Business Privacy Policy
1. Scope: two distinct layers
This Policy explains how EUROPEAN DIGITAL STORES, S.L. ("EDS") processes personal data in connection with ULOX Business. Two layers must be distinguished, as different rules apply:
| Layer | Who decides | Applicable document |
|---|---|---|
| Workspace content (messages, files, vault, documents) | The customer company, as controller. EDS is processor. | Data Processing Addendum (DPA) |
| Contractual relationship and service operation (onboarding, billing, support, security) | EDS, as controller. | This Policy |
If you are an employee or contractor of a customer company and want to know what your company does with workspace information, you must contact them: they decide. See section 10.
2. Controller
- Identity: EUROPEAN DIGITAL STORES, S.L. — tax ID B-70983770
- Address: Calle José Echegaray, 8, Edificio Alvia 3, offices 7 and 8, 28232 Las Rozas (Madrid), Spain
- Privacy contact:
privacy@ulox.org - Supervisory authority: Spanish Data Protection Agency (
www.aepd.es)
3. What we cannot see
The content of a ULOX Business workspace is encrypted on the user's device, before it leaves it. EDS holds no decryption keys.
As a result, EDS cannot read messages, open files, consult the credential vault, index documents, profile the content, train models on it or deliver it in readable form to anyone — including the customer company itself or a public authority. This is not a revocable internal policy: it is a technical limitation inherent to the product's design.
Nor do we use our customers' data for advertising, sell it or disclose it to third parties for commercial purposes. ULOX Business contains no advertising networks or third-party trackers.
4. Data we do process
| Category | Detail |
|---|---|
| Customer company data | Name, tax ID, address, verified domain and billing details. |
| Administrator data | Name, corporate email address and contact details needed to manage the agreement. |
| User corporate identity | Blinded index of the corporate email (not the plaintext address), opaque cryptographic pseudonym, role, status and activity timestamps. The plaintext address is deleted after the invitation is sent. |
| Billing data | Amounts, frequency and payment status. Card data is handled directly by the payment provider; EDS does not store it. |
| Technical operating data | IP addresses in security logs, device identifiers for notifications, and aggregated availability metrics. |
| Support | Communications you send us and their content. |
5. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Providing and maintaining the contracted Service | Performance of a contract (Art. 6(1)(b) GDPR) |
| Billing and collections | Performance of a contract and legal obligation (Art. 6(1)(b) and (c)) |
| Platform security, abuse and fraud prevention | Legitimate interest (Art. 6(1)(f)) |
| Handling support requests | Performance of a contract and legitimate interest |
| Compliance with accounting, tax and authority requirements | Legal obligation (Art. 6(1)(c)) |
| Service communications (operational notices, legal changes) | Performance of a contract and legitimate interest |
6. Retention periods
- Contractual relationship data: for the term of the agreement and thereafter for the limitation period of actions arising from it.
- Accounting and tax records: the periods required by law.
- Encrypted workspace material: as set out in the DPA — deletion after the export period and purging of continuity copies within a maximum of ninety (90) calendar days.
- Security logs: only as long as strictly necessary for their purpose.
7. Recipients
Data may be disclosed to the providers acting as processors or subprocessors listed in Annex III of the DPA (infrastructure, transactional email, payments and push notifications), and to public authorities where legally required.
Faced with an authority request, EDS can only hand over what it holds: unintelligible encrypted material and service data. Never readable content, because it does not have it.
8. International transfers
Processing takes place on servers located in the European Union. Occasional transfers to providers outside the EEA (transactional email and push notifications) rely on adequacy decisions or Standard Contractual Clauses with supplementary measures, and involve minimal data — never content.
9. Individual rights
Any individual may exercise the rights of access, rectification, erasure, restriction, portability and objection, and withdraw consent where processing is based on it, by writing to privacy@ulox.org with proof of identity.
If the request concerns workspace content, it must be addressed to the customer company, which is the controller. EDS, as processor, will forward it without delay.
Every individual has the right to lodge a complaint with the Spanish Data Protection Agency or with the supervisory authority in their country.
10. Information for employees and contractors
If you access ULOX Business because your company gave you a corporate credential:
- The workspace and its content belong to your company, which decides what is stored, who has access and for how long.
- Your administrator can see the governance action log (onboarding, offboarding, role and permission changes) and manage your access, but neither they nor EDS can read encrypted content they do not legitimately access with their own credential.
- Your password never reaches the server at any point, not even in encrypted form, thanks to the authentication protocol used.
- To exercise your rights over workspace information, contact your company.
11. Security
EDS applies the technical and organisational measures described in Annex II of the DPA: end-to-end encryption, authentication without knowledge of the password, opaque identifiers, email minimisation, encryption in transit, second factor, internal access control and continuous monitoring.
12. Changes
This Policy may be updated for legal, technical or operational reasons. Material changes will be communicated to the customer with reasonable notice through the contact channels in the agreement.
13. Contact
- Privacy:
privacy@ulox.org - Legal matters:
legal@ulox.org - Post: Calle José Echegaray, 8, Edificio Alvia 3, offices 7 and 8, 28232 Las Rozas (Madrid), Spain.
