Last Updated: Dec 03, 2024
BOTI Box is committed to protecting your privacy and ensuring that your personal data is handled in a safe and responsible manner. This GDPR Compliance page outlines how we comply with the General Data Protection Regulation (GDPR).
1. Data Controller
BOTI Box acts as the data controller for the personal data you provide to us. If you have any questions or concerns regarding the processing of your data, please contact us:
BOTI Box
Email: info@botibox.com
Phone: (612) 234-1676
2. Personal Data We Collect
We may collect and process the following personal data:
- Name
- Email address
- Mailing address
- Phone number
- Payment information
- Order history
- Technical data (e.g., IP address, browser type, and browsing behavior collected via cookies and similar technologies)
3. How We Use Your Personal Data
We use your personal data for the following purposes:
- To process and fulfill your orders
- To communicate with you regarding your orders and provide customer support
- To send reminders about incomplete purchases (abandoned cart emails)
- To send you marketing communications, if you have opted in to receive them
- To improve our website and services
- To analyze website traffic using Google Analytics
- To comply with legal obligations
You can opt out of marketing communications or abandoned cart emails at any time by clicking the unsubscribe link or contacting us at info@botibox.com.
4. Legal Basis for Processing
We process your personal data based on the following legal grounds:
- Contractual necessity: To fulfill a contract with you (e.g., processing your orders).
- Consent: When you have provided explicit consent (e.g., to receive marketing communications).
- Legal obligation: To comply with applicable laws (e.g., tax or regulatory requirements).
- Legitimate interests: For purposes such as improving our services, analyzing website traffic, or sending abandoned cart reminders, provided these do not override your rights and interests.
When processing is based on legitimate interests, we ensure a careful balancing of our interests and your privacy rights.
5. Google Analytics
We use Google Analytics to analyze website traffic and improve our services. This involves collecting information about your device, IP address, and browsing behavior through cookies. Google Analytics processes this data in compliance with GDPR, and you can learn more about how Google handles data at Google’s Privacy Policy.
You can opt out of Google Analytics tracking by using Google’s opt-out browser add-on.
6. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected and to comply with legal obligations. For example:
- Order data is retained for up to 7 years for tax purposes.
- Marketing data is retained until you withdraw consent or it becomes irrelevant.
After these periods, we securely delete or anonymize your data.
7. Your Rights
Under GDPR, you have the following rights regarding your personal data:
- Right to access: Request access to the data we hold about you.
- Right to rectification: Request corrections to inaccurate or incomplete data.
- Right to erasure: Request the deletion of your data, subject to certain conditions.
- Right to restrict processing: Request that we limit how we process your data under certain circumstances.
- Right to data portability: Receive your data in a structured, machine-readable format and have it transferred to another controller.
- Right to object: Object to data processing for specific purposes, including marketing or abandoned cart reminders.
- Right to withdraw consent: Withdraw consent for any processing based on your consent.
To exercise these rights, please contact us at info@botibox.com. We aim to respond within 30 days. You also have the right to lodge a complaint with a supervisory authority, such as [local authority name].
8. Data Security
We implement appropriate technical and organizational measures to protect your personal data from unauthorized access, disclosure, alteration, or destruction. These include encryption, secure servers, and restricted access controls. However, no security measure is completely foolproof, and we cannot guarantee absolute security.
9. Third-Party Disclosure
We do not sell, trade, or otherwise transfer your personal data to outside parties, except as described in this policy. We may share your data with trusted third parties, such as:
Payment processors
- Hosting providers
- Email marketing services
- Google Analytics
These parties process your data only for specified purposes and in compliance with GDPR.
10. International Transfers
Your personal data may be transferred to and processed in countries outside your residence. These countries may have data protection laws that differ from your country. To ensure your data is protected, we use appropriate safeguards, such as Standard Contractual Clauses or other mechanisms approved under GDPR.
11. Cookies
We use cookies and similar technologies to enhance your experience, analyze website traffic, and support our services.
- Analytics Cookies: These cookies collect aggregated data on how users interact with our site, including page visits and time spent on the site.
You can manage or disable cookies in your browser settings or opt out of analytics cookies using Google’s opt-out tool. For more details, see our Cookie Policy.
12. Children’s Data
We do not knowingly collect data from individuals under the age of 16 without parental consent. If you believe a child has provided us with their data, please contact us immediately.
13. Updates to This Policy
This policy is effective as of August 12, 2024. We may update it periodically. Significant changes will be communicated via email or a notice on our website.