Privacy Policy

Last updated: June 4,2025

General Information

The protection of our users' data is important to us. We therefore process user-related data exclusively on the basis of the legal provisions of the General Data Protection Regulation (GDPR), the Data Protection Act (DSG) and the Telecommunications Act (TKG 2003).
This data protection agreement provides information about the most important aspects of data processing on our website.

Boxbase Operator

The website “Boxbase” (https://boxbase.app) is operated by Luminous Falcon GmbH.
Further details can be found in our imprint (https://boxbase.app/imprint).

In the following Boxbase is named as the operator.

What data do we process?

Contact

Boxbase (Luminous Falcon GmbH, Littengasse 2B, 6850 Dornbirn, Austria) processes personal data as data controller within the meaning of the GDPR.

You can contact us via the contact form on the website or by email (hi@boxbase.app).
The information you provide will be stored by us for twelve months for the purpose of processing the inquiry and in the event of follow-up questions. We do not pass on this data.

Hosting

We host the content of our website with the following provider:

  • Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA

You can find out more about the standard contractual clauses and data processed through the use of Cloudflare in the privacy policy at https://www.cloudflare.com/de-de/privacypolicy/.

Disclaimer

Despite careful content control, we are not liable for external links to third-party content. The operators of the linked pages are solely responsible for their content.

Legal Basis

EU General Data Protection Regulation (GDPR)

The processing of your data by Luminous Falcon GmbH, the company behind Boxbase, is based on your consent or where such processing is necessary for the performance of a contract to which you are a party, or to take steps at your request before entering into a contract, in accordance with Article 6(1)(a)-(b) of the GDPR.

If you are a resident of the EEA, you have the following data protection rights:

  • You can access, correct, update, or request deletion of your personal information at any time by emailing hi@boxbase.app.
  • You can also request to restrict or object to the processing of your data, or request data portability, by contacting us at the same email address.
  • If we process your data based on consent, you may withdraw your consent at any time. This will not affect processing conducted prior to your withdrawal.
  • You have the right to lodge a complaint with your local data protection authority if you believe your data rights are being violated.

We respond to all requests in accordance with applicable data protection laws.

Children’s Online Privacy Protection

Boxbase is intended for use by adults and business entities. We do not knowingly collect personal data from individuals under the age of 13. If we become aware of such collection, we will delete the data promptly.

How Do We Protect Your Information?

Confidentiality

All personal data is protected with appropriate access controls. We do not collect or store sensitive financial data ourselves. Our infrastructure providers, including DigitalOcean, and Stripe are GDPR-compliant. All employees and contractors are bound by confidentiality obligations.

Transparency

We are committed to keeping you informed about any changes to our data protection practices. You can request details on how and where your data is processed at any time via hi@boxbase.app.

Monitoring

To ensure reliability and performance, we use a combination of internal and external monitoring tools.

Personal Data Breach Notification

In the event of a data breach, we will notify affected users and relevant authorities within 72 hours. The notification will include the scope, potential consequences, and mitigation actions.

A “personal data breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data.

How We Use Cookies

Cookies are small text files placed on your device to help the website function and collect information about your interaction. Only essential cookies are set without your consent; all others require your approval.

  • Strictly necessary cookies — These are essential for core functions like login and account management.
  • Performance cookies — Used to analyze how users interact with our site. These do not directly identify you.
  • Targeting cookies — Set by services like Meta Pixel to deliver relevant content or track usage across websites.

You can adjust your preferences at any time using our cookie settings panel.

CookieProviderPurposeTypeDuration
_fbpMeta (Facebook)Stores a unique ID to track visits across websites and deliver ads.Targeting3 months
__cf_bmAhrefsUsed to distinguish human users from bots.Functional30 minutes
CookieScriptConsentCookieScriptThis cookie is used by Cookie-Script.com service to remember Cookie-Script.com cookie banner to work properly.Strictly necessary1 year
XSRF-TOKENadmin.boxbase.appThis cookie is written to help with site security in preventing Cross-Site Request Forgery attacks.Strictly necessary1 hour 59 minutes

Do We Disclose Any Information to Outside Parties?

Boxbase does not sell, trade, or otherwise transfer your personally identifiable information to outside parties.

This excludes trusted third parties or subcontractors who help us operate our services, conduct business, or support you. These parties only access your data on a need-to-know basis and are contractually bound to confidentiality.

We may also release your information when required to comply with the law, enforce our policies, or protect our or others’ rights, property, or safety.

Subcontractors / Trusted Third Parties

Our current subcontractors include:

  • DigitalOcean, LLC
  • Stripe Payments Europe Ltd.
  • Ahrefs Pte. Ltd.
  • Cloudflare, Inc.

All providers have implemented necessary measures to comply with the GDPR.

Legally Required Disclosure

We will not disclose customer data to law enforcement except when instructed by you or legally required. If a government request is received, we aim to limit disclosure and will inform you (unless legally prohibited) with a copy of the request.

Third-Party Services

Our service may include links to third-party services. We are not responsible for the privacy policies or practices of those services and recommend reviewing their respective privacy policies.

Where Do We Store the Information?

No data stored by Boxbase is transferred or backed up outside the European Union. Our vendors are required to either store data in the EU or comply with mechanisms such as the EU-US Data Privacy Framework.

Personal Data Location

All databases are hosted on DigitalOcean, LLC in Amsterdam. Data is backed up regularly and stored in the same geographical region for up to 30 days to ensure recoverability.

Data Access

If you have a Boxbase account, you can access your data by logging into your dashboard.

You may also contact us at hi@boxbase.app to confirm whether we are processing your personal data.

Request for Rectification, Restriction, or Erasure

Rectification

You may request correction of inaccurate or outdated personal data at any time.

Restriction of Processing

You may request restricted processing if:

  • You contest the accuracy of the data (pending verification).
  • Processing is unlawful but you request restriction instead of deletion.
  • We no longer need the data but you need it for legal claims.

Erasure

You may request deletion of your personal data if:

  • The data is no longer needed for its original purpose.
  • You withdraw your consent with no other legal basis for processing.
  • The data has been unlawfully processed.
  • We are required to delete it for legal compliance.

Data Retention

Retention Policy

Due to tax regulations, membership and payment data may be retained for up to three fiscal years after service cancellation. All other account data is deleted immediately when request data erasure.

Legal Compliance

Retention periods are governed by legal obligations and cannot be changed unless required by law.

Your Consent

By using Boxbase, you consent to our Privacy Policy.

Changes to This Privacy Policy

We may update this policy periodically. Material changes will be communicated via the service, and the last updated date at the top of this page will reflect the latest version.

Complaints

You may lodge a complaint with your local data protection authority. You may also contact us about data protection matters by emailing hi@boxbase.app.