Privacy Policy
Office Maritim & NIU

Privacy Policy
Office Maritim & NIU

Privacy Policy
Office Maritim & NIU

Pending before publishing: confirm the registered address matches the premises address. This is an English translation; the Spanish version is the authoritative one and prevails in case of discrepancy.

Last updated: 13 July 2026

1. Data controller

Controller

BALSPLA Inmobiliaria, S.L. (“Office Maritim”, “we”)

Tax ID (CIF/NIF)

B56992381

Registered address

Calle del Riu Jalón, 13, 46022 València (Spain)

Premises

Office Maritim, Calle del Riu Jalón, 13, 46022 València (El Cabanyal)

Contact email

hola@officemaritim.com

Data protection matters

hola@officemaritim.com (subject: “Data protection”)

Office Maritim is a coworking space in El Cabanyal (Valencia). NIU is our AI-powered office manager, available via WhatsApp, SMS, email and voice call. This policy explains what personal data we process when you use our services or interact with NIU.

Processing is governed by Regulation (EU) 2016/679 (GDPR), Spanish Organic Law 3/2018 on Data Protection (LOPDGDD) and Law 34/2002 on Information Society Services (LSSI-CE).

2. Data we process

Depending on how you interact with us, we may process the following categories of data:

Identification and contact data. First and last name, phone number, WhatsApp identifier, email address and, where applicable, company.

Communication content. The messages you exchange with NIU via WhatsApp, SMS or email; voice call recordings and their transcripts; automatically generated summaries of each conversation; and the “notes” or memories NIU keeps to provide continuity of service (e.g. your preferences).

Space usage data. Desk bookings, tours and trials, bundles and passes purchased, event attendance and interaction, food orders and reviews, and shopping lists handled through NIU.

Billing and payment data. Data needed to issue invoices and record payment status. Collection and bank reconciliation are handled through our financial provider (Qonto); Office Maritim does not store full card details.

Guest data. If you register a guest, we process their first and last name, phone and/or email. You must have their consent before sharing this with us.

Access control data. Access logs for the building or certain areas via our access control system (UniFi/Ubiquiti).

Consent records. A record of acceptance of this policy, the channel used and the date/time.

We do not request special categories of data (Art. 9 GDPR). Please do not share sensitive information through NIU.

3. Purposes and legal bases

Purpose

Legal basis (Art. 6 GDPR)

Provide coworking services: bookings, tours, access, account management

Performance of a contract (Art. 6(1)(b))

Handle your questions and requests via NIU (text and voice)

Contract or pre-contractual steps (Art. 6(1)(b)); legitimate interest in answering enquiries (Art. 6(1)(f))

Record voice calls and transcribe them to handle your request and improve the service

Consent (Art. 6(1)(a)), obtained at the start of the call

Issue invoices, keep accounts and prevent fraud

Legal obligation (Art. 6(1)(c)) and contract (Art. 6(1)(b))

Premises access control and security

Legitimate interest in security (Art. 6(1)(f))

Send operational notices (confirmations, reminders, payment status)

Performance of a contract (Art. 6(1)(b))

Suggest events, food and community activities

Legitimate interest (Art. 6(1)(f)) or, for marketing messages, consent (Art. 6(1)(a))

Birthday greetings and customer-relationship messages

Consent (Art. 6(1)(a)) or legitimate interest (Art. 6(1)(f))

You may withdraw consent at any time (section 7), without affecting the lawfulness of prior processing.

4. Use of artificial intelligence

NIU runs on artificial intelligence systems that process your messages and, on calls, your voice, in order to understand and respond to your requests. Specifically:

• Language processing (understanding and drafting replies) is performed using AI models from Anthropic (Claude). • Voice, transcription and speech synthesis on calls are performed using ElevenLabs.

These providers act as data processors on behalf of Office Maritim and process data solely to provide the service to us. We do not make decisions producing legal or similarly significant effects based solely on automated processing (Art. 22 GDPR): NIU assists with operational tasks, and you can always request human assistance by writing to hola@officemaritim.com.

5. Recipients and processors

To provide the service we share data with providers acting as processors under Art. 28 GDPR data processing agreements:

Provider

Purpose

Processing location / transfer safeguard

Bird.com (Bird B.V.)

Sending and receiving WhatsApp and SMS messages

EU (Netherlands); SCCs where applicable

Meta / WhatsApp (WhatsApp Ireland Ltd. — WhatsApp Business Platform)

Transmission of WhatsApp messages; WhatsApp additionally applies its own terms and privacy policy

Ireland and United States; EU–US Data Privacy Framework / SCCs

ElevenLabs

Voice, transcription and speech synthesis on calls

United States; EU–US Data Privacy Framework / SCCs

Anthropic (Claude)

NIU’s natural language processing

United States; EU–US Data Privacy Framework / SCCs

Supabase

Database and data hosting

EU (AWS eu-west-1, Ireland)

Qonto (Olinda SAS)

Invoicing, payments and bank reconciliation

EU (France)

Cal.eu

Booking and scheduling (EU-hosted version of Cal.com)

European Union

Google (Workspace / Gmail / Drive)

Email and document storage

EU and United States; EU–US Data Privacy Framework / SCCs

Google Cloud

Hosting of our automation platform (n8n), which orchestrates the data flows above

Frankfurt, Germany (europe-west3) — EU

DocuSign

Electronic signature of documents

EU and United States; EU–US Data Privacy Framework / SCCs

Ubiquiti (UniFi)

Premises access control

On-premises and EU

We may also disclose data to public authorities, law enforcement, courts, or our legal and accounting advisors where required by law or necessary to defend our rights.

We do not sell your personal data or share it with third parties for their own advertising purposes.

6. International transfers

Some of our providers (e.g. Anthropic, ElevenLabs, Meta/WhatsApp, Google and DocuSign) may process data outside the European Economic Area, primarily in the United States. Where this happens, transfers rely on valid GDPR mechanisms: adequacy decisions (including, where applicable, the *EU–US Data Privacy Framework*) or the European Commission’s Standard Contractual Clauses, together with appropriate supplementary safeguards. You can request a copy of these safeguards at hola@officemaritim.com.

7. Retention periods

We keep your data while you are a service user and, afterwards, for the legally required periods:

• Contractual and billing data: for the duration of the relationship and then the applicable tax and commercial periods (generally up to 6 years under the Commercial Code; tax obligations, 4 years). • Conversations, recordings and transcripts: while you have an active relationship with us and at most 12 months from the last interaction, unless retention is needed for a claim. • Access control logs: 30 days, unless a security incident occurs. • Data processed on the basis of consent: until you withdraw consent.

Once these periods elapse, data is securely deleted or anonymised.

8. Your rights

You may exercise at any time the rights of access, rectification, erasure, objection, restriction of processing, portability and not to be subject to automated decisions, as well as withdraw any consent given.

To exercise them, write to hola@officemaritim.com or to the postal address in section 1, stating the right you wish to exercise. We may ask you to verify your identity. We will respond within one month.

If you believe we have not handled your request correctly, you have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD), C/ Jorge Juan 6, 28001 Madrid — www.aepd.es — https://www.aepd.es.

9. Security

We apply appropriate technical and organisational measures to protect your data against unauthorised access, loss or alteration, including encryption in transit, access controls and confidentiality agreements with our providers.

10. Minors

Our services are intended for people over 18. We do not knowingly collect data from minors. If you believe a minor has provided us with data, contact us and we will delete it.

11. Cookies

The Office Maritim website is hosted on Framer and uses only technical cookies necessary for its operation. We do not use advertising cookies. If we enable measurement or analytics cookies in the future, we will ask for your prior consent via a banner and update this section.

12. Changes to this policy

We may update this policy to reflect legal or service changes. We will publish the current version on this page with its update date and, for material changes, notify you through the usual channels.