KUNSINNA 7 IJIEM FIL-ĠIMGĦA • ĦALLAS IKTAR TARD B'KLARNA • SERVIZZ 24/7

Privacy Policy

Effective from 1 January 2026 · Last updated 16 February 2026

White Box Appliances ("we", "us", "our") is committed to protecting your privacy in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the Data Protection Act (Chapter 586 of the Laws of Malta). This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our website whitebox.com.mt and our services.

1. Data Controller

The data controller responsible for your personal data is:

White Box Appliances

69 Triq Fortunato Mizzi, Victoria, Gozo VCT 2578, Malta

Email: sales@whitebox.com.mt

Phone: +356 7905 5156

2. Data We Collect

We collect the following categories of personal data:

Information You Provide

  • Identity Data: First name, last name.
  • Contact Data: Email address, phone number, delivery address.
  • Order Data: Products purchased, services selected, order history, delivery preferences.
  • Communication Data: Messages sent to us via WhatsApp, email, or website forms.

Information Collected Automatically

  • Technical Data: IP address, browser type and version, device type, operating system.
  • Usage Data: Pages visited, time spent on pages, referring URL.
  • Cookie Data: See our cookie usage below.

We do not collect sensitive personal data (e.g., health data, political opinions, biometric data).

3. How We Use Your Data

We process your personal data for the following purposes and legal bases:

PurposeLegal Basis
Processing and fulfilling your ordersContract performance
Arranging delivery and installationContract performance
Processing paymentsContract performance
Warranty registration and supportContract performance / Legitimate interest
Responding to your enquiriesLegitimate interest
Improving our website and servicesLegitimate interest
Complying with legal obligations (e.g., tax records)Legal obligation

4. Data Sharing & Third Parties

We do not sell your personal data. We may share your data with the following categories of third parties, only to the extent necessary for the purposes described above:

  • Payment Processors: Stripe, Inc. (for online card and Klarna payments). Stripe processes your payment data under their own privacy policy.
  • Delivery Partners: Trusted delivery and installation technicians who require your name, address, and phone number to complete service.
  • Hosting & Infrastructure: Railway (hosting), Supabase (database), Vercel (CDN). Data is stored in EU data centres where possible.
  • Communication: WhatsApp (Meta) for customer support messaging. Resend for transactional emails.
  • Legal & Regulatory: Government authorities where required by Maltese or EU law.

5. Data Retention & Security

Retention

  • Order data: Retained for 7 years from the date of purchase (as required by Maltese tax law).
  • Warranty data: Retained for the duration of the warranty period plus 1 year.
  • Marketing preferences: Retained until you withdraw consent.
  • Technical/analytics data: Retained for up to 26 months.

Security

We implement appropriate technical and organisational measures to protect your personal data, including:

  • Encrypted transmission (HTTPS/TLS) across all pages.
  • Secure database storage with row-level access controls.
  • Regular security reviews and updates.
  • Staff training on data protection practices.

6. Cookies

Our website uses the following types of cookies:

  • Strictly Necessary: Required for the website to function (e.g., cart state, language preference). These cannot be disabled.
  • Analytics: Help us understand how visitors use the website in aggregate. No personally identifiable information is collected through analytics.

We do not use third-party advertising or tracking cookies. You can manage cookie preferences through your browser settings.

7. Your Rights

Under the GDPR, you have the following rights regarding your personal data:

  • Right of Access – Request a copy of the personal data we hold about you.
  • Right to Rectification – Request correction of inaccurate or incomplete data.
  • Right to Erasure ("Right to be Forgotten") – Request deletion of your data where there is no compelling reason for continued processing.
  • Right to Restriction – Request that we restrict processing of your data in certain circumstances.
  • Right to Data Portability – Request your data in a structured, machine-readable format.
  • Right to Object – Object to processing based on legitimate interest or for direct marketing purposes.

To exercise any of these rights, contact us at sales@whitebox.com.mt. We will respond within 30 days.

You also have the right to lodge a complaint with the Information and Data Protection Commissioner (IDPC) in Malta at idpc.org.mt.

8. Changes to This Policy

We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated "Last updated" date. We encourage you to review this page periodically.

Questions about your data? We're here to help.

Privacy Policy | White Box Appliances | White Box Outlet