top of page

Privacy Policy - Stand: 07.04.2026

​1. General Information

The protection of your personal data is a special concern for us. We process personal data exclusively in accordance with the applicable data protection laws, in particular the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), and the German Telecommunications Digital Services Data Protection Act (TDDDG).

This privacy policy informs you about the type, scope, and purpose of processing personal data in connection with our website and our online services of SYMBITEG GmbH, in particular our AI service for image editing.

This privacy policy applies to our main website as well as to our web application provided under a subdomain. Both offerings are part of our integrated online system. It does not apply to third-party websites or services that we link to directly or indirectly.

Our service is primarily aimed at users in the EU/EEA area. Use from other countries may be technically possible. Where personal data is processed in this context, this is done in accordance with the standards described in this privacy policy.

2. Controller

The controller for data processing within the meaning of the GDPR is:

SYMBITEG GmbH
Schäftlarnstraße 10
81371 Munich
Germany
Email: office@symbiteg.com

3. Data Protection Contact

If you have questions about the collection, processing, or use of your personal data, or about exercising your rights, you can contact us at:

SYMBITEG GmbH
Attn. Rainer Schild
Schäftlarnstraße 10
81371 Munich
Germany


Email: office@symbiteg.com

4. Data Processing When Accessing Our Website

When our websites are accessed, technical access data is processed by the respective hosting or platform service providers used, as required for provision and security of the website. This includes in particular:

• IP address of the requesting device
• date and time of access
• retrieved file or URL
• amount of transferred data
• browser type and browser version
• operating system
• referrer URL
• requesting provider

This data is processed to ensure website stability and security and to detect and defend against attacks.

 

Legal basis: Art. 6(1)(f) GDPR
Legitimate interest: secure, stable, and abuse-free operation of our websites and online services.

For the technical provision of our offerings, we use in particular:

• Wix.com Ltd., Yunitsman 5 St, Tel Aviv, Israel, for parts of our main website,
• Wix Online Platforms Limited, 1 Grant's Row, Dublin 2, D02HX96, Ireland, as the contact entity 

  designated by Wix in the EU/EEA context,
• Vercel Inc. and/or affiliated companies for hosting and deployment of our web application,
• Strato AG, Pascalstraße 10, 10587 Berlin, where used for technical infrastructure, domains, or other hosting services.

Where personal data is processed outside the EU or EEA in this context, this takes place only under the statutory requirements.

5. Contacting Us

If you contact us by email or by other means, we process the data you provide in order to handle your inquiry and, where applicable, follow-up questions.

This may include in particular:

• name
• email address
• message content
• other information voluntarily provided by you

Legal basis:

• Art. 6(1)(b) GDPR, where the inquiry is aimed at entering into or performing a contract
• Art. 6(1)(f) GDPR, where the inquiry is of another nature

Legitimate interest: processing contact inquiries and communicating with interested parties, customers, and other inquirers.

As a rule, we store this data for up to six months unless longer retention is required for contract performance, preservation of evidence, or due to legal obligations.

For email communication and sending certain messages, we use services of Zoho Corporation and ZeptoMail in particular.

6. Registration and User Account

Where use of our service requires or allows setting up a user account, we process the data collected during registration and account management.

This may include in particular:

• name
• email address
• login data
• password hash
• times of registration and logins
• booked products, credits, subscriptions, and order history
• user account settings

Purposes of processing:

• setting up and managing the user account
• providing protected functions
• contract performance
• abuse and fraud prevention
• support

Legal basis: Art. 6(1)(b) GDPR, Art. 6(1)(f) GDPR

We store account data for the duration of the user account and beyond where statutory retention obligations apply or retention is required for the assertion, exercise, or defense of legal claims.

7. Sign-In via Google

Where you choose sign-in or registration via Google, we process the data required for authentication and account assignment.

This may include in particular:

• name
• email address
• Google account ID or OAuth identifier
• technical authentication information

Processing is carried out for authentication, login, registration, and account assignment.

Legal basis: Art. 6(1)(b) GDPR

Where personal data is processed by Google in this context, Google's privacy information additionally applies.

8. Use of Our AI Image Editing Service

As part of our AI service, we process the data required to provide the functions you request.

 

This may include in particular:

• uploaded image files
• prompts or text inputs entered by you
• editing parameters initiated by you
• generated or edited image files (outputs)
• temporary processing data
• technical metadata and log data, e.g., job ID, timestamps, status and error codes
• IP address in server logs where technically required

Processing is carried out in particular for the following purposes:

• provision of the requested image editing
• combination, merging, or transformation of multiple images provided
• technical execution and error analysis
• IT security
• fraud and abuse prevention
• support and incident handling
• billing and contract administration

Legal basis:

• Art. 6(1)(b) GDPR for contract performance and pre-contractual measures
• Art. 6(1)(f) GDPR for IT security, logging, and abuse/fraud prevention
• Art. 6(1)(c) GDPR where statutory retention obligations exist

Uploaded images, prompts, or outputs are not used to train our own models unless you have given prior express consent.

Unless expressly stated otherwise, image content is not uploaded to external AI APIs for training or other independent third-party purposes. Processing takes place within our own technical infrastructure and/or with our processors and technical service providers insofar as this is required for service provision.

9. Payment Processing

If you book paid services, we process the data required for payment processing. Payment processing is carried out via PayPal (Europe) S.à r.l. et Cie, S.C.A., Luxembourg.

In particular, the following may be processed:

• name
• email address
• billing and payment data
• amount
• time of payment
• transaction ID
• payment status

Purposes of processing:

• payment processing
• fraud prevention
• accounting
• proof of payment
• compliance with commercial and tax obligations

Legal basis:

• Art. 6(1)(b) GDPR
• Art. 6(1)(c) GDPR
• Art. 6(1)(f) GDPR where this serves abuse and fraud prevention

Further information on processing by PayPal can be found in PayPal's privacy notices.

10. Email Dispatch and Transactional Communication

Depending on message type, we use in particular:

• Zoho Corporation / Zoho services for general email communication and campaigns,
• ZeptoMail for transactional emails.

In particular, the following may be processed:

• name
• email address
• sending time
• technical sending and delivery information
• content of the respective message where required for delivery

Processing takes place for communication with you, delivery of contract-related information, confirmations, system messages, and other requested notifications.

Legal basis: Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR

11. Recipients or Categories of Recipients

Personal data is disclosed only where this is required to fulfill our contractual or legal obligations, or where you have consented.

Recipients may in particular include:

• hosting, platform, and infrastructure service providers, in particular Wix, Vercel, and Strato
• payment service providers, in particular PayPal
• email and communication service providers, in particular Zoho and ZeptoMail
• authentication or login service providers, in particular Google, where you use a corresponding login 

  function
• IT and support service providers acting as processors
• internal departments involved in administration, support, accounting, or customer support
• authorities or courts where we are legally required to do so

Image content is not disclosed to third parties for other independent purposes.

12. Cookies and Similar Technologies

We do not use tracking or marketing cookies ourselves unless otherwise stated in this privacy policy.

Where technically necessary cookies or similar technologies are used for operating our website or expressly requested functions, this is based on Section 25(2) TDDDG. Subsequent processing of personal data is based, depending on the specific case, on Art. 6(1)(b) GDPR or Art. 6(1)(f) GDPR.

We use non-essential cookies or similar technologies only with your consent.

Legal basis: Section 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR

Where PayPal buttons, PayPal components, or comparable functions are loaded or integrated only in direct connection with payment processing expressly requested by you, this occurs only as part of the checkout process initiated by you. Where consent is legally required, we obtain it.

Please note that technically necessary cookies or similar technologies may be used on individual parts of our online system or in connection with integrated third-party components, even if we ourselves do not use tracking or marketing cookies.

13. Transfers to Third Countries

Personal data is transferred to countries outside the European Union or the European Economic Area only where this is required for contract performance, prescribed by law, or where you have consented.

In connection with payment processing via PayPal, the use of certain email, hosting, platform, or login services, and other technical service providers, transfers to third countries may occur. Such transfers take place only in accordance with legal requirements, in particular on the basis of an adequacy decision, appropriate safeguards, or other permissible transfer mechanisms.

Where Wix services are used, please note that Israel may be recognized by the European Commission as providing an adequate level of data protection. Further details are available in the privacy information of the respective providers.

14. Retention Period and Deletion

We store personal data only as long as required for the respective purposes or as long as statutory retention obligations exist.

Unless longer storage is expressly provided for in our service, the following principles apply in particular:

• image files and outputs: generally no permanent storage; processing only short-term and as technically

  required for editing, queueing, delivery, and case-specific troubleshooting
• prompts, job metadata, and technical logs: generally only to the extent required and regularly up to 30

  days for error analysis, IT security, and abuse prevention
• contact inquiries: generally up to 6 months after final handling
• contract, order, payment, and invoice data: according to statutory commercial and tax retention periods, regularly up to 10 years

Where required, backups are generally made without permanent archiving of the actual image content.

Where data is exceptionally stored longer, this is done only if and to the extent a legal basis exists.

15. Security of Processing

We implement appropriate technical and organizational measures to protect your data against loss, misuse, unauthorized access, unauthorized disclosure, or impermissible alteration.

This includes in particular:

• TLS-encrypted transmission
• role-based access control
• logging of security-relevant events
• server hardening
• regular deletion processes
• backups where required
• data-minimizing system design where possible

16. No Solely Automated Decision-Making

There is no solely automated decision-making with legal effect or similarly significant adverse impact within the meaning of Art. 22 GDPR.

17. Obligation to Provide Data

Providing certain personal data is required for entering into and performing the contract. This concerns in particular:

• contact data
• registration data
• payment data
• uploaded image files
• prompts or inputs required to perform the requested task

Without this data, we cannot provide our website functions, the requested AI service, or payment processing in whole or in part.

18. Your Rights

Under the statutory provisions, you are entitled in particular to the following rights:

• right of access
• right to rectification
• right to erasure
• right to restriction of processing
• right to data portability
• right to object to processing based on Art. 6(1)(f) GDPR
• right to withdraw granted consent with effect for the future

If you withdraw consent, the lawfulness of processing carried out until withdrawal remains unaffected.

 

To exercise your rights, a notification to the contact details above is sufficient.

19. Right to Lodge a Complaint with a Supervisory Authority

f you believe that the processing of your personal data violates data protection law, you have the right to lodge a complaint with a data protection supervisory authority.

The supervisory authority responsible for us is:

Bavarian State Office for Data Protection Supervision (BayLDA)
Promenade 18
91522 Ansbach
Germany

You may also contact any other competent data protection supervisory authority.

20. Transparenz zu KI-Bearbeitungen

Wir können bearbeitete Inhalte im Nutzer-Interface als „per KI bearbeitet“ kennzeichnen. Soweit technisch vorgesehen, können wir ergänzende Metadaten-Hinweise, z. B. in Form von XMP- oder C2PA-bezogenen Informationen, hinzufügen.

21. Transparency Regarding AI Edits

We may label edited content in the user interface as "edited by AI." Where technically provided, we may add supplementary metadata notices, e.g., in the form of XMP- or C2PA-related information.

22. Changes to This Privacy Policy

We reserve the right to amend this privacy policy where this is required due to changed legal, technical, or organizational conditions. The version available at the time of your visit is authoritative.

bottom of page