Privacy Policy

Effective Date: March 16, 2026

JOINBLE DIGITAL INTELLIGENCE SL (hereinafter "Joinble"), with CIF B26859876 and registered office at Calle Hermosilla 48, 1 D, 28001 Madrid, Spain, is committed to protecting your privacy. This Privacy Policy describes how we collect, use, store, and protect your personal information when you access our website (www.joinble.io), our mobile applications, software development kits, AI agent platform, and Joinble AI-KYC services. By using our services, you consent to the practices described in this policy. If you do not agree with this policy, please do not use our services.

1. Data Controller

The data controller responsible for processing your personal data is: JOINBLE DIGITAL INTELLIGENCE SL CIF: B26859876 Address: Calle Hermosilla 48, 1 D, 28001 Madrid, Spain Email: contact@joinble.io You may contact us at any time regarding your personal data by writing to the above email address.

2. Information We Collect

We may collect the following categories of personal data: - Identity data: name, surname, ID number (for KYC services). - Contact data: email address, phone number, company name. - Technical data: IP address, browser type, device information, operating system, access logs. - Usage data: information about how you use our website, platform, and services. - KYC data: for identity verification services, we may process biometric data, identity documents, and selfie images, always under strict security standards and with your explicit consent. - Communication data: any information you provide when contacting us or interacting with our support channels.

3. How We Use Your Information

We use your personal data for the following purposes: - To provide, operate, and maintain our services, including the AI agent platform and KYC verification services. - To customize and improve your experience with our AI agents. - To improve our fraud detection models and security systems. - To communicate with you about service updates, changes, and support requests. - To comply with legal obligations and regulatory requirements. - To protect our rights, privacy, safety, or property, and that of our users and third parties. - To analyze usage trends and improve our website and services.

4. Legal Basis for Processing

We process your personal data based on the following legal grounds: - Contractual necessity: processing is necessary to perform our contract with you or to take pre-contractual steps at your request. - Consent: where you have given explicit consent for specific processing activities (e.g., biometric data for KYC). - Legitimate interest: processing is necessary for our legitimate business interests, provided these do not override your rights and freedoms. - Legal obligation: processing is necessary to comply with applicable laws and regulations.

5. Data Sharing and Third Parties

We do not sell your personal data. We may share your data with: - Service providers: third-party vendors who assist us in providing our services (hosting, analytics, payment processing), always under appropriate data processing agreements. - Legal authorities: when required by law, regulation, legal process, or government request. - Business transfers: in connection with any merger, acquisition, or sale of assets, your data may be transferred as part of the transaction. All third parties with whom we share data are required to maintain the confidentiality and security of your personal information.

6. International Data Transfers

Your personal data may be transferred to and processed in countries outside the European Economic Area (EEA). When such transfers occur, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission, to protect your personal data in accordance with applicable data protection laws.

7. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements. For KYC data, retention periods are determined by applicable anti-money laundering and identity verification regulations. When your data is no longer required, we will securely delete or anonymize it.

8. Data Security

We implement bank-grade security measures, including end-to-end encryption, access controls, and regular security audits, to protect your personal data against unauthorized access, alteration, disclosure, or destruction. However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your personal data, we cannot guarantee its absolute security.

9. Your Rights

Under the General Data Protection Regulation (GDPR) and applicable Spanish data protection law, you have the following rights: - Right of access: to obtain information about whether we process your personal data and to access that data. - Right to rectification: to request correction of inaccurate or incomplete data. - Right to erasure: to request deletion of your data when it is no longer necessary for the purposes for which it was collected. - Right to restriction: to request that we restrict the processing of your data in certain circumstances. - Right to data portability: to receive your data in a structured, commonly used, machine-readable format. - Right to object: to object to processing based on legitimate interests or for direct marketing purposes. - Right to withdraw consent: where processing is based on consent, you may withdraw it at any time. To exercise any of these rights, please contact us at contact@joinble.io. We will respond within the timeframe established by applicable law.

10. Cookies

Our website uses cookies and similar tracking technologies to enhance your experience, analyze traffic, and for marketing purposes. For detailed information about the cookies we use, please refer to our Cookie Consent settings available on our website. You can manage your cookie preferences through your browser settings or through the cookie consent mechanism provided on our website.

11. Children's Privacy

Our services are not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child without parental consent, we will take steps to delete that information promptly.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. We will notify you of any material changes by posting the updated policy on our website with a new effective date. We encourage you to review this Privacy Policy periodically to stay informed about how we protect your data.

13. Supervisory Authority

If you believe that your data protection rights have been violated, you have the right to lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos - AEPD) at www.aepd.es, or with the supervisory authority of your country of residence.

If you have any questions about this document, contact us at contact@joinble.io.

Privacy Policy | Joinble