Privacy policy

Last updated: 18 August 2026

The protection of your personal data is important to us. In this Privacy Policy, we explain which personal data we process when you visit our online shop, place an order, contact us or use our other online services, for which purposes such processing takes place, on which legal bases it is carried out and which rights you have.

This Privacy Policy applies to the online shop barista.tools, including the associated shop, checkout, customer account, contact, newsletter, review and customer service functions.

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Otto Hauck
Hauck Barista Tools
Fraham 18
5273 Roßbach bei Mauerkirchen
Austria

Phone: +43 650 944 00 50
Email: info@barista.tools
VAT ID: ATU68885815

If you have any questions regarding data protection or wish to exercise your data protection rights, you can contact us using the contact details above.

2. Principles and Legal Bases of Data Processing

We process personal data only where there is a legal basis for doing so and where the processing is necessary for a specified purpose.

Depending on the processing activity, the following legal bases may apply in particular:

  • Art. 6(1)(a) GDPR – Consent: in particular for newsletters and marketing communications as well as non-essential analytics, statistics and marketing technologies.
  • Art. 6(1)(b) GDPR – Performance of a contract and pre-contractual measures: in particular for orders, payments, deliveries, customer accounts, product enquiries, returns, complaints and other contract-related service matters.
  • Art. 6(1)(c) GDPR – Legal obligation: in particular for tax, commercial, corporate, customs and statutory retention obligations.
  • Art. 6(1)(f) GDPR – Legitimate interests: in particular for IT and system security, prevention of misuse and fraud, general business communication, internal organisation, quality assurance and the establishment, exercise or defence of legal claims.

Where processing is based on Art. 6(1)(f) GDPR, we also take the rights and interests of the data subjects into account as part of a balancing of interests.

3. Shopify – Shop Platform and Hosting

Our online shop is operated using the e-commerce platform Shopify.

For merchants and customers in the European Economic Area, Shopify services are provided in particular by Shopify International Limited, Ireland, as well as by other companies and service providers within the Shopify group.

Shopify provides functions including:

  • hosting and technical shop infrastructure;
  • shopping cart and checkout;
  • customer accounts;
  • order management;
  • payment integration;
  • security and fraud prevention;
  • language, market and country settings;
  • technical privacy and consent functions.

In this context, the following personal data may in particular be processed:

  • IP address;
  • browser and device information;
  • operating system;
  • time and duration of access;
  • pages and shop functions accessed;
  • cookie, session and device identifiers;
  • contact details;
  • billing and delivery addresses;
  • shopping cart and checkout information;
  • order and transaction data;
  • customer account and login information;
  • security and log data.

Where Shopify processes personal data exclusively on our behalf, such processing is carried out under a data processing arrangement.

For certain Shopify services, Shopify also processes personal data under its own responsibility as a data controller.

Further information:

Shopify Network Intelligence and Enhanced Services

Shopify Network Intelligence is enabled in our shop.

As a result, Shopify may process certain information about your interactions with our shop together with information about your interactions with Shopify and other Shopify merchants in order to provide so-called Enhanced Services.

These services may in particular be used to:

  • provide you with a more personalised shopping experience;
  • improve shop and product experiences;
  • improve the performance and security of the shop;
  • understand how customers interact with our shop and our marketing activities;
  • detect and prevent fraud and misuse;
  • provide more relevant advertising where legally permitted and subject to your consent.

For these purposes, information about your activities in our shop may be shared with Shopify and other service providers and recipients. These recipients may also be located in other countries.

Other Shopify merchants do not thereby gain direct access to our customer data.

For certain processing activities carried out in connection with Enhanced Services, Shopify may act as an independent data controller. In this respect, Shopify’s own privacy information also applies.

Where consent is required for specific functions, the choices you make through our Shopify privacy settings are taken into account.

Through the Shopify Privacy Portal, you can obtain further information about processing by Shopify and, where applicable, exercise privacy rights, objections or privacy preferences directly with Shopify.

4. Technical Log and Security Data

When operating our online shop, technical information is processed where necessary for the secure, stable and proper operation of the service.

This may include in particular:

  • IP address;
  • time of access;
  • browser and device information;
  • resources accessed;
  • technical error messages;
  • security events;
  • information concerning abusive or unusual access.

The processing serves in particular to provide our online service, ensure IT and system security and detect and prevent unauthorised or abusive use.

The legal basis is Art. 6(1)(f) GDPR.

5. Cookies and Similar Technologies

Our shop uses cookies and comparable technologies such as Local Storage, pixels, session identifiers and other technical identifiers.

Strictly Necessary Technologies

Strictly necessary technologies are used where required in order to provide the shop and functions explicitly requested by you.

This applies in particular to:

  • shopping cart;
  • checkout;
  • login and customer account;
  • session management;
  • security and fraud prevention;
  • language and market settings;
  • storage of your privacy and cookie choices.

Under Section 165(3) of the Austrian Telecommunications Act 2021 (TKG 2021), consent is in particular not required where the storage of or access to information on a terminal device is strictly necessary in order to provide a service expressly requested by the user.

Where personal data is processed in this context, processing is based, depending on the respective function, in particular on Art. 6(1)(b) or Art. 6(1)(f) GDPR.

Analytics and Marketing Technologies

Non-essential analytics, statistics and marketing technologies are controlled in regions where prior consent is required in accordance with the choices made via our Shopify privacy settings.

Our cookie banner is configured so that analytics and marketing technologies are not enabled by default in the relevant configured consent regions. You may consent to or reject their use.

Any consent given can be changed or withdrawn at any time with effect for the future using the cookie or privacy settings available in the shop.

For users in Germany, we also take into account the applicable requirements concerning the storage of or access to information on terminal devices.

Voluntary Storage in the Browser

Where individual forms offer an optional function to save entered information in the browser for later use, such storage takes place only if you make the corresponding choice. Locally stored browser data can be deleted via your browser settings.

6. Customer Account

If you create a customer account or use the customer account functions provided through Shopify, we process in particular:

  • name;
  • email address;
  • telephone number, where provided;
  • billing and delivery addresses;
  • order history;
  • returns and service information;
  • account settings.

The processing is carried out for the purpose of setting up, providing and managing the customer account on the basis of Art. 6(1)(b) GDPR.

You may request deletion of your customer account. Order, invoice and business records that must be retained by law will remain stored until the applicable statutory retention periods have expired.

7. Orders and Contract Processing

When you place an order through our shop, we process the data necessary to process the order and perform the contract.

This may include in particular:

  • name;
  • billing and delivery address;
  • email address;
  • telephone number;
  • company name and VAT ID, where applicable;
  • products and product variants ordered;
  • quantities and prices;
  • payment method and payment status;
  • shipping method and shipping status;
  • order, invoice and document numbers;
  • time of order;
  • order notes provided by you.

The processing is carried out for the performance of the contract and pre-contractual measures in accordance with Art. 6(1)(b) GDPR.

Where data must be processed or retained due to statutory tax, commercial, corporate or customs obligations, processing is additionally based on Art. 6(1)(c) GDPR.

8. Inventory Management and Accounting with orgaMAX

For inventory management, order processing, customer and product management, the creation of delivery notes, invoices and credit notes, as well as payment reconciliation, we use orgaMAX, provided by:

deltra Business Software GmbH & Co. KG
Gildestraße 9
32760 Detmold
Germany

Our Shopify shop is connected to orgaMAX. Orders and the information required for order processing may therefore be transferred from Shopify and further processed in our inventory management system.

This may include in particular:

  • customer and contact details;
  • billing and delivery addresses;
  • order data;
  • products and quantities;
  • prices and taxes;
  • payment method and payment status;
  • shipping information;
  • invoice and document data;
  • return, cancellation and credit note information.

The processing is carried out in particular on the basis of Art. 6(1)(b) GDPR and, where legally required, Art. 6(1)(c) GDPR.

Where orgaMAX processes personal data on our behalf, this is carried out under a data processing arrangement.

orgaMAX Privacy Information

9. Payment Processing

Our online shop offers, in particular, payment in advance, PayPal and electronic payment methods integrated through Shopify.

The payment methods actually available may depend on the country, currency and checkout configuration.

Payment in Advance / Bank Transfer

When you pay by bank transfer, we process in particular:

  • name of the account holder;
  • bank information transmitted to us;
  • payment amount;
  • payment date;
  • payment reference.

The processing is carried out for payment allocation and contract performance pursuant to Art. 6(1)(b) GDPR and, with regard to legally required payment records, pursuant to Art. 6(1)(c) GDPR.

PayPal

If you select PayPal, the information required for payment processing is transmitted to PayPal (Europe) S.à r.l. et Cie, S.C.A., Luxembourg.

This may include in particular:

  • name;
  • email address;
  • billing and delivery address;
  • order amount;
  • currency;
  • order number;
  • transaction information.

PayPal processes certain information, in particular for payment processing, security and fraud checks and compliance with its own legal obligations, under its own responsibility as data controller.

The legal basis for our transmission of data is Art. 6(1)(b) GDPR.

PayPal Privacy Statement

Shopify Payments

Electronic payments and credit card payments may be processed through Shopify Payments and the payment and financial service providers used for this purpose.

The following data may in particular be processed:

  • name;
  • billing address;
  • payment amount and currency;
  • payment and transaction information;
  • payment status;
  • information about the payment method used;
  • technical security and fraud indicators.

We generally do not store complete credit card details for our own purposes.

The legal basis is Art. 6(1)(b) GDPR.

The privacy information of Shopify and the payment service providers involved also applies.

10. Shipping, Delivery and Customs Processing

For the delivery of your order, we transmit the information necessary for this purpose to the respective shipping, parcel, freight forwarding or logistics provider commissioned by us.

This may include in particular:

  • name;
  • delivery address;
  • email address, where required for shipping notifications;
  • telephone number, where required for delivery;
  • shipment and delivery information.

The legal basis is Art. 6(1)(b) GDPR.

For deliveries to countries outside the European Union, data may additionally be transferred to customs authorities, foreign authorities, transport providers and other bodies required for import or export processing.

This may include in particular product description, value of goods, shipping costs as well as recipient and address information.

Depending on the individual case, processing is based on Art. 6(1)(b) and/or Art. 6(1)(c) GDPR.

11. Contact, Contact Form and B2B Enquiries

If you contact us by email, contact form, telephone or other means, we process the information you provide in order to handle your enquiry.

This may include in particular:

  • name;
  • email address;
  • telephone number;
  • company;
  • order number;
  • content of your message;
  • documents and other information voluntarily provided by you.

For contract-related or pre-contractual enquiries, processing is based on Art. 6(1)(b) GDPR.

For other business enquiries, processing is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in the appropriate, efficient and traceable handling of customer and business enquiries.

B2B and Dealer Enquiries

For enquiries from companies, dealers and other business partners, we may additionally process company name, the role of the contact person, business contact details and VAT ID.

Depending on the individual case, processing is based on Art. 6(1)(b) or Art. 6(1)(f) GDPR.

12. Returns, Complaints, Warranty and Technical Service

In connection with returns, complaints, warranty cases and technical service requests, we process the information necessary to handle the respective matter.

This may include in particular:

  • contact details;
  • order and invoice information;
  • product information;
  • serial numbers or product identification numbers, where applicable;
  • fault descriptions;
  • correspondence;
  • shipping and returns information;
  • photos and videos voluntarily provided by you;
  • results of technical inspections and related documentation.

Depending on the individual case, processing is based on Art. 6(1)(b), Art. 6(1)(c) or Art. 6(1)(f) GDPR.

Our legitimate interests include, in particular, technical inspection, quality assurance, traceable documentation and the establishment, exercise or defence of legal claims.

Please do not provide special categories of personal data or other sensitive information unless such information is necessary to process your service request.

13. AI-Assisted Customer Service with HeiChat

We use the AI-assisted customer service solution HeiChat in our online shop.

Provider and processor:
GenCybers INC
1942 Broadway St. STE 314C
Boulder, Colorado
USA

HeiChat may also appear under the name Heicarbook in older or customer-related documentation.

The chat is identified in our shop as “HBT AI Assistant”. This is intended to make it clear to users that communication is automated and/or supported by artificial intelligence.

Data Processed

Depending on your enquiry, the following data may in particular be processed:

  • chat messages and conversation history;
  • timestamps and communication metadata;
  • name, email address or telephone number, where provided by you or required for handling the enquiry;
  • Shopify customer identifier;
  • order number and order status;
  • shipping, delivery and return information;
  • product information;
  • browser and device information;
  • IP address and approximate location information derived from it;
  • session and technical identifiers;
  • page and usage context;
  • technical log and security information.

HeiChat may access product, shop, knowledge base and policy information provided by us in order to answer customer enquiries.

AI Processing via OpenRouter and Anthropic

HeiChat uses OpenRouter to technically route AI requests to the selected model provider.

In our shop, Claude Sonnet 4.5 by Anthropic is currently selected as the AI model.

In order to generate a response, the current chat message, required previous conversation context, relevant instructions and content from our knowledge base as well as necessary product, order, shipping, returns or customer information may be transmitted to OpenRouter and the selected model provider.

According to the current information provided by HeiChat, customer chats, order information, customer data, shop content and knowledge base material are not used to train or fine-tune general-purpose AI models.

Legal Basis

For product-, order- or contract-related enquiries, processing is based on Art. 6(1)(b) GDPR.

For general customer service enquiries, processing is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in the fast and efficient handling of customer enquiries.

Use of the AI chat is voluntary.

Please do not provide special categories of personal data within the meaning of Art. 9 GDPR or other confidential information that is not necessary for handling your enquiry.

HeiChat Pixel

HeiChat uses a web pixel connected to Shopify. It serves in particular to provide the technical chat functionality and session continuity and, depending on the applicable privacy and consent settings, may also support functions such as performance measurement and order attribution.

HeiChat states that the storefront pixel operates within the Shopify Customer Privacy Framework. Processing depends on the Shopify configuration, the user’s location or region and the respective consent choice made by the visitor.

HeiChat also states that pixel data is not used for the sale of personal data, third-party retargeting or cross-site advertising profiles.

Retention Periods at HeiChat

According to the current information provided by HeiChat, the following standard retention periods apply in particular:

  • chat histories: generally for the duration of our active HeiChat subscription;
  • AI prompts and responses stored by HeiChat: generally for the duration of the active subscription;
  • customer identifiers and any stored order information: generally for the duration of the active subscription;
  • analytics and usage data: generally for the duration of the active subscription;
  • system, error and audit logs: generally 7 days;
  • backups: daily snapshots, generally retained for 30 days.

Following uninstall, HeiChat states that basic merchant configuration and customer chat histories may be retained for up to 12 months. Other data is deleted or anonymised in accordance with the Shopify privacy interfaces and applicable requirements unless a legal obligation requires continued retention.

International Data Transfers

HeiChat operates significant parts of its infrastructure on Amazon Web Services in the United States. OpenRouter and selected AI model providers may also process data in the United States or other third countries.

For transfers from the European Economic Area, HeiChat states that it uses, in particular, the European Commission’s Standard Contractual Clauses and, where the relevant recipient is certified, the EU-U.S. Data Privacy Framework, as well as supplementary safeguards.

We do not use HeiChat to make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you.

Further information:

14. Newsletter and Email Marketing with Klaviyo

For our newsletter “HAUCK Updates” and the management of our email marketing communications, we use:

Klaviyo, Inc.
125 Summer Street, Floor 6
Boston, MA 02110
USA

Klaviyo processes personal data, in particular as a processor, in connection with the services provided to us.

Newsletter Subscription

When you subscribe to our newsletter, we process in particular:

  • email address;
  • name, where applicable;
  • date/time and status of subscription;
  • consent information;
  • unsubscribe and objection information;
  • technical evidence of consent, where applicable.

Marketing emails are generally sent on the basis of your consent pursuant to Art. 6(1)(a) GDPR in conjunction with Section 174 TKG 2021, unless another legally permissible basis applies in an individual case.

You may withdraw your consent at any time with effect for the future, in particular by using the unsubscribe link contained in each marketing email or by sending an email to info@barista.tools.

Synchronisation between Shopify and Klaviyo

Our Shopify integration synchronises data with Klaviyo.

This may include in particular:

  • name;
  • email address;
  • telephone number, where available;
  • marketing and consent status;
  • language;
  • customer profile information;
  • order history;
  • products purchased or viewed;
  • order values;
  • customer and profile identifiers.

The synchronisation serves in particular to manage communication preferences, recipient lists, customer profiles and our email communications.

Marketing emails are sent only where an appropriate legal basis exists.

Onsite and Email-to-Website Tracking

Klaviyo is technically connected to our Shopify shop.

Depending on the respective consent decision, the following events may in particular be recorded:

  • active use of the shop;
  • product views;
  • search activity;
  • shopping cart activity;
  • other interactions with our online shop.

Email-to-website tracking is enabled. Klaviyo may append an encrypted parameter (_kx) to links contained in emails. After a click, this parameter may be used to recognise an email recipient on our website.

Klaviyo takes the Shopify Customer Privacy settings into account for Shopify shops. According to Klaviyo, visitors in the EEA, the United Kingdom and Switzerland are not identified through onsite tracking where the required consent has not been given.

Where consent is required, processing is based on Art. 6(1)(a) GDPR in conjunction with Section 165(3) TKG 2021.

No Individual Email Open Tracking

Individual email open tracking is disabled in our Klaviyo account.

We therefore currently do not use Klaviyo to evaluate on an individual basis whether a particular recipient has opened an email sent by us.

SMS marketing through Klaviyo is currently not used.

We also currently do not use our own Klaviyo pop-ups or Klaviyo signup forms.

International Data Transfers

Klaviyo processes personal data, among other locations, in the United States.

According to Klaviyo, it is certified under the EU-U.S. Data Privacy Framework. In addition, Klaviyo’s Data Processing Agreement provides for the European Commission’s Standard Contractual Clauses and further safeguards for international data transfers.

Further information:

15. Google Analytics 4

We use Google Analytics 4 (GA4) through the Shopify integration.

For users in the European Economic Area, the relevant Google services are provided in particular by Google Ireland Limited, Ireland.

Google Analytics is used to analyse and improve our online shop.

The following data may in particular be processed:

  • browser and device information;
  • pseudonymous online and client identifiers;
  • pages viewed;
  • source of a visit;
  • technical usage information;
  • product views;
  • shopping cart events;
  • checkout and purchase events;
  • IP-related information.

Where Google Analytics uses cookies or other non-essential identifiers, their use is based on your consent provided through our privacy settings pursuant to Art. 6(1)(a) GDPR.

If consent is refused, no analytics cookies are set or read. Depending on the Google Consent Mode configuration used, restricted cookieless measurement signals may nevertheless be transmitted to Google.

Any consent given may be withdrawn at any time with effect for the future through our cookie or privacy settings.

Google Privacy Policy

16. Google & YouTube / Google Merchant Center

We use the Shopify sales channel Google & YouTube.

Through this integration, our shop is currently connected in particular to the following Google services:

  • Google Merchant Center;
  • Google Analytics 4;
  • Google Business Profile.

Product information such as product name, description, price, availability and product images may be synchronised with Google Merchant Center in order to display our products in the relevant Google services.

Google Ads is currently not connected to our Shopify shop.

If this configuration changes, we will update this Privacy Policy accordingly.

Google Privacy Policy

17. Facebook and Instagram by Meta

We use the Shopify integration Facebook & Instagram by Meta and the associated Meta Business Tools.

For users in the European Economic Area, the responsible Meta company is in particular Meta Platforms Ireland Limited, Ireland.

In our shop, the integration includes both web-based and server-side event processing.

Depending on your consent and the respective configuration, the following data may in particular be processed or transmitted to Meta:

  • browser and device information;
  • IP-related information;
  • cookie and online identifiers;
  • page and product views;
  • shopping cart events;
  • checkout and purchase events;
  • transaction information;
  • customer identifiers used for matching, where applicable.

The processing may in particular serve to measure reach and campaign effectiveness, attribute shop events to marketing activities, improve advertising delivery and, where authorised by you, personalise advertising.

Where consent is required, processing is based on Art. 6(1)(a) GDPR.

Meta may also process certain information in connection with its own services under its own responsibility as data controller.

Meta Privacy Policy

18. Product and Shop Reviews with Judge.me

We use Judge.me for product and shop reviews.

Judge.me Ltd
c/o Buckworths
2nd Floor, 1–3 Worship Street
London, England EC2A 2AB
United Kingdom

Depending on how the service is used, the following data may in particular be processed:

  • name or display name;
  • email address;
  • order and product information;
  • star rating;
  • review text;
  • photos or videos voluntarily uploaded, where applicable;
  • verified purchase status;
  • technical information relating to the submission and management of a review.

Where Judge.me processes personal data on our behalf, such processing is carried out under a data processing arrangement.

Review Requests

Automatic review requests are currently generally sent 14 days after an order has been fulfilled.

Our current Judge.me configuration is set so that:

  • review requests are not sent to customers who have not consented to Shopify marketing emails or who have unsubscribed from them;
  • a maximum of one review email is sent per order;
  • a maximum of three products are included in that email for review;
  • separate review emails are not sent for each individual product;
  • general automatic reminder emails are disabled;
  • media reminder emails are disabled;
  • coupon emails and coupon reminder emails are disabled;
  • review requests to repeat customers stop once the order threshold configured by us has been reached.

As review requests in our current configuration are sent only to recipients who have the corresponding permission for marketing emails, such emails are generally sent on the basis of the relevant consent pursuant to Art. 6(1)(a) GDPR in conjunction with Section 174 TKG 2021.

Submitting and Publishing a Review

If you voluntarily submit a review, the information you provide is processed in particular for verification, moderation, administration, display and publication of the review.

Your email address is used in particular for attribution and verification and is not necessarily displayed publicly.

Automated sentiment analysis for reviews is enabled in Judge.me. Review content may therefore be automatically analysed with regard to its general sentiment.

This does not result in a decision based solely on automated processing that produces legal effects concerning you or similarly significantly affects you.

Judge.me Privacy Policy

19. External Links and Social Networks

Our online shop may contain links to external websites, social networks and other platforms.

Where a simple external link is used, data is generally transmitted to the external provider only once you click the link.

From that point onwards, the privacy rules of the respective external provider also apply.

Where external content is embedded directly in our shop and this causes non-essential data transfers, such content is activated, where legally required, in accordance with your consent choice.

20. Recipients of Personal Data

Personal data is disclosed to recipients only where this is necessary for the purposes described, where a legal obligation exists or where another legal basis applies.

Recipients or categories of recipients may include in particular:

  • Shopify and companies within the Shopify group;
  • inventory management and accounting providers;
  • payment service providers, banks and payment processors;
  • shipping, parcel, freight forwarding and logistics providers;
  • customs, tax and other authorities;
  • IT, hosting, security and maintenance providers;
  • newsletter and communication providers;
  • analytics and marketing providers;
  • review service providers;
  • AI and customer service providers;
  • tax advisers, legal advisers and other professional advisers;
  • courts and public authorities.

Where service providers process personal data solely on our behalf, they are engaged in accordance with Art. 28 GDPR.

21. Transfers to Third Countries

Some of the service providers used by us or their subprocessors are located outside the European Union or European Economic Area or process personal data there.

Personal data is transferred only in compliance with the requirements of Art. 44 et seq. GDPR.

Depending on the recipient, the following transfer mechanisms may in particular apply:

  • adequacy decisions of the European Commission;
  • the EU-U.S. Data Privacy Framework for appropriately certified U.S. recipients;
  • Standard Contractual Clauses of the European Commission;
  • Binding Corporate Rules;
  • other safeguards or derogations provided for by law.

Where Standard Contractual Clauses are used, supplementary technical and organisational safeguards may also be applied.

22. Sources of Personal Data

We obtain personal data primarily directly from you, for example when you place an order, use a customer account, contact us, subscribe to our newsletter or submit a review.

In individual cases, we also receive personal data from the platforms and service providers used for the relevant contract or service processing, in particular Shopify, payment service providers, shipping providers or other systems described in this Privacy Policy.

23. Requirement to Provide Personal Data

For the mere use of our online shop, you are generally not required to provide directly identifying information such as your name or postal address.

However, for an order, delivery, payment or certain service activities, the provision of the personal data required for the respective purpose is necessary. Without this information, we may be unable to perform the relevant contract or provide the requested service.

Information expressly marked as voluntary or not required for the respective purpose does not have to be provided.

24. Retention Periods

We generally store personal data only for as long as necessary for the respective processing purpose or for as long as statutory retention obligations apply.

Order, invoice, accounting and tax-related records are generally retained for seven years in accordance with Austrian statutory retention obligations.

Longer retention periods may apply where required by specific tax, corporate, customs or procedural provisions.

Data may also be retained where necessary for ongoing proceedings or for the establishment, exercise or defence of legal claims.

General correspondence that is not subject to a statutory retention obligation is deleted once the processing purpose no longer applies and there are no overriding reasons for continued storage.

Newsletter data is generally processed until consent is withdrawn or the recipient unsubscribes. Necessary records of consents, withdrawals and objections may be retained beyond that point where required to comply with our accountability obligations or for legal defence.

For individual external services, the retention periods described in the respective sections of this Privacy Policy also apply.

25. Data Security

Taking into account the state of the art, implementation costs and the nature, scope, context and purposes of processing, we implement appropriate technical and organisational measures in accordance with Art. 32 GDPR.

Depending on the relevant system, these may include measures relating to:

  • access restrictions;
  • authentication;
  • secure data transmission;
  • system and application security;
  • data backup;
  • restoration;
  • organisational access controls.

Absolute security of electronic systems and data transmissions cannot be technically guaranteed.

26. Automated Decision-Making

As a general rule, we do not make decisions based solely on automated processing within the meaning of Art. 22 GDPR that produce legal effects concerning you or similarly significantly affect you.

Payment, security or fraud prevention providers may carry out automated risk, security or fraud assessments under their own responsibility.

Such processing is also subject to the privacy information of the respective service provider.

27. Your Data Protection Rights

Subject to the applicable legal requirements, you have the following rights in particular:

Right of Access

Under Art. 15 GDPR, you may request information as to whether and which personal data concerning you is processed by us.

Right to Rectification

Under Art. 16 GDPR, you may request the correction of inaccurate personal data or the completion of incomplete personal data.

Right to Erasure

Under the conditions of Art. 17 GDPR, you may request the deletion of your personal data.

Statutory retention obligations or other legally permissible reasons may prevent immediate deletion.

Right to Restriction of Processing

Under the conditions of Art. 18 GDPR, you may request restriction of processing.

Right to Data Portability

Where the requirements of Art. 20 GDPR are met, you may receive the personal data you have provided in a structured, commonly used and machine-readable format or request its transmission to another controller.

Right to Object

Where processing is based on Art. 6(1)(e) or Art. 6(1)(f) GDPR, you may object to such processing pursuant to Art. 21 GDPR on grounds relating to your particular situation.

Where personal data is processed for direct marketing purposes, you may object to such processing at any time without giving reasons.

Withdrawal of Consent

You may withdraw any consent you have given at any time with effect for the future.

The lawfulness of processing carried out on the basis of your consent before its withdrawal remains unaffected.

To exercise your data protection rights, please contact us at:

info@barista.tools

Where we have reasonable doubts concerning the identity of the person making a request, we may request additional information where necessary to verify that person’s identity appropriately.

28. Right to Lodge a Complaint

If you believe that the processing of your personal data infringes applicable data protection law, you have the right to lodge a complaint with a competent data protection supervisory authority.

In Austria, you may in particular contact:

Austrian Data Protection Authority
Barichgasse 40–42
1030 Vienna
Austria

Phone: +43 1 52 152-0
Email: dsb@dsb.gv.at

Austrian Data Protection Authority

Your right to lodge a complaint with another supervisory authority competent under Art. 77 GDPR remains unaffected.

29. Data Protection Terms Explained

The following explanations are intended to make this Privacy Policy easier to understand. The legal definitions and provisions of the GDPR remain authoritative.

Personal Data

Personal data is information relating to an identified or identifiable natural person. Examples include a person’s name, address, email address, telephone number, customer number or, depending on the context, technical identifiers such as an IP address.

Controller

The controller determines the purposes for which and the means by which personal data is processed.

For processing activities relating to barista.tools whose purposes and means are determined by us, the controller stated in Section 1 is generally responsible. Individual external providers may act as independent controllers for certain processing activities of their own.

Processor

A processor is a service provider that processes personal data on behalf of and in accordance with the instructions of a controller.

Consent

Consent is a freely given, informed and unambiguous indication of agreement to a specific processing activity involving personal data. Consent may be withdrawn at any time with effect for the future.

Processing

Processing generally means any operation performed on personal data, for example collecting, recording, storing, organising, retrieving, using, transmitting, altering, restricting or deleting data.

Third Country

For data protection purposes, a third country is generally a country outside the European Union and the European Economic Area. Special data protection requirements apply to transfers of personal data to such countries.

Profiling

Profiling means automated processing of personal data in which information is used to evaluate, analyse or predict certain personal aspects relating to an individual.

Not every statistical evaluation or technical analysis automatically constitutes profiling within the meaning of data protection law.

30. Changes to this Privacy Policy

We review this Privacy Policy regularly and update it in particular where there are changes to:

  • legal requirements;
  • our online shop;
  • our Shopify configuration;
  • apps and service providers used;
  • tracking or marketing functions;
  • payment or shipping processes;
  • data processing activities or retention periods.

The current version will be published in our online shop.

Last updated: 18 August 2026