Hibox for Nonprofits GDPR Policy

Effective Date: September 29, 2026

Policy at a glance

This policy explains how Hibox handles personal data of people in Europe, the UK, and Switzerland. We control a small amount of data about our website visitors and account contacts. Everything our nonprofit customers put into Hibox belongs to them, and we process it only on their instructions. You have rights over your data, and you can use them by emailing support@hibox.co.

This summary is for convenience only. The full policy below is what applies.

1.Introduction

This policy explains how Hibox LLC, doing business as Hibox for Nonprofits (“Hibox,” “we,” “us”), handles personal data under the European Union General Data Protection Regulation (“EU GDPR”), the United Kingdom General Data Protection Regulation and Data Protection Act 2018 (“UK GDPR”), and the Swiss Federal Act on Data Protection. In this policy, “GDPR” means all of these laws.

It applies to personal data about people in the European Economic Area (EEA), the United Kingdom, and Switzerland. It adds to our Privacy Policy, which still applies. If the two conflict for these people, this policy controls.

Back to top

2.Our Two Roles

Under GDPR, a controller decides why and how personal data is used. A processor handles personal data only on a controller’s instructions.

  • Hibox is a controller for personal data about our website visitors, people who contact us, and the people who manage Hibox accounts, including billing and support contacts.
  • Hibox is a processor for Customer Data. This is the information our nonprofit customers (“Customers”) put into Hibox about their participants, families, staff, volunteers, donors, and others. Each Customer is the controller of its own Customer Data.
Back to top

4.Data We Process for Customers

When Hibox processes Customer Data, the Customer decides what data to collect, why, and on what legal basis. We process Customer Data only on the Customer’s documented instructions and only to provide the Hibox service.

Our Data Processing Agreement includes the terms GDPR Article 28 requires, such as confidentiality, security, use of subprocessors, help with individual rights requests, breach notice, and deletion or return of data at the end of the service.

If you are a participant, family member, staff member, volunteer, or donor of an organization that uses Hibox, that organization is responsible for your data. Please contact them first. If you contact us, we will pass your request to the organization.

Back to top

5.Special Categories and Children

Special category data. Customers may store data GDPR treats as especially sensitive, such as health details (for example, allergies and medications), racial or ethnic origin, or religious beliefs. Customers must have a valid condition under GDPR Article 9 before collecting it and should use Hibox permissions to limit who can see it.

Children. The age at which a child can give their own consent online ranges from 13 to 16 depending on the country. Where a Customer relies on consent for a child below that age, the Customer must get consent from the parent or guardian. Hibox never uses children’s data for marketing or profiling.

Back to top

6.International Data Transfers

Hibox is based in the United States, and personal data is stored and processed in the United States on Amazon Web Services (AWS). When personal data comes from the EEA, UK, or Switzerland, it is transferred to and processed in the United States. We protect it with encryption in transit and at rest, strict access controls, and the other measures described in this policy and our Data Processing Agreement.

Back to top

7.Subprocessors

We use a small number of subprocessors to provide Hibox, including AWS for hosting, Twilio for text messages, SendIt for email, Stripe for payments, Checkr and Sterling for background screening, and OpenAI for AI features. The full list, with what each one does, is in Annex C of our Data Processing Agreement.

Each subprocessor is bound by a written contract with data protection terms at least as strong as ours. We give Customers at least 30 days notice before adding or replacing a subprocessor, and Customers may object.

Back to top

8.Your Rights

Under GDPR, you have the right to:

  • Access a copy of your personal data
  • Correct data that is wrong or incomplete
  • Delete your data, in some cases
  • Restrict how we use your data, in some cases
  • Receive your data in a common, machine readable format and have it sent to another company (portability)
  • Object to our use of your data based on legitimate interests, and to direct marketing at any time
  • Withdraw consent at any time, where we rely on consent. This does not affect use before you withdrew.
  • Not be subject to decisions made only by automated means that have legal or similarly significant effects. Hibox does not make these kinds of decisions.

How to make a request. Email support@hibox.co. We will verify your identity and respond within one month. We may extend this by two more months for complex requests and will tell you if we do. Requests are free unless they are clearly unfounded or excessive.

Data a Customer controls. If your request is about Customer Data, we will send it to the organization that controls it and help them respond.

Complaints. You can complain to the data protection authority where you live or work. In the UK, this is the Information Commissioner’s Office (ICO). We would appreciate the chance to address your concern first.

Back to top

9.Data Retention

We keep personal data only as long as we need it for the purposes above.

  • Account and support data is kept while the account is active, and deleted or anonymized within 30 days after it closes, unless the law requires us to keep it longer.
  • Billing records are kept as long as tax and accounting laws require.
  • Marketing data is kept until you opt out or withdraw consent.
  • Customer Data is kept as the Customer directs. After an account closes, the Customer has 30 days to export its data, and we then delete it within 30 days. Backups are kept for up to 30 days.
Back to top

10.Security and Data Breaches

We protect personal data with measures that fit the risk, including encryption in transit and at rest, role based access controls, logical separation of each Customer’s data, regular backups, and monitoring. Our full list of measures is in Annex B of our Data Processing Agreement.

If a breach happens:

  • For data we control, we will notify the relevant data protection authority within 72 hours of becoming aware of it when required. If the breach is likely to put people at high risk, we will also tell the people affected without undue delay.
  • For Customer Data, we will notify the Customer without undue delay, and no later than 72 hours after confirming the breach, so the Customer can meet its own duties.
Back to top

11.Cookies

For visitors from the EEA, UK, and Switzerland, we use only essential cookies unless you agree to others. Essential cookies keep you logged in and keep Hibox secure. Analytics and other non essential cookies are set only after you give consent through our cookie banner. You can change your choice at any time through the cookie settings link on our website.

Back to top

12.Changes to This Policy

We may update this policy from time to time. We will post the new version on this page and change the date at the top. For major changes, we will notify account administrators by email before the changes take effect.

Back to top

13.Contact Us

For questions about this policy or your data, contact us at:

Hibox LLC, doing business as Hibox for Nonprofits
916 3rd Ave.
Fusion Building
Sheldon, IA 51201
United States
support@hibox.co
Back to top