top of page


for the website as of September 2020

When operating the website ("website"), data is processed that relates to natural persons or can be related to natural persons (personal data). With this data protection declaration, we would like to inform you about what data is involved, how it is processed and what rights you have as the data subject.

This data protection declaration fulfills the information requirements of Article 13 of the General Data Protection Regulation (GDPR). It is based on the definition of terms in Art. 4 GDPR.


HYLBOX GmbH, as operator of the website, is responsible for processing. A data protection officer has not been appointed. Those affected can contact us via the e-mail address team[at] with questions about data protection and the assertion of data subject rights.  


Neither we nor the processor commissioned by us to operate the website (Strato AG) can draw direct conclusions about the identity of the visitor.

Connection and page construction as well as presentation of the website

The connection and page setup requires the retrieval of the IP address of your device used as well as information about the browser used on the device.  In addition, session cookies are used. Session cookies temporarily store the internet access and are deleted when the browser is closed. This data is collected, processed and used for the technical and administrative purposes of establishing a connection and maintaining it stable, as well as for optimal page display for the respective end device.

The collection, processing and use of the data takes place to fulfill a contract to which the data subject is a party, or it is necessary to carry out pre-contractual measures which are carried out at the request of the data subject (Article 6 (1) b) GDPR).

Statistics and information or data security

In addition, log data of website visits, such as access to image or HTML files, are collected. This data is collected in a log file. Visits to the website are statistically recorded on the basis of the log data and can be evaluated by us if necessary. In addition to statistical analysis, data processing also serves to optimize the operation of the website and to ensure the confidentiality, availability and integrity of the website, in particular to be able to detect and ward off attacks.

The following categories of log data are collected, processed and used in connection with the domain Client IP address, request line (path to the destination address without the domain), status code (e.g. 404-" The desired website does not exist under the specified URL"), size of the response body (size of the temporarily downloaded files), referrer sent by the client (page from which the visitor came to the website) and user agent sent by the client (information on Art and version of the browser and the operating system of the end device used for the visit).

To support our analysis, we have included the NEW RELIC tool on the website. In particular, the following data is processed: the anonymous data is not personal data and is only listed for better understanding:

Anonymous: Analytics, Browser Information, Cookie Data, Date/Time, Demographic Data, Hardware/Software Type, Interaction Data, Page Views, Serving Domains

Pseudonym: IP Address, Name , Address, Phone Number, Email Address, PII Collected via 3rd Parties, Login, EU- IP Address

New Relic, Inc. is a Delaware Corporation located at 188 Spear Street, Suite 1200, San Francisco, CA 94105, USA. Data is transferred to a third country. As suitable guarantees for the security of the transmitted data, we have agreed standard data protection clauses in accordance with Article 46 (1) c) GDPR with NEW RELIC.

The collection, processing and use of the data is based on the legitimate interests of optimizing website operation and data and information security (Article 6 (1) f) GDPR).

newsletter _

We offer you the opportunity to receive the latest information via newsletter. We only use the e-mail address you have provided. To verify that the e-mail address actually belongs to the person ordering the newsletter, we use the double opt-in procedure. Customers will then regularly receive our newsletter to the e-mail address specified and verified by the customer. The subscription to the newsletter can be canceled at any time and free of charge.  

We have integrated ASCEND by WIX to send the newsletter.  For this purpose, the e-mail address of the customer is processed by on our behalf. Ltd. is based in Israel, which is considered by the European Commission as a country offering an adequate level of protection for personal data of citizens of EU member states.  

The collection, processing and use of the data takes place to fulfill a contract to which the data subject is a party, or it is necessary to carry out pre-contractual measures which are carried out at the request of the data subject (Article 6 (1) b) GDPR).

Contact form, order, delivery and returns

In order to provide our service - rental of the lighting technology and accessories we offer - we process personal data. On the one hand, this can be the personal data of the customer and contractual partner (if the customer is a natural person) or of the customer's employees (if the customer is a legal person). These are the contact details of the people with whom we process the order, delivery and return, such as last name, first name, phone number and email address. This data is processed by us in the backend for the purpose of providing services and to fulfill legal obligations (e.g. tax and commercial law storage obligations according to GoBD) and deleted after the purpose or legal basis no longer applies.  

If the customer is a natural person, the data is collected, processed and used to fulfill a contract to which the data subject is party, or it is necessary to carry out pre-contractual measures that are carried out at the request of the data subject (Art. 6 (1) b) GDPR).

If the data subject is an employee of the customer, the data is collected, processed and used on the basis of our legitimate interest in providing services to the customer (Article 6 (1) f) GDPR).

The data is also collected, processed and used to fulfill legal obligations (Art. 6 (1) c) GDPR).


Those affected have the right:

  • pursuant to Art. 7 Para. 3 GDPR to revoke the consent given to us at any time;

  • to request information about the personal data processed by us in accordance with Art. 15 GDPR;

  • in accordance with Art. 16 GDPR, to immediately request the correction of incorrect or incomplete personal data stored by us;

  • in accordance with Art. 17 GDPR, to request the deletion of the personal data stored by us;

  • pursuant to Art. 18 GDPR to demand the restriction of the processing of personal data;

  • in accordance with Art. 20 GDPR to receive personal data in a structured, common and machine-readable format or to request transmission to another person responsible and

  • to complain to a supervisory authority in accordance with Art. 77 GDPR.  




Due to the further development of the website or due to changed legal or official requirements, it may become necessary to change this data protection declaration.

bottom of page