Privacy Policy
PRIVACY POLICY
1) INFORMATION ABOUT THE COLLECTION OF PERSONAL DATA AND CONTACT DETAILS OF THE CONTROLLER
1.1
We are pleased that you are visiting our website and thank you for your interest. Below, we inform you about how we handle your personal data when using our website. Personal data is any data by which you can be personally identified.
1.2
The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is Boxein. The controller is the natural or legal person who alone or jointly with others determines the purposes and means of processing personal data.
1.3
For security reasons and to protect the transmission of personal data and other confidential content (e.g., orders or inquiries), this website uses SSL or TLS encryption. You can recognize an encrypted connection by the “https://” string and the lock symbol in your browser bar.
2) DATA COLLECTION WHEN VISITING OUR WEBSITE
When you use our website for informational purposes only (i.e., if you do not register or otherwise provide us with information), we only collect data that your browser transmits to our server (so-called “server log files”).
When you access our website, we collect the following data necessary to display the website:
-
Visited website
-
Date and time of access
-
Amount of data sent in bytes
-
Source/referral from which you accessed the page
-
Browser used
-
Operating system used
-
IP address (possibly anonymized)
Processing is carried out in accordance with Art. 6 (1) (f) GDPR based on our legitimate interest in improving the stability and functionality of our website. The data will not be shared or used for other purposes. However, we reserve the right to review server log files if there are concrete indications of unlawful use.
3) COOKIES
To make your visit to our website attractive and enable certain functions, we use cookies on various pages. Cookies are small text files stored on your device.
Some cookies are deleted after the browser session ends (session cookies). Others remain on your device and allow us or partner companies (third-party cookies) to recognize your browser on your next visit (persistent cookies).
If cookies are set, they collect and process certain user information such as browser data, location data, and IP address values.
Persistent cookies are automatically deleted after a specified period, which may vary depending on the cookie.
Some cookies simplify the ordering process (e.g., remembering shopping cart contents for a later visit). If personal data is processed via cookies, processing is carried out in accordance with:
-
Art. 6 (1) (b) GDPR (contract performance), or
-
Art. 6 (1) (f) GDPR (legitimate interest in optimal website functionality and customer-friendly design).
You can configure your browser to inform you about cookie settings and decide individually whether to accept them or exclude them for certain cases or generally. Please note that disabling cookies may limit website functionality.
4) CONTACTING US
When you contact us (e.g., via contact form or email), personal data is collected. The data collected via contact forms is visible in the respective form.
The data is used exclusively to respond to your inquiry and for related technical administration.
Legal basis:
-
Art. 6 (1) (f) GDPR (legitimate interest in responding)
-
Art. 6 (1) (b) GDPR (if contact aims at concluding a contract)
Your data will be deleted after final processing unless legal retention obligations apply.
5) DATA PROCESSING WHEN OPENING A CUSTOMER ACCOUNT AND FOR CONTRACT PROCESSING
Personal data is collected and processed according to Art. 6 (1) (b) GDPR when you provide it to perform a contract or open a customer account.
Your customer account can be deleted at any time by contacting us.
After full contract processing or account deletion, data is blocked considering tax and commercial retention periods and deleted after expiration unless further consent is given.
6) USE OF DATA FOR DIRECT MARKETING
6.1 Email Newsletter Subscription
If you subscribe to our newsletter, we will regularly send you information about our offers. Only your email address is mandatory.
We use the double opt-in procedure. You will receive a confirmation email to verify your subscription.
Legal basis: Art. 6 (1) (a) GDPR (consent)
You may unsubscribe at any time via the unsubscribe link or by contacting us.
6.2 Newsletter to Existing Customers
If you provided your email address when purchasing goods/services, we may send you offers for similar products.
Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in personalized advertising)
You can object to this at any time.
7) DATA PROCESSING FOR ORDER HANDLING
Personal data is shared with shipping companies for delivery and financial institutions for payment processing.
Legal basis: Art. 6 (1) (b) GDPR
Payment providers used:
-
SOFORT (Klarna Group)
- AMEX/MASTERCARD
- Apple Pay
These providers may conduct credit checks where necessary.
8) REVIEW REMINDER
We may send you a one-time review reminder email if you have explicitly consented (Art. 6 (1) (a) GDPR).
9) SOCIAL MEDIA PLUGINS
We use social plugins for:
-
Facebook
-
Google+
-
Instagram
These are integrated using a secure Shariff solution to protect your data.
Data collection purpose and scope can be found in each provider’s privacy policy.
10) ONLINE MARKETING
We use:
-
DoubleClick by Google
-
Google Ads Conversion Tracking
Legal basis: Art. 6 (1) (f) GDPR
These tools use cookies to display relevant advertisements and measure campaign performance.
You may disable cookies or opt out via Google settings.
11) WEB ANALYTICS SERVICES
Google Analytics (Universal Analytics)
This website uses Google Analytics with IP anonymization ("_anonymizeIp()").
Legal basis: Art. 6 (1) (f) GDPR
You can prevent tracking by:
-
Browser settings
-
Installing Google’s opt-out browser plugin
12) RETARGETING / REMARKETING
We use:
-
Facebook Pixel
-
Google Ads Remarketing
Data collected is anonymized for us but may be processed by Facebook/Google according to their privacy policies.
Legal basis: Art. 6 (1) (a) GDPR (consent)
13) YOUR RIGHTS
Under GDPR, you have the following rights:
-
Right of access (Art. 15 GDPR)
-
Right to rectification (Art. 16 GDPR)
-
Right to erasure (Art. 17 GDPR)
-
Right to restriction of processing (Art. 18 GDPR)
-
Right to data portability (Art. 20 GDPR)
-
Right to withdraw consent (Art. 7 (3) GDPR)
-
Right to lodge a complaint (Art. 77 GDPR)
Right to Object
You may object at any time to processing based on legitimate interests.
If data is processed for direct marketing, you have the right to object at any time.
14) DATA RETENTION PERIOD
Personal data is stored according to statutory retention periods (e.g., commercial and tax law).
After expiration, data is routinely deleted unless required for contract fulfillment or there is a legitimate interest in further storage.