Global Privacy Policy
EntBox Ai Inc.
Effective date: July 31st, 2026 | Last updated: August 3rd, 2026
1. Introduction and Scope
EntBox Ai Inc. (“EntBox,” “we,” “us” or “our”) provides the BoxAI Platform and related websites and services (collectively, the “Services”). This Privacy Policy explains how we collect, use, disclose and protect Personal Data, and the rights and choices available to individuals. This is our single, universal global Privacy Policy — it is not tailored to any individual customer, and it is the policy our Master Services Agreement (and any other customer agreement) references when we commit to handle Personal Data in accordance with our Privacy Policy and applicable law. Capitalized terms not defined here have the meanings given in the Agreement.
Controller vs. processor. This Policy describes our practices where we act as a Controller — for example, Personal Data we collect from website visitors, prospective customers, job applicants, and the administrators and users of Customer accounts. Where our Customers submit Personal Data into the Platform for processing (e.g., their own end-customer records, tickets, or billing data), we act as a Processor on that Customer’s behalf, and that processing is governed by our Data Processing Addendum and the Customer is the Controller pursuant to its own privacy policy, not this one.
2. Who We Are and How to Reach Us
Data controller: EntBox Ai Inc., 2560 Anthem Village Drive, Ste 130, Henderson, NV 89052. For privacy questions or to exercise your rights, contact us at privacy@entbox.ai or the addresses in Section 16. Where we process EEA/UK personal data on behalf of a customer (as a Processor), that processing is governed by our Data Processing Addendum.
3. Personal Information We Collect
Depending on how you interact with us, we may collect the following categories of personal information — from you directly, automatically through your use of the Services, and from third parties such as our customers, recruiters and service providers:
| Category | Examples | Typical source |
|---|---|---|
| Identifiers & contact data | Name, email, phone, employer, job title, account username. | You; our customer (account admin). |
| Account & profile data | Login credentials, roles/permissions, preferences, support history. | You; the Services. |
| Billing & transaction data | Billing contact, plan, invoices. Fees are invoiced (ACH/wire/check); we do not process card data. | You. |
| Usage & device data | IP address, device/browser, log data, pages viewed, feature usage. | Automatic via the Services. |
| Communications | Emails, support tickets, chat, and call transcripts, voice content and AI-generated summaries where applicable. | You; communications providers. |
| Marketing data | Marketing preferences, event/webinar registrations. | You; marketing tools. |
| Recruitment & hiring data | For job applicants and prospective/current employees and contractors: contact details, CV/résumé, employment and education history, skills, references, interview notes and assessments, and right-to-work / eligibility information. | You (applicant); recruiters/agencies; references. |
We collect recruitment & hiring data to evaluate applications and manage the recruitment, hiring and onboarding of employees and contractors, including future and prospective personnel. We do not intentionally collect special-category / sensitive personal information through our own Controller activities. We do not direct the Services to children (see Section 13). We do not collect or use biometric identifiers (such as voiceprints or faceprints) to identify individuals in providing the Services.
4. How We Use Personal Information
- Provide, operate, maintain and secure the Services and customer accounts;
- Authenticate users, manage access, and prevent fraud and abuse;
- Process billing, invoicing and payments;
- Provide customer support and respond to enquiries;
- Recruit, evaluate and onboard employees and contractors, and manage applications and the hiring process;
- Communicate about the Services, including service and security notices, and — where permitted — marketing;
- Analyze and improve the Services, including aggregated and de-identified analytics;
- Comply with legal obligations and enforce our agreements; and
- Other purposes disclosed at the point of collection or with your consent.
5. Legal Bases for Processing (EEA / UK)
Where the GDPR or UK GDPR applies, we rely on the following legal bases:
| Purpose | Legal basis |
|---|---|
| Providing and operating the Services; account administration; billing | Performance of a contract (Art. 6(1)(b)). |
| Security, fraud prevention, service improvement, basic analytics | Legitimate interests (Art. 6(1)(f)). |
| Recruitment and hiring of employees and contractors | Steps prior to entering a contract and/or legitimate interests (Art. 6(1)(b)/(f)); legal obligation (Art. 6(1)(c)) where applicable, e.g., right-to-work checks. |
| Marketing communications | Consent (Art. 6(1)(a)), where required. |
| Legal, tax and regulatory compliance | Legal obligation (Art. 6(1)(c)). |
6. AI Features and Automated Processing
The BoxAI Platform uses artificial-intelligence and large-language-model technology to provide its features. The following describes our approach; for Personal Data processed inside the Platform on a Customer’s behalf, the DPA and the Model-Provider terms control.
- AI Providers. The Services send inputs — which may include support queries and knowledge-base content — to our AI subprocessors to generate responses, including for knowledge-base retrieval (RAG), which is an active feature. Our AI subprocessors are identified in the subprocessor table in Section 8.
- Training. As of the Last updated date of this Policy, we do not use your Personal Data to train AI models.
- Accuracy. AI outputs are probabilistic and may be inaccurate or incomplete; they are intended to be reviewed by a human before reliance.
- Automated decision-making. We do not use the Services to make decisions producing legal or similarly significant effects about individuals based solely on automated processing without human involvement. Where AI features assist a decision, a human reviews the output before any action is taken. Individuals in the EEA/UK have the right not to be subject to solely automated decisions with legal or similarly significant effect, and, where applicable state law provides, you may have the right to opt out of certain profiling; to exercise these rights, contact us as described in Section 16.
7. Cookies and Similar Technologies
Our website uses cookies and similar technologies (such as local storage) only as necessary to operate the site, maintain security and session integrity, and keep you signed in where you have an account. Cookies are small text files placed on your device; similar technologies perform comparable functions.
We do not use cookies or similar technologies for advertising, cross-site tracking, or behavioral profiling. We do not use cookies to sell Personal Data or to "share" it for cross-context behavioral advertising.
Because we set only strictly necessary cookies, we do not display a consent banner. You can block or delete cookies through your browser settings; doing so may affect how the site functions. If we introduce analytics, functional or other non-essential cookies in future, we will update this Policy and, where required by law, obtain your consent before those cookies are set.
8. How We Disclose Personal Data
We disclose Personal Data to service providers and subprocessors that perform functions on our behalf, to corporate affiliates, in connection with a corporate transaction, to comply with law, and with your consent. We do not sell Personal Data.
Key service providers and subprocessors include:
| Subprocessor | Function |
|---|---|
| Google Cloud Platform (Google LLC) | Cloud hosting and infrastructure (US regions); each customer tenant is provisioned in its own Google Cloud project. |
| Anthropic | AI model inference (Claude): support, agent-search, and knowledge-base retrieval responses. |
| OpenAI | AI embeddings for knowledge-base retrieval (RAG); ingested knowledge-base and support content, and end-user search queries. |
| Deepgram | Speech-to-text and text-to-speech for the voice/IVR product, where enabled. |
| Twilio | Telephony/voice (IVR), SMS and click-to-call, where enabled. |
| Resend | Outbound customer email, where enabled. |
| Google (Gmail API) | Outbound customer email for tenants configured to send via Gmail, where enabled. |
| GoHighLevel | CRM synchronization (contact records, opportunity/pipeline stage, tags), where enabled. |
| Google Maps Platform | Address geocoding, where enabled; full customer service addresses. |
| Slack | Delivery of notification content to a customer or Entbox workspace, where enabled. |
| US Census Geographic Coder | Address geocoding fallback where no Maps key is configured; customer service addresses. |
9. International Data Transfers
We are based in the United States and process Personal Data in the U.S. (our cloud regions are in the United States). Where we process Personal Data on behalf of a Customer that includes EEA, UK or Swiss Personal Data, that processing is governed by our Data Processing Addendum, and transfers rely on appropriate safeguards, including the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum.
10. Data Retention
We retain Personal Data for as long as necessary to fulfill the purposes described in this Policy. As general guidance: Customer account and Services data is retained for the term of the Customer Agreement and for a limited period afterwards, in accordance with the Customer Agreement; database backups cycle out on an approximately 7-day schedule; website, prospect and marketing data is retained until no longer needed or until you opt out; and data of unsuccessful job applicants is retained for approximately 12 months. We may retain information longer where required by law or to resolve disputes or enforce our agreements.
11. Security and Data Breach Notification
We maintain an information-security program with administrative, technical and physical safeguards designed to protect Personal Data against unauthorized access, use, disclosure, alteration and destruction. Our Services are hosted on Google Cloud Platform. These safeguards include encryption of Personal Data at rest (AES-256) and in transit (TLS 1.2+ at the public edge, with enforced SSL on all customer production database connections), role-based access controls, and the technical and organizational measures described in our Data Processing Addendum, overseen by our security lead. As of the date of this Policy we are working toward SOC 2 and ISO/IEC 27001 certification but have not completed a SOC 2 audit or an ISO/IEC 27001 certification; we do not represent certification until obtained. No method of transmission or storage is completely secure.
If we become aware of a Personal Data breach affecting your Personal Data, we will investigate, take steps to mitigate it, and notify affected individuals, applicable authorities and affected customers without undue delay and as required by applicable law. Where we act as a Processor on a Customer’s behalf, we will notify that Customer without undue delay in accordance with the DPA so they can meet their own notification obligations.
12. Your Privacy Rights and Choices
Subject to applicable law and verification of your identity, you may have rights to access, correct, delete, port, restrict or object to the processing of your Personal Data, and to withdraw consent. To exercise rights, contact us as described in Section 16. We will not discriminate against you for exercising your rights.
12(a). EEA, UK and Switzerland
If you are in the EEA, UK or Switzerland, you have the rights described above under the GDPR / UK GDPR, including the right to lodge a complaint with your supervisory authority. Where processing is based on consent, you may withdraw it at any time without affecting prior processing.
12(b). California (CCPA / CPRA)
California residents have the right to know the categories and specific pieces of Personal Data we collect, the right to delete and to correct, and the right to opt out of the “sale” or “sharing” of Personal Data and to limit use of sensitive Personal Data. We do not sell Personal Data and do not “share” it for cross-context behavioral advertising. The categories we collect and disclose are described in Sections 3 and 8. You may use an authorized agent to submit requests.
12(c). Other U.S. states and jurisdictions
Residents of other U.S. states with comprehensive privacy laws, and individuals in other jurisdictions, may have similar rights, including rights to access, correct, delete and opt out of certain processing. We honor these rights as applicable law requires.
13. Children’s Privacy
The Services are not directed to children and are intended for business use only. We do not knowingly collect Personal Data from children under 18. If you believe a child has provided us Personal Data, contact us and we will take appropriate steps to delete it.
14. Third-Party Links and Services
The Services may link to third-party websites and services that we do not control. Their privacy practices are governed by their own policies, and we are not responsible for them.
15. Changes to This Policy
We may update this Policy from time to time. We will post the updated version with a new “Last updated” date and, where required, provide additional notice. Prior versions of this Policy are available on request at privacy@entbox.ai. Your continued use of the Services after an update constitutes acceptance of the revised Policy to the extent permitted by law.
16. How to Contact Us
- Privacy enquiries and rights requests: privacy@entbox.ai
- Postal: EntBox Ai Inc., 2560 Anthem Village Drive, Ste 130, Henderson, NV 89052