Legal
Security
Last updated 11 September 2026
Our clients share data that shapes deals, portfolio decisions and board agendas. Security is therefore part of how we deliver. This page describes how we protect that data, how we work with AI providers, and what we do when something goes wrong.
Principles
- EU first. Infrastructure we control runs in the European Union. Suppliers outside the EU are used only where the GDPR's safeguards are in place and the client agrees.
- Least data, least access. We process only what an engagement needs, and only the people working on it can reach it.
- Human oversight. AI systems we build support decisions and do not take them alone; a named person is accountable for each system we deliver and for how its outputs are checked.
- Transparency. Clients know which suppliers touch their data, where it is stored and how long it is kept.
Protecting data
- Data is encrypted in transit (TLS 1.2 or higher) and at rest on the systems we use.
- Access is tied to named individuals, protected by multi-factor authentication, granted on a need-to-know basis and revoked when a role or engagement ends.
- Each client's environment and data are kept separate from other clients' and from our internal business systems.
- Backups are encrypted and we test that they can be restored.
- Retention and deletion follow the data processing agreement of each engagement; at the end, data is returned or deleted and we confirm this in writing.
Working with AI providers
Applied AI means working with AI providers. We treat them as sub-processors and hold them to the same standard as any other supplier:
- Contracts that exclude the use of client data to train or improve models, with data processing agreements in place.
- EU processing where the provider offers it; otherwise the GDPR's transfer safeguards, agreed with the client in advance.
- Data minimisation in every prompt and pipeline: models receive what a task needs, not whole datasets by default.
- Logging of what was sent and returned where the engagement requires it, so outputs can be traced and reviewed.
- For each system we assess with the client where it sits under the EU AI Act, which of us is provider and which deployer, and which obligations follow; purpose, data and oversight are documented as part of the delivery, not afterwards.
This website
The site is a static build served only over HTTPS, enforced with HSTS. It has no server-side code, no accounts and no database of its own. The introduction form is delivered by Formspark over an encrypted connection; analytics load only after consent. Dependencies are kept current and every change is reviewed before it goes live.
Suppliers
We select suppliers on their security posture, contractual guarantees and data location, and we review them periodically. For each engagement, the client receives the list of sub-processors involved and is informed before it changes.
Incidents
If we discover or are told of a security incident affecting client data, we contain it, assess the impact and inform the affected client without undue delay. We give the client the facts it needs for its own obligations, including the 72-hour notification to the supervisory authority where that applies. Where we are the controller ourselves, we notify the Autoriteit Persoonsgegevens within 72 hours where required, and the people affected where the risk to them is high. We keep a record of every incident and what we changed afterwards.
Reporting a vulnerability
If you have found a weakness in our website or systems, please tell us at hi@symphonia-labs.com with "Security" in the subject line. We confirm receipt within two working days and tell you what we do with your report. We will not take legal action over research that stays within these rules: access, change or copy no data beyond what is needed to demonstrate the issue, do not disrupt the service or use social engineering, and give us a reasonable period to fix the issue before you publish. Our suppliers' systems are outside this scope, and we do not pay bounties.
Questions
Clients and prospective clients can request our security documentation, including our list of sub-processors and our standard data processing agreement, at hi@symphonia-labs.com.