1.Introduction#
Boxcurve S.L. ("we", "our", or "us") is an AI governance infrastructure company based in Spain. We provide platform and advisory services to regulated enterprises governing AI adoption. We are committed to protecting your privacy and ensuring the security of your personal data. We do not sell your personal information to any party, under any circumstances.
This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website boxcurve.com or use our services as a customer.
We comply with the General Data Protection Regulation (GDPR) (EU) 2016/679, the Spanish Organic Law 3/2018 on Personal Data Protection and Digital Rights Guarantee (LOPDGDD), Regulation (EU) 2024/1689 (the EU AI Act), and other applicable data protection laws. By accessing or using our services, you acknowledge that you have read and understood this policy.
2.Data Controller#
The data controller responsible for your personal data is:
3.Information We Collect#
3.1 Personal Data
We may collect personal information that you voluntarily provide to us when you:
- Request information about our platform or advisory services
- Fill out a contact form or inquiry form
- Subscribe to our newsletter or updates
- Request a working session, briefing, or proposal
- Enter into a service agreement with us
- Apply for employment opportunities
This information may include:
- Full name and surname
- Email address
- Phone number
- Company name and VAT number
- Job title and professional information
- Project requirements and operational context
- Billing and payment information (when applicable)
3.2 Automatically Collected Data
When you visit our website, we may automatically collect certain information about your device and usage patterns through cookies and similar technologies:
- IP address and approximate location
- Browser type and version
- Operating system
- Referring website
- Pages viewed and time spent on pages
- Date and time of access
- Device information and unique identifiers
4.How We Use Your Information#
We use the information we collect for the following purposes:
- Providing platform and advisory services
- Responding to your inquiries and project requests
- Preparing and sending proposals
- Managing customer relationships and engagements
- Sending service-related communications and updates
- Improving our website, services, and user experience
- Analysing usage patterns and market trends
- Marketing our services (with your consent)
- Complying with legal and tax obligations under Spanish law
- Protecting our rights and preventing fraud
You may withdraw consent to marketing communications at any time by clicking the unsubscribe link in any marketing email we send, or by emailing privacy@boxcurve.com. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
5.Our Role as Controller and Processor#
This Privacy Policy describes how Boxcurve processes personal data as a data controller in the context of our website, marketing activities, and direct customer relationships.
When Boxcurve processes personal data on behalf of customers through our platform (Unity, Uvid, Bienterra), we act as a data processor governed by a separate Data Processing Agreement (DPA) entered into with each customer. The terms of that DPA, not this policy, govern that processing.
This distinction matters: customer-controlled data processed through our platform remains under the customer's control and within their sovereign environment. Boxcurve does not access, use, or repurpose customer data outside the scope of the DPA.
6.Use of AI in our Processing#
As an AI governance company, transparency about our own use of AI is fundamental to who we are.
6.1 We do not use your data to train AI models.
We do not use personal data collected through our website, our marketing, or our customer relationships to train, fine-tune, or improve our AI models. Customer-controlled data processed through our platform under a Data Processing Agreement is never used for model training.
6.2 AI in our own operations.
Where we use AI tools to process visitor or customer relationship data (for example, in customer support, sales operations, or internal workflow tools), we do so in accordance with Article 22 GDPR. We do not make decisions producing legal or similarly significant effects based solely on automated processing of your personal data.
6.3 EU AI Act compliance.
Boxcurve complies with Regulation (EU) 2024/1689 (the EU AI Act) in the design, development, and deployment of its products and in its own use of AI systems.
7.Legal Basis for Processing#
We process your personal data based on the following legal grounds under GDPR:
- Consent (Article 6.1.a GDPR): For marketing communications and non-essential cookies.
- Contract (Article 6.1.b GDPR): To provide our platform and advisory services.
- Legal Obligations (Article 6.1.c GDPR): To comply with Spanish tax, accounting, and business laws.
- Legitimate Interests (Article 6.1.f GDPR): For business development, security, and service improvement, balanced against your rights.
8.Cookies and Similar Technologies#
We use cookies in compliance with Spanish Law 34/2002 on Information Society Services (LSSI). Our website uses the following types of cookies:
- Strictly Necessary Cookies: Essential for website functionality (no consent required).
- Preference Cookies: Remember your settings and preferences.
- Analytics Cookies: Help us understand website usage.
- Marketing Cookies: Used for targeted advertising (only with consent).
You can manage your cookie preferences through our cookie banner or your browser settings. For full details, see our Cookie Policy.
9.Data Sharing and Disclosure#
We do not sell your personal information.
We may share your information with:
- Service Providers: Cloud hosting (Microsoft Azure, AWS), email services, analytics providers, and other vendors who assist our operations under contract.
- Professional Advisors: Lawyers, accountants, and auditors bound by professional confidentiality.
- Business Partners: Only with your explicit consent for joint projects or services.
- Legal Authorities: When required by Spanish law, court orders, or to protect our rights.
- Business Transfers: In the case of merger, acquisition, or sale of assets.
All data transfers outside the EEA are protected by appropriate safeguards described in Section 13.
10.Data Retention#
We retain your personal data according to the following criteria:
- Customer Data: Duration of the business relationship plus 6 years (Spanish commercial law requirements under Codigo de Comercio Article 30).
- Tax Records: Minimum of 4 years from the end of the relevant tax year (Spanish General Tax Law).
- Marketing Contacts: Until you unsubscribe or after 3 years of inactivity.
- Job Applications: 1 year after the recruitment process ends.
- Website Analytics: 26 months.
After the applicable retention period, personal data is deleted or anonymised securely.
11.Your Data Protection Rights#
Under GDPR and LOPDGDD, you have the following rights:
- Right to Access: Obtain confirmation and a copy of your personal data.
- Right to Rectification: Correct inaccurate or incomplete data.
- Right to Erasure ("Right to be Forgotten"): Request deletion of your data in certain circumstances.
- Right to Restrict Processing: Limit how we use your data.
- Right to Data Portability: Receive your data in a structured, machine-readable format.
- Right to Object: Oppose processing based on legitimate interests or direct marketing.
- Right to Withdraw Consent: Withdraw consent at any time without affecting prior processing.
- Right Not to be Subject to Automated Decision-Making: Not be subject to decisions based solely on automated processing.
To exercise these rights, submit a data protection request or email us at privacy@boxcurve.com.
We will respond to your request within one month of receipt, in accordance with Article 12(3) GDPR. Where requests are complex or numerous, we may extend this period by a further two months and will inform you of the extension within the first month.
We may request additional information to verify your identity where there are reasonable doubts that you are the data subject. Identity verification will be proportionate and consistent with the principle of data minimisation.
12.Data Security#
We implement appropriate technical and organisational measures to protect your personal data, including encryption in transit and at rest, role-based access controls, regular security assessments, and staff training. Our security measures align with the Spanish National Security Scheme (ENS) and recognised industry standards (ISO 27001).
Our systems are designed with privacy and security as foundational principles, including data minimisation, purpose limitation, secure development practices, and continuous monitoring.
Breach notification. In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the AEPD within 72 hours of becoming aware of the breach in accordance with Article 33 GDPR. Where required under Article 34 GDPR, we will also notify affected individuals without undue delay.
However, no internet transmission is completely secure, and we cannot guarantee absolute security.
13.International Data Transfers#
Your data may be transferred outside the EEA for service provision, including to our cloud and software service providers. We ensure appropriate safeguards through:
- Adequacy decisions by the European Commission for transfers to recognised countries (including the United Kingdom, Switzerland, Japan, and others).
- The EU-US Data Privacy Framework for transfers to certified US recipients, in accordance with the European Commission's adequacy decision of 10 July 2023 and updated EDPB guidance.
- EU Standard Contractual Clauses (2021) for transfers to countries without an adequacy decision.
- Binding Corporate Rules where applicable.
Where required, we conduct Transfer Impact Assessments to evaluate the level of protection in the recipient country.
14.Children's Privacy#
Our services are not intended for individuals under 14 years of age (the age of digital consent in Spain under LOPDGDD Article 7). We do not knowingly collect personal data from children. If you become aware that a child has provided us with personal data, please contact us immediately at privacy@boxcurve.com.
15.Changes to This Privacy Policy#
We may update this Privacy Policy to reflect changes in our practices, technologies, legal requirements, or for other operational reasons. We will notify you of material changes through our website or by email. The "Last updated" date at the top indicates the most recent revision.
16.Contact Us#
For any questions, concerns, or to exercise your rights regarding this Privacy Policy or our data practices, please contact us:
This Privacy Policy is available in Spanish on request. Contact privacy@boxcurve.com.
17.Supervisory Authority#
If you are not satisfied with our response or believe we are processing your data unlawfully, you have the right to lodge a complaint with: