We, Box Inc (a company owned by Stora Enso Oyj), are committed to protecting the personal data of users (‘you’) which we collect when you visit our website boxinc.com.
Below you will find more information about what personal data we collect when you visit and use our website and how and for what purposes we process it. We only collect, process and use your personal data in compliance with the following principles and in observance of the applicable data protection legislation.
Questions about data protection in relation to our website and the services provided through our website can be sent to us / our data protection manager using the contact details in section 1 below.
1. Data Controller
Stora Enso Oyj
Address: P.O.Box 309, FIN-00101, Helsinki, Finnland
Telephone: (+358) 2046 111
(hereinafter “Box Inc” or “we”).
Stora Enso Oyj jointly processes and shares the data collected via this website with our subsidiaries based on a separate arrangement. We are happy to provide you with the essence of that arrangement on request. You can contact us at firstname.lastname@example.org
2. Collection and storage of personal data and the type and purpose of their use
2.1 When you visit our website
When you visit our website boxinc.com, information is automatically sent by the browser used on your end device to our website servers. This information is stored temporarily in what is called a log file that is kept separate from other personal data you might provide throughout your use of our website. The following information is collected during this process without any action on your part:
- IP address of the requesting device,
- Date and time of access,
- Name and URL of the requested file,
- Website from which access is obtained (Referrer URL),
- Browser used and, where applicable, your device’s operating system and the identity of your access provider.
We process the specified data for the following purposes:
- Ensuring that the website can establish a connection smoothly,
- ensuring that our website is easy to use,
- analysis of system security and stability, as well as
- for additional administrative purposes.
The specified data is stored in a form that enables identification of the persons concerned for a maximum period of 7 days, unless a security-relevant event occurs (e.g. a DDoS attack). In the event of a security-relevant event, server log files are stored until the security-relevant event is eliminated and fully resolved.
The legal basis for the data processing is our legitimate interest, which is based on the data collection purposes listed above. We do not on any account use the data collected for the purpose of identifying you. The provision of this data is not required by law or contract or to enter into a contract. You are not obliged to provide the personal data. It is not, however, possible to access the website if the data are not provided.
2.2 When you send an email to our customer service
We offer you the possibility to contact us by using the email-link “Kundendienst” on the bottom of our website which automatically opens the email program (such as Microsoft Outlook, iOS Mail-App) installed on your device. The email address of our customer service is automatically inserted into your email program to enable you to send your inquiry directly to our customer service. A valid e-mail address is required for this so that we know who the inquiry is coming from and can respond to it. Additional information can be provided on a voluntary basis.
If your request concerns a contract to which you are a party or concerns the implementation of pre-contractual measures, data processing will be carried out as a necessity for the performance or preparation of a contract conclusion. For all other enquiries, data processing for the purpose of contacting us is carried out on the basis of legitimate interests. In this case our legitimate interest is the processing of your request.
The personal data collected by us when you contact us are deleted in accordance with statutory requirements once your inquiry has been dealt with.
2.3 When you subscribe to our newsletter
If you have provided your express consent, we use your name and e-mail address to send you our newsletter on a regular basis. Stating an e-mail address is sufficient for receiving the newsletter.
You can unsubscribe at any time by using the link at the end of each newsletter.
Furthermore, you have the possibility to contact us via a chat function on our website. We only collect, process and use the information you provide during the chat conversations to process your inquiry. We store details of the chat history, including your uploaded files (if any) and IP address, until your inquiry has been dealt with.
Our provider for the chat function is HelpCrunch, a service of the company Helpcrunch Corporation (721 Colorado Avenue, Suite 101 Palo Alto, CA USA 94303).
When you use the chat, HelpCrunch temporarily collects your IP address to determine the country from which the chat was started and to provide a personalized customer service. The collection of your IP address serves no other purpose and HelpCrunch does not store it permanently.
Your personal data that is collected during Live Chat will be stored and transmitted to HelpCrunch servers in the USA. For transmission of personal data to the USA appropriate guarantees in form of standard contractual clauses are in place, a copy of which we will provide you with upon request at email@example.com.
2.5 Registration of a user account
If you are an entrepreneur (§ 14 BGB), a legal entity under public law or a special fund under public law, you also have the option of creating a user account (Partner Supplier Account or Buyer Account) on our website so that you can use the additional functions of the website and marketplace as described in our Terms and Conditions for Buyers (e.g. online requests for quotation for the supply of packaging-related products and services).
You have to specify your first and last name, company name and address, VAT number, telephone number and e-mail address and set a password for this. Your user account is not publicly visible.
The photos and other content uploaded by you may not contain any personal data of third parties without their express consent. If you obtain consent from third parties for this purpose, you are obliged to inform these persons about the scope of data processing by Box Inc and to provide them with all required data subject information.
Data you have to specify during the registration process is processed because it is necessary to perform the contract that you have entered into by registering for a user account on our website.
3. Disclosure of data
- You have given your express consent to this,
- disclosure is necessary for the purposes of pursuing our legitimate interests or the legitimate interests of the third party and there is no reason to assume that you have any overriding interest in your data not being disclosed which is worthy of protection,
- disclosure as required by law, and
- this is permitted by law and required for the performance of contractual relationships with you.
5. Analytics tools
The tracking measures listed below which are used by us are carried out on the basis of your consent you provide on a voluntary basis. By using these tracking measures we want to ensure that our website is designed in line with your user preferences, can be optimized continuously and that we can provide you with personalized recommendations based on your usage patterns. We also use the tracking measures to statistically record the use of our website and for the purpose of optimizing our offer for you. The provision of these data is not required by law or contract or to enter into a contract. You are not obliged to provide these personal data.
The individual data processing purposes and data categories are specified under the relevant tracking tools.
5.1 Use of Google Analytics with anonymization function
We use Google Analytics, a web analysis service of Google Inc. (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; hereinafter “Google”) for the purpose of designing our websites in line with your user preferences and continuously optimizing these. Pseudonymized usage profiles are created and cookies are used in this context. The information generated by the cookies about your use of this website such as
- type/version of browser,
- operating system used,
- referrer URL (last website visited),
- host name of the accessing computer (IP address),
- time of server request,
are transferred to a Google server in the USA and stored there. The information is used to analyze the use of the website, to compile reports on website activities and to provide additional services associated with website and internet use for market research and design of these websites in line with user preferences. This information may also be disclosed to third parties if this is required by law or if these third parties process these data for us. Your IP address will on no account be combined with other Google data. IP addresses are anonymized so that they cannot be linked to any specific person (IP masking).
You can also prevent the installation of these cookies by configuring your browser software settings accordingly; we would, however, advise you that in this case you may not be able to use all website functions fully. You can also prevent the data generated by the cookie and data relating to your use of the website being collected (including your IP address) and the processing of these data by Google by downloading and installing a browser add-on.
Instead of using a browser add-on, in particular for browsers on mobile end devices, you can also prevent data being collected by Google Analytics by clicking on this link. An opt-out cookie is set that prevents your data being col-lected in future when you visit this website. The opt-out cookie is only valid in this browser and for our websites and is stored on your device. If you delete the cookies in this browser, you will have to place the opt-out cookie again.
Addition information on privacy in connection with Google Analytics can for example be found here: Google Analytics Help.
We also use Google Analytics to evaluate data from AdWords and the double-click cookie for statistical purposes.
We also use the web analysis service Hotjar provided by Hotjar Ltd. (“Hotjar”). Hotjar is a European company headquartered in Malta (Hotjar Ltd, Level 2, St Julians Business Centre, 3, Elia Zammit Street, St Julians STJ 1000, Malta).
This tool allows movements to be tracked on websites that use Hotjar (referred to as heatmaps). It can for example be identified how far users scroll and which buttons user click on and how often. It is also possible with the help of this tool to obtain feedback directly from users of the website. We obtain valuable information in this way that enables us to make our website even quicker and more user-friendly.
The usage data collected are only processed in pseudonymized form and the data are not used to combine usage profiles with your personal data. We can therefore only track which buttons have been clicked on, mouse movements, how far has been scrolled, the screen size of the device, device type and browser information, geographical location (only country) and the preferred language in order to display our website. Areas of the websites in which your personal data or personal data of third parties are shown are automatically hidden by Hotjar and therefore cannot be tracked at any time.
Hotjar also offers each user the possibility with the help of a “Do Not Track Header” to prevent the use of Hotjar so that no data on the visit to the relevant website are recorded. This is a setting which the latest versions of all common browsers support. For this, you browser sends a request to Hotjar stating that the tracking of the relevant user is to be deactivated. If you use our website with different browsers/computers/devices, you will have to configure the “Do Not Track Header” separately for each of these browsers/computers.
If we receive your e-mail address in connection with the sale of a Service and you have not objected to this, we also reserve the right to send you information on our own similar Services by e-mail on a regular basis as this constitutes a legitimate interest of BoxInc. You may object to this use of your e-mail address at any time by sending a message to firstname.lastname@example.org or via a link provided for this purpose in the advertising mail.
If you do not want us to collect information regarding your visit to our platform and the use of our services, applications and tools, you may opt out at any time with future effect by disabling cookies in your browser or device settings.
6.1 Google Tag Manager
We use Google Tag Manager which is a solution that allows us to manage website tags through a single interface. Tags are small pieces of code on your website that are used, among other things, to measure traffic and visitor behavior, capture the impact of online advertising and social channels, deploy remarketing and targeting, and test and optimize your website. The Tag Manager tool itself (which implements the tags) is a cookie-free domain. The tool triggers other tags that may themselves collect data. Google Tag Manager does not access this data.
6.2 Facebook Pixel
We also carry out retargeting using the Facebook pixel.
We use the Facebook pixel of Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland (“Facebook”) for retargeting. The Facebook pixel serves to present visitors to this website with interest-based adverts based on the information regarding their use of this website in the social network Facebook or when they visit websites that participate in the Facebook advertising network (“Facebook Ads”).
The Facebook pixel is a program code implemented on this website. The program code can prompt the storage of certain information on your end device in the form of cookies and trigger the transfer of certain data to Facebook. This includes information which is generated for technical reasons via the Hypertext Transfer Protocol (HTTP) when you access the website, for example your IP address, as well as information already stored in cookies on your end device, for example your Facebook ID. When you access the website, Facebook can therefore detect that you have visited this website and what content you have accessed. If you have a user account on Facebook, Facebook can relate this information to your user account.
6.3 Google Ads
We also use Google Ads for remarketing purposes. This tool is used to present you with interest-based ads on other websites and apps that participate in the Google advertising network. Your browser stores cookies that allow us to recognize you as a visitor when you visit websites that are part of the Google advertising network. These pages may then present advertisements to you that relate to content previously viewed on our website or other websites or apps that use Google's remarketing feature. For this purpose, anonymous data about your use of the platform is stored and transmitted to a Google server in the USA and stored there. For the USA, the European Commission has issued an adequacy decision (EU/US Privacy Shield) under which Google is certified. These cookies are not used for personal identification. However, if you do not want Google Ad's remarketing function to work, you may opt out of data collection for these purposes by selecting the appropriate settings here, by deactivating cookies in your browser or device settings.
Additional information on privacy in connection with Google Ads can be found at https://policies.google.com/technologies/ads?hl=de.
6.4 Twitter Universal Website Tag
We also use the Twitter Universal Website Tag as a tool for visit action analysis (‘conversion tracking’). Conversion tracking enables us to measure our return on investment by tracking the actions users take after viewing or engaging with our ads on Twitter. A single code snippet is placed on our website to track Twitter ads, optimise ads based on collection data, build targeted audiences and remarket to qualifies leads.
If you do not want Twitter's tag function to work, you may opt out of data collection for these purposes by selecting the appropriate settings at https://twitter.com/personalization, by deactivating cookies in your browser or device settings. Additional information on privacy in connection with the Twitter Universal Website Tag can be found at https://twitter.com/de/privacy.
6.5 LinkedIn Insight Tag
LinkedIn does not share any personally identifiable information with us, but only provides aggregated reports about the website's target audience and ad performance.
If you do not want LinkedIn's tag function to work, as a LinkedIn user you may opt out of data collection for these purposes by selecting the appropriate settings for your LinkedIn account at https://www.linkedin.com/psettings/advertising/actions-that-showed-interest, by deactivating cookies in your browser or device settings.
Additional information on privacy in connection with the LinkedIn Insight Tag can be found at https://www.linkedin.com/help/lms/answer/65521/the-linkedin-insight-tag-frequently-asked-questions?lang=de and https://www.linkedin.com/legal/cookie-policy.
6.6 Microsoft Ads Universal Event Tracking
Microsoft Advertising doesn't resell this data to third parties or share it with other advertisers.
If you do not want Microsoft's tag function to work, you may opt out of data collection by deactivating cookies in your browser or device settings.
Additional information on privacy in connection with Microsoft Ads can be found at https://privacy.microsoft.com/de-de/privacystatement.
During your website visit we use the widespread SSL process (Secure Socket Layer) in connection with a modern encryption level. This is normally 256-bit encryption. Whether an individual page of our website is transmitted in encrypted form can be seen with the closed key or lock icon in your browser’s status bar.
We have also taken technical and organizational security measures to protect your personal data against loss, destruction, manipulation and unauthorized access.
All our employees and any service providers who work for us are obliged to comply with all applicable data protection legislation. Our security measures are subject to a continuous improvement process and our privacy policies are constantly revised. Please ensure that you have the most up-to-date version.
8. Rights of data subjects
You have the right:
- to obtain information about the personal data processed by us;
- to obtain without undue delay the rectification or completion of your personal data stored by us;
- to obtain the erasure of the personal data stored by us, unless the processing is necessary for exercising the right of freedom of expression or information, for compliance with a legal obligation, for reasons of public interest or for the establishment exercise or defense of legal claims. If we have made your personal data public, we are obliged, taking account of available technology and the technical possibilities, to inform controllers which are processing the personal data that the you have requested the erasure by such controllers of any links to, or copy or replication of, those personal data;
- to obtain the restriction of the processing of your personal data if you contest the accuracy of the personal data, the processing is unlawful, but you oppose their erasure and we no longer require the data, but you require these for the establishment, exercise or defense of legal claims or you have objected to their processing;
- to receive your personal data in a structure, commonly used and machine-readable format or have such transmitted to another controller;
- to withdraw your consent given to us at any time. This means that we may no longer continue the data processing based on this consent in future, and
- to complain to a supervisory authority. You can usually contact the supervisory authority at your normal place of residence or your workplace or where we are headquartered for this.
9. Right to object
If your personal data are processed on the basis of legitimate interests, you have the right to object to the processing of your personal data if grounds for this relating to your particular situation exist or the objection is to direct marketing. In the latter case you have a general right to object, which is implemented by us without any particular situation being specified. Sending an appropriate e-mail to email@example.com is sufficient if you wish to exercise your right to withdraw consent or your right to object.
When you visit our website, we ask you to allow us to store information on your computer in the form of cookies. Cookies are small files sent from an internet server to your browser and stored on your hard disk. Information is stored in the cookie which is generated in each case in connection with the end device specifically used. This does not, however, mean that we as a result receive any direct knowledge of your identity. We use the term “cookies” in this policy to refer to all files that collect information in this way.
Cookies on the one hand serve to make our offer easier for you to use. We use session cookies for example to detect that you have already visited individual pages of our website. These are automatically deleted when you leave our website. We also use temporary cookies to optimize user-friendliness which are stored on your end device for a specifically determined period of time. If you visit our website again in order to use our services, it is automatically detected that you have already visited us and which entries you have made and settings you have chosen so that you do not have to enter these again.
The following cookies are used on our website:
Used to analyze the use of the website, to compile reports on website activities and to provide additional services associated with website and internet use for market research. Further information is available here.
|Name||Purpose and content||Expires|
|_ga||Registers a unique ID that is used to generate statistical data on how the visitor uses the website.||2 years|
|_gat||Used by Google Analytics to throttle request rate||1 day|
|_gid||Registers a unique ID that is used to generate statistical data on how the visitor uses the website.||1 day|
|__utma||This cookie stores the number of each visitor's visits and the time and date of the first visit, previous visits and the current visit.||2 years|
|__utmt||This cookie is used to throttle the request rate.||10 minutes|
|__utmb||This cookie is used to log how long each visitor stays at a website, i.e. when the visit begins and when it ends. This cookie stores the moment in time when a visitor enters a site.||30 minutes|
|__utmc||This cookie is used to log how long each visitor stays at a website, i.e. when the visit begins and when it ends. This cookie stores the moment in time when a visitor leaves a site.||30 minutes|
|__utmv||This cookie stores the category into which the visitor fits.||2 years|
|__utmz||This cookie stores the source or campaign that explains what route the user used to come to the website.||6 months|
|Name||Purpose and content||Expires|
|ads/ga-audiences||Used by Google AdWords to re-engage visitors that are likely to convert to customers based on the visitor 's online behavior across websites.||Session|
Used to analyze the use of the website, to compile reports on website activities and to provide additional services associated with website and internet use for market research
|Name||Purpose and content||Expires|
|_ga||Registers a unique ID that is used to generate statistical data on how the visitor uses the HotJar.||2 years|
Used to present interest-based advertisements to you on the social network Facebook or when you visit websites that participate in the Facebook Advertising Network based on information about your use of this website ("Facebook Ads").
|Name||Purpose and content||Expires|
|fr||Used to distinguish users.||3 months|
Auth0: Used for management of log-in process towards the application. Handles users log-in/log-out procedure, is being used to create, validate accounts.
|Name||Purpose and content||Expires|
|did||Used for user authentication.||4 years|
Used to provide functionality of chat with BoxInc support by means of chat window overlay.
|Name||Purpose and content||Expires|
|_ga||Registers a unique ID that is used to generate statistical data on how the visitor uses the HelpCrunch.||2 years|
|boxlyTeaserCookieConsent||Boxinc.com - Validity of cookie consent action||365 days|
|device-referrer||Boxinc.com - Device identification||365 days|
|device-source||Boxinc.com - Language mutation identification||365 days|
|ARRAffinity||Boxinc.com - Supports stateless application instance on hosting cloud service.||Session|
Local Storage subsystem
|Name||Purpose and content||Expires|
|helpcrunch.com-helpcrunch-1-device-source||Stores information about source web page accessing HelpCrunch.||N/A|
|helpcrunch.com-helpcrunch-1-visit-end-time||Stores information about end time of use of last chat session with HelpCrunch.||N/A|
|helpcrunch.com-helpcrunch-1-device-referrer||Stores information about referring web site BoxInc.com||N/A|
|helpcrunch.com-helpcrunch-1-visit-start-time||Stores information about start time of use of last chat session with HelpCrunch.||N/A|
|helpcrunch.com-helpcrunch-1-page-views||Stores information about amount of visited pages on boxinc.com while having HelpCrunch overlay opened.||N/A|
|helpcrunch.com-helpcrunch-1-chat-window-state||Stores information about current state of HelpCrunch overlay.||N/A|
|helpcrunch.com-helpcrunch-1-visits-count||Stores information about amount of visits of user on BoxInc.com based on anonymized ID in HelpCrunch cookie.||N/A|
|i18nextLng||Stores information about next possible language that user can select.||N/A|
|auth||Stores information about verified validity of user's login based on Auth0 login procedure.|
Last modified: 06.04.2020