Skip to content

Privacy policy

Last updated: 26 September 2026

Data controller

The data controller is Weber Energy Partners, a Danish sole proprietorship owned by Oscar Weber, which operates Symbolon. Questions about this policy, or about your data: contact@symbolon.energy.

Whose data this covers

Symbolon is a business-to-business platform. The personal data we handle belongs to people acting for companies: users with an account, business contacts we reach out to about PPAs, and anyone who visits the site.

What we collect

  • Account users: name, work email, phone (optional), company name, country, industry and a short company description. The listings you create, and the message you write when you express interest in a listing.
  • Business contacts: name, job title, company, work email or phone where available, the public LinkedIn profile address, headline and location, notes on our conversations, and a record of what we sent and when.
  • Booking a call: your name, work email, company, the time you chose and anything you write about what you would like to talk about.
  • Everyone who visits: our server logs the IP address, time, requested page and browser type of each request. We use no analytics or tracking — see the cookie policy.
  • Passwords are handled by our login provider Supabase — we never see or store them ourselves.

Where business contact data comes from

If we contact you without you having signed up, we found your name and role on LinkedIn (including LinkedIn Sales Navigator), your company's website or public company registers. We only look for people whose role is plausibly related to buying or selling electricity.

Why we use it, and on what legal basis

  • Running your account and the marketplace — matching listings, showing public listings to other users, and writing to you about your account. Basis: the contract you enter into when you create an account (GDPR art. 6(1)(b)).
  • Introducing buyers and sellers. When you express interest in a listing, or someone expresses interest in yours, the broker passes your name and contact details to the other side so the two companies can talk. This is the service you signed up for (art. 6(1)(b)). Nobody sees the other side's identity on the platform itself.
  • Holding the call you booked — sending you the invitation and meeting you at the agreed time. Basis: steps you ask us to take before a possible agreement (art. 6(1)(b)).
  • Contacting businesses about PPAs — our legitimate interest in offering a relevant business service to people whose job it concerns (art. 6(1)(f)). You can object at any time, and we will stop.
  • Security — server logs are kept to detect and stop abuse and attacks. Basis: our legitimate interest in keeping the platform and its data safe (art. 6(1)(f)).

Matching on the platform only ranks listings by how well their terms fit. It makes no decision about you that has legal or similarly significant effects.

Who we share it with

We do not sell personal data or pass it on for anyone else's marketing. Besides the introductions described above, data is handled by these providers on our behalf:

  • Hostinger — the server that runs the platform and its database, in Frankfurt, Germany.
  • Supabase — login, and the emails that confirm your account and reset your password.
  • Google — our email and calendar (Google Workspace), which send the booking invitation, and Google Meet, where the call takes place.
  • GitHub — stores a nightly backup of the database. The backup is encrypted on our server before it is sent, so GitHub cannot read it.

Supabase, Google and GitHub are US companies. Where data may be accessed from outside the EU/EEA, the transfer relies on the EU–US Data Privacy Framework or the European Commission's standard contractual clauses. LinkedIn is its own data controller for messages we exchange there.

How long we keep it

  • Accounts: for as long as the account is open. When you delete it, your name, email and phone are erased straight away. If you were the last user from your company, the company name, company description and the text of its listings and messages are erased too, and its listings are taken off the marketplace. What remains — such as that a listing for 10 years of baseload once existed — can no longer be tied to you, and is kept only as statistics.
  • Business contacts who never become customers: deleted 12 months after our last contact, unless a conversation is still going. If you ask us not to contact you, we keep only your LinkedIn profile address or email, and only so we can make sure we never contact you again.
  • Booked calls: deleted from the platform 90 days after the call. The invitation and any emails stay in our mailbox and calendar like other business correspondence.
  • Server logs: overwritten automatically once they reach a fixed size — normally within a few weeks, sooner when traffic is high.
  • Backups: deleted after 90 days at the latest. Data you have had erased can therefore live on in an encrypted backup for up to 90 days. Should we ever have to restore one, we erase it again before the platform goes back online.

Your rights

You have the right to access the data we hold about you, to have it corrected or erased, to restrict our use of it, to receive it in a machine-readable format, and to object to our use of it — including an unconditional right to object to being contacted for marketing. We answer within one month.

You can delete your account yourself under My profile. For everything else, write to contact@symbolon.energy.

You may also complain to the data protection authority in your own country — in Denmark Datatilsynet (datatilsynet.dk), in Norway Datatilsynet (datatilsynet.no), in Sweden IMY (imy.se) and in Finland the Data Protection Ombudsman (tietosuoja.fi).

How we protect it

All traffic is encrypted (HTTPS). Other users never see who is behind a listing. Access to the database is limited to the broker, and backups are encrypted before they leave the server.