Data Protection

Last updated: June 2026

1. Applicable Legal Framework

The processing of personal data carried out by 33 Human AI is governed by:

2. Principles Governing Our Processing

We apply the principles set out in Article 5 GDPR to every processing activity:

3. Technical and Organisational Security Measures

3.1 Technical measures

3.2 Organisational measures

4. Sub-Processors

In accordance with Article 28 GDPR, third parties that process personal data on our behalf act as sub-processors and have signed a Data Processing Agreement (DPA). All sub-processors provide sufficient guarantees regarding appropriate technical and organisational measures:

You may request an up-to-date list of sub-processors by writing to contact@33humanai.com.

5. Data Breach Management

We maintain an internal incident management procedure in accordance with Article 33 GDPR:

  1. Detection and identification — our monitoring systems detect anomalous access or incidents. The technical team assesses the scope and risk of the breach.
  2. Notification to the supervisory authority — where the breach is likely to result in a risk to the rights and freedoms of individuals, we notify the Agencia Española de Protección de Datos (AEPD) within 72 hours of becoming aware of it.
  3. Communication to data subjects — where the breach is likely to result in a high risk, we communicate this to affected individuals without undue delay.
  4. Documentation — we record all security breaches, including those that do not require notification, to comply with the accountability principle.

6. Data Protection Officer (DPO)

At present, the size and nature of our processing activities do not legally require the designation of a Data Protection Officer under Article 37 GDPR. However, we have appointed an internal privacy lead whom you may contact on any data protection matter:

7. Cookie Policy

We use only strictly necessary technical cookies for the operation of the website. We do not use tracking, behavioural advertising, or third-party analytics cookies.

As this cookie is strictly necessary to remember a display preference requested by the user, it does not require consent under Recital 25 of Directive 2002/58/EC and the AEPD's Cookie Use Guide.

You can delete this cookie at any time via your browser settings. Disabling it will not affect the functionality of the site.

8. Data Protection Impact Assessments (DPIA)

We carry out Data Protection Impact Assessments (DPIAs) in accordance with Article 35 GDPR whenever we introduce new processing activities that are likely to result in a high risk to individuals' rights and freedoms, in particular where processing involves:

As our voice technology involves processing audio recordings that may contain personal information, we have carried out the relevant impact assessments for all voice processing modules.

9. How to Exercise Your Rights

You may exercise your rights of access, rectification, erasure, restriction, portability and objection:

We will respond within 30 calendar days. For complex or numerous requests, we may extend this period by a further 60 days, informing you accordingly.

Complaint to the supervisory authority

If you believe we have infringed your rights, you may lodge a complaint with the competent supervisory authority, without prejudice to any other administrative or judicial remedy:

You may also contact the supervisory authority in your EU country of residence or place of work. A list of EU supervisory authorities is available at edpb.europa.eu.

10. Updates to This Document

We review this document periodically to reflect changes in our practices, applicable legislation, or the services we offer. The current version will always be available on this page with the date of the last update shown at the top.

For further queries on data protection, please write to contact@33humanai.com.

Data Protection | 33 Human AI