Last updated: 17.08.2025
Stereobox.ai (“we,” “our,” or “us”) is operated by
Itmex Solutions LTD,
Office 15249, 182-184 High Street, North East Ham, London, United Kingdom, E6 2JA. We respect your privacy and are committed to protecting your personal data.
This Privacy & Cookies Policy explains how we collect, use, disclose, and safeguard your information when you use our Platform.
1. Information We Collect
We may collect the following categories of information:
1. Account Information – such as your name, email address, and login credentials when you create an account.
2. Payment Information – payment details are processed securely by third-party providers; we do not store full payment card details.
3. Usage Data – information about how you interact with the Platform, including IP address, browser type, operating system, and device identifiers.
4. Generated Content – any audio, voice, or files you create using our AI tools.
5. Cookies & Tracking Data – information collected through cookies and similar technologies (see Section 7 below).
2. How We Use Your Information
We process your personal data for specific, lawful purposes. These include:
2.1 Service Delivery
• To create and manage your user account.
• To provide access to AI-powered voice generation tools.
• To process your requests, transactions, and purchased services.
2.2 Platform Functionality & Improvement
• To ensure the Platform operates correctly, efficiently, and securely.
• To monitor usage trends and analyze user behavior to improve features and user experience.
• To personalize your experience, such as remembering settings or preferences.
2.3 Communications
• To send important service-related notices, such as updates to our Terms, policies, or security alerts.
• To respond to your inquiries, requests, or customer support needs.
• To send optional marketing or promotional communications (only where you have given consent, and you may opt out at any time).
2.4 Fraud Prevention & Security
• To detect, prevent, and investigate fraudulent activity, abuse of the Platform, or violations of our Terms.
• To maintain the integrity and security of our systems, including monitoring for unauthorized access or malicious behavior.
2.5 Legal & Regulatory Compliance
• To comply with applicable laws, including intellectual property enforcement, financial record-keeping, tax obligations, and data protection laws.
• To cooperate with regulatory authorities, law enforcement, or judicial processes when required.
2.6 Research & Development
• To improve and train our AI systems, we may use anonymized and aggregated data (never identifiable personal data without consent).
• To test and develop new features and services.
3. Legal Basis for Processing
We only process your personal data where we have a valid legal basis under the UK GDPR and EU GDPR. Depending on the nature of your interactions with the Platform, we may rely on one or more of the following bases:
3.1 Contractual Necessity
Processing is necessary to perform our agreement with you. For example:
• Creating and managing your user account.
• Providing access to voice generation tools and related services.
• Processing payments and delivering purchased plans.
3.2 Consent
Where you explicitly agree to certain processing, such as:
• Receiving marketing or promotional communications.
• Allowing us to use optional cookies or similar technologies.
• Participating in surveys, beta programs, or user feedback initiatives.
You may withdraw your consent at any time by adjusting your preferences or contacting us (see Section 12).
3.3 Legitimate Interests
We may process your data where it is reasonably necessary for our legitimate business interests, provided that your rights and freedoms are not overridden. These include:
• Ensuring the security and integrity of the Platform.
• Preventing fraud, abuse, or misuse of services.
• Analyzing user behavior to improve features, usability, and performance.
• Communicating with you about non-marketing service updates.
3.4 Legal Obligations
We may process and retain your data as required by law, such as:
• Compliance with tax, accounting, and financial regulations.
• Responding to valid legal requests from authorities.
• Enforcing intellectual property rights and complying with DMCA or similar takedown laws.
3.5 Vital Interests
In rare cases, we may process your data to protect your vital interests or those of another person, for example, in urgent security or safety matters.
4. Sharing of Information
We do not sell or rent your personal data. However, we may share your information with carefully selected third parties in the following circumstances:
4.1 Service Providers & Business Partners
We engage trusted third-party providers to perform services on our behalf, including:
• Payment processors – to securely process transactions and manage billing.
• IT hosting & infrastructure providers – to operate and maintain the Platform (e.g., cloud hosting, server management).
• Analytics providers – to help us understand usage patterns and improve user experience.
• Customer support tools – to manage inquiries and support requests.
These providers are only permitted to use your data as necessary to perform their functions and are contractually bound to protect it.
4.2 Legal & Regulatory Disclosures
We may disclose your personal data where required to do so by law, regulation, legal process, or government request. This includes:
• Responding to court orders, subpoenas, or regulatory investigations.
• Complying with obligations under intellectual property laws (e.g., DMCA takedowns).
• Enforcing our Terms & Conditions and protecting our rights or the rights of others.
4.3 Business Transfers
In the event of a merger, acquisition, restructuring, or sale of assets, your data may be transferred as part of the business transaction. In such cases, we will ensure that the recipient continues to handle your data in accordance with this Policy.
4.4 Protection of Rights
We may share information where we reasonably believe it is necessary to:
• Detect, prevent, or address fraud, abuse, or security risks.
• Protect the safety, rights, or property of users, the public, or
Itmex Solutions LTD.
4.5 With Your Consent
In cases where sharing is not covered above, we will seek your explicit consent before sharing your personal data with third parties.
5. Data Retention
We retain personal data only for as long as it is reasonably necessary to fulfill the purposes outlined in this Policy, or as required by law. Retention periods vary depending on the category of data:
5.1 Account Information
• Retained for the duration of your account.
• If you delete your account, we will erase or anonymize your personal data within a reasonable period (typically within 30–90 days), unless retention is required for legal, regulatory, or fraud-prevention purposes.
5.2 Payment Information
• We do not store full payment card details.
• Transaction records and billing information are retained for a minimum of six (6) years to comply with UK tax and accounting laws.
5.3 Usage Data & Technical Logs
• Retained for system security, troubleshooting, and analytics.
• Typically kept for 12–24 months, after which they may be aggregated or anonymized.
5.4 Generated Content
• Stored temporarily to provide functionality and allow you to access or download your files.
• May be deleted after a reasonable period of inactivity or anonymized for internal research and improvement (never disclosed in identifiable form without consent).
5.5 Legal & Regulatory Data
• Certain data may be retained beyond account deletion if necessary to comply with applicable law, enforce our Terms, resolve disputes, or assist with investigations.
5.6 Anonymization & Aggregation
Where possible, we may anonymize or aggregate personal data so that it no longer identifies you. Such data may be retained indefinitely for research, analytics, and service improvement.
6. Data Security
We implement appropriate technical, organizational, and administrative safeguards to protect your personal data against unauthorized access, loss, misuse, disclosure, or alteration. These measures may include:
• Encryption of data in transit (SSL/TLS).
• Secure storage and controlled access to systems.
• Regular monitoring, audits, and vulnerability assessments.
• Access controls and authentication for staff and contractors.
6.1 Third-Party Security
Where we rely on third-party service providers (such as hosting, payment processing, or analytics), we require them to maintain security standards consistent with industry best practices.
6.2 User Responsibilities
You are responsible for maintaining the confidentiality of your account credentials and for ensuring that you do not share them with unauthorized persons. If you suspect any unauthorized access or breach of security, you must notify us immediately at usersupport@stereobox.ai.
6.3 Limitations
While we take reasonable steps to protect your data, no system is completely secure. We cannot guarantee the absolute security of your data, and any transmission of information to us is at your own risk.
7. Cookies & Tracking Technologies
Cookies are small text files placed on your device by websites you visit. They are widely used to make websites work, enhance functionality, and provide analytics information. Cookies may be “session cookies” (deleted when you close your browser) or “persistent cookies” (stored until they expire or are manually deleted).
7.1 Types of Cookies We Use:
Essential Cookies: These are strictly necessary for the Platform to function. Without them, services like account login, security, or payment processing cannot be provided.
Performance & Analytics Cookies: These collect information about how users interact with the Platform, such as pages visited and error messages encountered. We use this data to improve performance, usability, and design.
Preference Cookies: These store your preferences and settings (such as language, cookie choices, or saved login details) to provide a more personalized experience.
Marketing & Targeting Cookies: These may be used, with your consent, to deliver relevant advertising on third-party platforms or to measure the effectiveness of campaigns.
Third-Party Cookies: Some cookies are set by third parties providing services on our Platform (such as analytics tools or payment processors). We do not control these cookies, and their use is governed by the privacy policies of the third parties.
7.2 Other Tracking Technologies
In addition to cookies, we may use similar technologies such as pixels, web beacons, and local storage to achieve similar purposes, such as tracking engagement or enabling features.
7.3 Cookie Consent
On your first visit to our Platform, you will be presented with a cookie banner or pop-up asking you to set your preferences. You may:
• Accept all cookies.
• Reject non-essential cookies.
• Manage preferences by selecting which categories you consent to.
You may change your consent choices at any time via the cookie settings link provided on our Platform.
7.4 Managing Cookies
Most web browsers allow you to control cookies through their settings. You can configure your browser to:
• Block all cookies.
• Delete existing cookies.
• Notify you before a cookie is stored.
Please note that disabling essential cookies may limit the functionality of the Platform.
7.5 Legal Basis for Cookies
• Essential cookies are processed on the basis of legitimate interests (ensuring core functionality).
• Non-essential cookies (analytics, marketing, preferences) are processed on the basis of your consent.
8. International Data Transfers
As we are based in the United Kingdom, your personal data may be transferred to and processed in countries outside the UK and the European Economic Area (EEA), where data protection standards may differ from those in your country of residence.
8.1 Safeguards for Transfers
Whenever we transfer your personal data to a country outside the UK or EEA that does not provide an adequate level of protection, we implement appropriate safeguards to protect your information, such as:
• Standard Contractual Clauses (SCCs) approved by the UK Information Commissioner’s Office (ICO) and/or the European Commission.
• International Data Transfer Agreements (IDTAs) where required under UK law.
• Binding contractual commitments with third-party service providers requiring them to maintain equivalent levels of data protection.
8.2 Third-Party Processors
Some of our third-party service providers (e.g., hosting, payment processors, analytics tools) may be located outside the UK/EEA. We ensure that such providers process your data only in accordance with this Policy and under appropriate safeguards.
8.3 User Acknowledgment
By using the Platform, you acknowledge that your personal data may be transferred to jurisdictions outside your country of residence, subject to the safeguards outlined above.
9. Your Rights
Under the UK GDPR and EU GDPR, you have a number of rights regarding your personal data. We are committed to enabling you to exercise these rights.
9.1 Right of Access
You have the right to request a copy of the personal data we hold about you, along with information about how we process it.
9.2 Right to Rectification
You may request that we correct or update any inaccurate or incomplete personal data.
9.3 Right to Erasure (“Right to be Forgotten”)
You may request that we delete your personal data where:
• The data is no longer necessary for the purposes for which it was collected.
• You withdraw consent (where consent was the legal basis).
• You object to processing and there are no overriding legitimate grounds.
• The processing was unlawful or required to be erased by law.
This right may not apply where retention is necessary for compliance with legal obligations or for the establishment, exercise, or defense of legal claims.
9.4 Right to Restrict Processing
You may request that we temporarily restrict the processing of your personal data where:
• You contest the accuracy of the data.
• The processing is unlawful but you oppose erasure.
• We no longer need the data but you require it for legal claims.
• You have objected to processing and verification of overriding grounds is pending.
9.5 Right to Data Portability
You may request to receive your personal data in a structured, commonly used, and machine-readable format, and to have that data transmitted to another controller where technically feasible.
9.6 Right to Object
You may object at any time to:
• Processing of your personal data based on our legitimate interests.
• Processing for direct marketing purposes (including profiling related to marketing).
9.7 Right to Withdraw Consent
Where processing is based on your consent, you may withdraw that consent at any time. Withdrawal will not affect the lawfulness of processing carried out before withdrawal.
9.8 Automated Decision-Making and Profiling
We do not carry out decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects on you.
9.9 Exercising Your Rights
To exercise your rights, please contact us at usersupport@stereobox.ai. We may request proof of identity to verify your request. We will respond within the timeframes required by law (typically within one month).
9.10 Right to Complain
If you believe that we have not handled your personal data correctly, you have the right to lodge a complaint with your local data protection authority. In the UK, this is the Information Commissioner’s Office (ICO):
https://ico.org.uk/
10. Children’s Privacy
The Platform is intended for users aged 18 and over. We do not knowingly collect or process personal data from children under the age of 18.
10.1 Parental Responsibility
If you are a parent or guardian and believe that your child has provided us with personal data, please contact us immediately at usersupport@stereobox.ai. We will take steps to verify and, if necessary, delete such information without undue delay.
10.2 Unintentional Collection
If we become aware that we have collected personal data from a child without appropriate consent, we will promptly delete that information and, where appropriate, terminate the associated account.
10.3 Compliance with Law
We comply with applicable child data protection laws, including the UK GDPR, EU GDPR, and similar international regulations. The Platform is not designed to attract, target, or market to minors.
11. Changes to This Policy
We reserve the right to update, modify, or replace this Privacy & Cookies Policy at any time to reflect changes in our practices, legal requirements, or operational needs.
11.1 Notification of Changes
When we make changes, we will update the “Last Updated” date at the top of this Policy. In some cases, we may also provide additional notice (such as a banner on the Platform, email notification, or pop-up).
11.2 Material Changes
If we make material changes that affect your rights or the way we process your personal data, we will provide clear notice and, where required by law, seek your consent before the changes take effect.
11.3 Acceptance of Changes
By continuing to use the Platform after the updated Policy has been posted, you acknowledge and agree to the revised terms. If you do not agree with the changes, you must stop using the Platform.
12. Contact Us
If you have any questions, concerns, or requests regarding this Privacy & Cookies Policy or the way we handle your personal data, please contact us using the details below:
Itmex Solutions LTD
Office 15249, 182-184 High Street, North East Ham, London, United Kingdom, E6 2JA
Email: usersupport@stereobox.ai
We will respond to all valid requests within the timeframes required by applicable data protection laws.