Last updated: 7.4.2025.
We at HEDBOX are committed to protecting your personal data and respecting your privacy in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and applicable Slovenian data protection laws.
This Privacy Policy explains how we collect, use, and protect your personal information when you visit our website or use our services.

1. Controller Information
Company Name: HEDBOX DOO
Registered Address: Poslovna Cona A10, 4208 Šenčur, Slovenia
Company Registration Number: 6687695000
VAT ID (if applicable): SI43487114
Email: gpsr@hedbox.com
Phone: +386 (40) 316 553

2. What Personal Data We Collect
We may collect and process the following categories of personal data:
    • Contact details (name, email, phone number, address)
    • Order and payment information
    • Account details (if you create an account on our site)
    • Browsing data (IP address, browser type, operating system, referring URLs)
    • Cookies and tracking data (see our Cookie Policy for more)

3. Legal Bases for Processing
We process your personal data only when legally permitted, such as:
    • To fulfill a contract (e.g. processing your order)
    • With your consent (e.g. for newsletters or marketing)
    • To comply with legal obligations (e.g. invoicing)
    • For our legitimate interests (e.g. website security, fraud prevention)

4. How We Use Your Data
We use your personal data to:
    • Process and deliver your orders
    • Respond to your inquiries or support requests
    • Provide you with important account and transaction information
    • Send you marketing communications (only with your consent)
    • Improve our website and services
    • Comply with applicable legal requirements

5. Who We Share Your Data With
We may share your personal data with:
    • Service providers (e.g. payment processors, delivery partners, IT providers)
    • Legal authorities if required by law
    • Third-party tools (such as Google Analytics, with anonymized data)
We do not sell your personal data to any third party.

6. International Data Transfers
We store and process your data within the EU/EEA. If we transfer your data outside the EU, we will ensure appropriate safeguards are in place, such as Standard Contractual Clauses.

7. How Long We Store Your Data
We retain your data only as long as necessary for the purposes stated above, or as required by law (e.g. accounting and tax regulations). When no longer needed, your data will be securely deleted or anonymized.

8. Your Rights Under GDPR
As a data subject, you have the right to:
    • Access your personal data
    • Rectify inaccurate or incomplete data
    • Request erasure (“right to be forgotten”)
    • Restrict or object to processing
    • Data portability
    • Withdraw consent at any time (for processing based on consent)
    • Lodge a complaint with a supervisory authority (in Slovenia: Informacijski pooblaščenec)
To exercise any of these rights, please contact us at gpsr@hedbox.com.

9. Cookies and Tracking
We use cookies and similar technologies to improve your experience. For more details, please refer to our [Cookie Policy].

10. Security of Your Data
We implement appropriate technical and organizational measures to protect your personal data from unauthorized access, loss, misuse, or alteration.

11. Changes to This Policy
We reserve the right to update this Privacy Policy at any time. Changes will be posted on this page with an updated revision date. Please check back regularly.

If you have any questions or concerns about this Privacy Policy, please contact us at:
📧 gpsr@hedbox.com
📞 +386 (40) 316 553