GDPR & TDDDG Compliance

Privacy Policy

Information on the nature, scope, and purpose of personal data processing under Articles 13 and 14 of the EU General Data Protection Regulation (GDPR) and the German TDDDG.

1. Data Controller

The entity responsible for data processing on this website is:

[Insert Full Name / Company Name]
[Street Address & House Number]
[Postal Code and City, Germany]
Email: datenschutz@starbucksspeisekarte.de

2. Web Hosting & Server Log Files

Our website is hosted with a professional web hosting provider (Hostinger International Ltd.). When accessing our web pages, the web server automatically collects and stores technical server log information transmitted by your browser:

  • IP address of the accessing client device
  • Date, time, and timezone of the server request
  • Name and URL of the retrieved file/page
  • Data volume transferred and HTTP status code
  • Referrer URL (previously visited website)
  • Browser type, version, and operating system

Legal Basis: Art. 6(1)(f) GDPR (legitimate interest in ensuring technical stability, cybersecurity, and uninterrupted delivery of website content). Server logs are automatically purged in compliance with statutory retention limits.

3. Cookies & Local Storage (Section 25 TDDDG)

This website utilizes strictly necessary local storage technologies (Cookies & LocalStorage) to support basic functionality such as bilingual language switching (German / English) and cookie consent preferences.

  • Strictly Necessary Storage: Stores language selection and session preferences. Legal basis: Section 25(2)(2) TDDDG in conjunction with Art. 6(1)(f) GDPR.
  • Marketing & Ad Tracking: No invasive third-party ad trackers are currently deployed. If optional analytics or advertising tools are introduced in the future, they will strictly require prior explicit consent (Art. 6(1)(a) GDPR).

4. Contact Inquiries via Email & Form

When you communicate with us via email or our contact form, your transmitted personal data (name, email address, message body) will be stored to process your inquiry and any follow-up questions.

Legal Basis: Art. 6(1)(b) GDPR (pre-contractual measures or contractual fulfillment) or Art. 6(1)(f) GDPR (legitimate interest in promptly responding to editorial correspondence).

5. Your Rights as a Data Subject

Under the GDPR, you are entitled to the following statutory rights regarding your personal data:

  • Right of Access (Art. 15 GDPR): Request confirmation and access to personal data processed.
  • Right to Rectification (Art. 16 GDPR): Correct inaccurate or incomplete data.
  • Right to Erasure (Art. 17 GDPR): Request deletion of stored personal data (“Right to be Forgotten”).
  • Right to Restriction of Processing (Art. 18 GDPR).
  • Right to Data Portability (Art. 20 GDPR).
  • Right to Object (Art. 21 GDPR): Object at any time on grounds relating to your particular situation.

Pursuant to Art. 77 GDPR, you also have the right to lodge a complaint with a competent data protection supervisory authority, in particular in the EU Member State of your habitual residence, place of work, or place of the alleged infringement.

6. SSL/TLS Encryption

For security reasons and to protect the transmission of confidential communications, this website uses comprehensive SSL/TLS encryption. An encrypted connection is identifiable by “https://” in your browser’s address bar and the closed padlock symbol.