The personal data we collect about you depends on the particular activities carried out through our website. We will collect and use the following personal data about you:
name, address (delivery, shipping, registered), contact information, including email address and telephone number and company details;
information to check and verify your identity;
your billing information, transaction and payment card or other payment method information, e.g., bank account and payment details;
details of any information, feedback or other matters you give to us by phone, email, post or via social media;
your account details, such as username and login details;
your activities on, and use of, our website;
your professional interests;
your professional online presence, e.g., LinkedIn profile;
information about the services we provide to you;
your contact history, purchase history and saved items;
information about how you use our website and technology systems;
your responses to surveys, competitions and promotions; and
boxxe does not collect or process sensitive personal data (race, ethnic origin, political opinion, religious or philosophical beliefs, trade union membership, genetic data, biometric data, sexual orientation of health data).
We collect personal data from you:
directly, when you enter or send us information, such as when you for example, register with us, contact us (including via email), send us feedback, purchase products or services via our website, post material to our website and complete customer surveys or participate in competitions via our website; and
indirectly, such as your browsing activity while on our website; we will usually collect information indirectly using the technologies explained in the section on ‘Cookies and other tracking technologies’ below.
Under data protection law, we can only use your personal data if we have a proper reason, for example:
where you have given consent;
to comply with our legal and regulatory obligations;
for the performance of a contract with you or to take steps at your request before entering into a contract; or
for our legitimate interests or those of a third party.
A legitimate interest is when we have a business or commercial reason to use your personal data, so long as this is not overridden by your own rights and interests. We will carry out an assessment when relying on legitimate interests, to balance our interests against your own. You can obtain details of this assessment by contacting us (see ‘How to contact us’ below).
The table below explains what we use your personal data for and why:
|What we use your personal data for
|Creating and managing your account with us
|To perform our contract with you or to take steps at your request before entering into a contract
|Providing products and/or services to you
|To perform our contract with you or to take steps at your request before entering into a contract
|Conducting checks to identify you and verify your identity or to help prevent and detect fraud against you or us
|To comply with our legal and regulatory obligations
|Enforcing legal rights or defend or undertake legal proceedings
|Depending on the circumstances:
— to comply with our legal and regulatory obligations
— in other cases, for our legitimate interests, i.e. to protect our business, interests and rights
|Customising our website and its content to your particular preferences based on a record of your selected preferences or on your use of our website
|Depending on the circumstances: — your consent as gathered e.g., by the separate cookies tool on our website—see ‘Cookies and other tracking technologies’ below — where we are not required to obtain your consent and do not do so, for our legitimate interests, i.e., to be as efficient as we can so we can deliver the best service to you at the best price If you have provided such a consent, you may withdraw it at any time by changing the setting on the cookies tool (this will not affect the lawfulness of our use of your personal data in reliance on that consent before it was withdrawn)
|Retaining and evaluating information on your recent visits to our website and how you move around different sections of our website for analytics purposes to understand how people use our website so that we can make it more intuitive or to check our website is working as intended
|Depending on the circumstances: — your consent as gathered by the separate cookies tool on our website]—see ‘Cookies and other tracking technologies’ below — where we are not required to obtain your consent and do not do so, for our legitimate interests, i.e., to be as efficient as we can so we can deliver the best service to you at the best price If you have provided such a consent you may withdraw it at any time by clearing your cookie settings and rejecting when you revisit our website (this will not affect the lawfulness of our use of your personal data in reliance on that consent before it was withdrawn)
|Communications with you not related to marketing, including about changes to our terms or policies or changes to the products AND/OR services or other important notices
|Depending on the circumstances: — to comply with our legal and regulatory obligations — in other cases, for our legitimate interests, i.e., to be as efficient as we can so we can deliver the best service to you at the best price
|Protecting the security of systems and data used to provide the services
|To comply with our legal and regulatory obligations We may also use your personal data to ensure the security of systems and data to a standard that goes beyond our legal obligations, and in those cases our reasons are for our legitimate interests, i.e., to protect systems and data and to prevent and detect criminal activity that could be damaging for you and/or us
|Statistical analysis to help us understand our customer base
|For our legitimate interests, i.e., to be as efficient as we can so we can deliver the best service to you at the best price
|Updating and enhancing customer records
|Depending on the circumstances: — to perform our contract with you or to take steps at your request before entering into a contract — to comply with our legal and regulatory obligations — where neither of the above apply, for our legitimate interests, e.g., making sure that we can keep in touch with our customers about existing orders and new products
|Disclosures and other activities necessary to comply with legal and regulatory obligations that apply to our business, e.g. to record and demonstrate evidence of your consents where relevant
|To comply with our legal and regulatory obligations
|Marketing our services to existing and former customers
|For our legitimate interests, i.e., to promote our business to existing and former customers See ‘Marketing’ below for further information
|The audit of our ISO certifications (to the extent not covered by ‘activities necessary to comply with legal and regulatory obligations’ above)
|For our legitimate interests, i.e., to maintain our accreditations so we can demonstrate we operate at the highest standards
|To share your personal data with members of our group and third parties that will or may take control or ownership of some or all of our business (and professional advisors acting on our or their behalf) in connection with a significant corporate transaction or restructuring, including a merger, acquisition, asset sale, initial public offering or in the event of our insolvency. In such cases information will be anonymised where possible and only shared where necessary
|Depending on the circumstances: — to comply with our legal and regulatory obligations — in other cases, for our legitimate interests, i.e., to protect, realise or grow the value in our business and assets
We will use your personal data to send you updates (by email, telephone or post) about our products and/or services, including exclusive offers, promotions or new products and/or services, events, webinars. We have a legitimate interest in using your personal data for marketing purposes (see above ‘How and why we use your personal data’). This means we do not need your consent to send you marketing information. If we change our marketing approach in the future so that consent is needed, we will ask for this separately and clearly.
You have the right to opt out of receiving marketing communications at any time by:
For more information on your right to object at any time to your personal data being used for marketing purposes, see ‘Your rights’ below.
We do not sell any of our marketing data to third parties.
We routinely share personal data with:
We or the third parties mentioned above occasionally also share personal data with:
More details about who we share your personal data with and why are set out in the table below.
|Processing operation (use) by recipient
|Relevant categories of personal data transferred to recipient
|We use Google Analytics (GA4) cookies to collect data about the visitors to the site which includes the number of visitors, session duration, pages visited during the session etc. and whether visitors return. Google Analytics will assign a unique “ID” to a user of the boxxe website at the point they register an account with us for the purpose of tracking their activity on the boxxe website. This information is anonymous and cannot be used to identify you personally unless you end up becoming a boxxe customer. Google Analytics cannot use the ID to work out who you are.
|Device’s IP address (processed during your session and stored in a de-identified form) geographic location (country only), and the preferred language used to display our website. Google Analytics stores this information on our behalf in a pseudonymized user profile.
|This includes a device's IP address (processed during your session and stored in a de-identified form), device screen size, device type (unique device identifiers), browser information, geographic location (country only), and the preferred language used to display our website. Hotjar stores this information on our behalf in a pseudonymized user profile.
|Device’s IP address (processed during your session and stored in a de-identified form) geographic location (country only), and the preferred language used to display our website. Klevu stores this information on our behalf in a pseudonymized user profile.
|Dotdigital is a SaaS cross-channel marketing automation platform and services provider that helps brands devise successful, personalized marketing campaigns across multiple channels (e.g. email). Paired with its Microsoft Dynamics 365 CRM integration, boxxe is able to deliver tailored marketing to its customers.
|Contact data (such as email address, contact number, name or other contact details), marketing preferences, IP address and usage information (including online navigation data, location data and browser data).
In addition, depending on the products/services and your interaction with us, we may also need to disclose your personal data to third parties for the performance of a contract with you, to meet a legal obligation or for our legitimate interests, which may include but is not limited to:
If you would like more information about who we share our data with and why, please contact us (see ‘How to contact us’ below).
It is sometimes necessary for us to transfer your personal data to countries other than the UK, and these countries may have data protection laws that differ from the laws of the UK.
Specifically, our group companies and our website servers are located in the EU and UK, however, some of our third-party service providers, and partners operate around the world. This means that when we collect your personal data, we may process it in a number of different countries.
In the event we cannot or choose not to continue to rely on either of those mechanisms at any time we will not transfer your personal data outside the UK unless we can do so on the basis of an alternative mechanism or exception provided by UK data protection law and reflected in an update to this policy.
More details about the countries outside the UK to which your personal data is transferred are set out in the table below.
|Processing operation (use) by recipient
|Adequacy regulation further to paragraph 5(1)(a) of Part 3 of Schedule 21 to the Data Protection Act 2018 https://www.hotjar.com/legal/support/dpa/
|In order to facilitate online payments through boxxe’s ecommerce portal, where applicable, Stripe may Process Payment Account Details, bank account details, billing/shipping address, name, date/time/amount of transaction, device ID, email address, IP address/location, order ID, payment card details, tax ID/status, unique customer identifier, identity information including government issued documents (e.g., national IDs, driver’s licenses and passports).
|UK Data Transfer Addendum https://stripe.com/gb/legal/dpa
|Vaimo has access to certain categories of boxxe customer personal data (names, addresses, DOB, email, number, location, device and diagnostic data, connection data), by virtue of hosting the boxxe website.
|Adequacy regulation further to paragraph 5(1)(a) of Part 3 of Schedule 21 to the Data Protection Act 2018. Vaimo also has a legally valid intra-group agreement in place and no data is transferred to any entity who is not a party to it.
|Boxxe will provide certain information about its customers to Dotdigital in order for it to be able to provide automated marketing services that are tailored to its specific customer interests.
|Adequacy regulation further to paragraph 5(1)(a) of Part 3 of Schedule 21 to the Data Protection Act 2018. https://dotdigital.com/terms/data-processing-agreement/
We retain your personal data for as long as is necessary to fulfil the purpose that we collected it for, including the satisfaction of any legal, accounting or reporting requirements. This includes data for tax and accounting requirements under applicable law. If you make a purchase from boxxe, we will keep the information for tax and accounting requirements under applicable law.
Data is reviewed regularly and only retained where necessary. To determine the appropriate retention period of your data, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from a loss of confidentiality to the data and any legal requirements to retain such personal data. Once any legal requirements have expired for the data, we destroy all personal data associated with you and the product or service that you have purchased.
If you stop using your account we will delete or anonymise your account data after seven years.
The confidentiality of your information is extremely important to us. boxxe use reasonable physical, technical and organisational measures to safeguard the personal data you provide to us.
All data collected by boxxe is stored on our own IT system that is administered by boxxe staff. The boxxe IT system has been accredited to ISO 27001, Cyber Essentials and Cyber Essentials Plus.
It is important that the personal data we hold about you is accurate and current. Please keep us informed if the personal data we hold about you changes.
Data protection legislation provides you with several rights which you can enforce by contacting us at email@example.com, including:
|Access to a copy of your personal data
|The right to be provided with a copy of your personal data
|Correction (also known as rectification)
|The right to require us to correct any mistakes in your personal data
|Erasure (also known as the right to be forgotten)
|The right to require us to delete your personal data—in certain situations
|Restriction of use
|The right to require us to restrict use of your personal data in certain circumstances, e.g. if you contest the accuracy of the data
|The right to receive the personal data you provided to us, in a structured, commonly used and machine-readable format and/or transmit that data to a third party—in certain situations
|To object to use
|The right to object: — at any time to your personal data being used for direct marketing (including profiling) — in certain other situations to our continued use of your personal data, e.g. where we use your personal data for our legitimate interests unless there are compelling legitimate grounds for the processing to continue or the processing is required for the establishment, exercise or defence of legal claims
|Not to be subject to decisions without human involvement
|The right not to be subject to a decision based solely on automated processing (including profiling) that produces legal effects concerning you or similarly significantly affects you We do not make any such decisions based on data collected by our website
|The right to withdraw consents
|If you have provided us with a consent to use your personal data you have a right to withdraw that consent easily at any time You may withdraw consents by emailing firstname.lastname@example.org Withdrawing a consent will not affect the lawfulness of our use of your personal data in reliance on that consent before it was withdrawn
You may also find it helpful to refer to the guidance from the UK’s Information Commissioner on your rights under the UK GDPR.
If you would like a copy of some or all of your personal data, please send an email to email@example.com. In certain circumstances we reserve the right to charge a reasonable fee to comply with your request and we will ensure we respond to you within the deadlines set out within the applicable legislation.
We may request specific information from you to help us confirm your identity and your right to access, and to provide you with the personal data that we hold about you or make your requested changes. Data protection legislation may allow or require us to refuse to provide you with access to some or all the personal data that we hold about you or to comply with any requests made in accordance with your rights referred to above. If we cannot provide you with access to your personal data, or process any other request we receive, we will inform you of the reasons why, subject to any legal or regulatory restrictions.
Please send any requests relating to the above to firstname.lastname@example.org specifying your name and the action you would like us to undertake.
From time to time, we may need to update or modify this policy to reflect changes in our organisation or business practices, data collection practices or legislation. We reserve the right to amend this policy at any time, for any reason, without notice to you, other than the posting of the amended policy on this website. It is recommended to check the website regularly for the most up to date version.
We welcome any comment regarding this policy. You can contact our Data Protection Officer by email at email@example.com or by mail to boxxe Limited, Artemis House, Eboracum Way, York, YO31 7RE. This is in addition to your right to contact the Information Commissioners Office if you are unsatisfied with our response to any issues you raise at https://ico.org.uk/global/contact-us/ .