Privacy Policy

Last updated: 20.07.2025

This Privacy Policy informs you about the nature, scope, and purpose of the processing of personal data on our website [www.caffeiny.com] ("Website"). The processing of your data is carried out in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”), the Austrian Data Protection Act (DSG), and other relevant legal provisions.

1. Controller

Caffeiny GesbR
Talgasse 121150 Vienna
Austria
Email: office@caffeiny.com

2. Data Collection and Processing

We process your personal data only if this is necessary for the provision of a functional website and our content and services. The following categories of data may be processed:

2.1 Website Access (Server Log Files)

When visiting our Website, the following data is automatically transmitted and stored by our hosting provider (Webflow):

- IP address
- Date and time of access
- Accessed pages/files
- Referrer URL
- Browser type and version
- Operating system

The processing is based on Art. 6(1)(f) GDPR (legitimate interest in the secure operation of the website).

2.2 Contacting Us

If you contact us via email or contact form, the data you provide (e.g., name, email address, message) will be stored to process your inquiry.Legal basis: Art. 6(1)(b) GDPR (performance of pre-contractual measures).

2.3 Orders and Payments

When placing an order, we process the following data:

- Name
- Address
- Email
- Ordered products
- Payment data (processed via Stripe)
- Payment transactions are processed via Stripe Payments Europe Ltd.

Stripe may process data in the USA. Data processing complies with GDPR through appropriate safeguards (e.g., SCCs).Legal basis: Art. 6(1)(b) GDPR (contract performance).

3. Cookies and Tracking Technologies

We may use cookies and similar technologies (e.g., local storage) to ensure the functionality and optimization of our Website.

You will be informed via a cookie banner and may consent to non-essential cookies in accordance with Art. 6(1)(a) GDPR.

Types of cookies used:

- Essential (e.g., for cart functionality)
- Analytical (e.g., Google Analytics – if used)

You may withdraw your consent at any time via the cookie settings.

4. Third Party Services

4.1 Webflow

Hosting and CMS provided by Webflow, Inc., 398 11th Street, San Francisco, CA 94103, USA.Data is stored on servers within the EU where possible. Webflow is contractually obligated to ensure GDPR compliance.

4.2 Stripe

As noted above, payment data is handled by Stripe. Data may be transmitted to the USA.For more information, see: https://stripe.com/privacy

5. Data Retention

We store personal data only as long as necessary to fulfill contractual or legal obligations or to pursue legitimate interests. Data required for tax or commercial law purposes will be retained for the statutory periods (usually 7 years).

6. Your Rights under the GDPR

You have the following rights with regard to your personal data:

Right of access
(Art. 15 GDPR)
Right to rectification
(Art. 16 GDPR)
Right to erasure
(Art. 17 GDPR)
Right to restriction of processing
(Art. 18 GDPR)
Right to data portability (Art. 20 GDPR)
Right to object
(Art. 21 GDPR)
Right to lodge a complaint with the Austrian Data Protection Authority:
Österreichische Datenschutzbehörde, Barichgasse 40-42, 1030 Vienna

If you have given consent, you may withdraw it at any time with future effect.

7. Data Security

We take appropriate technical and organizational security measures to protect your personal data against loss, manipulation, or unauthorized access.

8. International Transfers

Where we process data outside the EU/EEA (e.g., through Stripe or Webflow), we ensure GDPR compliance through Standard Contractual Clauses (SCCs) or other appropriate safeguards.

9. Changes to This Policy

We reserve the right to update this Privacy Policy at any time in compliance with applicable legal requirements. The current version will always be available on our Website.