, referring URLs, and interaction events.
- Device data: browser type, operating system, screen resolution, and language preferences.
- Network data: IP address (anonymised where possible), approximate geographic location derived from IP address.
3. Lawful Basis for Processing
Under Article 6 of the GDPR, we process personal data on the following lawful bases:
- Consent (Article 6(1)(a)): Where you have given clear consent for us to process your personal data for a specific purpose, such as subscribing to communications or accepting non-essential cookies.
- Contractual necessity (Article 6(1)(b)): Where processing is necessary for the performance of a contract with you, or to take steps at your request prior to entering a contract, such as processing an enterprise evaluation request.
- Legitimate interests (Article 6(1)(f)): Where processing is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests. This includes website analytics, security monitoring, and improving our services.
- Legal obligation (Article 6(1)(c)): Where processing is necessary for compliance with a legal obligation to which we are subject.
4. How We Use Your Data
We use personal data for the following purposes:
- Responding to enquiries and providing requested information about our products and services.
- Processing enterprise evaluation requests and managing business relationships.
- Sending relevant communications where you have opted in or where we have a legitimate interest.
- Improving our website, products, and services through analytics and usage patterns.
- Ensuring the security of our website and detecting potential threats or abuse.
- Complying with legal and regulatory obligations.
5. Data Sharing
We do not sell your personal data. We may share your data with the following categories of recipients:
- Service providers: Trusted third-party providers who assist us in operating our website and services (e.g., hosting providers, analytics services, email delivery). These providers process data only on our instructions and are bound by data processing agreements.
- Professional advisers: Lawyers, auditors, and consultants where necessary for the provision of professional services.
- Legal requirements: Where disclosure is required by law, regulation, legal process, or governmental request.
- Business transfers: In connection with a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction.
6. International Transfers
Where we transfer personal data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission.
- Transfers to countries recognised by the European Commission as providing adequate data protection.
- Other lawful transfer mechanisms as permitted under the GDPR.
7. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. Our general retention periods are:
- Contact and enquiry data: 3 years from last interaction, unless an ongoing business relationship exists.
- Website analytics data: 26 months (anonymised and aggregated where possible).
- Contractual records: 7 years from the end of the contractual relationship, as required by Irish law.
When data is no longer required, it is securely deleted or anonymised.
8. Cookies and Analytics
Our website uses cookies and similar technologies to enhance your experience and understand how our website is used.
8.1 Essential Cookies
These are strictly necessary for the website to function and cannot be switched off. They include cookies for security, session management, and accessibility preferences.
8.2 Analytics Cookies
With your consent, we use analytics services to understand website usage patterns. These cookies collect anonymised data about page views, navigation paths, and interaction events. You may withdraw consent at any time through our cookie preferences.
8.3 Managing Cookies
You can manage your cookie preferences through your browser settings or through our cookie consent mechanism. Blocking certain cookies may affect the functionality of our website.
9. Your Rights Under the GDPR
Under Articles 13 to 22 of the GDPR, you have the following rights regarding your personal data:
- Right of access (Article 15): You have the right to request a copy of the personal data we hold about you.
- Right to rectification (Article 16): You have the right to request correction of inaccurate or incomplete personal data.
- Right to erasure (Article 17): You have the right to request deletion of your personal data where there is no compelling reason for continued processing.
- Right to restriction of processing (Article 18): You have the right to request that we restrict the processing of your personal data in certain circumstances.
- Right to data portability (Article 20): You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit it to another controller.
- Right to object (Article 21): You have the right to object to processing based on legitimate interests or direct marketing at any time.
- Right to withdraw consent: Where processing is based on consent, you may withdraw that consent at any time without affecting the lawfulness of processing carried out prior to withdrawal.
- Right not to be subject to automated decision-making (Article 22): You have the right not to be subject to decisions based solely on automated processing that produce legal effects or similarly significantly affect you.
To exercise any of these rights, contact us at privacy@symphonix-health.com. We will respond to your request within 30 days.
10. Right to Lodge a Complaint
If you believe that our processing of your personal data infringes the GDPR, you have the right to lodge a complaint with a supervisory authority. Our lead supervisory authority is:
Data Protection Commission (An Coimisiun um Chosaint Sonrai)
21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland
Website: www.dataprotection.ie
You also have the right to lodge a complaint with the supervisory authority in the EU member state of your habitual residence or place of work.
11. Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include encryption in transit and at rest, access controls, regular security assessments, and staff training on data protection.
12. Children's Privacy
Our website and services are not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child without appropriate consent, we will take steps to delete that data.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated policy on this page with a revised effective date. We encourage you to review this page periodically.
14. Contact Us
If you have any questions about this Privacy Policy, your personal data, or wish to exercise your rights, please contact us:
Email: privacy@symphonix-health.com
Address: Symphonix Health, Dublin, Ireland