Privacy & Cookie Policy

Effective Date: 30/08/2024

Last Updated: 17/03/2026

This Privacy & Cookie Policy explains how BBOX AI Limited, a company registered in Malta (company number C 109598) with its registered office at Level 3, Tower Business Centre, Triq IT-Torri, Swatar, Birkirkara, BKR 4013, Malta (“BBOX AI”, “we”, “our” or “us”), collects, uses, stores, shares, and otherwise processes personal data, including through the use of cookies and similar technologies.

This policy applies when you visit our website, interact with us as a business contact, communicate with us, create or administer an account, or otherwise engage with us in connection with our business and services.

1. Who We Are

BBOX AI provides enterprise messaging, automation, and related data-processing services to business clients.

BBOX AI acts as a data controller in relation to personal data processed for its own purposes, including website operation, account administration, business communications, onboarding, support, compliance, security, fraud prevention, billing, and marketing where permitted by law.

BBOX AI acts as a data processor where it processes personal data solely on behalf of its clients in connection with the services provided to them.

2. What Personal Data We Collect

You Provide:

  • Name, company name, job title

  • Email address, phone number

  • Messages or requests via forms or email

Automatically Collected:

  • IP address, browser type, device, session logs

  • Page visits, duration, interaction data

  • Cookies and similar technologies

From Third Parties, where lawful and relevant:

  • Public business sources and directories

  • Events or marketing partners, or referrals

  • Service providers or integrations used in connection with our services

3. How We Use Personal Data

We use your data to:

  • Provide and maintain our website and platform

  • Enable delivery of messages through telecom partners

  • Validate phone numbers for deliverability

  • Handle opt-out preferences and subscription controls

  • Respond to inquiries and provide support

  • Monitor service performance and prevent abuse

  • Fulfil legal, regulatory and contractual obligations

4. Legal Bases for Processing

We process personal data on one or more of the following legal bases:

Contractual necessity – where processing is necessary to provide our website, platform, or services, or to take steps prior to entering into a contract.

Legitimate interests – including operating, securing, improving, and administering our website, platform, and services; managing business relationships; validating data quality; preventing fraud and abuse; and carrying out limited B2B communications where permitted by law.

Consent – where consent is required by law, including for non-essential cookies and certain marketing communications.

Legal obligations – where processing is necessary to comply with applicable legal, regulatory, accounting, telecom, or compliance obligations.

You may withdraw your consent at any time by contacting privacy@b-box.ai or through the relevant consent management tool where available.

5. Number Validation & Data Quality

To support service quality, deliverability, fraud prevention, and operational efficiency, we may process contact data using automated validation tools, including checks on formatting, routing, or reachability.

Where such processing is carried out for BBOX AI’s own service integrity, security, or business administration purposes, the legal basis is our legitimate interests. Where such processing is carried out solely on behalf of a client as part of the services, BBOX AI acts as processor in accordance with the applicable client arrangement.

6. Opt-Out and Subscription Management

Our platform may support unsubscribe mechanisms, including links, reply keywords, or similar controls, depending on the relevant channel and service configuration. Opt-out events may be processed and, where applicable, communicated to clients through reporting or callback functionality. Opt-out preferences may be stored for as long as reasonably necessary to honour such preferences and prevent further messaging, subject to applicable law.

7. APIs and Callbacks

Our APIs allow clients to:

  • Send and receive messages

  • Manage delivery reports and opt-outs

  • Validate phone numbers

Clients are responsible for securely configuring and protecting API credentials and callback URLs.

8. Data Sharing and International Transfers

We may share personal data with:

  • Hosting and cloud infrastructure providers

  • Telecom carriers and message aggregators

  • CRM, analytics and automation platforms

  • Legal or regulatory authorities (where required)

If we transfer personal data outside the European Economic Area, we will ensure that such transfer is carried out in accordance with applicable data protection law and subject to an appropriate transfer mechanism, including an adequacy decision, Standard Contractual Clauses, or another valid safeguard where required.

9. Data Retention

We retain personal data only as long as necessary:

Data Type

Retention Period

Contact and account data

3 years after last activity

Message logs and metadata

12 months (default)

Cookie and analytics data

As set out in our cookie banner, cookie settings tool, or otherwise for the period technically necessary for the relevant cookie or analytics purpose

Legal and compliance records

As required by law

 

Cookie retention periods may vary depending on the relevant cookie and are communicated through our cookie banner, consent tool, or browser-level cookie information where applicable.

10. Your Rights

Subject to applicable law, you may have the right to:

  • Access your personal data

  • Request rectification of inaccurate or incomplete data

  • Request erasure of your personal data

  • Request restriction of processing

  • Object to processing, including for direct marketing

  • Request data portability

  • Withdraw consent at any time where processing is based on consent

To exercise these rights, please contact: privacy@b-box.ai

If your personal data is processed by BBOX AI solely on behalf of one of our clients, you should contact that client in the first instance, as they act as the relevant controller for that processing.

You may also lodge a complaint with the competent supervisory authority. In Malta, this is the Information and Data Protection Commissioner (IDPC): https://idpc.org.mt

11. Cookie Usage

Cookies are small files stored on your device to support website functionality, security, preferences, analytics, and, where permitted, marketing activities.
We use essential cookies where necessary for the operation of the website or platform. We use non-essential cookies, including analytics and marketing cookies, only where required consent has been obtained through our cookie banner or consent management tool.

a) Types of Cookies:

  • Essential cookiesRequired for platform login, security, and core functions

  • Functional cookiesStore user settings and preferences

  • Analytics cookiesTrack website usage (e.g., via Google Analytics)

  • Marketing cookiesTrack interaction with emails and ads (e.g., LinkedIn)

b) Third-Party Cookies:

Some cookies are set by services such as:

  • Google Analytics

  • LinkedIn

  • CRM or email marketing providers

c) Cookie Management:

You can manage or withdraw your cookie preferences at any time through our cookie banner or consent management tool, where available. You may also control or delete cookies through your browser settings, although this may affect website functionality.

12. Security

We implement appropriate technical and organisational measures designed to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction, damage, or disclosure. Such measures may include encryption in transit, access controls, logging, monitoring, and other security measures appropriate to the nature of the data and services.

Despite these efforts, no system can be guaranteed to be completely secure. We will respond to personal data breaches as required by applicable law.

13. Communication

We may contact you in connection with your account, your use of our services, your inquiries, compliance matters, or other business-related communications. Where required by law, marketing communications will be sent only on the basis of the appropriate legal basis, and you may opt out at any time.

14. Policy Changes

We may revise this document periodically. The updated version will be published with a new “Last Updated” date at the top of this page.

15. Contact Information

BBOX AI Limited
Company Number: C 109598
Address:
Level 3, Tower Business Centre
Triq IT-Torri, Swatar
Birkirkara, BKR 4013
Malta

Email: privacy@b-box.ai | info@b-box.ai