1. Scope: two distinct layers

This Policy explains how EUROPEAN DIGITAL STORES, S.L. ("EDS") processes personal data in connection with ULOX Business. Two layers must be distinguished, as different rules apply:

LayerWho decidesApplicable document
Workspace content (messages, files, vault, documents)The customer company, as controller. EDS is processor.Data Processing Addendum (DPA)
Contractual relationship and service operation (onboarding, billing, support, security)EDS, as controller.This Policy

If you are an employee or contractor of a customer company and want to know what your company does with workspace information, you must contact them: they decide. See section 10.

2. Controller

3. What we cannot see

As a result, EDS cannot read messages, open files, consult the credential vault, index documents, profile the content, train models on it or deliver it in readable form to anyone — including the customer company itself or a public authority. This is not a revocable internal policy: it is a technical limitation inherent to the product's design.

Nor do we use our customers' data for advertising, sell it or disclose it to third parties for commercial purposes. ULOX Business contains no advertising networks or third-party trackers.

4. Data we do process

CategoryDetail
Customer company dataName, tax ID, address, verified domain and billing details.
Administrator dataName, corporate email address and contact details needed to manage the agreement.
User corporate identityBlinded index of the corporate email (not the plaintext address), opaque cryptographic pseudonym, role, status and activity timestamps. The plaintext address is deleted after the invitation is sent.
Billing dataAmounts, frequency and payment status. Card data is handled directly by the payment provider; EDS does not store it.
Technical operating dataIP addresses in security logs, device identifiers for notifications, and aggregated availability metrics.
SupportCommunications you send us and their content.

5. Purposes and legal bases

PurposeLegal basis
Providing and maintaining the contracted ServicePerformance of a contract (Art. 6(1)(b) GDPR)
Billing and collectionsPerformance of a contract and legal obligation (Art. 6(1)(b) and (c))
Platform security, abuse and fraud preventionLegitimate interest (Art. 6(1)(f))
Handling support requestsPerformance of a contract and legitimate interest
Compliance with accounting, tax and authority requirementsLegal obligation (Art. 6(1)(c))
Service communications (operational notices, legal changes)Performance of a contract and legitimate interest

6. Retention periods

7. Recipients

Data may be disclosed to the providers acting as processors or subprocessors listed in Annex III of the DPA (infrastructure, transactional email, payments and push notifications), and to public authorities where legally required.

Faced with an authority request, EDS can only hand over what it holds: unintelligible encrypted material and service data. Never readable content, because it does not have it.

8. International transfers

Processing takes place on servers located in the European Union. Occasional transfers to providers outside the EEA (transactional email and push notifications) rely on adequacy decisions or Standard Contractual Clauses with supplementary measures, and involve minimal data — never content.

9. Individual rights

Any individual may exercise the rights of access, rectification, erasure, restriction, portability and objection, and withdraw consent where processing is based on it, by writing to privacy@ulox.org with proof of identity.

If the request concerns workspace content, it must be addressed to the customer company, which is the controller. EDS, as processor, will forward it without delay.

Every individual has the right to lodge a complaint with the Spanish Data Protection Agency or with the supervisory authority in their country.

10. Information for employees and contractors

If you access ULOX Business because your company gave you a corporate credential:

11. Security

EDS applies the technical and organisational measures described in Annex II of the DPA: end-to-end encryption, authentication without knowledge of the password, opaque identifiers, email minimisation, encryption in transit, second factor, internal access control and continuous monitoring.

12. Changes

This Policy may be updated for legal, technical or operational reasons. Material changes will be communicated to the customer with reasonable notice through the contact channels in the agreement.

13. Contact