Data Protection
Last updated: June 2026This document complements the Privacy Policy of 33 Human AI and details our General Data Protection Regulation (EU) 2016/679 (GDPR) compliance framework, including the security measures we apply, how we manage sub-processors, our cookie policy, and the procedure for exercising your rights with the supervisory authority.
1. Applicable Legal Framework
The processing of personal data carried out by 33 Human AI is governed by:
- Regulation (EU) 2016/679 (GDPR) — General Data Protection Regulation.
- Spanish Organic Law 3/2018 (LOPDGDD) — on Personal Data Protection and digital rights guarantee.
- Directive (EU) 2016/680 — on data processed for law enforcement purposes (to the extent applicable).
- Spanish Law 34/2002 (LSSI) — on Information Society Services and Electronic Commerce, regarding cookies.
2. Principles Governing Our Processing
We apply the principles set out in Article 5 GDPR to every processing activity:
- Lawfulness, fairness and transparency — we always inform individuals about data processing before collecting their data.
- Purpose limitation — data is collected for specified purposes and not used for incompatible ones.
- Data minimisation — we only collect data that is strictly necessary.
- Accuracy — we keep data up to date and correct inaccuracies without delay.
- Storage limitation — data is deleted once it is no longer needed for the purpose it was collected.
- Integrity and confidentiality — we apply appropriate technical and organisational security measures.
- Accountability — we document and are able to demonstrate GDPR compliance.
3. Technical and Organisational Security Measures
3.1 Technical measures
- TLS 1.2+ encryption on all communications between the browser and our servers.
- Encryption at rest for all databases and storage systems.
- Role-based access control (RBAC): only authorised personnel can access personal data.
- Multi-factor authentication (MFA) on all systems containing personal data.
- Encrypted daily backups with quarterly restoration tests.
- Audit logs of access to systems containing personal data, retained for 12 months.
- Regular vulnerability assessments and timely application of security patches.
3.2 Organisational measures
- Annual data protection training for all staff with access to personal data.
- Confidentiality clauses in employment and collaboration contracts.
- Documented incident management and data breach notification procedure.
- Internal acceptable use policy for information systems.
- Record of Processing Activities (RoPA) maintained in accordance with Article 30 GDPR.
4. Sub-Processors
In accordance with Article 28 GDPR, third parties that process personal data on our behalf act as sub-processors and have signed a Data Processing Agreement (DPA). All sub-processors provide sufficient guarantees regarding appropriate technical and organisational measures:
| Provider | Service | Data location | Transfer safeguards |
|---|---|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure and voice processing | EU (eu-west-1, Ireland) | DPA + Standard Contractual Clauses |
| Twilio Inc. | Voice communications and messaging | EU where available | DPA + Standard Contractual Clauses |
| [Email provider] | Corporate email management | EU | DPA |
You may request an up-to-date list of sub-processors by writing to contact@33humanai.com.
5. Data Breach Management
We maintain an internal incident management procedure in accordance with Article 33 GDPR:
- Detection and identification — our monitoring systems detect anomalous access or incidents. The technical team assesses the scope and risk of the breach.
- Notification to the supervisory authority — where the breach is likely to result in a risk to the rights and freedoms of individuals, we notify the Agencia Española de Protección de Datos (AEPD) within 72 hours of becoming aware of it.
- Communication to data subjects — where the breach is likely to result in a high risk, we communicate this to affected individuals without undue delay.
- Documentation — we record all security breaches, including those that do not require notification, to comply with the accountability principle.
6. Data Protection Officer (DPO)
At present, the size and nature of our processing activities do not legally require the designation of a Data Protection Officer under Article 37 GDPR. However, we have appointed an internal privacy lead whom you may contact on any data protection matter:
Privacy Lead — 33 Human AI
contact@33humanai.com
Subject: "Privacy / Data Protection"
7. Cookie Policy
We use only strictly necessary technical cookies for the operation of the website. We do not use tracking, behavioural advertising, or third-party analytics cookies.
| Cookie | Type | Purpose | Duration |
|---|---|---|---|
33hai_theme | Technical / Preference | Store visual theme preference (light or dark mode) | 1 year |
As this cookie is strictly necessary to remember a display preference requested by the user, it does not require consent under Recital 25 of Directive 2002/58/EC and the AEPD's Cookie Use Guide.
You can delete this cookie at any time via your browser settings. Disabling it will not affect the functionality of the site.
8. Data Protection Impact Assessments (DPIA)
We carry out Data Protection Impact Assessments (DPIAs) in accordance with Article 35 GDPR whenever we introduce new processing activities that are likely to result in a high risk to individuals' rights and freedoms, in particular where processing involves:
- Large-scale processing of sensitive data.
- Systematic evaluation of personal data through profiling.
- Processing using new technologies with significant impact.
As our voice technology involves processing audio recordings that may contain personal information, we have carried out the relevant impact assessments for all voice processing modules.
9. How to Exercise Your Rights
You may exercise your rights of access, rectification, erasure, restriction, portability and objection:
By email: contact@33humanai.com
Subject: "GDPR Rights Request — [Right you wish to exercise]"
Attach: a copy of a valid identity document (passport, national ID, etc.)
We will respond within 30 calendar days. For complex or numerous requests, we may extend this period by a further 60 days, informing you accordingly.
Complaint to the supervisory authority
If you believe we have infringed your rights, you may lodge a complaint with the competent supervisory authority, without prejudice to any other administrative or judicial remedy:
- Agencia Española de Protección de Datos (AEPD)
- Website: www.aepd.es
- C/ Jorge Juan, 6, 28001 Madrid, Spain
- Phone: +34 901 100 099 / +34 912 663 517
You may also contact the supervisory authority in your EU country of residence or place of work. A list of EU supervisory authorities is available at edpb.europa.eu.
10. Updates to This Document
We review this document periodically to reflect changes in our practices, applicable legislation, or the services we offer. The current version will always be available on this page with the date of the last update shown at the top.
For further queries on data protection, please write to contact@33humanai.com.