Privacy Notice
We take the protection of your personal data seriously and comply with the applicable data protection laws, in particular the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG), as well as this privacy policy. We process personal data of our users only to the extent necessary to provide a functional website and our content, services, and offers.
Personal data is any information relating to an identified or identifiable natural person.
This privacy policy provides an overview of the type of personal data processed and the purposes for which it is used. It also explains how we ensure the protection of your personal data.
1. Name and contact details of the controller
This privacy information applies to data processing by:
Controller:
ERNST Kaffeeröster
Owner: Maren Ernst
Bonner Straße 56
50677 Cologne, Germany
Phone: (+49) 221 16823207 or (+49) 16096625344
Email: hallo@ernst-kaffee.de
Website: www.ernst-kaffee.de
2. Collection and storage of personal data as well as type and purpose of their use
a) When visiting our website
You can visit our website www.ernst-kaffee.de without providing personal information about yourself.
When using the website for informational purposes only, i.e. if you do not register or otherwise transmit information to us, we only collect the personal data that your browser transmits to our server. When you access our website, your browser automatically sends information to our server. This information is temporarily stored in a log file. The following data is collected without your intervention and stored until it is automatically deleted:
IP address of the requesting computer,
date and time of access,
name and URL of the accessed file,
website from which the access is made (referrer URL),
browser used and, if applicable, the operating system of your computer as well as the name of your access provider, language and version of the browser software.
This data is processed for the following purposes:
ensuring a smooth connection setup of the website,
ensuring comfortable use of our website,
evaluation of system security and stability, and
for further administrative purposes.
The legal basis for data processing is Art. 6(1)(f) GDPR. Our legitimate interest follows from the purposes listed above. Under no circumstances do we use the collected data to draw conclusions about your person.
In addition, we use cookies when you visit our website. Further information can be found in section 4 of this privacy policy.
b) When using our webshop
When using our webshop, for example by placing orders, accepting offers, registering, or communicating with us, we process your personal data exclusively for the purpose of initiating or fulfilling a contract.
The legal basis for data processing is Art. 6(1)(b) GDPR.
When using our webshop, the following personal data provided by you may be processed:
First and last name (company name if applicable)
Address
Telephone number (landline and/or mobile)
Fax number (if applicable)
Email address
IBAN (if required for payment processing)
Credit card number including security code (if required for payment processing)
This data is processed for the purpose of fulfilling contractual obligations, in particular for shipping goods, processing payments including invoicing, handling warranty claims, and related communication.
You may also voluntarily create a customer account in which your personal data can be stored for future purchases. When creating an account, the data you provide will be stored revocably. You can delete your account and data at any time in the customer area.
3. Disclosure of data to third parties
Your personal data will not be transferred to third parties for purposes other than those listed below. In particular, data will not be passed on to third parties for advertising purposes without your explicit consent.
We only share your personal data if:
you have given your explicit consent in accordance with Art. 6(1)(a) GDPR;
it is necessary for the performance of a contract in accordance with Art. 6(1)(b) GDPR, e.g. to banks for payment processing or to shipping companies for delivery and tracking;
there is a legal obligation in accordance with Art. 6(1)(c) GDPR; or
the transfer is necessary to assert, exercise or defend legal claims in accordance with Art. 6(1)(f) GDPR.
We offer payment via PayPal. The provider is PayPal (Europe) S.à.r.l. et Cie, S.C.A., Luxembourg. If you choose PayPal, we transfer your personal data required for payment processing (Art. 6(1)(b) GDPR). Further information can be found in PayPal’s privacy policy: https://www.paypal.com/de/webapps/mpp/ua/privacy-full
4. Cookies
We use cookies on our website. These are small files that your browser automatically creates and stores on your device. Cookies do not cause damage and do not contain viruses or malware.
Cookies store information related to your specific device. However, this does not mean that we gain direct knowledge of your identity.
Cookies are used to improve user experience. Session cookies recognize that you have already visited pages and are deleted after leaving the website.
Temporary cookies are also used to save preferences for future visits.
The data processed by cookies is necessary for the purposes mentioned above in accordance with Art. 6(1)(f) GDPR.
Most browsers accept cookies automatically. You can configure your browser to refuse cookies or notify you before a cookie is set. Disabling cookies completely may limit website functionality.
5. Data retention and deletion
Personal data is deleted when it is no longer necessary for its purpose, unless legal retention obligations apply. These may require storage for up to 10 years (e.g. accounting data) or 6 years (business correspondence). During retention, data is restricted and deleted afterwards.
6. Your rights
You have the right:
to withdraw your consent at any time (Art. 7(3) GDPR);
to request information about your stored data (Art. 15 GDPR);
to request correction of inaccurate data (Art. 16 GDPR);
to request deletion (Art. 17 GDPR);
to request restriction of processing (Art. 18 GDPR);
to receive your data in a portable format (Art. 20 GDPR);
to lodge a complaint with a supervisory authority (Art. 77 GDPR).
7. Right to object
If your personal data is processed based on legitimate interests (Art. 6(1)(f) GDPR), you have the right to object at any time. Please send your request to hallo@ernst-kaffee.de.
8. Data security
We use appropriate technical and organizational measures to protect your data against loss, manipulation, or unauthorized access. We use SSL/TLS encryption to ensure secure data transmission.
9. Updates to this privacy policy
This privacy policy is effective as of May 2018.
Due to legal or technical changes, updates may be necessary. The current version is always available on our website.