Privacy Policy | Symbium

Privacy Policy

Effective Date: June 2, 2025

We are Symbium Corp. (referred to as “Symbium,” “Company,” “us,” “our,” or “we”) and our mission is to reinvent the citizen-to-government experience by providing instant permitting and automated compliance solutions in the building and licensing space. We recognize that personal privacy is important, and that our processing of personal information is a critical part of how we can achieve our mission while maintaining the trust of property owners, contractors, and government partners. We've developed this privacy policy to explain our technologies and to describe how and why we collect, use, and share your information.

Our Services

This privacy policy (“Policy”) applies to personal information we process from our website located at symbium.com (“Site”), our instant permitting and compliance software platform (“Platform”), our mobile applications (“Applications”), and based on other interactions you have with us (collectively, our “Services”). Our Services include instant permitting and automated compliance checks across a range of project types.

The Policy applies to all users of our Services, including, but not limited to, property owners and contractors who submit permit applications, government users who rely on Symbium for compliance checks on publicly-submitted applications, and visitors to our Site. This Policy does not cover our processing of information about employees, job candidates, or contractors.

1. Personal Information We Collect

When we use the term “personal information,” we mean any information that can be used to identify you, directly or indirectly, as an individual person. We collect several types of personal information from our users to provide our instant permitting services and ensure compliance with applicable building codes and regulations.

Personal Information You Provide

We request and collect information when you choose to use our Services. You can choose not to provide us with certain information below, but you may not be able to use some or all of our Services without providing the necessary information for permit processing and compliance verification.

Information We Automatically Collect

When you use our Services, we automatically collect certain personal information about how you use them and the devices you use to access them. This information helps us provide better services and ensure platform security.

Information We Collect from Third Parties

Symbium collects information, including personal information, from various third-party sources to provide comprehensive permit processing services and ensure compliance verification. We do not control how these third parties process your personal information, and any questions about their disclosure practices should be directed to them.

2. How We Use Personal Information

In addition to the specific uses discussed above, we collect and use personal information for several purposes related to providing instant permitting services, ensuring compliance with applicable codes and regulations, and improving our platform to better serve property owners, contractors, and government partners.

We use personal information to provide access to our instant permitting Services, including automated compliance checking against applicable building, zoning, and energy codes. Our platform performs real-time verification of project details against current code requirements to enable instant permit issuance for eligible projects. We use automated decision-making systems to evaluate permit applications, verify code compliance, validate contractor credentials, and calculate applicable fees. These automated processes are designed to speed up permit issuance while ensuring all safety and regulatory requirements are met.

We use your information to improve and develop our Services by analyzing how the platform is used, identifying areas for enhancement, and developing new features that better serve our users. This includes monitoring platform performance, testing new compliance checking algorithms, and updating our systems to reflect changes in building codes and regulations across different jurisdictions.

We use personal information to communicate with users about their accounts, permit applications, and platform updates. This includes sending notifications about permit status, changes to applicable codes or requirements, and important updates about our Services. We also use your information to process and fulfill permit applications, calculate fees, and coordinate with government partners to ensure proper permit issuance and record-keeping.

We may provide users with updates, offers, and announcements about new features, additional services, jurisdictional expansions, and improvements to our platform. We also use your information to solicit feedback about your experience and gather input on potential enhancements to our Services.

We use personal information to provide administrative services, manage account preferences, and respond to technical issues or disputes. This includes troubleshooting platform problems, resolving permit processing issues, and ensuring that our Services meet the needs of all users.

To help us optimize and personalize our Services, we analyze usage patterns, user preferences, and platform interactions. This helps us provide more relevant features, improve user interfaces, and customize the experience for different types of users including property owners, contractors, and government personnel.

We use your information to administer, manage, and grow our organization, including business planning, financial management, and strategic development. This helps us expand our Services to new jurisdictions and develop additional features that support those efforts.

We create and maintain a trusted and safer environment by detecting and preventing fraud, spam, abuse, and security incidents. We conduct security investigations and risk assessments, comply with our legal obligations, and perform checks against databases and other information sources including professional licensing verification. We also use your information to resolve disputes, enforce our agreements with third parties, and ensure compliance with our Terms of Service and other policies.

As we determine necessary in our sole discretion, we may use your information to ensure the safety and integrity of our users, employees, third parties, members of the public, and our Services. This includes responding to security threats, preventing misuse of our platform, and maintaining the reliability of our instant permitting system.

3. How We Share Personal Information

We share personal information in several ways to provide our instant permitting services, ensure compliance with applicable regulations, and maintain the security and integrity of our platform.

We do not sell personal information for monetary consideration. However, some of our data sharing practices, particularly with analytics providers or advertising partners, may be considered "sharing" under certain state privacy laws. You have the right to opt out of such sharing where applicable.

4. Privacy Rights and Choices

You have several rights regarding your personal information, and the specific rights available to you may vary depending on your state of residence and the nature of your interaction with our Services.

To exercise these rights, send an email to hello@symbium.com. We will verify your identity before processing your request to protect your personal information from unauthorized access. We aim to respond to verified requests within 45 days, though this period may be extended by an additional 45 days if necessary, and we will notify you of any extension.

5. State-Specific Privacy Rights

Residents of certain states have additional privacy rights under state privacy laws. These rights supplement the general rights described above and provide additional protections for personal information.

6. Data Security and Retention

We implement comprehensive physical, technical, and administrative safeguards designed to protect your personal information against unauthorized access, disclosure, alteration, and destruction. Our security measures are designed to provide a level of security appropriate to the risk of processing personal information and are regularly reviewed and updated to address evolving threats.

Our technical safeguards include encryption of personal information both in transit and at rest using industry-standard encryption protocols. We use secure communication channels for all data transmissions, maintain firewalls and intrusion detection systems to protect our networks, and implement access controls with multi-factor authentication to limit access to personal information. We regularly monitor our systems for security vulnerabilities and conduct security assessments to identify and address potential risks.

Our administrative safeguards include comprehensive employee training on privacy and security requirements, background checks for employees with access to personal information, and clear policies and procedures governing the handling of personal information. We limit access to personal information to employees who need it to perform their job functions and regularly review and update our security policies and procedures.

As a provider of government technology services, we comply with federal security requirements including the Federal Information Security Modernization Act (FISMA) where applicable. This includes implementing security controls that meet federal standards for protecting government information and maintaining appropriate documentation of our security measures.

We retain personal information for different periods depending on the type of information and the purposes for which it was collected. Account information is retained while your account is active and for seven years after account closure to meet legal and regulatory requirements. Permit application information is retained for ten years or longer as required by government record retention schedules, as this information may be needed for future inspections, compliance verification, or legal proceedings. Property information from public records is retained as long as necessary to provide our services and may be retained indefinitely as it supports our platform's core functionality.

In the event of a data security incident, we have procedures in place to respond quickly and effectively. We will notify affected individuals and relevant authorities within the timeframes required by applicable law, provide information about the nature of the incident and steps being taken to address it, and offer appropriate assistance to affected individuals.

7. Children's Privacy

Our Services are designed for use by adults and are not intended for children under the age of 16. We do not knowingly collect personal information from children under 16 years of age. If you are under 16, please do not use our Services or provide any personal information to us.

If we become aware that we have collected personal information from a child under 16 without appropriate consent, we will take steps to delete such information promptly. If you believe that we may have collected information from a child under 16, please contact us immediately at hello@symbium.com so that we can take appropriate action.

Parents and legal guardians have the right to review any personal information we may have collected about their child, request deletion of such information, and refuse to permit further collection or use of their child's information. To exercise these rights, parents can contact us using the information provided in the Contact Us section below.

8. No International Data Transfers

We primarily operate within the United States and store personal information on servers located in the United States. We are committed to complying with applicable restrictions on international data transfers, including restrictions related to national security concerns. We do not transfer personal information to countries or entities that have been identified as presenting national security risks under applicable U.S. law and policy.

9. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or business operations. When we make changes, we will update the effective date at the top of this Policy and take appropriate steps to notify you of significant changes.

For material changes that significantly affect your privacy rights or how we handle your personal information, we will provide prominent notice through our website, email notifications to registered users, or in-app notifications when you access our Services. We may also seek your explicit consent for certain changes that significantly expand how we use your personal information.

For non-material changes such as clarifications, minor updates, or changes that do not affect your rights, we will post the updated Policy on our website and update the effective date. We encourage you to review this Policy periodically to stay informed about how we protect your personal information.

Your continued use of our Services after changes become effective constitutes your acceptance of the updated Policy. If you do not agree with any changes, you may discontinue use of our Services and contact us to discuss your account options.

10. Contact Us

If you have questions about this Privacy Policy, want to exercise your privacy rights, or need assistance with your account, you can contact us through several channels.

For privacy-related questions and requests, please email us at hello@symbium.com. Please include "Privacy Request" in the subject line and provide sufficient detail about your request to help us respond appropriately. We aim to respond to privacy inquiries within five business days.

For general questions about our Services, you can contact us through our website contact form. Our customer support team can assist with account questions, technical issues, and general information about our platform.

We are committed to addressing your privacy concerns and questions promptly and thoroughly. If you are not satisfied with our response to your privacy inquiry, you may have the right to file a complaint with your state's attorney general or data protection authority, or to appeal our decision regarding your privacy request where such rights are provided by applicable law.