Privacy Policy

Last updated: December 2025

1. Introduction

Welcome to DormBox ("we", "us", "our"). DormBox provides residents with access to shared household utilities through smart rental cupboards located in student housing facilities.

This Privacy Policy explains what personal data we collect, why we collect it, how we use it, and what rights you have under the General Data Protection Regulation (GDPR / AVG).

If you have any questions, you can contact us at team@dormbox.nl.

2. Data Controller

DormBox B.V.
Artemissingel 236, 1363TG Almere, Netherlands
Email: team@dormbox.nl

DormBox acts as the data controller for personal data processed through our platform and services.

3. Personal Data We Collect

We only collect data necessary to provide the DormBox service. This includes:

  • Full name
  • Email address
  • User ID assigned by our system
  • Account creation date ("Member since")
  • Order history (items rented, timestamps, price and return status)

We do not store:

  • Payment card numbers (handled by Stripe)
  • IP addresses or device identifiers

4. Purpose and Legal Basis of Processing

a) Providing and operating the DormBox service

We use your data to create and maintain your account, authenticate access, enable item rentals, and resolve service issues.

Legal basis: Contract performance (Article 6(1)(b) GDPR)

b) Improving service quality and preventing misuse

We may use aggregated information from usage activity to monitor performance, prevent damage, and improve availability.

Legal basis: Legitimate interest (Article 6(1)(f) GDPR)

c) Sharing information with housing providers

Where DormBox is operated in partnership with a student housing organisation, we may share limited data (name, email, user ID and relevant usage) to confirm eligibility, troubleshoot issues, or resolve disputes.

Legal basis: Contract performance and legitimate interest

We do not process your data for advertising or profiling.

5. Sharing Personal Data

Housing providers

We may share limited data with housing providers when necessary to:

  • confirm residence eligibility
  • resolve access or damage issues
  • support user assistance

Third-party processors

We work with trusted service providers, such as:

  • Stripe for payments
  • Cloud infrastructure hosts: Railway and GoDaddy

These organisations process data under contractual agreements and must comply with GDPR/AVG.

We never sell or commercially trade personal data.

6. Data Storage and Security

We store data in secure systems and restrict access to authorised personnel only.

  • Passwords are stored hashed, never as plain text
  • Technical and organisational measures protect your information

7. Retention Periods

We retain data only as long as necessary:

  • Account data: while your account is active
  • Order history: up to 12 months after account closure, unless longer retention is required for legal purposes

After retention periods expire, data is deleted or irreversibly anonymised.

Stripe independently manages financial record retention as required by law.

8. Your Rights

Under GDPR, you have the right to:

  • access your data
  • correct inaccurate data
  • delete your account and personal information
  • request data portability
  • object to processing based on legitimate interest

You can exercise these rights via your DormBox account or by contacting team@dormbox.nl.

9. Deleting Your Account

You may delete your DormBox account at any time.

Upon deletion we:

  • remove or anonymise your personal information
  • retain only the minimum data required to fulfil legal obligations or resolve disputes

10. Data Transfers Outside the EEA

If we transfer data to service providers outside the European Economic Area, we ensure appropriate safeguards such as:

  • EU adequacy decisions
  • Standard Contractual Clauses (SCCs)

11. Data Breach Procedure

In the event of a personal data breach that could risk your rights, we will:

  • investigate and mitigate impact
  • notify Autoriteit Persoonsgegevens within 72 hours where required
  • inform affected users without undue delay

12. Changes to This Policy

We may update this Privacy Policy from time to time. The latest version will always be published on dormbox.nl and indicated by the "Last updated" date.

13. Contact Information

To ask questions or make requests regarding this Privacy Policy or your data, you may contact us at:

team@dormbox.nl
DormBox B.V.
Artemissingel 236, 1363TG Almere, Netherlands