PRIVACY POLICY of Symbio3D
Last updated: 25/01/2026
1. INTRODUCTION AND SCOPE
This privacy policy sets out how Symbio3D, a company specializing in 3D printing and three-dimensional modeling, collects, uses, retains and protects your personal data when you browse and use our website www.symbio3d.com.
Our commitment: Symbio3D attaches the utmost importance to the protection of your personal data and is committed to strictly complying with the legislation in force, in particular the General Data Protection Regulation (GDPR) of 27 April 2016 and the amended French Data Protection Act of 6 January 1978.
Type of website: Our website is a professional showcase and e-commerce platform dedicated to 3D printing services, enabling the presentation of our services, quote requests, and the placing of orders online.
Scope: This policy applies to all personal data collected via our website, our contact forms, our commercial exchanges, and when using our 3D printing services.
2. DATA CONTROLLER
Data controller:
- SIRET number: 98874855400017
- Email: contact@symbio3d.com
- Telephone: 0613712949
- Address: 45 lot les 2 Roses 84700 Sorgues
Data Protection Officer (DPO):
In accordance with Article 37 of the GDPR, and given the nature of our activities, we have appointed a Data Protection Officer whom you can contact at: dpo@symbio3d.com or at the postal address mentioned above.
3. DATA COLLECTED
3.1 Types of data collected
We collect the following categories of personal data:
Identification data:
- First and last name (required)
- Company name (where applicable)
- Full postal address (required for delivery)
- Telephone number (required)
- Email address (required)
Contact and commercial data:
- Order and quote history
- Communication preferences
- Correspondence and exchanges
- Billing data
Technical browsing data:
- IP address
- Browser type and version
- Operating system
- Pages visited and browsing time
- Approximate geolocation data (city/region)
- Cookies and trackers (see dedicated section)
Data relating to 3D files:
- 3D modeling files submitted for printing
- Associated technical specifications
- File metadata
3.2 Mandatory or optional nature
Fields marked with an asterisk (*) in our forms are mandatory. This data is necessary to:
- Process your quote requests and orders
- Ensure the delivery of your products
- Comply with our legal and accounting obligations
Other data is optional and helps us improve the quality of our services.
3.3 Collection methods
Your data is collected through the following means:
- Contact and quote request forms
- Online ordering process
- Telephone and email exchanges
- Cookies and similar technologies
- Files submitted for 3D printing
- Synbio3D file exchange platform
4. PURPOSES AND LEGAL BASES OF PROCESSING
4.1 Purposes of processing
We use your personal data for the following purposes:
Commercial management (legal basis: performance of the contract - Art. 6(1)(b) GDPR):
- Processing of quote requests and orders
- Invoicing and payment tracking
- Customer relationship management
- After-sales service and technical support
Communication and marketing (legal basis: consent - Art. 6(1)(a) GDPR or legitimate interest - Art. 6(1)(f) GDPR):
- Sending newsletters and commercial information (with prior consent)
- Information about our new services and technologies
- Invitations to professional events
Improvement of our services (legal basis: legitimate interest - Art. 6(1)(f) GDPR):
- Statistical analysis of website traffic
- Improvement of the user experience
- Development of new services
Legal obligations (legal basis: legal obligation - Art. 6(1)(c) GDPR):
- Retention of invoices and accounting documents
- Compliance with tax obligations
- Cooperation with the competent authorities
4.2 Legitimate interest assessment
Where we rely on legitimate interest, we have carried out a proportionality assessment weighing our legitimate commercial interests against your rights and freedoms. This assessment is documented and available upon request.
5. RECIPIENTS AND DATA SHARING
5.1 Internal recipients
Your personal data is accessible only to Symbio3D employees who are strictly authorized within the scope of their duties (sales, technical and administrative departments).
5.2 Processors and partners
We may transmit some of your data to our processors and partners, exclusively in the context of providing our services:
Technical service providers:
- Web hosting and cloud computing providers
- IT maintenance providers
- Online payment solution providers
Logistics partners:
- Carriers and delivery services
- Storage companies
Service providers:
- Accounting firms
- Marketing service providers (with consent)
5.3 Guarantees and controls
All our processors are subject to strict contractual confidentiality and security obligations. We regularly verify their GDPR compliance through audits and compliance questionnaires.
5.4 No sale or transfer
Firm commitment: Symbio3D formally undertakes never to sell, rent or transfer your personal data to third parties for commercial purposes without your prior explicit consent.
5.5 Mandatory disclosure
We may be required to disclose your personal data in the following cases:
- Judicial or administrative requisition
- Protection of our rights, property or safety
- Compliance with an overriding legal obligation
- Prevention of fraud or illegal activities
6. RETENTION PERIOD
6.1 General principles
We retain your personal data only for as long as necessary for the purposes for which it was collected, in accordance with the principles of data minimization and storage limitation.
6.2 Specific periods
Active customer data: 3 years from the last order or contact
Prospecting data: 3 years from the last contact or the exercise of the right to object
Accounting and tax data: 10 years from the close of the financial year (legal obligation)
3D files and technical data: Immediately after delivery, unless there is an express request for retention or deletion
Browsing data (cookies): 13 months maximum
Commercial correspondence: 5 years from the last exchange
6.3 Automatic deletion
Upon expiry of the periods mentioned above, your data is automatically deleted from our systems, unless a longer retention period is required by law.
7. USERS' RIGHTS
7.1 Your rights
In accordance with the GDPR and the French Data Protection Act, you have the following rights:
- Right of access (Art. 15 GDPR): Obtain confirmation that data concerning you is being processed and access that data
- Right to rectification (Art. 16 GDPR): Have inaccurate or incomplete data corrected
- Right to erasure (Art. 17 GDPR): Obtain the deletion of your data under certain conditions
- Right to restriction of processing (Art. 18 GDPR): Obtain the temporary suspension of processing
- Right to object (Art. 21 GDPR): Object to the processing of your data on grounds relating to your particular situation
- Right to data portability (Art. 20 GDPR): Receive your data in a structured, standard format
- Right to withdraw consent: Withdraw your consent at any time for processing based on this legal basis
7.2 Procedure for exercising your rights
To exercise your rights, you can:
- Contact us by email: dpo@symbio3d.com
- Send us a letter to the postal address mentioned in section 2
- Use the dedicated contact form on our website
Supporting documents: To ensure the security of your data, we may ask you to prove your identity by providing a copy of a valid identity document.
Response time: We undertake to respond to your requests within a maximum of one month from receipt of your request.
7.3 Right to lodge a complaint
You have the right to lodge any complaint concerning the way we process your personal data with the Commission Nationale de l'Informatique et des Libertés, CNIL (the French data protection authority):
- Website: www.cnil.fr
- Postal address: CNIL - 3 Place de Fontenoy - TSA 80715 - 59334 LILLE CEDEX
- Telephone: 01 53 73 22 22
8. DATA SECURITY
8.1 Technical measures
We implement robust technical security measures:
- Encryption: SSL/TLS encryption for all transmissions of sensitive data, or failing that, HTTPS
- Access control: Strong authentication and profile-based permissions management
- Backups: Regular, encrypted backups with restoration tests
- Monitoring: 24/7 system monitoring and intrusion detection
- Updates: Systems and security patches kept constantly up to date
8.2 Organizational measures
- Staff training: Regular awareness-raising and training of employees on data protection issues
- Security policy: Strict internal procedures for the management of personal data
- Incident management: Procedure for notifying data breaches to the CNIL within 72 hours
- Regular audits: Periodic assessment of our security measures
8.3 Data location
Your personal data is hosted within the European Union, with certified providers meeting the highest security standards.
9. COOKIES AND TRACKERS
9.1 Definition and use
Our website uses cookies and other trackers to improve your browsing experience and analyze the use of our services.
9.2 Types of cookies used
- Strictly necessary cookies: Essential for the operation of the website (session, security, cart)
- Performance cookies: Audience measurement and statistical analysis (Google Analytics)
- Functionality cookies: Remembering your browsing preferences
- Advertising cookies: Content personalization (only with consent)
9.3 Consent management
In accordance with the latest regulatory developments of 2025, we ask for your explicit consent before placing non-essential cookies. You can:
- Accept or refuse cookies on your first visit
- Change your preferences at any time via our cookie management center
- Configure your browser to block cookies
9.4 Retention period
Cookies are retained for a maximum period of 13 months and your consent is requested again annually.
10. CHANGES TO THE POLICY
10.1 Evolution of the policy
Symbio3D reserves the right to modify this privacy policy at any time, in particular to take into account regulatory or technological developments or changes to our services.
10.2 Informing users
Any substantial change to this policy will be brought to your attention by:
- Email notification for registered customers
- Publication of a visible notice on our website
- Updating of the last modified date
10.3 Recommended review
We recommend that you review this policy regularly to stay informed of any changes.
11. CONTACT
11.1 Questions about this policy
For any questions regarding this privacy policy or the exercise of your rights, you can contact us:
By email: dpo@symbio3d.com or contact@symbio3d.com
By post:
Symbio3D - Data Protection Department
45 lot les 2 Roses 84700 Sorgues
By telephone: +33 6 13 71 29 49 (Monday to Friday, 9 a.m. to 6 p.m.)
11.2 Response commitment
We undertake to respond to you as soon as possible and at the latest within one month of receiving your request.
12. NOTICE REGARDING PENALTIES
12.1 Information on applicable penalties
In accordance with Article 83 of the GDPR, failure to comply with this privacy policy and with personal data protection obligations may result in significant administrative penalties:
- Fines of up to 20 million euros or 4% of annual worldwide turnover
- Criminal penalties in the event of serious offenses
12.2 Protection of the company
This privacy policy is also intended to protect Symbio3D against:
- Claims relating to the processing of personal data
- Regulatory penalties, by demonstrating our compliance
- Reputational risks related to data management
12.3 Mutual compliance with obligations
By using our services, you agree to comply with this policy and to report to us any potential breach of which you may become aware.
---
This privacy policy has been drafted in compliance with the GDPR and the French Data Protection Act, drawing on best practices in the 3D printing and additive manufacturing sector.