Back to home

Privacy Policy

Last updated: 13 August 2026

1. Data Controller

IMG VENTURES LIMITED, trading as 127box
A private company limited by shares incorporated under the laws of Ireland
Registered office: 77 Camden Street Lower, Dublin, D02 XE80, Ireland
Registered with the Companies Registration Office under number 820947
Email: hello@127box.com

(hereinafter "127box", "we", "us")

2. Scope

This Policy explains how 127box collects, uses, discloses, and protects personal data of website visitors, registered Customers, and persons who contact us. It applies under Regulation (EU) 2016/679 (GDPR) and the Irish Data Protection Act 2018.

3. Personal Data We Collect

3.1 Account and Identity Data

  • Full name (or registered company name)
  • Email address
  • Billing address
  • VAT identification number (B2B)
  • Authentication credentials (hashed password)

Source: Customer at registration. Legal basis: Performance of the contract (Article 6(1)(b) GDPR).

3.2 Payment Data

Payment method type, last 4 digits of card, cardholder name, billing country, transaction history. 127box does NOT store full card numbers or CVV. Payment data is processed by Stripe Payments Europe Ltd. Legal basis: Contract; legal obligation.

3.3 Service Usage Data

Cloud Server identifiers, domain registrations, SSL certificate metadata, resource usage metrics. We do NOT inspect content of Customer servers. Legal basis: Contract; legitimate interest.

3.4 Technical and Log Data

IP address, browser type, OS, timestamps, dashboard access, error logs, security events. Legal basis: Legitimate interest (security, fraud prevention).

3.5 Communications Data

Email correspondence, support tickets. We do not currently operate phone or chat support. Legal basis: Contract; legitimate interest.

3.6 What We Do NOT Collect

  • Telephone numbers (we do not request them)
  • Full payment card numbers / CVV (handled by Stripe)
  • Special categories of personal data (Article 9 GDPR — health, biometric, religious, etc.)
  • Identity documents / KYC data (not required for our services)
  • Content of Customer servers, files, or applications (except in security incident investigation or as required by law)
  • Browsing behavior outside 127box.com

4. Purposes of Processing

4.1 Service Provision

Account management, server/domain provisioning, payment processing, invoicing. Basis: Article 6(1)(b) GDPR.

4.2 Customer Support

Inquiry response, troubleshooting. Basis: Article 6(1)(b), 6(1)(f).

4.3 Billing, Accounting, Tax

Invoicing, accounting records, reporting to the Irish Revenue Commissioners. Basis: Article 6(1)(c) GDPR (Irish and EU tax, accounting and corporate regulations, in particular the Companies Act 2014).

4.4 Security and Abuse Prevention

Monitoring for unauthorized access, fraud, AUP violations. Basis: Article 6(1)(f); legal obligation.

4.5 Service Improvement

Aggregated usage analytics. We do NOT profile individual Customers for marketing. Basis: Article 6(1)(f).

4.6 Transactional Communications

Service-related emails (welcome, server provisioned, payment receipts, renewal reminders). Basis: Contract.

4.7 Marketing Communications

We do NOT currently send marketing newsletters. If introduced, explicit opt-in consent will be requested.

5. Recipients of Personal Data

5.1 Subprocessors

SubprocessorRoleLocation
Hetzner Online GmbHCloud server hostingGermany, Finland
Hostnet B.V. (Openprovider)Domain registration, DNSNetherlands
Stripe Payments Europe Ltd.Payment processingIreland (transit USA)
Resend, Inc.Transactional emailUSA
Supabase / Lovable CloudDatabase, authEU
Cloudflare, Inc.DNS / CDN / DDoSGlobal

5.2 Other Recipients

Tax and accounting professionals (legal obligation); public authorities when required by law (court order, the Data Protection Commission, the Competition and Consumer Protection Commission, the Revenue Commissioners, An Garda Síochána); successor entities in M&A.

We do NOT sell personal data and do NOT disclose to advertising networks.

6. International Data Transfers

For transfers outside the EEA (Stripe, Resend, Cloudflare), we rely on EU Standard Contractual Clauses (SCCs), EU–US Data Privacy Framework (DPF) certification, or other valid GDPR transfer mechanisms.

7. Retention

Data categoryRetention period
Account data (active)Duration of contract
Account data (after closure)4 years (statute of limitations)
Billing / invoicing records6 years (Companies Act 2014)
Server / security logs12 months unless extended for incident
Email correspondence3 years after last interaction
Payment records (Stripe)per Stripe policy
WHOIS / domain dataduration of registration + ICANN-mandated periods

After expiry, data is securely deleted or anonymized.

8. Your Rights

Under GDPR you have:

  • Right of Access (Art. 15)
  • Right to Rectification (Art. 16)
  • Right to Erasure (Art. 17)
  • Right to Restriction (Art. 18)
  • Right to Data Portability (Art. 20)
  • Right to Object (Art. 21)
  • Right to Withdraw Consent (Art. 7(3))
  • Right Not to be Subject to Automated Decision-Making (Art. 22)

Right to Lodge a Complaint

Data Protection Commission (Irish supervisory authority)
6 Pembroke Row, Dublin 2, D02 X963, Ireland
Web: dataprotection.ie

Residents of other EU Member States may also lodge a complaint with their local supervisory authority.

How to Exercise Your Rights

Email hello@127box.com with sufficient identification, the right you wish to exercise, and any specifics. Response within 1 month (extendable by 2 months for complex requests). Free of charge except for manifestly unfounded or excessive requests.

9. Security

We implement appropriate technical and organizational measures:

  • TLS 1.2+ encryption in transit
  • Hashed and salted password storage
  • Role-based access controls
  • Logging of administrative actions
  • Sub-processor selection based on demonstrable security practices
  • 72-hour data breach notification per Article 33 GDPR

Notify hello@127box.com of any suspected unauthorized access.

10. Children

Services are not directed to children under 16. We do not knowingly collect data from children. Contact hello@127box.com to delete inadvertently collected data.

11. Cookies

127box uses only strictly necessary cookies. We do not use marketing, advertising, or analytics tracking cookies. See the Cookie Policy.

12. Data Protection Officer (DPO)

127box is not currently required to appoint a DPO under Article 37 GDPR. For data protection inquiries: hello@127box.com.

13. Changes

Material changes will be communicated by email at least 30 days in advance, where practicable.

14. Contact

IMG VENTURES LIMITED, trading as 127box
hello@127box.com
77 Camden Street Lower, Dublin, D02 XE80, Ireland