1. Data Controller
IMG VENTURES LIMITED, trading as 127box
A private company limited by shares incorporated under the laws of Ireland
Registered office: 77 Camden Street Lower, Dublin, D02 XE80, Ireland
Registered with the Companies Registration Office under number 820947
Email: hello@127box.com
(hereinafter "127box", "we", "us")
2. Scope
This Policy explains how 127box collects, uses, discloses, and protects personal data of website visitors, registered Customers, and persons who contact us. It applies under Regulation (EU) 2016/679 (GDPR) and the Irish Data Protection Act 2018.
3. Personal Data We Collect
3.1 Account and Identity Data
- Full name (or registered company name)
- Email address
- Billing address
- VAT identification number (B2B)
- Authentication credentials (hashed password)
Source: Customer at registration. Legal basis: Performance of the contract (Article 6(1)(b) GDPR).
3.2 Payment Data
Payment method type, last 4 digits of card, cardholder name, billing country, transaction history. 127box does NOT store full card numbers or CVV. Payment data is processed by Stripe Payments Europe Ltd. Legal basis: Contract; legal obligation.
3.3 Service Usage Data
Cloud Server identifiers, domain registrations, SSL certificate metadata, resource usage metrics. We do NOT inspect content of Customer servers. Legal basis: Contract; legitimate interest.
3.4 Technical and Log Data
IP address, browser type, OS, timestamps, dashboard access, error logs, security events. Legal basis: Legitimate interest (security, fraud prevention).
3.5 Communications Data
Email correspondence, support tickets. We do not currently operate phone or chat support. Legal basis: Contract; legitimate interest.
3.6 What We Do NOT Collect
- Telephone numbers (we do not request them)
- Full payment card numbers / CVV (handled by Stripe)
- Special categories of personal data (Article 9 GDPR — health, biometric, religious, etc.)
- Identity documents / KYC data (not required for our services)
- Content of Customer servers, files, or applications (except in security incident investigation or as required by law)
- Browsing behavior outside 127box.com
4. Purposes of Processing
4.1 Service Provision
Account management, server/domain provisioning, payment processing, invoicing. Basis: Article 6(1)(b) GDPR.
4.2 Customer Support
Inquiry response, troubleshooting. Basis: Article 6(1)(b), 6(1)(f).
4.3 Billing, Accounting, Tax
Invoicing, accounting records, reporting to the Irish Revenue Commissioners. Basis: Article 6(1)(c) GDPR (Irish and EU tax, accounting and corporate regulations, in particular the Companies Act 2014).
4.4 Security and Abuse Prevention
Monitoring for unauthorized access, fraud, AUP violations. Basis: Article 6(1)(f); legal obligation.
4.5 Service Improvement
Aggregated usage analytics. We do NOT profile individual Customers for marketing. Basis: Article 6(1)(f).
4.6 Transactional Communications
Service-related emails (welcome, server provisioned, payment receipts, renewal reminders). Basis: Contract.
4.7 Marketing Communications
We do NOT currently send marketing newsletters. If introduced, explicit opt-in consent will be requested.
5. Recipients of Personal Data
5.1 Subprocessors
| Subprocessor | Role | Location |
|---|---|---|
| Hetzner Online GmbH | Cloud server hosting | Germany, Finland |
| Hostnet B.V. (Openprovider) | Domain registration, DNS | Netherlands |
| Stripe Payments Europe Ltd. | Payment processing | Ireland (transit USA) |
| Resend, Inc. | Transactional email | USA |
| Supabase / Lovable Cloud | Database, auth | EU |
| Cloudflare, Inc. | DNS / CDN / DDoS | Global |
5.2 Other Recipients
Tax and accounting professionals (legal obligation); public authorities when required by law (court order, the Data Protection Commission, the Competition and Consumer Protection Commission, the Revenue Commissioners, An Garda Síochána); successor entities in M&A.
We do NOT sell personal data and do NOT disclose to advertising networks.
6. International Data Transfers
For transfers outside the EEA (Stripe, Resend, Cloudflare), we rely on EU Standard Contractual Clauses (SCCs), EU–US Data Privacy Framework (DPF) certification, or other valid GDPR transfer mechanisms.
7. Retention
| Data category | Retention period |
|---|---|
| Account data (active) | Duration of contract |
| Account data (after closure) | 4 years (statute of limitations) |
| Billing / invoicing records | 6 years (Companies Act 2014) |
| Server / security logs | 12 months unless extended for incident |
| Email correspondence | 3 years after last interaction |
| Payment records (Stripe) | per Stripe policy |
| WHOIS / domain data | duration of registration + ICANN-mandated periods |
After expiry, data is securely deleted or anonymized.
8. Your Rights
Under GDPR you have:
- Right of Access (Art. 15)
- Right to Rectification (Art. 16)
- Right to Erasure (Art. 17)
- Right to Restriction (Art. 18)
- Right to Data Portability (Art. 20)
- Right to Object (Art. 21)
- Right to Withdraw Consent (Art. 7(3))
- Right Not to be Subject to Automated Decision-Making (Art. 22)
Right to Lodge a Complaint
Data Protection Commission (Irish supervisory authority)
6 Pembroke Row, Dublin 2, D02 X963, Ireland
Web: dataprotection.ie
Residents of other EU Member States may also lodge a complaint with their local supervisory authority.
How to Exercise Your Rights
Email hello@127box.com with sufficient identification, the right you wish to exercise, and any specifics. Response within 1 month (extendable by 2 months for complex requests). Free of charge except for manifestly unfounded or excessive requests.
9. Security
We implement appropriate technical and organizational measures:
- TLS 1.2+ encryption in transit
- Hashed and salted password storage
- Role-based access controls
- Logging of administrative actions
- Sub-processor selection based on demonstrable security practices
- 72-hour data breach notification per Article 33 GDPR
Notify hello@127box.com of any suspected unauthorized access.
10. Children
Services are not directed to children under 16. We do not knowingly collect data from children. Contact hello@127box.com to delete inadvertently collected data.
11. Cookies
127box uses only strictly necessary cookies. We do not use marketing, advertising, or analytics tracking cookies. See the Cookie Policy.
12. Data Protection Officer (DPO)
127box is not currently required to appoint a DPO under Article 37 GDPR. For data protection inquiries: hello@127box.com.
13. Changes
Material changes will be communicated by email at least 30 days in advance, where practicable.
14. Contact
IMG VENTURES LIMITED, trading as 127box
hello@127box.com
77 Camden Street Lower, Dublin, D02 XE80, Ireland