Back to Box

Box · Legal

Privacy policy

Box brings communication from accounts you choose into one inbox. This policy describes the data flows behind that service, the choices you have, and the limits of our access.

Who is responsible

Nivora Works, enterprise/VAT number BE 1041.516.417, Julius en Maurits Sabbestraat 15, 8000 Bruges, Belgium (“Nivora”, “Box”, “we”) is the controller for your Box account, billing, product security, support and website use. Contact box@nivoraworks.com for privacy questions or rights requests.

When an organisation uses Box to handle messages about its employees, customers, prospects or other contacts, that organisation normally determines why those communications are processed and is the controller. Nivora then acts as its processor for that customer content. Our Data Processing Addendum applies to that processing and is available at box.nivoraworks.com/dpa.

Data we process

Account and organisation data: name, email address, authentication identifiers, avatar, language and display settings, plan, team membership, company and billing details, onboarding answers, notification preferences and support correspondence.

Waitlist and marketing data: the email address you submit, the Box signup source, subscription status, signup and unsubscribe timestamps, an unsubscribe token, and delivery or bounce events. The address and invitation content are sent to our email-delivery provider when we contact the list.

Connected-account data: provider, mailbox or channel identifiers, public profile details, connection status and encrypted OAuth or linked-device credentials. Provider refresh tokens and long-lived channel credentials are stored server-side in a secrets vault. A Box login session is stored on your own browser or device so you can remain signed in.

Communication data: email headers, snippets, bodies and attachments when needed to show or act on mail; imported chat and team messages, participants, timestamps, delivery state, reactions, attachments and conversation metadata; drafts and the replies or actions you submit.

AI data: prompts, selected messages or mail excerpts needed for a request, generated answers and drafts, conversation history, writing-style settings, tool calls, confirmation state and token/usage records. Box never gives an AI action permission to send or move communication without the confirmation controls shown in the product.

Technical and security data: IP address and request metadata processed by hosting providers, device and browser type, session and OAuth state, push subscription or device token, coarse event/error data, rate-limit counters and security logs. The public website does not run client-side behavioural analytics or advertising trackers. Its hosting provider still processes ordinary request metadata needed to deliver and protect the site.

Communications may contain sensitive or special-category data because another person placed it in a message. Box does not ask you to provide such data and does not use it to infer sensitive traits. It is processed only to deliver the user-directed communication feature, subject to the customer’s lawful instructions.

Why we process it and our legal bases

Contract: to create and secure your account, connect the services you request, synchronise and display communication, send your instructions, provide teams, notifications, support and paid features, and administer your subscription.

Consent: when you submit the waitlist form, to record your address and send the Box access invitation and related launch messages described beside the form. Every marketing message must offer an unsubscribe route. Withdrawal applies to future messages; a minimal suppression record can be kept to honour the opt-out and demonstrate compliance.

Legitimate interests: to prevent abuse and fraud, protect users and infrastructure, diagnose failures, measure service reliability, maintain minimal product analytics, enforce limits and improve features. We balance these interests against the sensitivity of private communications and minimise the data used.

Legal obligations: to keep required accounting records, answer lawful requests and comply with tax, consumer, security and data-protection law. Consent is used where the law requires it, such as optional device permissions, marketing or a provider authorisation that you can withdraw. Withdrawing a connection stops future provider access but does not make earlier lawful processing unlawful.

Gmail and Google user data

Box requests the Gmail gmail.modify scope for its visible email-client features. It reads messages, headers, bodies and attachments to show them; marks messages read or unread; applies labels; moves mail between Inbox, Archive, Spam and Trash; creates drafts; and sends the replies or new messages you choose. Box does not request the broader mail.google.com scope and does not permanently delete Gmail messages.

The use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google data is not sold, used for advertising, used to determine creditworthiness, or used to train a general-purpose AI model. It is transferred only as needed for the user-facing Box feature you request, for security, or where law requires it.

Email lists and recent metadata are cached on your device to make the mailbox responsive. The web cache deliberately excludes loaded message bodies and attachments. Full content is fetched when you open it or ask Box AI to use it. If an AI answer quotes or summarises mail, that resulting Box AI conversation remains in your history until you delete it or your account. Do not enable AI for content you are not authorised to send to the listed AI provider.

Human access to Google user data is prohibited except when you give documented permission for specific support, access is necessary for a security investigation, the data is aggregated and anonymised for internal operations, or access is required by law. Access is limited to what that purpose requires.

Disconnect Gmail in Settings → Accounts to stop syncing, revoke Box access at Google and delete the stored Box credential. You can also revoke Box at myaccount.google.com/permissions.

Outlook and Microsoft data

For Outlook, Hotmail and Microsoft 365, Box requests Mail.ReadWrite and Mail.Send to display, organise, draft and send mail, and User.Read to identify the mailbox. Offline access allows the requested connection to continue without asking you to sign in each hour.

Microsoft content is subject to the same Box minimisation, AI, human-access, security and retention practices described for email above. Disconnecting in Settings → Accounts stops Box access and deletes the credential held by Box, but Microsoft does not provide Box with a compatible per-user token-revocation endpoint. Remove the app separately from your Microsoft account or organisation if you also want to withdraw the Microsoft-side consent grant.

Chat channels, WhatsApp and team communication

When you connect an eligible Instagram, Messenger, Facebook Page or WhatsApp account, Box imports and stores the selected conversation history and later messages so the unified inbox, search, notifications and replies work. The provider continues to hold its own copy under its terms.

The official Meta APIs are used where available. A linked-device WhatsApp connection, if offered, behaves like another device attached to your WhatsApp account and is not the official WhatsApp Business Cloud API. It may be interrupted or withdrawn by the provider. Disconnecting requires Box to unlink that device or unsubscribe the relevant Meta webhooks before it removes the Box credential and imported account data. Deleting a credential does not itself remove an underlying Facebook Login grant; that grant can be removed in Facebook settings.

Team messages and files are stored in Box for the team and are visible only to authorised team members under the team’s access rules. A team owner is responsible for membership and for removing access promptly when somebody leaves.

AI processing

Box sends only the prompt and communication context needed for the AI feature you invoke to the AI provider listed in our Subprocessor Register. AI features are optional. API data is not used to train the provider’s general models by default, unless Nivora were to opt in; Nivora has not authorised such training.

The AI provider may retain limited abuse-monitoring records under its enterprise/API settings and legal obligations. Box requests non-persistent API responses where supported. AI output can be wrong or incomplete, so you must review important drafts and actions before confirming them.

Box does not make legal, employment, credit, insurance or similarly significant decisions about you solely by automated means. Safety classification and suggested actions assist the user and remain reviewable.

Who receives data

We use service providers for authentication, database and encrypted storage, application hosting, infrastructure, AI processing, payment processing and push delivery. The current providers, purpose, location and transfer safeguards are listed at box.nivoraworks.com/subprocessors. They may process data only for the contracted service and applicable legal duties.

Resend receives the recipient address, sender, subject, invitation or marketing content and delivery metadata when Nivora sends a Box waitlist message. It does not receive connected mailbox or chat content for that purpose.

Google, Microsoft, Meta/WhatsApp and Apple are also recipients when you direct Box to connect to or communicate through their services. They process data under their own terms for their platform functions. Stripe acts as a processor for some payment operations and as an independent controller for regulated payment, fraud and compliance activities.

We may disclose the minimum necessary data where required by a binding legal request, to protect users and the service, or in a corporate transaction subject to confidentiality and prior notice where lawful. We do not sell personal data or share private communications with data brokers or advertising networks.

International transfers

The primary Box database is configured in the European Union. Some providers or their subprocessors can process support, delivery, security, payment or AI data outside the EEA. Where an adequacy decision does not apply, we rely on the European Commission Standard Contractual Clauses and relevant provider data-processing terms, and apply supplementary safeguards where the transfer risk requires them.

You can request a copy or summary of the applicable transfer safeguards at box@nivoraworks.com.

Retention and deletion

Account, preference, connected-chat and team content is kept while the account or connection is active because it is needed for the service. Disconnecting a channel stops future syncing and removes its stored credential and imported channel data after any required provider cleanup succeeds. Deleting the Box account removes account data, messages, AI conversations, connection credentials and user-scoped files from active systems, subject to required remote cleanup succeeding and limited backup rotation or a legal hold. Provider-side consent remains until separately withdrawn where the provider does not offer Box a compatible revocation endpoint, including Microsoft consent and an underlying Facebook Login grant.

Email bodies and attachments are fetched from the email provider when needed and are not retained in the durable web mailbox cache. Recent headers, sender, subject, snippet, folder and timestamps can remain in that user-scoped device cache until sign-out, account deletion, site-data clearing or replacement by newer rows. AI conversation content remains until you delete the conversation or account.

A waitlist address remains active until you unsubscribe or ask us to delete it. After opt-out, we may retain the minimum address and suppression evidence needed to ensure we do not add or contact it again and to demonstrate compliance. Resend states that email and log data on its standard plans is retained for 30 days, with protected backups persisting for seven days.

OAuth handshake records are short-lived and expire after the connection attempt. Pending AI actions expire after a short confirmation window. Operational queues, fraud controls and security logs are retained only for the period reasonably needed to deliver, secure and troubleshoot the service, then deleted or de-identified; an active investigation or legal duty can require longer retention.

Invoices and supporting accounting records are retained for ten years where Belgian tax and bookkeeping law requires it. They do not contain message bodies. Payment providers may keep regulated payment records under their own legal duties. Backup copies are isolated from ordinary use and disappear on the hosting provider’s rolling schedule rather than being restored as active account data.

Security and confidentiality

We use risk-based technical and organisational controls including TLS in transit, encrypted managed storage, a server-side secrets vault for provider credentials, tenant-scoped database policies, least-privilege service access, input and rate controls, dependency and secrets scanning, restricted administrative access, backups and incident procedures. We test controls and correct findings according to severity.

No internet service can truthfully promise perfect security. You must protect your device and account, use a unique password and available multi-factor authentication, keep team membership current and report suspicious access promptly. Send vulnerability reports to box@nivoraworks.com with the subject “Security report”; do not include private message content in the initial report.

Your rights and choices

Depending on the law that applies, you can request access, a copy, correction, deletion, restriction, portability or objection, and withdraw consent where consent is the basis. Email box@nivoraworks.com. We verify identity and normally respond within one month. If your organisation controls the communication, contact it first; we will assist it as processor.

You can disconnect a provider in Settings → Accounts, delete individual AI conversations, change optional notification permissions and delete your account in Settings. Provider permissions can also be revoked directly at the provider.

You may complain to the Belgian Data Protection Authority at dataprotectionauthority.be or to the competent authority where you live or work. Contacting us first can help us resolve the issue quickly but is not required.

Children and changes

Box is a business communication service and is not directed to children under 16. Do not create an account for a child or connect a child’s communications without a valid legal basis and appropriate safeguards.

We will update this policy when data uses or providers materially change. The date above identifies the version. For a material new use of connected data, we will provide prominent notice and request consent where required before that use begins.

Last updated: 5 September 2026 · Nivora Works · Bruges, Belgium