Effective Date: September 29, 2026
This policy explains how Hibox handles personal data of people in Europe, the UK, and Switzerland. We control a small amount of data about our website visitors and account contacts. Everything our nonprofit customers put into Hibox belongs to them, and we process it only on their instructions. You have rights over your data, and you can use them by emailing support@hibox.co.
This summary is for convenience only. The full policy below is what applies.
This policy explains how Hibox LLC, doing business as Hibox for Nonprofits (“Hibox,” “we,” “us”), handles personal data under the European Union General Data Protection Regulation (“EU GDPR”), the United Kingdom General Data Protection Regulation and Data Protection Act 2018 (“UK GDPR”), and the Swiss Federal Act on Data Protection. In this policy, “GDPR” means all of these laws.
It applies to personal data about people in the European Economic Area (EEA), the United Kingdom, and Switzerland. It adds to our Privacy Policy, which still applies. If the two conflict for these people, this policy controls.
Back to topUnder GDPR, a controller decides why and how personal data is used. A processor handles personal data only on a controller’s instructions.
GDPR requires a legal basis for each use of personal data. When Hibox is the controller, we use the following.
| Purpose | Personal data | Legal basis |
|---|---|---|
| Setting up and running accounts | Names, work email, phone, job title, login details | Performing our contract with the Customer; our legitimate interest in serving the people who use Hibox for their organization |
| Billing and payments | Billing contact details, invoices, payment records | Performing our contract; legal obligation (tax and accounting) |
| Support | Support requests and related contact details | Performing our contract; legitimate interest in helping our customers |
| Service and security messages | Contact details | Legitimate interest in keeping customers informed and the service secure |
| Security, fraud prevention, and system logs | IP address, device and browser data, activity logs | Legitimate interest in protecting Hibox and our customers |
| Improving Hibox | Usage data about features and performance | Legitimate interest in improving our service |
| Marketing emails | Name, email, organization | Consent, or legitimate interest where the law allows for business contacts. You can opt out at any time. |
| Website analytics and non essential cookies | Cookie IDs, pages viewed, device data | Consent |
| Legal compliance | Any data needed to respond to legal requests or enforce our terms | Legal obligation; legitimate interest in protecting our rights |
Where we rely on legitimate interests, we have balanced our interests against your rights. You can ask us for more detail about that balance.
Back to topWhen Hibox processes Customer Data, the Customer decides what data to collect, why, and on what legal basis. We process Customer Data only on the Customer’s documented instructions and only to provide the Hibox service.
Our Data Processing Agreement includes the terms GDPR Article 28 requires, such as confidentiality, security, use of subprocessors, help with individual rights requests, breach notice, and deletion or return of data at the end of the service.
If you are a participant, family member, staff member, volunteer, or donor of an organization that uses Hibox, that organization is responsible for your data. Please contact them first. If you contact us, we will pass your request to the organization.
Back to topSpecial category data. Customers may store data GDPR treats as especially sensitive, such as health details (for example, allergies and medications), racial or ethnic origin, or religious beliefs. Customers must have a valid condition under GDPR Article 9 before collecting it and should use Hibox permissions to limit who can see it.
Children. The age at which a child can give their own consent online ranges from 13 to 16 depending on the country. Where a Customer relies on consent for a child below that age, the Customer must get consent from the parent or guardian. Hibox never uses children’s data for marketing or profiling.
Back to topHibox is based in the United States, and personal data is stored and processed in the United States on Amazon Web Services (AWS). When personal data comes from the EEA, UK, or Switzerland, it is transferred to and processed in the United States. We protect it with encryption in transit and at rest, strict access controls, and the other measures described in this policy and our Data Processing Agreement.
Back to topWe use a small number of subprocessors to provide Hibox, including AWS for hosting, Twilio for text messages, SendIt for email, Stripe for payments, Checkr and Sterling for background screening, and OpenAI for AI features. The full list, with what each one does, is in Annex C of our Data Processing Agreement.
Each subprocessor is bound by a written contract with data protection terms at least as strong as ours. We give Customers at least 30 days notice before adding or replacing a subprocessor, and Customers may object.
Back to topUnder GDPR, you have the right to:
How to make a request. Email support@hibox.co. We will verify your identity and respond within one month. We may extend this by two more months for complex requests and will tell you if we do. Requests are free unless they are clearly unfounded or excessive.
Data a Customer controls. If your request is about Customer Data, we will send it to the organization that controls it and help them respond.
Complaints. You can complain to the data protection authority where you live or work. In the UK, this is the Information Commissioner’s Office (ICO). We would appreciate the chance to address your concern first.
Back to topWe keep personal data only as long as we need it for the purposes above.
We protect personal data with measures that fit the risk, including encryption in transit and at rest, role based access controls, logical separation of each Customer’s data, regular backups, and monitoring. Our full list of measures is in Annex B of our Data Processing Agreement.
If a breach happens:
We may update this policy from time to time. We will post the new version on this page and change the date at the top. For major changes, we will notify account administrators by email before the changes take effect.
Back to topFor questions about this policy or your data, contact us at:
Hibox LLC, doing business as Hibox for Nonprofits