MiemBoxApp - Privacy Policy

Privacy Policy

In accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR), the Spanish Organic Law 3/2018 on Personal Data Protection and Guarantee of Digital Rights (LOPDGDD), and Law 34/2002 on Information Society Services and Electronic Commerce (LSSI-CE)

Last updated: March 2026

1. Data Controller

MiemBoxApp is a SaaS platform operated by [COMPANY_NAME], with tax ID [NIF] and registered address at [ADDRESS]. For data protection inquiries, contact us at [PRIVACY_EMAIL].

Within this platform:

For questions about why your data is processed or to exercise your rights, contact your organization's administrator. For questions about how the platform handles your data technically, contact us at [PRIVACY_EMAIL].

2. What Data We Process

CategoryDataPurpose
AccountEmail, username, display name, preferred languageAuthentication, identification within the platform
SecurityHashed password, login timestamps, IP address, user agentAccount security, fraud prevention, audit logging
ProfileFirst name, last name, avatarDisplay within the organization
MembershipPhone, address, date of birth, tax ID (if provided by your organization)Organization management as determined by your Data Controller
ActivityEvent attendance, meeting responses, communication read statusOrganization coordination
FinancialDonation records, tax certificates (if applicable)Financial management and legal tax obligations
PreferencesCommunication preferences, privacy settingsRespecting your choices about notifications and visibility

3. Legal Basis for Processing

Your personal data is processed on the following legal bases:

4. Your Rights

Under the GDPR and LOPDGDD, you have the following rights:

RightDescriptionHow to exercise
AccessObtain a copy of your personal dataContact your organization admin; data export is available
RectificationCorrect inaccurate dataEdit your profile in Settings, or contact your admin
ErasureRequest deletion of your dataContact your organization admin
PortabilityReceive your data in a structured formatExcel export available through your organization
RestrictionLimit how your data is processedContact your organization admin
ObjectionObject to specific processing activitiesUse communication preferences in Settings > Privacy
Automated decisionsNot be subject to decisions based solely on automated processingNot applicable — MiemBoxApp does not perform automated profiling or decision-making

You also have the right to lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos — AEPD) at www.aepd.es.

5. Communication Preferences

You can control which non-essential communications you receive:

These preferences can be changed at any time in Settings > Privacy. Transactional emails (password resets, security alerts, invitation links) cannot be disabled as they are essential for account operation.

6. Data Retention

7. Data Security

We implement the following technical measures to protect your data:

8. Cookies and Local Storage

MiemBoxApp uses only essential storage mechanisms required for the application to function:

StoragePurposeDuration
Session StorageAuthentication token (JWT)Browser session only
Local StorageTheme preference, language, organization infoUntil cleared

We do not use tracking cookies, analytics services, advertising pixels, or any third-party tracking technologies.

9. International Data Transfers

Your data is hosted within the European Union. If any sub-processor requires data transfer outside the EU, appropriate safeguards (Standard Contractual Clauses or adequacy decisions) are applied in accordance with Chapter V of the GDPR.

10. Sub-processors

MiemBoxApp uses the following sub-processors to provide the service:

Sub-processorPurposeLocation
Cloud hosting providerInfrastructure and data storageEU
Email service providerTransactional email deliveryEU/US (with appropriate safeguards)

For details on processor obligations and sub-processor management, see our Data Processing Agreement.

11. Children's Data

MiemBoxApp does not knowingly collect personal data from children under the age of 14 (as per LOPDGDD Article 7). Organization administrators are responsible for ensuring that minors' data is processed with appropriate parental or guardian consent.

12. Limitations of Liability

13. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices or legal requirements. When we do, the "Last updated" date at the top will be revised. For significant changes, we will notify users through the platform.

14. Contact

For questions about this Privacy Policy or how MiemBoxApp handles your data, contact us at [PRIVACY_EMAIL].

To exercise your data subject rights, please contact your organization administrator, who is the Data Controller responsible for your personal data.