1. Who we are
Julians Serdjuks, a self-employed individual carrying out registered economic activity in the Republic of Latvia ("Symbocar", "we"), operates the Symbocar vehicle-maintenance companion. We are the data controller under Regulation (EU) 2016/679 ("GDPR") for the processing described in this policy. Privacy contact: support@symbocar.com. This policy covers both personal users and individuals acting for businesses on the business portal.
2. What data we process
| Category | Examples | Source |
|---|---|---|
| Identity | Account UID, display name, email, preferred language and timezone | You, at signup and in Settings |
| Vehicle | Make, model, year, VIN, license plate, mileage and mileage history, nickname | You |
| Service history | Service events (date, mileage, description, parts, cost, provider), notes | You + Connected Shops whose entries you accept |
| Vehicle health | Active and resolved issues on your vehicles | The Assistant's auto-log + you |
| Conversations | Your chat with the Symbocar Assistant | Necessary to provide the Assistant |
| Photos and documents you attach | Images you send in chat — photos of your vehicle or a part, and documents you choose to photograph such as service bills, invoices or receipts | You, when you attach them |
| Voice recordings | The audio recorded when you use voice input, and its transcript | You, when you use the microphone |
| Vehicle-issue assistance record | The Assistant's reasoning behind each piece of guidance | Generated by the Service |
| Calendar | Events you create in Symbocar | You |
| Shop connections | Which businesses you granted which access to which vehicles, with full grant/revoke history | You |
| Consent log | Versioned record of which legal documents you accepted and when | The Service |
| Session log | When your account opened the app, and which app (personal, business, worker) — timestamp only, no IP address, device identifier or location | The Service |
| Operational logs | Request logs, error traces, latency metrics — no personal content unless you typed it into a message | Our cloud infrastructure |
We do not process special categories of personal data (Art. 9 GDPR) — vehicle "health" data is mechanical, not biomedical. We do not currently run advertising, sell personal data, or build marketing profiles. If that ever changes we will tell you in advance and — where the law requires it — ask for your consent before your data is used in that way.
3. Why we process it — lawful bases (Art. 6 GDPR)
- Operating your account and the core features — Contract (Art. 6(1)(b)).
- Proactive maintenance alerts and reminders — Contract + Legitimate interest (Art. 6(1)(f)).
- Sharing data with shops you connect — Consent (Art. 6(1)(a)), captured per shop per vehicle, revocable at any time.
- Security, abuse prevention, audit trails — Legitimate interest (Art. 6(1)(f)).
- Consent records and AI-transparency audit trail — Legal obligation (Art. 6(1)(c)).
Where we rely on legitimate interest, you may object (Section 8).
4. The Symbocar Assistant and automated decision-making
The Assistant is a single AI agent (see About the AI). Two automated flows touch your records: (1) the health-issue auto-log — when the Assistant identifies an issue needing attention, an entry is written to your vehicle's health dashboard, and you can dismiss any auto-logged entry with one click; (2) proactive maintenance alerts — threshold-based notifications that are informational only. Neither flow produces legal or similarly significant effects on you (Art. 22 GDPR); we provide the override paths anyway. For every piece of guidance, a reasoning record is kept for 24 months and included in your data export (Art. 15(1)(h) GDPR).
5. Who receives your data
5.1 Connected Shops — only with your consent. A shop you link can propose service-log entries for your acceptance; nothing enters your record until you accept. A shop you grant Service Book access can read your vehicle's service history — with cost and provider information withheld by design. You can revoke any grant at any time; revocation is immediate. Each shop is an independent data controller of the data it lawfully receives, contractually restricted to servicing your vehicle.
5.2 What we send to our AI providers, and who they are:
The Assistant cannot answer without sending your question and the relevant vehicle context to an AI provider. This is what leaves our systems each time you send a message:
- your message text;
- your vehicle's details — make, model, year, nickname, VIN, licence plate, current mileage and health score;
- your service history for that vehicle — recent entries including dates, mileage, work done, parts and cost;
- summary figures derived from that history — total spend, average cost per service, average daily and annual mileage, days since the last service;
- outstanding maintenance alerts for the vehicle;
- a list of the other vehicles in your garage (make, model, year);
- any photo or document you attach to that message.
We do not send your name or your email address to any AI provider.
If you use voice input, your recording is additionally sent to Groq to be transcribed into text. If you have the Assistant read replies aloud, the reply text is sent to Google Cloud Text-to-Speech. Voice is entirely optional — if you type, no audio is ever sent.
| Provider | What it receives | Location / safeguard |
|---|---|---|
| Google Vertex AI (Gemini models) — the Assistant's AI model | Everything listed above: your message, vehicle details, service history and attachments | US (us-central1) — EU–US Data Privacy Framework; your data is not used to train models |
| Groq — speech-to-text, only if you use voice input | Your voice recording, transcribed and not retained for training | US — EU Standard Contractual Clauses; audio processed transiently |
| Google Cloud Text-to-Speech — only if you have replies read aloud | The Assistant's reply text | EU / Google DPA; not used for training |
| Google Cloud (hosting, database, secrets, logging) | Hosting and storage | EU (europe-north1, Finland) |
| Google Firebase Authentication | Sign-in and identity | Google DPA; EU–US Data Privacy Framework |
Equivalent protection. Every provider above is bound by a written data-processing agreement obliging them to protect your data to a standard equivalent to this policy: they may process it only on our instructions and only to deliver the feature you asked for, they may not use it to train their models, they may not sell or share it, and they must apply appropriate security measures. Transfers outside the EU/EEA rely on the EU–US Data Privacy Framework or EU Standard Contractual Clauses.
We do not currently sell or rent personal data; if that ever changes we will give advance notice and obtain your consent where the law requires it. We disclose data to authorities only where legally required.
5.3 Google API Services — Limited Use. Symbocar's use and transfer of information received from Google APIs (sign-in profile data via Firebase Authentication) adheres to the Google API Services User Data Policy, including the Limited Use requirements. That data is used solely for sign-in and identity.
6. International transfers
Your stored data resides in the EU (Finland). Where a processor operates from the United States (Section 5.2), transfers rely on the EU–US Data Privacy Framework or EU Standard Contractual Clauses, with only the minimum data needed for the specific feature transferred.
7. How long we keep data
| Category | Retention |
|---|---|
| Account profile | Until you delete your account |
| Vehicles + service history | Until you delete the vehicle (its history is deleted with it) or close your account |
| Chat working memory | 7-day rolling window |
| Vehicle-issue assistance records | 24 months |
| Health issues | Until resolved + 12 months, or vehicle deletion |
| Consent log | While your account exists |
| Session log | 90 days |
| Operational logs | 30 days |
We maintain a fuller retention schedule internally, describing exactly what triggers each deletion.
8. Your rights
- Access (Art. 15) — one-click export: a machine-readable ZIP of everything we hold on you, including the Assistant's reasoning records.
- Rectification (Art. 16) — edit your profile, vehicles, and records directly.
- Erasure (Art. 17) — delete your account in Settings → Account & Data. Your account is locked immediately and everything we hold about you is permanently erased 30 days later, including assistance records and search-index entries. Those 30 days exist so an accidental deletion can be undone: sign in again within that window to cancel. After it elapses the erasure runs automatically and cannot be reversed. Where a shop linked a workshop ticket to you, the shop's own business record survives with your identity detached.
- Restriction (Art. 18) and objection (Art. 21) — contact us.
- Portability (Art. 20) — the export ZIP is machine-readable JSON.
- Withdraw consent (Art. 7(3)) — per shop in the app; for the Service overall by declining the disclosure.
- Complain (Art. 77) — to the Latvian supervisory authority or the authority of your country of residence.
We respond within one month (Art. 12(3) GDPR). Contact: support@symbocar.com.
9. Business portal users
If you register or work for a shop on the business portal, we additionally process: business name, location, contact email, your role, verification status, and your actions on tickets and service logs. Lawful bases: contract and legitimate interest / legal obligation. Customer vehicle data your shop accesses through the portal is governed by Section 5.1 and the Business Terms — your shop is the controller of what it receives.
10. Cookies and local storage
Symbocar currently uses no advertising or third-party analytics cookies. If we introduce analytics or advertising technology later, we will update this policy first and ask for your consent before any non-essential cookie is set. Today we use only what the Service needs to function:
| Item | Type | Purpose | Lifetime |
|---|---|---|---|
| __session | Cookie (first-party) | Authenticated session; carries language/timezone rendering hints | Session |
| pref_lang | Cookie (first-party) | Remembers your interface language | 1 year |
| Auth tokens | Local storage | Keeping you signed in | Until sign-out |
| Consent/display flags | Local storage | Remembering accepted disclosure versions | Until cleared |
Because all of these are strictly necessary or store your explicit preference, no cookie-consent banner is required; this section is the disclosure required by the ePrivacy rules.
11. Security
TLS on all connections; row-level security in the database scopes every query to the authenticated identity, in addition to application-layer authorization; a tamper-evident audit trail records every write to user data; secrets live in a managed secret store. To report a security vulnerability, contact support@symbocar.com.
12. Children
Symbocar is not directed at children under 16. If you believe a child holds an account, contact support@symbocar.com and we will delete it.
13. Changes to this policy
Material changes trigger a re-acceptance flow on your next login; minor wording fixes do not.