Privacy Policy

Last updated: June 2026

1. Data Controller

2. Data We Collect

We only collect the data you provide to us or that is generated automatically when you browse our website:

2.1 Contact form

When you fill in the contact form, we process the following data:

2.2 Browsing data

Our server may automatically log your IP address, browser type, operating system, pages visited, and the date and time of access for security and technical maintenance purposes. This data is not linked to your personal identity unless required to investigate security incidents.

2.3 Cookies

We use a single session cookie (33hai_theme) to remember your visual theme preference (light or dark mode). This cookie contains no personally identifiable information and is not shared with third parties. For more information, see our Data Protection page.

3. Purpose and Legal Basis

4. Retention Period

Contact form data is retained for as long as necessary to handle your enquiry and, once the relationship ends, for 3 years to address any potential claims, unless the law requires a longer period.

Technical browsing logs are automatically deleted after 12 months.

If you have given consent for marketing communications, we retain your data until you withdraw that consent.

5. Recipients and Data Processors

We do not sell or transfer your personal data to third parties for commercial purposes. We may share data with the following service providers, who act as data processors under contract:

All processors have signed a Data Processing Agreement (DPA) in accordance with Article 28 GDPR.

6. International Data Transfers

As a general rule, your data is processed within the European Economic Area (EEA). Where any provider is located outside the EEA, we ensure that the transfer is subject to appropriate safeguards under the GDPR, such as Standard Contractual Clauses approved by the European Commission or an adequacy decision.

7. Your Rights

As a data subject, you may exercise the following rights at any time:

To exercise any of these rights, send an email to contact@33humanai.com with the subject line "GDPR Rights Request", attaching a copy of a valid identity document. We will respond within 30 days.

If you believe we have infringed your rights, you may lodge a complaint with the Spanish supervisory authority, the Agencia Española de Protección de Datos (AEPD): www.aepd.es. You may also contact the supervisory authority in your country of residence within the EU.

8. Security

We apply appropriate technical and organisational measures to protect your data against unauthorised access, loss, destruction, or accidental disclosure. These include: TLS encryption on all communications, role-based access control, encrypted backups, and periodic security reviews.

9. Minors

Our services are directed at business professionals and companies. We do not knowingly collect data from individuals under 14 years of age. If you believe a minor has submitted data without authorisation, please contact us so we can delete it promptly.

10. Changes to This Policy

We may update this policy to reflect changes in our practices or applicable law. The current version will always be available on this page with the date of the last update. Where changes are material, we will notify you by email if we hold your contact details.

11. Contact

For any questions regarding this policy or the processing of your personal data:

Privacy Policy | 33 Human AI