Privacy Policy
Last updated: June 2026At 33 Human AI we are committed to protecting your privacy. This policy explains what data we collect, why we process it, and what your rights are under the General Data Protection Regulation (EU) 2016/679 (GDPR) and the Spanish Organic Law 3/2018 on Personal Data Protection (LOPDGDD).
1. Data Controller
| Company name | 33 Human AI, S.L. |
| Tax ID | [Company Tax ID] |
| Registered address | [Full registered address], Spain |
| contact@33humanai.com | |
| Website | https://33humanai.com |
2. Data We Collect
We only collect the data you provide to us or that is generated automatically when you browse our website:
2.1 Contact form
When you fill in the contact form, we process the following data:
- Full name — to identify you and personalise communication.
- Company — to understand the context of your enquiry.
- Email address — to reply to you.
- Phone number (optional) — if you prefer to be contacted by phone.
- Message — a description of your enquiry or interest.
2.2 Browsing data
Our server may automatically log your IP address, browser type, operating system, pages visited, and the date and time of access for security and technical maintenance purposes. This data is not linked to your personal identity unless required to investigate security incidents.
2.3 Cookies
We use a single session cookie (33hai_theme) to remember your visual theme preference (light or dark mode). This cookie contains no personally identifiable information and is not shared with third parties. For more information, see our Data Protection page.
3. Purpose and Legal Basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Handling your enquiry or demo request | Art. 6(1)(b) — steps taken at your request prior to entering a contract |
| Sending service information if you request it | Art. 6(1)(a) — your consent |
| Technical maintenance and site security | Art. 6(1)(f) — legitimate interests of the controller |
| Compliance with legal obligations | Art. 6(1)(c) — compliance with a legal obligation |
4. Retention Period
Contact form data is retained for as long as necessary to handle your enquiry and, once the relationship ends, for 3 years to address any potential claims, unless the law requires a longer period.
Technical browsing logs are automatically deleted after 12 months.
If you have given consent for marketing communications, we retain your data until you withdraw that consent.
5. Recipients and Data Processors
We do not sell or transfer your personal data to third parties for commercial purposes. We may share data with the following service providers, who act as data processors under contract:
- Amazon Web Services (AWS) — cloud hosting and processing infrastructure on EU servers (eu-west region).
- Corporate email provider — to manage replies to your enquiries.
- Web performance analytics tools — using anonymised or pseudonymised data only.
All processors have signed a Data Processing Agreement (DPA) in accordance with Article 28 GDPR.
6. International Data Transfers
As a general rule, your data is processed within the European Economic Area (EEA). Where any provider is located outside the EEA, we ensure that the transfer is subject to appropriate safeguards under the GDPR, such as Standard Contractual Clauses approved by the European Commission or an adequacy decision.
7. Your Rights
As a data subject, you may exercise the following rights at any time:
- Access — obtain confirmation of whether we process your data and a copy of it.
- Rectification — request correction of inaccurate or incomplete data.
- Erasure ("right to be forgotten") — request deletion of your data when it is no longer necessary.
- Restriction of processing — request that we suspend processing while a dispute is resolved.
- Data portability — receive your data in a structured, machine-readable format.
- Objection — object to processing based on our legitimate interests or for direct marketing.
- Withdrawal of consent — without affecting the lawfulness of processing before withdrawal.
To exercise any of these rights, send an email to contact@33humanai.com with the subject line "GDPR Rights Request", attaching a copy of a valid identity document. We will respond within 30 days.
If you believe we have infringed your rights, you may lodge a complaint with the Spanish supervisory authority, the Agencia Española de Protección de Datos (AEPD): www.aepd.es. You may also contact the supervisory authority in your country of residence within the EU.
8. Security
We apply appropriate technical and organisational measures to protect your data against unauthorised access, loss, destruction, or accidental disclosure. These include: TLS encryption on all communications, role-based access control, encrypted backups, and periodic security reviews.
9. Minors
Our services are directed at business professionals and companies. We do not knowingly collect data from individuals under 14 years of age. If you believe a minor has submitted data without authorisation, please contact us so we can delete it promptly.
10. Changes to This Policy
We may update this policy to reflect changes in our practices or applicable law. The current version will always be available on this page with the date of the last update. Where changes are material, we will notify you by email if we hold your contact details.
11. Contact
For any questions regarding this policy or the processing of your personal data:
33 Human AI, S.L.
[Registered address], Spain
contact@33humanai.com