Enterprise Box AI
PlatformCompareProductsProcessWhy Us
PrivacyGet Started

BoxAI Global Privacy Policy

EntBox Ai Inc.

Effective date: July 14, 2026 | Last updated: July 14, 2026

1. Introduction and Scope

EntBox Ai Inc. (“EntBox,” “we,” “us” or “our”) provides the BoxAI platform and related websites and services (collectively, the “Services”). This Privacy Policy explains how we collect, use, disclose and protect personal information, and the rights and choices available to individuals. This is our single, universal global Privacy Policy — it is not tailored to any individual customer, and it is the policy our customer agreements reference when we commit to handle data in accordance with our Privacy Policy and applicable law.

Controller vs. processor. This Policy describes our practices where we act as a controller — for example, personal information we collect from website visitors, prospective customers, job applicants, and the administrators and users of customer accounts. Where our business customers submit personal data into the platform for processing (e.g., their own end-customer records, tickets, or billing data), we act as a processor on that customer’s behalf, and that processing is governed by our Data Processing Addendum and the customer’s own privacy notices — not by this Policy.

2. Who We Are and How to Reach Us

Data controller: EntBox Ai Inc., 11500 S Eastern Ave, Ste 150, Henderson, NV 89052. For privacy questions or to exercise your rights, contact us at privacy@entbox.ai or the addresses in Section 16. Where we process EEA/UK personal data on behalf of a customer (as a processor), that processing is governed by our Data Processing Addendum.

3. Personal Information We Collect

Depending on how you interact with us, we may collect the following categories of personal information — from you directly, automatically through your use of the Services, and from third parties such as our customers, recruiters and service providers:

CategoryExamplesTypical source
Identifiers & contact dataName, email, phone, employer, job title, account username.You; our customer (account admin).
Account & profile dataLogin credentials, roles/permissions, preferences, support history.You; the Services.
Billing & transaction dataBilling contact, plan, invoices. Fees are invoiced (ACH/wire/check); we do not process card data.You.
Usage & device dataIP address, device/browser, log data, pages viewed, feature usage.Automatic via the Services.
CommunicationsEmails, support tickets, chat, call/voice metadata where applicable.You; communications providers.
Marketing dataMarketing preferences, event/webinar registrations.You; marketing tools.
Recruitment & hiring dataFor job applicants and prospective/current employees and contractors: contact details, CV/résumé, employment and education history, skills, references, interview notes and assessments, and right-to-work / eligibility information.You (applicant); recruiters/agencies; references.

We collect recruitment & hiring data to evaluate applications and manage the recruitment, hiring and onboarding of employees and contractors, including future and prospective personnel. We do not intentionally collect special-category / sensitive personal information through our own controller activities. We do not direct the Services to children (see Section 13).

4. How We Use Personal Information

  • Provide, operate, maintain and secure the Services and customer accounts;
  • Authenticate users, manage access, and prevent fraud and abuse;
  • Process billing, invoicing and payments;
  • Provide customer support and respond to enquiries;
  • Recruit, evaluate and onboard employees and contractors, and manage applications and the hiring process;
  • Communicate about the Services, including service and security notices, and — where permitted — marketing;
  • Analyze and improve the Services, including aggregated and de-identified analytics;
  • Comply with legal obligations and enforce our agreements; and
  • Other purposes disclosed at the point of collection or with your consent.

5. Legal Bases for Processing (EEA / UK)

Where the GDPR or UK GDPR applies, we rely on the following legal bases:

PurposeLegal basis
Providing and operating the Services; account administration; billingPerformance of a contract (Art. 6(1)(b)).
Security, fraud prevention, service improvement, basic analyticsLegitimate interests (Art. 6(1)(f)).
Recruitment and hiring of employees and contractorsSteps prior to entering a contract and/or legitimate interests (Art. 6(1)(b)/(f)); legal obligation (Art. 6(1)(c)) where applicable, e.g., right-to-work checks.
Marketing communicationsConsent (Art. 6(1)(a)), where required.
Legal, tax and regulatory complianceLegal obligation (Art. 6(1)(c)).

6. AI Features and Automated Processing

The BoxAI platform uses artificial-intelligence and large-language-model technology to provide its features. The following describes our approach; for personal data processed inside the platform on a customer’s behalf, the DPA and the Model-Provider terms control.

  • Model provider. The Services send inputs — which may include support queries and knowledge-base content — to our AI model provider, Anthropic, to generate responses, including for knowledge-base retrieval (RAG), which is an active feature. We do not log full prompts or responses.
  • Training. As of the effective date of your agreement, we do not use your data to train AI models, and we do not permit our AI model provider to use data transmitted through the Services to train its models; such data is processed at inference time only.
  • Accuracy. AI outputs are probabilistic and may be inaccurate or incomplete; they are intended to be reviewed by a human before reliance.

7. How We Disclose Personal Information

We disclose personal information to service providers and subprocessors that perform functions on our behalf, to corporate affiliates, in connection with a corporate transaction, to comply with law, and with your consent. We do not sell personal information.

Key service providers / subprocessors (we maintain an up-to-date subprocessor list consistent with the DPA):

ProviderFunction
Google Cloud Platform (Google LLC)Cloud hosting and infrastructure (US regions); per-tenant project isolation.
AnthropicAI model inference (Claude) for support, agent-search and knowledge-base retrieval.
TwilioTelephony / voice (IVR), where enabled.
ResendOutbound customer email, where enabled.

8. International Data Transfers

We are based in the United States and process personal information in the U.S. (our cloud regions are in the United States). Where we process personal data on behalf of a customer that includes EEA, UK or Swiss personal data, that processing is governed by our Data Processing Addendum, and transfers rely on appropriate safeguards, including the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum.

9. Data Retention

We retain personal information for as long as necessary to fulfill the purposes described in this Policy. As general guidance: customer account and Services data is retained for the term of the customer agreement and for approximately 60 days after termination, after which it is deleted or returned in accordance with the DPA; database backups cycle out on an approximately 7-day schedule; website, prospect and marketing data is retained until no longer needed or until you opt out; and data of unsuccessful job applicants is retained for approximately 12 months. We may retain information longer where required by law or to resolve disputes or enforce our agreements. When personal data is no longer required, we delete or de-identify it.

10. Security and Data Breach Notification

We maintain an information-security program with administrative, technical and physical safeguards designed to protect personal information against unauthorized access, use, disclosure, alteration and destruction. Our Services are hosted on Google Cloud Platform. These safeguards include encryption of personal information at rest (AES-256) and in transit (TLS 1.2+ at the public edge, with enforced SSL on all database connections), role-based access controls, and the technical and organizational measures described in our Data Processing Addendum, overseen by our security lead. As of the date of this policy we are working toward SOC 2 and ISO/IEC 27001 certification but have not completed a SOC 2 audit or an ISO/IEC 27001 certification; we do not represent certification until obtained. No method of transmission or storage is completely secure.

If we become aware of a personal-data breach affecting your personal information, we will investigate, take steps to mitigate it, and notify affected individuals and applicable authorities and customers as required by law and our contractual commitments, without undue delay and within 72 hours of confirming a reportable breach. Where we act as a processor on a customer’s behalf, we will notify that customer in accordance with the DPA so they can meet their own notification obligations.

11. Your Privacy Rights and Choices

Subject to applicable law and verification of your identity, you may have rights to access, correct, delete, port, restrict or object to the processing of your personal information, and to withdraw consent. To exercise rights, contact us as described in Section 16. We will not discriminate against you for exercising your rights.

11(a). EEA, UK and Switzerland

If you are in the EEA, UK or Switzerland, you have the rights described above under the GDPR / UK GDPR, including the right to lodge a complaint with your supervisory authority. Where processing is based on consent, you may withdraw it at any time without affecting prior processing.

11(b). California (CCPA / CPRA)

California residents have the right to know the categories and specific pieces of personal information we collect, the right to delete and to correct, and the right to opt out of the “sale” or “sharing” of personal information and to limit use of sensitive personal information. We do not sell personal information and do not “share” it for cross-context behavioral advertising. The categories we collect and disclose are described in Sections 3 and 7. You may use an authorized agent to submit requests.

11(c). Other U.S. states and jurisdictions

Residents of other U.S. states with comprehensive privacy laws, and individuals in other jurisdictions, may have similar rights, including rights to access, correct, delete and opt out of certain processing. We honor these rights as applicable law requires.

12. Children’s Privacy

The Services are not directed to children and are intended for business use. We do not knowingly collect personal information from children under 18. If you believe a child has provided us personal information, contact us and we will take appropriate steps to delete it.

13. Third-Party Links and Services

The Services may link to third-party websites and services that we do not control. Their privacy practices are governed by their own policies, and we are not responsible for them.

14. Changes to This Policy

We may update this Policy from time to time. We will post the updated version with a new “Last updated” date and, where required, provide additional notice. Your continued use of the Services after an update constitutes acceptance of the revised Policy to the extent permitted by law.

15. How to Contact Us

  • Privacy enquiries and rights requests: privacy@entbox.ai
  • Postal: EntBox Ai Inc., 11500 S Eastern Ave, Ste 150, Henderson, NV 89052
Enterprise Box AI

The Institutional Intelligence Layer. A synthesis layer that connects every ticket, call, document, and decision your organization has ever made.

Built by Enterprise BoxAI

Platform
ServicesAI CapabilitiesArchitectureCompare
Company
AboutCareersBlogContact
Resources
DocumentationCase StudiesAPI ReferenceSupport
© 2026 Enterprise BoxAI. All rights reserved.
PrivacyTermsSecurity