Privacy Policy

1. Effective date: 6 May 2026

(Applies to all services provided through skillzybox.com and related communication channels.)

2. Purpose of this Policy

This Privacy Policy explains how we collect, use, store, and protect your personal data when you interact with our website or purchase from Skillzy Box. We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and the Finnish Data Protection Act (Tietosuojalaki 1050/2018).

3. Data Controller

The controller responsible for your personal data is Zaklab Tmi, operating under the brand Skillzy Box.
For all privacy-related matters, contact us at: customer.service@skillzybox.com

4. What We Collect

We collect only the data necessary to operate our services:

  • Order and account data: name, email, phone (optional), billing and delivery address, order contents, payment method, and transaction details.
  • Customer service data: messages, order number, and any attachments you provide.
  • Marketing data (with consent): name, email, preferences, and subscription status.
  • Technical and cookie data: IP address, device type, browser, pages viewed, and cookie identifiers for site operation and analytics.
  • Return and withdrawal data: withdrawal notices, return requests, order number, returned product details, refund details, timestamps, and related communication.

5. Purposes and Legal Bases for Processing

Your data is processed for the following purposes and legal grounds:

  • Purpose Legal basis (GDPR)
  • Processing and delivering orders, payments, and returns: Art. 6(1)(b) — performance of a contract
  • Customer communication and support: Art. 6(1)(b),(f) — contract / legitimate interest
  • Accounting, taxation, and legal obligations: Art. 6(1)(c) — legal obligation
  • Website security, analytics, and fraud prevention: Art. 6(1)(f) — legitimate interest
  • Marketing emails and non-essential cookies: Art. 6(1)(a) — consent
  • Processing withdrawals, returns, refunds, and related customer confirmations: Art. 6(1)(b) — performance of a contract, and Art. 6(1)(c) — legal obligation.

You may withdraw your consent at any time without affecting the lawfulness of prior processing.

6. Cookies

Cookies Policy

Our store is hosted on Shopify, which uses essential cookies to enable secure checkout and core store functionality.

What are cookies?
Cookies are small text files stored on your device when you visit a website. They help the site recognize your device and remember your preferences.

Types of cookies we use:

  1. Required cookies
    These are necessary for the website to function properly (e.g. shopping cart, checkout, security). These cookies cannot be disabled.
  2. Personalization cookies (with consent)
    These cookies store information about your preferences and interactions to personalize your experience on the website, such as remembering your settings or previously viewed products.
  3. Marketing cookies (with consent)
    These may be used to show relevant ads or track performance of advertising campaigns (e.g. Meta/Facebook Pixel).
  4. Analytics cookies (with consent)
    These help us understand how visitors use our website (e.g. pages visited, time spent). We may use analytics tools such as Google Analytics, which are only activated with your consent.

Managing cookies
You can accept or reject non-essential cookies through our cookie banner. You can also manage cookies through your browser settings.

Disabling cookies
If you disable or block cookies in your browser, some parts of the website, including cart and checkout functionality, may not function properly.

You can change or withdraw your cookie consent at any time via the cookie settings on our website.

7. Third-Party Service Providers

We share personal data only with trusted partners who process it on our behalf for:

  • Website hosting and e-commerce operations;
  • Payment processing;
  • Shipping and fulfilment;
  • Marketing and email services;
  • Analytics and security.

These providers act as data processors under agreements ensuring GDPR compliance.
Payment details such as full card numbers are handled directly by payment providers; Skillzy Box never stores them.

8. Data Location and Transfers

Your data is primarily processed within the EU/EEA.
If any data is transferred outside the EEA, we ensure protection through EU Standard Contractual Clauses or equivalent safeguards.

9. Data Retention

We keep data only as long as necessary for each purpose:

  • Order and invoicing data: retained for at least six years after the end of the financial year, or longer if required by Finnish accounting or tax law.
  • Customer service records: retained while the matter is active and for a limited period afterwards.
  • Marketing data: retained until you unsubscribe or withdraw consent, or after prolonged inactivity.
  • Cookies and analytics: per tool’s standard retention period or until you withdraw consent.

After the retention period, data is securely deleted or anonymized.

10. Your Rights Under GDPR

You have the right to:

  • Access your data and receive a copy;
  • Rectify inaccurate or incomplete data;
  • Erase data (“right to be forgotten”) in certain situations;
  • Restrict processing in specific circumstances;
  • Object to processing based on legitimate interest or to direct marketing at any time;
  • Data portability for data you provided based on consent or contract;
  • Withdraw consent at any time.

To exercise these rights, contact us at customer.service@skillzybox.com.


We may need to verify your identity before fulfilling your request.


You also have the right to file a complaint with the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto) if you believe your data has been processed unlawfully.

11. Security

We apply technical and organizational measures to protect your personal data, including access controls, encryption where appropriate, secure hosting, and employee confidentiality.

While no system is completely immune to risks, we continuously monitor and update our security measures.

12. Children

Our online store is intended for customers aged 18 or older, or younger customers only with guardian consent.

We do not knowingly collect personal data from children under 16 without appropriate guardian involvement. If we become aware that such data has been collected, we will delete it promptly unless we are legally required to retain it.

13. Changes to This Policy

We may update this policy to reflect legal or operational changes.

The latest version is always available on our website and includes the effective date.

Material updates may be communicated by email or via on-site notice.

14. Contact and Controller Information

Controller: Zaklab Tmi (operating under the brand Skillzy Box)
Y-tunnus: 3570495-6
Address: Tankomäenkatu 11 B 3, 00950 Helsinki, Finland
Email: customer.service@skillzybox.com