Legal

Privacy Policy

Last updated · June 12, 2026

Citibox Boxco is built on a simple promise: your memory belongs to you. This policy explains what we collect, why we collect it, how we protect it, and the controls you have over it.

1. Who we are

Citibox Boxco SP SA (“Citibox Boxco”, “we”, “us”) is a Delaware corporation with offices in San Madrid, Spain. We operate the Citibox Boxco assistant, the citibox-boxco.com website and the Citibox Boxco dashboard. For privacy questions contact [email protected].

2. Data we collect

We collect only what is required to operate the assistant:

  • Account data — name, email, hashed password, billing country.
  • Memory data — notes, meetings, decisions and files you or your integrations send to Citibox Boxco.
  • Usage data — anonymised events used to detect errors and measure reliability.
  • Payment data — handled by our processors; we never store full card numbers.

3. How we use data

We use your data to run the service, personalise your assistant, process payments, prevent fraud, respond to support and comply with our legal obligations. We do not sell your data and we do not use your memory to train third-party foundation models.

4. Legal bases (GDPR)

We process personal data on the basis of contract (delivering the service you purchased), legitimate interest (security, fraud prevention, product improvement), consent (marketing emails, non-essential cookies) and legal obligation (tax, accounting).

5. Storage and security

Data is stored in ISO 27001 certified data centres in the EU. All data is encrypted in transit (TLS 1.3) and at rest (AES-256). Access is restricted to a small on-call team and every request is audited.

6. Sharing and subprocessors

We share limited data with vetted subprocessors: cloud hosting, email delivery, payment processing and error monitoring. A current list is available on request. We never share your memory with advertisers.

7. Retention

Account and memory data are kept while your account is active. When you delete your account, we erase your data within 30 days, except where retention is required by law (e.g. invoices — 10 years in the EU).

8. Your rights

You can access, correct, export or delete your data at any time from the dashboard, or by writing to [email protected]. You may also lodge a complaint with your local data protection authority.

9. Children

Citibox Boxco is not intended for people under 16. We do not knowingly collect data from children.

10. Changes

We will notify you of material changes by email at least 14 days before they take effect.

Questions about this policy? Write to [email protected]. We reply within two business days.