Privacy policy

 

Privacy Policy

Last updated: 8 September 2026

1. Controller

The controller within the meaning of the General Data Protection Regulation (“GDPR”) and other applicable data protection laws is:

Phoenix Coffee Roasters GmbH
Jagdweg 1–3
Entrance: Rosenstraße 92
01159 Dresden
Germany

Managing Directors: Frederick Bauer-Stäb and Tobias Heppner

Phone: +49 (0)351 48618819
Email: info@phoenix-coffeeroasters.com


2. General Information on Data Processing

We take the protection of your personal data seriously.

Personal data means any information relating to an identified or identifiable natural person. This includes, for example, your name, email address, postal address, telephone number, IP address, order data, online identifiers or information about how you use our website.

We process personal data only where there is a legal basis for doing so.

Depending on the processing activity, the following legal bases may apply in particular:

Art. 6(1)(a) GDPR – Consent
where you have expressly given us your consent, in particular for analytics, marketing, tracking or newsletter purposes.

Art. 6(1)(b) GDPR – Performance of a contract and pre-contractual measures
where processing is necessary for an order, coffee subscription, seminar booking, customer account, loyalty programme or another service requested by you.

Art. 6(1)(c) GDPR – Legal obligation
where we are required by law to process or retain data.

Art. 6(1)(f) GDPR – Legitimate interests
where processing is necessary for the purposes of our legitimate interests or those of a third party and your interests, fundamental rights and freedoms do not override those interests. This includes, in particular, the secure and efficient provision of our online shop, fraud prevention, customer service and the improvement of our services.

Where information is stored on your device or information already stored on your device is accessed, we additionally comply with Section 25 of the German Telecommunications-Digital-Services Data Protection Act (TDDDG).

Non-essential cookies, pixels and similar technologies are generally used only after your prior consent.


3. Retention Period

We generally retain personal data only for as long as necessary for the respective processing purpose.

Where statutory retention obligations apply, in particular under tax or commercial law, we retain the relevant data for the legally prescribed period.

After expiry of the respective periods, the data will be deleted or anonymised unless another legal basis permits further processing.

For individual external services, the retention period may additionally depend on our respective settings and the requirements of the relevant service provider.


4. Recipients and Processors

We use external service providers to operate our online shop and provide our services.

These providers receive personal data only to the extent necessary to provide the respective service.

Where service providers process personal data solely on our instructions, such processing is carried out on the basis of a data processing agreement pursuant to Art. 28 GDPR.

Other recipients, in particular payment service providers, social networks or certain advertising platforms, may process personal data partly under their own data protection responsibility.


5. Transfers of Data to Third Countries

Some of the providers we use or their subprocessors are located outside the European Union or the European Economic Area.

Personal data is transferred to third countries only in compliance with Arts. 44 et seq. GDPR.

Where the European Commission has adopted an adequacy decision for the relevant country, the transfer may be based on that decision.

For appropriately certified companies in the United States, the EU-U.S. Data Privacy Framework may in particular serve as the transfer mechanism.

Otherwise, the European Commission’s approved Standard Contractual Clauses pursuant to Art. 46 GDPR and, where appropriate, additional technical and organisational measures may be used.


6. Shopify

We operate our online shop using the e-commerce platform Shopify.

The provider for merchants in the European Economic Area is generally:

Shopify International Limited, Ireland

Shopify provides us, among other things, with the technical infrastructure for our online shop, product pages, shopping cart, checkout, customer accounts, orders and various other shop functions.

The following data may in particular be processed:

  • IP address

  • browser and device information

  • pages visited

  • date and time of access

  • shopping cart contents

  • customer ID

  • name

  • email address

  • telephone number

  • billing and delivery address

  • order information

  • payment information or payment references

  • information about returns and refunds

  • other data entered during the ordering or checkout process

Processing is carried out in particular on the basis of Art. 6(1)(b) GDPR where necessary to fulfil an order.

The technical provision and security of our online shop are additionally based on Art. 6(1)(f) GDPR.

Shopify may use affiliated companies and subprocessors outside the EEA.

Data relating to persons in the EEA is generally initially processed by Shopify International Limited in Ireland. For further international transfers, Shopify states that it uses, among other things, approved Binding Corporate Rules, Standard Contractual Clauses and other transfer mechanisms permitted under applicable data protection law.


7. Shopify Content Delivery Network

Shopify uses a globally distributed Content Delivery Network (“CDN”) to provide the contents of our online shop quickly and securely.

In this context, your IP address in particular may be processed in order to deliver content through a suitable server and to detect technical disruptions and security risks.

The legal basis is Art. 6(1)(f) GDPR.

Our legitimate interest is the fast, stable and secure provision of our online shop.


8. Server Log Data

When you visit our website, technically necessary information is processed.

This may include in particular:

  • IP address

  • date and time of access

  • page or file accessed

  • referrer URL

  • browser type and version

  • operating system

  • device information

  • language settings

  • HTTP status codes

  • technical error and security information

The processing is carried out to ensure the secure and stable operation of our website and to detect attacks or technical errors.

The legal basis is Art. 6(1)(f) GDPR.


9. Cookies, Local Storage, Pixels and Similar Technologies

Our website uses cookies and comparable technologies such as Local Storage, Web Storage and tracking pixels.

We use technically necessary technologies, for example, for:

  • shopping cart

  • checkout

  • login and customer account

  • language and country selection

  • security

  • payment processing

  • storage of your privacy choices

Where the storage of or access to information on your device is strictly necessary, this is based on Section 25(2) TDDDG.

Non-essential analytics, marketing or personalisation technologies are generally used only after your consent pursuant to Section 25(1) TDDDG and Art. 6(1)(a) GDPR.

An up-to-date overview of the cookies and technologies actually used can be found in the Cookie Settings on our website.


10. Consent Management with Consentmo

We use Consentmo GDPR Compliance to manage your cookie and privacy choices.

The service is provided under the Consentmo brand by:

iSense Ltd., Sofia, Bulgaria, and affiliated companies.

Consentmo enables us, in particular, to record and technically implement your decision as to which non-essential analytics, marketing or personalisation services may be used.

The following data may in particular be processed:

  • your consent decision

  • selected categories

  • date and time of the decision

  • technical information

  • browser and device information

  • where applicable, IP address

When processing data relating to our shop visitors, Consentmo generally acts as a processor.

The processing serves in particular to implement your privacy choices and to demonstrate consent where required.

The legal bases are Art. 6(1)(c) GDPR in conjunction with statutory documentation obligations and, additionally, Art. 6(1)(f) GDPR.

Technically necessary storage is based on Section 25(2) TDDDG.

You can change your decision at any time via the Cookie Settings on our website.


11. Contact

If you contact us by email, telephone or contact form, we process the data you provide in order to respond to your enquiry.

This may include in particular:

  • name

  • email address

  • telephone number

  • company

  • order number

  • content of your message

If your enquiry relates to an existing or potential contract, processing is carried out on the basis of Art. 6(1)(b) GDPR.

For other enquiries, processing is carried out on the basis of Art. 6(1)(f) GDPR.

Our legitimate interest is to be able to respond to enquiries from our customers and interested parties.


12. Customer Account

You can create a customer account in our online shop.

The following data may in particular be processed:

  • name

  • email address

  • telephone number

  • postal address

  • saved delivery addresses

  • customer ID

  • order history

  • subscription information

  • loyalty points and credit balances

The customer account is used in particular to manage orders and other functions of our shop used by you.

The legal basis is Art. 6(1)(b) GDPR.

You may request deletion of your customer account at any time, provided that no statutory retention obligations prevent deletion.


13. Orders

If you place an order in our online shop, we process the data required to fulfil the order.

This may include in particular:

  • name

  • billing address

  • delivery address

  • email address

  • telephone number

  • products ordered

  • grind size and product variants

  • order quantity

  • order value

  • payment method

  • shipping method

  • discount information

  • customer ID

  • transaction and order number

The legal basis is Art. 6(1)(b) GDPR.

Where invoice and order data must be retained due to statutory requirements, further processing is carried out on the basis of Art. 6(1)(c) GDPR.


14. Merchandise Management and Order Processing with WeClapp

We use WeClapp for internal merchandise management, order processing and invoicing.

Provider:

weclapp GmbH
Germany

The following data may in particular be processed:

  • customer master data

  • contact details

  • billing and delivery addresses

  • orders

  • products

  • invoices

  • payments

  • shipping information

  • communication information

The processing is carried out to fulfil your order and to comply with statutory tax and commercial law obligations.

The legal bases are Art. 6(1)(b) and Art. 6(1)(c) GDPR.


15. Payment Processing

Depending on the payment method selected at checkout, we use external payment service providers for payment processing.

These may include in particular:

PayPal (Europe) S.à r.l. et Cie, S.C.A., Luxembourg

Klarna Bank AB (publ), Sweden

Shopify Payments / Shop Pay

Stripe Payments Europe Ltd., Ireland, where Stripe is used for the respective payment method.

When you select a payment method, the information required for payment processing is transmitted to the relevant payment service provider.

This may include:

  • name

  • address

  • email address

  • order amount

  • currency

  • transaction number

  • payment information

  • device and security information

The payment service providers may process further data for authentication, fraud prevention, creditworthiness or risk assessment and compliance with statutory obligations.

The legal basis for payment processing is generally Art. 6(1)(b) GDPR.

Where a payment service provider processes personal data for its own legal or regulatory purposes, it acts under its own data protection responsibility in this respect.


16. Shipping with DHL and DPD

We use DHL and DPD, in particular, for the delivery of our orders.

For this purpose, we transmit the data required for delivery to the respective shipping provider.

This includes in particular:

  • name

  • delivery address

  • where applicable, further delivery information

Where this is required for shipping notifications or delivery coordination and is requested by you, your email address or telephone number may additionally be transmitted.

The legal basis for shipping is Art. 6(1)(b) GDPR.


17. Newsletter and Email Marketing with Klaviyo

We use Klaviyo for newsletters, automated emails and email marketing.

Provider:

Klaviyo, Inc., Boston, Massachusetts, USA

If you subscribe to our newsletter, we process in particular:

  • email address

  • where applicable, name

  • time of registration

  • consent status

  • other information provided voluntarily

Processing is based on your consent pursuant to Art. 6(1)(a) GDPR.

You may withdraw your consent at any time with effect for the future, in particular via the unsubscribe link in our emails.

Advertising to Existing Customers

Where the requirements of Section 7(3) of the German Act Against Unfair Competition (UWG) are met, we may inform existing customers by email about our own similar products.

The data protection legal basis is Art. 6(1)(f) GDPR.

You may object to this use of your email address at any time without incurring any additional costs.

Newsletter Performance Measurement

Where you have given the relevant consent, Klaviyo may be used to measure whether newsletters are opened and which links contained in them are clicked.

The following data may in particular be processed:

  • email address

  • opens

  • clicks

  • time of interaction

  • browser and device information

  • IP-related information

The legal basis is Art. 6(1)(a) GDPR.

Klaviyo Tracking on Our Website

Where you have consented to the Marketing category, Klaviyo may additionally collect information about your behaviour in our online shop.

This may include in particular:

  • page views

  • product views

  • search activity

  • shopping cart actions

  • checkout events

  • orders

  • order values

  • referrer

  • pseudonymous identifiers

  • browser and device information

This information may be linked to an existing newsletter, customer or order profile.

Access to your device is based on Section 25(1) TDDDG.

The subsequent processing of personal data is based on Art. 6(1)(a) GDPR.

Klaviyo also processes personal data in the United States. According to Klaviyo, it participates in the EU-U.S. Data Privacy Framework and additionally uses Standard Contractual Clauses for certain other data transfers.


18. Coffee Subscriptions with Seal Subscriptions

We use Seal Subscriptions for our coffee subscriptions.

Provider:

Seal Subscriptions
Podutiška cesta 94
1000 Ljubljana
Slovenia

Seal Subscriptions enables the technical management of:

  • recurring orders

  • delivery intervals

  • subscription products

  • subscription status

  • pauses

  • changes

  • cancellations

The following data may in particular be processed:

  • name

  • email address

  • billing address

  • delivery address

  • customer ID

  • order information

  • subscription information

  • product information

  • payment references

  • IP address and technical network data

For automatically billed subscriptions, Seal Subscriptions also states that it processes limited card information such as card type, expiry date and the last four digits of the payment card.

According to Seal Subscriptions, full payment card details are not stored.

The processing is necessary to set up and manage your coffee subscription.

The legal basis is Art. 6(1)(b) GDPR.

Seal Subscriptions states that data processed by the app is stored on servers in Toronto, Canada.

Where the requirements of the European Commission’s adequacy decision for Canada are met, the transfer may be based on that decision.


19. Loyalty and Rewards Programme with BLOY Loyalty

We use BLOY Loyalty Points & Rewards for our loyalty and rewards programme.

The service is offered under the BLOY brand and is associated with BSS Commerce.

If you use our loyalty programme, the following data may in particular be processed:

  • customer ID

  • name

  • email address

  • telephone number

  • postal address

  • order history

  • products purchased

  • order values

  • points earned

  • points redeemed

  • discounts

  • vouchers

  • credit balances

  • store credit

  • information about actions within the loyalty programme

  • IP address

  • browser and device information

  • approximate location information

The processing is carried out in particular to calculate loyalty points, assign them to your customer account and manage rewards, discounts and credit balances.

If you voluntarily register for our loyalty programme or use the corresponding function of your customer account, processing is carried out for the performance of the loyalty programme on the basis of Art. 6(1)(b) GDPR.

Technical processing required to ensure security and functionality may additionally be based on Art. 6(1)(f) GDPR.

BLOY states that personal customer and usage data is stored on servers in the United States.

Where data is processed outside the EEA, this is carried out in compliance with Arts. 44 et seq. GDPR.


20. Product Reviews with Judge.me

We use Judge.me to collect, manage and display product reviews.

Provider:

Judge.me Ltd
c/o Buckworths
1–3 Worship Street
London EC2A 2AB
United Kingdom

When acting for merchants, Judge.me generally processes personal data as a processor.

If you submit a review, the following data may in particular be processed:

  • name or display name

  • email address

  • rating

  • review text

  • product reference

  • order information

  • information about whether the purchase is verified

  • IP address

  • browser and device information

The processing is carried out to collect customer reviews, verify their authenticity and display them on our website and, where applicable, in connected Shopify services.

The legal basis is Art. 6(1)(f) GDPR.

Our legitimate interest is to transparently present the experiences of our customers and provide interested parties with a better basis for making purchasing decisions.

Where we send review requests by email, this is done only if the applicable statutory requirements are met.

Where consent is required, the legal basis is Art. 6(1)(a) GDPR.

The United Kingdom is currently covered by an adequacy decision of the European Commission.

Judge.me also states that certain data may be processed by subprocessors outside the United Kingdom.


21. Coffee Quiz with RevenueHunt

We use Product Recommendation Quiz by RevenueHunt for our interactive coffee quiz and the product recommendations generated from it.

Provider:

Durian Capital Inc.
Intershore Chambers
Road Town, Tortola
British Virgin Islands

RevenueHunt helps us select products that match your stated coffee and flavour preferences based on your answers.

The following data may in particular be processed:

  • quiz answers

  • coffee and product preferences

  • result and recommendation data

  • quiz or session ID

  • IP address

  • browser information

  • operating system

  • device information

  • approximate location information

  • interactions with the quiz

If you voluntarily provide your email address or other contact details within the quiz, these data may also be processed.

Depending on our technical configuration, quiz answers and contact details may additionally be transferred to Shopify or Klaviyo.

The processing of your quiz answers is carried out in order to provide the product recommendation expressly requested by you.

The legal basis is Art. 6(1)(b) GDPR or, where no contractual relationship is yet being initiated, our legitimate interest pursuant to Art. 6(1)(f) GDPR in providing you with voluntarily requested product advice.

Contact details or quiz information will be used for newsletters or other marketing purposes only where the relevant consent has been obtained.

The legal basis in such cases is Art. 6(1)(a) GDPR.

Where RevenueHunt uses non-essential cookies or comparable technologies on your device, this takes place only after your consent pursuant to Section 25(1) TDDDG.

RevenueHunt is operated by Durian Capital Inc. in the British Virgin Islands. According to RevenueHunt, its servers are hosted with Amazon AWS in the United States.

RevenueHunt states that it uses the EU-U.S. Data Privacy Framework, where applicable, and Standard Contractual Clauses for international data transfers.

The recommendations generated by the quiz do not constitute a decision based solely on automated processing within the meaning of Art. 22 GDPR that produces legal effects concerning you or similarly significantly affects you.


22. Seminar and Event Bookings with Appointo

For certain seminar, course, event or appointment bookings, we may use Appointo / Appointment Booking App ointo.

Provider:

Sidepanda Services LLP
Bangalore
India

If you book a corresponding service via our website, the following data may in particular be processed:

  • name

  • email address

  • telephone number

  • requested service

  • event

  • date

  • time

  • number of participants

  • order information

  • other information voluntarily provided

The processing is carried out to organise your booking, plan capacities and send booking confirmations and, where applicable, reminders.

The legal basis is Art. 6(1)(b) GDPR.

Appointo / SidePanda states that it uses technical hosting infrastructures such as AWS and Heroku.

This may result in personal data also being processed outside the EEA.

Such data transfers are carried out only in compliance with Arts. 44 et seq. GDPR.


23. Affiliate Programme with GoAffPro

We use GoAffPro for our affiliate and referral programme.

Provider:

GoAffPro
16, Sector 20
Haryana
India

GoAffPro enables us to determine whether a purchase on our website was generated via an affiliate link or a code assigned to an affiliate.

This allows us, in particular, to calculate commissions correctly.

The following data may in particular be processed:

  • affiliate ID

  • referrer

  • time of access

  • affiliate link

  • discount code

  • pseudonymous visitor ID

  • session ID

  • pages visited

  • order information

  • order value

  • technical device and browser information

According to GoAffPro, the following identifiers or cookies are used in particular for affiliate visitors:

ref – affiliate reference

gfp_v_id – visitor session ID

gfp_v_expires – session expiry time

Where this information is stored on or read from your device, this takes place only after your consent pursuant to Section 25(1) TDDDG.

The legal basis for subsequent processing of personal data is Art. 6(1)(a) GDPR.

For our registered affiliate partners, the following data may additionally be processed:

  • name

  • email address

  • contact details

  • payment details

  • commission data

This processing is carried out for the performance of the affiliate agreement on the basis of Art. 6(1)(b) GDPR.

GoAffPro states that it uses data centres in Falkenstein and Nuremberg in Germany as well as in Virginia in the United States.

The provider itself is based in India.

Where data is processed outside the EEA, this is carried out in compliance with Arts. 44 et seq. GDPR.


24. Google Analytics

We use Google Analytics, a web analytics service provided by:

Google Ireland Limited
Gordon House
Barrow Street
Dublin 4
Ireland

Google Analytics helps us understand how visitors use our online shop.

The following information may in particular be processed:

  • page views

  • product views

  • clicks

  • scroll and interaction events

  • session duration

  • entry and exit pages

  • referrer

  • approximate geographical information

  • browser

  • operating system

  • device type

  • pseudonymous user and session identifiers

  • purchases and other e-commerce events

The analysis helps us understand the reach, usage and technical performance of our online shop and improve our services.

Google Analytics is activated only if you have consented to the relevant Analytics category.

The legal bases are Section 25(1) TDDDG for storing or accessing information on your device and Art. 6(1)(a) GDPR for subsequent processing.

You may withdraw your consent at any time via our Cookie Settings.

Google states that individual IP addresses of users in the EU, Switzerland and the United Kingdom are not logged or stored in Google Analytics. IP addresses are initially used to derive approximate location information and are then discarded.

Google may also process personal data outside the EEA through affiliated companies and service providers.

For international data transfers, Google uses the applicable legal transfer mechanisms, including, where relevant, the EU-U.S. Data Privacy Framework and Standard Contractual Clauses.


25. Meta Pixel for Facebook and Instagram Advertising

We use the Meta Pixel on our website.

The provider for users in the European Economic Area is:

Meta Platforms Ireland Limited
Merrion Road
Dublin 4, D04 X2K5
Ireland

The Meta Pixel enables us to determine whether visitors perform certain actions in our online shop after interacting with an advertisement on Facebook or Instagram.

The following data may in particular be processed:

  • page views

  • product views

  • searches

  • shopping cart actions

  • start of checkout

  • purchases

  • order value

  • currency

  • browser and device information

  • IP address

  • referrer

  • cookie and online identifiers

Meta may use this information in particular to measure conversions, create audiences and optimise advertising campaigns.

The Meta Pixel is activated only if you have previously consented to the Marketing category.

The legal bases are Section 25(1) TDDDG and Art. 6(1)(a) GDPR.

You may withdraw your consent at any time via our Cookie Settings.

If you are simultaneously logged into Facebook or Instagram, Meta may be able to associate the transmitted information with your account there.

For certain processing activities within the Meta Business Tools, Meta and we may act as joint controllers or as separate independent controllers.

Meta is generally independently responsible for further processing within the Facebook and Instagram platforms.

Meta may also process personal data outside the EEA. For this purpose, Meta uses the applicable data protection transfer mechanisms.


26. ChatGPT Ads Conversion Tracking / OpenAI Pixel

We use conversion tracking for ChatGPT Ads provided by OpenAI.

For data relating to individuals in the European Economic Area, processing within the OpenAI Ad Tools is carried out by:

OpenAI Ireland Limited
Ireland

The OpenAI Pixel enables us to determine whether visitors perform certain actions in our online shop after clicking on an advertisement displayed in ChatGPT.

The following events may in particular be processed:

  • page views

  • product views

  • adding products to the shopping cart

  • start of checkout

  • completed orders

  • order value

  • currency

  • technical information relating to the visit

If you click on a ChatGPT advertisement, OpenAI may append a click reference known as oppref to the URL of our website.

The OpenAI Pixel may collect this click reference and store it in a first-party cookie in order to attribute subsequent conversion events to the previous advertising click.

The processing is carried out for the measurement, attribution and optimisation of our advertising campaigns on ChatGPT Ads.

The OpenAI Pixel is activated only if you have previously consented to the Marketing category.

The legal bases are Section 25(1) TDDDG and Art. 6(1)(a) GDPR.

You may withdraw your consent at any time via our Cookie Settings.

OpenAI and we may each act as independent controllers for certain processing activities within the OpenAI Ad Tools.

According to OpenAI, OpenAI Ireland Limited processes EEA data falling within the scope of European data protection law in connection with the Ad Tools.

Where onward transfers to countries without an adequate level of data protection are necessary, OpenAI uses appropriate data protection transfer mechanisms.


27. Embedded YouTube Videos

On individual pages, we may embed videos from YouTube.

Provider:

Google Ireland Limited
Gordon House
Barrow Street
Dublin 4
Ireland

When an embedded YouTube video is loaded, the following data may in particular be transmitted to Google:

  • IP address

  • page visited

  • browser information

  • device information

  • interaction with the video

  • cookie and online identifiers

If you are simultaneously logged into your Google or YouTube account, Google may be able to associate your use with your account.

YouTube content is loaded only where the required consent has been granted.

The legal bases are Section 25(1) TDDDG and Art. 6(1)(a) GDPR.


28. Google Fonts

We use fonts from Google Fonts.

According to our current technical configuration, these fonts are hosted locally on our website.

Therefore, merely loading the locally hosted fonts does not establish a connection to Google servers.

If the technical integration changes in the future, we will update this Privacy Policy accordingly.


29. Customer Surveys and Feedback

We may occasionally conduct voluntary customer surveys in order to improve our services, products and customer experience.

In this context, we process the data you provide as part of the respective survey.

Where a survey is conducted anonymously, no personally identifiable results are stored.

For surveys involving personal data, processing is carried out, depending on the design of the survey, on the basis of your consent pursuant to Art. 6(1)(a) GDPR or our legitimate interest pursuant to Art. 6(1)(f) GDPR.


30. Social Media Profiles

We operate company profiles in particular on:

  • Instagram

  • Facebook

  • YouTube

If you access one of these platforms via a link on our website, personal data is generally processed by the respective platform provider only after you access the relevant platform.

If you interact with us there, for example by sending us a message or commenting on a post, we process the information you provide in order to communicate with you.

Depending on the content of the communication, the legal basis is Art. 6(1)(b) or Art. 6(1)(f) GDPR.

The platform operators may independently process usage, device and profile data for their own purposes.

Facebook and Instagram

The provider for users in the European Economic Area is:

Meta Platforms Ireland Limited, Ireland

In connection with certain statistical analyses of our company profiles, Meta and we may act as joint controllers for individual processing activities.

YouTube

The provider for users in the EEA is:

Google Ireland Limited, Ireland

The respective privacy policies of the platform operators additionally apply to processing carried out by them.


31. Withdrawal of Consent and Cookie Settings

Where processing is based on your consent, you may withdraw that consent at any time with effect for the future.

The lawfulness of processing carried out prior to the withdrawal remains unaffected.

You may change or withdraw consent for analytics, marketing and similar technologies at any time via the Cookie Settings on our website.

Newsletter consent may additionally be withdrawn via the unsubscribe link contained in our emails.


32. Right to Object to Processing

Where we process personal data on the basis of Art. 6(1)(f) GDPR, you have the right under Art. 21 GDPR to object to such processing at any time on grounds relating to your particular situation.

Where personal data is processed for direct marketing purposes, you may object to such processing at any time without having to provide specific reasons.

You may exercise your right to object in particular by sending an email to:

info@phoenix-coffeeroasters.com


33. Your Data Protection Rights

Subject to the statutory requirements, you have the following rights in particular:

Right of Access – Art. 15 GDPR

You may request information about which personal data we process about you.

Right to Rectification – Art. 16 GDPR

You may request correction of inaccurate personal data or completion of incomplete personal data.

Right to Erasure – Art. 17 GDPR

You may request deletion of your personal data subject to the statutory requirements.

Right to Restriction of Processing – Art. 18 GDPR

Under certain circumstances, you may request that processing of your data be restricted.

Right to Data Portability – Art. 20 GDPR

Where the applicable requirements are met, you may receive personal data in a structured, commonly used and machine-readable format or request that it be transmitted to another controller.

Right to Object – Art. 21 GDPR

You may object to processing subject to the statutory requirements.

Withdrawal of Consent – Art. 7(3) GDPR

You may withdraw any consent you have given at any time with effect for the future.

To exercise your rights, you may contact:

info@phoenix-coffeeroasters.com


34. Right to Lodge a Complaint with a Supervisory Authority

Under Art. 77 GDPR, you have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data infringes data protection law.

The supervisory authority particularly competent for us is:

Sächsische Datenschutz- und Transparenzbeauftragte
Maternistraße 17
01067 Dresden
Germany

You may generally also contact a data protection supervisory authority at your place of residence or habitual residence.


35. Requirement to Provide Certain Data

For purely informational use of our website, you generally do not have to actively provide personal data.

However, certain information is required if you wish, for example, to:

  • place an order

  • create a customer account

  • enter into a coffee subscription

  • participate in the loyalty programme

  • book a course or seminar

  • become an affiliate partner

Without the respective required data, we may not be able to provide the requested service.

Consent to analytics or marketing tracking is voluntary and is not a condition for placing an order.


36. Data Security

We use appropriate technical and organisational measures to protect personal data in particular against:

  • loss

  • manipulation

  • unauthorised access

  • unlawful disclosure

  • destruction

Our website is generally transmitted using TLS/SSL encryption.

Despite appropriate security measures, absolute protection cannot be guaranteed when data is transmitted over the internet.


37. Changes to this Privacy Policy

We may update this Privacy Policy if our website, the services we use or the applicable legal requirements change.

The version currently published on our website applies.

Last updated: 8 September 2026