Privacy policy
Privacy Policy
Last updated: 8 September 2026
1. Controller
The controller within the meaning of the General Data Protection Regulation (“GDPR”) and other applicable data protection laws is:
Wildkaffee GmbH – Wildkaffee Rösterei
An der Zugspitze 3
82491 Grainau
Germany
Represented by: Leonhard Wild and Stefanie Wild
Phone: +49 8821 7546715
Email: info@wild-kaffee.de
2. General Information on Data Processing
We take the protection of your personal data seriously.
Personal data means any information relating to an identified or identifiable natural person. This includes, for example, your name, postal address, email address, telephone number, IP address, customer number, order data and online identifiers.
We process personal data only where there is a legal basis for doing so.
Depending on the processing activity, the following legal bases may apply in particular:
Art. 6(1)(a) GDPR – Consent
where you have expressly consented to processing, for example for newsletters, analytics, marketing or tracking purposes.
Art. 6(1)(b) GDPR – Performance of a contract and pre-contractual measures
where processing is necessary to fulfil an order, coffee subscription, customer account or another service requested by you.
Art. 6(1)(c) GDPR – Legal obligation
where we are required by law to process or retain personal data.
Art. 6(1)(f) GDPR – Legitimate interests
where processing is necessary for the purposes of our legitimate interests or those of a third party and your interests, fundamental rights and freedoms do not override those interests. This includes, in particular, the secure and efficient provision of our online shop, fraud prevention, customer service and the improvement of our services.
Where information is stored on your device or information already stored on your device is accessed, we additionally comply with Section 25 of the German Telecommunications-Digital-Services Data Protection Act (TDDDG).
We generally use non-essential cookies, pixels and comparable tracking technologies only after your prior consent.
3. Retention Period
We generally retain personal data only for as long as necessary for the respective processing purpose.
Where statutory retention obligations apply, in particular under commercial and tax law, we retain the relevant data for the legally prescribed period.
After expiry of the respective retention period, the data will be deleted unless another legal basis exists for further processing.
Additional retention periods may apply to individual external services. These depend on our settings and the requirements of the respective provider.
4. Recipients and Processors
We use external service providers to operate our online shop and provide our services.
These providers receive personal data only to the extent necessary to provide the respective service.
Where a service provider processes personal data solely on our instructions, processing is carried out on the basis of a data processing agreement pursuant to Art. 28 GDPR.
Other recipients, in particular payment service providers, shipping companies or certain advertising platforms, may process personal data partly under their own data protection responsibility.
5. Transfers of Data to Third Countries
Some of the service providers we use or their subprocessors are located outside the European Union or the European Economic Area.
Personal data is transferred to such third countries only in accordance with Arts. 44 et seq. GDPR.
Where the European Commission has adopted an adequacy decision for the respective country, the transfer may be based on that decision.
For appropriately certified companies in the United States, the EU-U.S. Data Privacy Framework may in particular serve as a legal basis.
Otherwise, the European Commission’s Standard Contractual Clauses pursuant to Art. 46 GDPR and, where appropriate, additional technical and organisational safeguards may be used.
6. Operation of Our Online Shop with Shopify
We operate our online shop using the e-commerce platform Shopify.
For merchants in the European Economic Area, the relevant provider is generally:
Shopify International Limited
Ireland
Shopify provides us in particular with functions for:
-
hosting
-
product presentation
-
shopping cart
-
checkout
-
customer accounts
-
orders
-
payments
-
shop administration
-
security and fraud prevention
The following personal data may in particular be processed:
-
IP address
-
browser and device information
-
pages visited
-
date and time of access
-
customer ID
-
name
-
email address
-
telephone number
-
billing and delivery address
-
shopping cart contents
-
orders
-
payment and transaction information
-
discount and voucher information
-
returns and refunds
Where processing is necessary to fulfil an order or another service requested by you, it is based on Art. 6(1)(b) GDPR.
The secure and reliable technical provision of our shop is additionally based on Art. 6(1)(f) GDPR.
Shopify International Limited initially processes data relating to customers in the EEA in Ireland. Shopify may use affiliated companies and subprocessors outside the EEA to provide its services. International transfers are carried out using the transfer mechanisms provided for by applicable law.
7. Shopify Content Delivery Network
Shopify uses a globally distributed Content Delivery Network (“CDN”).
This enables website content to be delivered via geographically suitable servers.
In this context, your IP address in particular may be processed.
The processing serves to provide our online shop quickly, reliably and securely.
The legal basis is Art. 6(1)(f) GDPR.
8. Server Log Data
When you visit our website, technically necessary information is processed.
This may include in particular:
-
IP address
-
date and time
-
page or file accessed
-
referrer URL
-
browser type and version
-
operating system
-
device information
-
language settings
-
HTTP status codes
-
technical error and security information
The processing serves the technical provision, stability, security and error analysis of our website.
The legal basis is Art. 6(1)(f) GDPR.
9. Cookies, Local Storage and Similar Technologies
Our online shop uses cookies and comparable technologies such as:
-
Local Storage
-
Session Storage
-
Web Storage
-
tracking pixels
-
online identifiers
We use technically necessary technologies, among other things, to:
-
store the shopping cart
-
provide the checkout
-
enable customer accounts
-
save language and region settings
-
process payments
-
provide security functions
-
store your cookie choices
Where storage or access is strictly necessary, this is based on Section 25(2) TDDDG.
Non-essential analytics, marketing or personalisation technologies are generally used only after your consent pursuant to Section 25(1) TDDDG and Art. 6(1)(a) GDPR.
An up-to-date overview of the cookies and technologies actually used can be found in the Cookie Settings on our website.
10. Consent Management with Complianz
We use Complianz Consent for Shopify to manage your cookie and privacy choices.
The service is provided by iubenda s.r.l., Milan, Italy, under the Complianz brand.
Complianz enables us in particular to:
-
obtain consent
-
control individual categories of cookies and tracking services
-
document consent
-
implement withdrawals
-
block tracking technologies before the required consent has been obtained
The following information may in particular be processed:
-
consent status
-
selected categories
-
time of the decision
-
technical identifiers
-
where applicable, browser and device information
The processing serves in particular to comply with legal requirements relating to obtaining and documenting consent.
The legal basis is in particular Art. 6(1)(c) GDPR and, additionally, Art. 6(1)(f) GDPR.
Technically necessary storage on your device is based on Section 25(2) TDDDG.
You can change or withdraw your selection at any time via the Cookie Settings on our website.
11. Contact
If you contact us, for example by email, telephone or contact form, we process the information you provide.
This may include in particular:
-
name
-
email address
-
telephone number
-
company
-
order number
-
content of your message
If your enquiry relates to an existing or potential contract, processing is carried out on the basis of Art. 6(1)(b) GDPR.
For general enquiries, processing is based on Art. 6(1)(f) GDPR.
Our legitimate interest is to respond to customer and prospective customer enquiries.
12. Customer Account
You can create a customer account in our online shop.
The following data may in particular be processed:
-
name
-
email address
-
telephone number
-
postal address
-
saved delivery addresses
-
customer ID
-
order history
-
subscription information
-
loyalty points and credit balances
The processing is carried out to provide and manage your customer account on the basis of Art. 6(1)(b) GDPR.
You may request deletion of your customer account at any time, provided that no statutory retention obligations prevent deletion.
13. Orders
If you place an order in our online shop, we process the data necessary to perform the contract.
This may include in particular:
-
name
-
billing address
-
delivery address
-
email address
-
telephone number
-
items ordered
-
variants and grind size
-
quantity
-
order value
-
discount codes
-
payment method
-
shipping method
-
customer ID
-
order number
-
transaction information
The legal basis is Art. 6(1)(b) GDPR.
Where invoice, payment or order data must be retained due to statutory requirements, further processing is carried out on the basis of Art. 6(1)(c) GDPR.
14. Merchandise Management and Order Processing with WeClapp
We use WeClapp for merchandise management, order processing and invoicing.
Provider:
weclapp GmbH
Germany
The following data may in particular be processed:
-
customer master data
-
name
-
contact details
-
billing and delivery addresses
-
orders
-
product information
-
invoices
-
payment status
-
shipping information
-
communications relating to orders
The processing serves to fulfil your order and comply with commercial and tax law obligations.
The legal bases are Art. 6(1)(b) and Art. 6(1)(c) GDPR.
15. Payment Processing
Depending on the payment method selected, we use various payment service providers.
These currently include in particular:
Klarna
Klarna Bank AB (publ), Sweden
PayPal
PayPal (Europe) S.à r.l. et Cie, S.C.A., Luxembourg
Shop Pay / Shopify Payments
Services provided by the Shopify group of companies.
Stripe
Stripe Payments Europe Ltd., Ireland
When you select a payment method, the following information may in particular be transmitted to the relevant payment service provider:
-
name
-
billing address
-
email address
-
order amount
-
currency
-
payment method
-
transaction information
-
device and security information
Payment service providers may additionally process data for authentication, fraud prevention, risk assessment and compliance with their own statutory obligations.
Processing for the purpose of executing the payment is generally based on Art. 6(1)(b) GDPR.
Where payment service providers process data for their own legal or regulatory purposes, they act as independent controllers in this respect.
16. Shipping with DHL
We currently ship our B2C orders using DHL GoGreen Plus.
For the purpose of shipping, we transmit the information required for delivery to DHL.
This includes in particular:
-
name
-
delivery address
-
where applicable, additional delivery information
The processing and transmission are carried out to fulfil your order on the basis of Art. 6(1)(b) GDPR.
Where your email address or telephone number is additionally transmitted to DHL for shipment notifications or delivery coordination and consent is required for this purpose, processing is based on Art. 6(1)(a) GDPR.
17. Newsletter and Email Marketing with Klaviyo
We use Klaviyo for our newsletter, automated emails, customer communication and email marketing.
Provider:
Klaviyo, Inc.
Boston, Massachusetts
USA
If you subscribe to our newsletter, we process in particular:
-
email address
-
where applicable, name
-
time of registration
-
consent status
-
where applicable, further data provided voluntarily
The legal basis for sending the newsletter is your consent pursuant to Art. 6(1)(a) GDPR.
You may withdraw your consent at any time with effect for the future, in particular via the unsubscribe link in our emails.
Advertising to Existing Customers
Where the legal requirements of Section 7(3) of the German Act Against Unfair Competition (UWG) are met, we may inform existing customers by email about our own similar products and services.
The data protection legal basis is Art. 6(1)(f) GDPR.
You may object to this use of your email address at any time.
Newsletter Tracking
Where you have given the relevant consent, we may analyse:
-
whether an email was opened
-
which links were clicked
-
time of opening or interaction
-
device used
-
browser information
-
IP-related information
The processing is carried out on the basis of Art. 6(1)(a) GDPR.
Klaviyo Tracking in the Online Shop
Where you have consented to the relevant Marketing category, Klaviyo may collect information about your usage behaviour in our online shop.
This may include in particular:
-
page views
-
product views
-
searches
-
shopping cart actions
-
checkout events
-
orders
-
order values
-
referrer
-
browser and device information
-
pseudonymous identifiers
This information may be linked to an existing customer, order or newsletter profile.
Access to your device is based on Section 25(1) TDDDG.
The legal basis for the subsequent processing of personal data is Art. 6(1)(a) GDPR.
Klaviyo also processes data in the United States. Klaviyo participates in the EU-U.S. Data Privacy Framework and uses additional data protection safeguards for other transfer scenarios.
18. Coffee Subscription with Seal Subscriptions
We use Seal Subscriptions for our coffee subscription service.
Seal Subscriptions enables in particular:
-
recurring orders
-
delivery intervals
-
automatic renewals
-
pauses
-
changes
-
cancellations
-
management of subscription products
The following data may in particular be processed:
-
name
-
email address
-
billing address
-
delivery address
-
customer ID
-
product information
-
subscription status
-
delivery interval
-
order information
-
payment references
-
technical network data
According to the provider, Seal Subscriptions processes personal customer data transmitted by the Shopify merchant in order to provide the service.
According to the provider, the data is stored on servers in Toronto, Canada.
The processing is carried out to manage your coffee subscription on the basis of Art. 6(1)(b) GDPR.
Subject to the applicable legal requirements, Canada is covered by an adequacy decision of the European Commission.
19. Loyalty Programme with BLOY Loyalty
We use BLOY Loyalty Points & Rewards for our loyalty and rewards programme.
The service is provided by BSS Commerce, Hanoi, Vietnam.
If you use our loyalty programme, the following data may in particular be processed:
-
customer ID
-
name
-
email address
-
telephone number
-
postal address
-
order history
-
products purchased
-
order values
-
points earned
-
points redeemed
-
discounts
-
vouchers
-
store credit
-
information about actions within the loyalty programme
The data is processed in order to:
-
calculate loyalty points
-
assign points to your customer account
-
manage point balances
-
provide rewards and credit
-
process redemptions
Processing within the loyalty programme functions used by you is based on Art. 6(1)(b) GDPR.
Technical data may additionally be processed on the basis of Art. 6(1)(f) GDPR where necessary for the secure provision of the service.
BSS Commerce states that it uses server and cloud infrastructure outside the EEA, in particular in the United States, for Shopify apps.
Where a transfer to a third country takes place, this is carried out in compliance with Arts. 44 et seq. GDPR.
20. Product Reviews with Judge.me
We use Judge.me to collect and display product reviews.
Provider:
Judge.me Ltd
1–3 Worship Street
London EC2A 2AB
United Kingdom
If you submit a review or use a review function, the following data may in particular be processed:
-
name or display name
-
email address
-
rating
-
review text
-
product reference
-
order information
-
information about a verified purchase
-
IP address
-
technical device and usage information
Judge.me generally processes customer data transmitted by merchants as a processor.
The processing serves to collect customer reviews, verify their authenticity and display reviews in our shop.
The legal basis is generally Art. 6(1)(f) GDPR.
Our legitimate interest is to transparently present the experiences of our customers and enable other customers to make more informed purchasing decisions.
Where we send you a review request by email and consent is required for this purpose, processing is based on Art. 6(1)(a) GDPR.
The United Kingdom is currently covered by an adequacy decision of the European Commission.
21. Trusted Shops
Services and widgets from Trusted Shops are integrated into our website.
Provider:
Trusted Shops SE
Subbelrather Straße 15C
50823 Cologne
Germany
Trusted Shops enables in particular:
-
display of the Trusted Shops Trustmark
-
display of reviews
-
buyer protection
-
where applicable, review invitations following an order
Display of the Trustbadge and Widgets
When the Trustbadge or corresponding widgets are loaded, the following data may in particular be processed:
-
IP address
-
date and time
-
browser and device information
-
technical access data
The processing serves to display Trusted Shops services and provide the relevant functions securely and reliably.
Where processing is based on legitimate interests, the legal basis is Art. 6(1)(f) GDPR.
Our legitimate interest is in particular to increase trust and security when purchasing from our online shop.
For certain processing activities relating to the Trustbadge, Trusted Shops and we may act as joint controllers within the meaning of Art. 26 GDPR.
Buyer Protection and Review Invitations
If you use the relevant Trusted Shops services or have consented to them, the following information may in particular be processed or transmitted to Trusted Shops after an order:
-
email address
-
order number
-
time of order
-
order value
-
where applicable, products purchased
The applicable legal basis depends on the specific function and may in particular be Art. 6(1)(a) or Art. 6(1)(b) GDPR.
22. Affiliate Programme with GoAffPro
We use GoAffPro for our affiliate and referral programme.
Provider:
GoAffPro
Haryana
India
GoAffPro enables us to determine whether a purchase was generated via an affiliate link or a code assigned to an affiliate.
The following data may in particular be processed:
-
affiliate ID
-
affiliate link
-
referrer
-
time of visit
-
pseudonymous visitor ID
-
session ID
-
discount code
-
pages visited
-
order information
-
order value
-
browser and device information
According to GoAffPro, the following cookies are used in particular for visitors arriving via affiliate links:
ref – affiliate reference
gfp_v_id – visitor session ID
gfp_v_expires – session expiry date
Where information is stored on or read from your device for this purpose, this takes place only after your consent pursuant to Section 25(1) TDDDG.
The legal basis for subsequent processing of personal data is Art. 6(1)(a) GDPR.
For registered affiliate partners, the following data may additionally be processed:
-
name
-
email address
-
contact details
-
payment information
-
commission data
This processing is carried out for the performance of the affiliate relationship pursuant to Art. 6(1)(b) GDPR.
GoAffPro states that it uses data centres in Germany and the United States, among other locations. The company itself is based in India.
23. Google Analytics
We use Google Analytics to analyse the use of our online shop.
Provider:
Google Ireland Limited
Gordon House
Barrow Street
Dublin 4
Ireland
Google Analytics may in particular collect the following information:
-
page views
-
product views
-
clicks
-
scroll and interaction events
-
sessions
-
session duration
-
entry and exit pages
-
referrer
-
approximate geographical information
-
browser
-
operating system
-
device type
-
pseudonymous user and session identifiers
-
shopping cart actions
-
checkout events
-
purchases and order values
The processing serves in particular to analyse the reach and use of our website and improve our shop.
Google Analytics is activated only if you have previously consented to the relevant Analytics category.
The legal bases are Section 25(1) TDDDG and Art. 6(1)(a) GDPR.
You may withdraw your consent at any time via our Cookie Settings.
According to Google, individual IP addresses of users in the EU are not logged or stored when data is collected via Google Analytics. IP addresses are initially used to derive approximate location information and are then discarded.
Google may also process data outside the EEA through affiliated companies and service providers.
Google Signals
Where Google Signals is enabled in our Analytics configuration, additional aggregated information may be used relating to users who have enabled personalised advertising in their Google accounts.
This may in particular enable cross-device statistics.
The function is used only where the required consent has been obtained.
24. Google Ads and Conversion Tracking
We use Google Ads to display advertising for our online shop and measure the success of our advertising campaigns.
The provider is Google Ireland Limited.
If you reach our website via a Google advertisement, conversion tracking may be used to process information about whether you subsequently perform certain actions, for example:
-
visit product pages
-
add products to the shopping cart
-
start the checkout
-
complete an order
Online identifiers, cookies, device information, browser information, pages visited and conversion events may in particular be processed.
Where remarketing is used, information about your use of our shop may be used to create audiences for subsequent advertising.
Google Ads and corresponding marketing technologies are activated only after your consent.
The legal bases are Section 25(1) TDDDG and Art. 6(1)(a) GDPR.
25. Google Tag Manager
We use Google Tag Manager provided by Google Ireland Limited for the technical management of tracking and marketing tags.
Google Tag Manager enables various services to be integrated and managed centrally.
The Tag Manager is used in particular for the technical triggering of the services configured by us.
Where analytics or marketing services are triggered via Google Tag Manager, this takes place only in accordance with your previously selected cookie preferences.
The legal basis depends on the respective service integrated.
26. Google reCAPTCHA
We may use Google reCAPTCHA to protect individual forms against spam and automated access.
The provider is Google Ireland Limited.
The following information may in particular be processed:
-
IP address
-
browser information
-
device information
-
time of access
-
mouse and keyboard interactions
-
further technical information used to assess whether access is made by a human or an automated system
Where reCAPTCHA is not used as a strictly technically necessary service, it is activated only after the relevant consent has been obtained.
In this case, the legal basis is Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG.
27. Meta Pixel – Facebook and Instagram
We use the Meta Pixel on our website.
The provider for users in the European Economic Area is:
Meta Platforms Ireland Limited
Merrion Road
Dublin 4
Ireland
The Meta Pixel enables us to measure the success of our advertising on Facebook and Instagram and optimise our advertising campaigns.
The following information may in particular be processed:
-
page views
-
product views
-
searches
-
shopping cart actions
-
start of checkout
-
completed purchases
-
order value
-
currency
-
browser information
-
device information
-
IP address
-
referrer
-
cookie and online identifiers
Meta may use this information to measure conversions, create audiences and optimise advertising.
The Meta Pixel is activated only if you have previously consented to the Marketing category.
The legal bases are Section 25(1) TDDDG and Art. 6(1)(a) GDPR.
You may withdraw your consent at any time via our Cookie Settings.
Meta may, where applicable, link data to existing Facebook or Instagram accounts and further process it within its own services.
For certain processing activities within the Meta Business Tools, Meta and we may act as joint controllers pursuant to Art. 26 GDPR. Meta is independently responsible for subsequent processing within its own services.
28. Embedded YouTube Videos
Videos from YouTube may be embedded on individual pages of our website.
Provider:
Google Ireland Limited
Gordon House
Barrow Street
Dublin 4
Ireland
When a YouTube video is loaded or played, the following data may in particular be processed:
-
IP address
-
page visited
-
browser information
-
device information
-
interactions with the video
-
cookie and online identifiers
If you are simultaneously logged into a Google or YouTube account, Google may be able to associate the use with your account.
YouTube content is loaded only where the required consent has been obtained.
The legal bases are Section 25(1) TDDDG and Art. 6(1)(a) GDPR.
29. Google Fonts
We use fonts from Google Fonts.
According to our current technical configuration, the fonts required for the website are hosted locally.
Therefore, merely loading the locally hosted fonts does not establish a direct connection to Google servers.
If this technical integration changes, we will update this Privacy Policy accordingly.
30. Social Media Profiles
We operate company profiles in particular on:
-
Facebook
-
Instagram
-
TikTok
-
Pinterest
-
YouTube
Links to these platforms are generally integrated into our website as ordinary links. Merely visiting our website does not automatically establish a connection to the respective social network.
Only when you follow a corresponding link will you be taken to the respective platform provider.
If you interact with us there, for example by:
-
following us
-
commenting on a post
-
liking a post
-
sending us a message
we may process the information provided by you in order to communicate with you.
Depending on the type of interaction, the legal basis is Art. 6(1)(b) or Art. 6(1)(f) GDPR.
The respective platform operators additionally process personal data under their own responsibility.
Facebook and Instagram
The provider for users in the EEA is Meta Platforms Ireland Limited, Ireland.
For certain statistical analyses of our company pages, Meta and we may act as joint controllers pursuant to Art. 26 GDPR.
TikTok
The provider for users in the EEA is generally:
TikTok Technology Limited
Dublin
Ireland
TikTok may in particular process usage, profile, device, interaction and communication data.
The provider for users in the EEA is:
Pinterest Europe Ltd.
Dublin
Ireland
YouTube
The provider for users in the EEA is Google Ireland Limited.
31. Social Media Competitions
Where we run competitions on our social media channels, we process the participant data necessary for this purpose.
Depending on the design of the competition, this may include in particular:
-
name or profile name
-
comments and reactions
-
email address
-
postal address in the event of winning
-
where applicable, further information required to fulfil the prize
The processing is carried out for the purpose of administering the respective competition on the basis of Art. 6(1)(b) GDPR.
Data relating to winners may additionally be processed where necessary to comply with legal obligations.
Where a competition takes place via Facebook, Instagram, TikTok or another platform, the respective platform operator independently processes personal data in accordance with its own privacy policy.
32. Customer Surveys
We may conduct voluntary customer surveys in order to improve our products and services.
In this context, we process the data you provide as part of the respective survey.
Where the survey is conducted anonymously, no personal survey results are stored.
For surveys involving personal data, the legal basis depends on the respective design and may in particular be Art. 6(1)(a) or Art. 6(1)(f) GDPR.
33. Withdrawal of Consent and Cookie Settings
Where processing is based on your consent, you may withdraw that consent at any time with effect for the future.
The lawfulness of processing carried out prior to withdrawal remains unaffected.
You may change or withdraw consent for analytics, marketing and other non-essential technologies at any time via the Cookie Settings on our website.
Newsletter consent may additionally be withdrawn via the unsubscribe link in our emails.
34. Right to Object
Where we process personal data on the basis of Art. 6(1)(f) GDPR, you have the right under Art. 21 GDPR to object to such processing on grounds relating to your particular situation.
Where personal data is processed for direct marketing purposes, you may object to such processing at any time without giving reasons.
You may exercise your right to object in particular by sending an email to:
35. Your Data Protection Rights
Subject to the statutory requirements, you have the following rights in particular:
Right of Access – Art. 15 GDPR
You may request information as to whether and which personal data we process about you.
Right to Rectification – Art. 16 GDPR
You may request correction of inaccurate personal data and completion of incomplete personal data.
Right to Erasure – Art. 17 GDPR
You may request deletion of your personal data subject to the statutory requirements.
Right to Restriction of Processing – Art. 18 GDPR
Under certain circumstances, you may request that the processing of your personal data be restricted.
Right to Data Portability – Art. 20 GDPR
Where the legal requirements are met, you may receive your personal data in a structured, commonly used and machine-readable format or request that it be transmitted to another controller.
Right to Object – Art. 21 GDPR
You may object to the processing of your personal data subject to the statutory requirements.
Withdrawal of Consent – Art. 7(3) GDPR
You may withdraw consent already given at any time with effect for the future.
To exercise your rights, you may contact us at:
36. Right to Lodge a Complaint with a Data Protection Supervisory Authority
Under Art. 77 GDPR, you have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data infringes applicable data protection law.
The authority particularly competent for us is:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18
91522 Ansbach
Germany
You may generally also contact a data protection supervisory authority at your place of residence or habitual residence.
37. Requirement to Provide Data
For purely informational use of our website, you generally do not have to actively provide personal data.
However, certain information is required if you wish, for example, to:
-
place an order
-
create a customer account
-
enter into a coffee subscription
-
participate in the loyalty programme
-
purchase a barista course
-
become an affiliate partner
Without the respective required data, we may not be able to provide the requested service.
Consent to analytics or marketing tracking is voluntary and is generally not a condition for placing an order.
38. Data Security
We implement appropriate technical and organisational measures to protect personal data in particular against:
-
loss
-
alteration
-
unauthorised access
-
unlawful disclosure
-
destruction
Our website is generally transmitted using TLS/SSL encryption.
Despite appropriate security measures, absolute protection cannot be guaranteed when data is transmitted over the internet.
39. Changes to this Privacy Policy
We may amend this Privacy Policy if:
-
our website changes
-
the services we use change
-
the technical configuration changes
-
legal requirements change
The version currently published on our website applies.
Last updated: 8 September 2026