Privacy Policy for Co-Barista
Effective Date: 23 August 2026
Introduction
Your privacy is important to us. This Privacy Policy explains which personal data Co-Barista processes, why we process it, how we protect it, and which rights you have under the General Data Protection Regulation (GDPR) and other applicable data protection laws.
1. Personal Data We Process
You can use parts of Co-Barista without creating an account. If you create an account, we process:
- Account and authentication data: your email address, a user identifier, and authentication-related metadata such as account creation date and last sign-in time.
- Security and technical data: information needed to secure and operate the service, which may include IP address, device and app information, authentication events, and error or crash information.
- Usage data: limited information about how the app and its features are used, where this is necessary to maintain and improve the service.
We use your email address to create and authenticate your account, provide account-related functions, communicate essential service information, prevent misuse, and help you recover access to your account. We do not use your email address for advertising without a separate legal basis and, where required, your consent.
2. Purposes and Legal Bases
We process personal data only where necessary and on an applicable legal basis:
- Performance of a contract (Article 6(1)(b) GDPR): to create and manage your account, authenticate you, and provide the app’s requested functions.
- Legitimate interests (Article 6(1)(f) GDPR): to keep the app secure and reliable, prevent fraud and misuse, diagnose errors, and improve the service. We balance these interests against your rights and freedoms.
- Legal obligations (Article 6(1)(c) GDPR): where processing or retention is required by applicable law.
- Consent (Article 6(1)(a) GDPR): where we ask for consent for an optional activity. You may withdraw your consent at any time with effect for the future.
3. Data Minimisation and Retention
We follow the principles of purpose limitation, data minimisation, storage limitation, and privacy by design. We collect only the data reasonably necessary for the purposes described above, limit access to authorised persons and service providers, and do not use personal data for incompatible purposes.
Account data is generally retained while your account is active. If you delete your account or ask us to delete it, we delete or anonymise the associated personal data unless limited retention is necessary to comply with law, establish or defend legal claims, prevent fraud, or complete deletion from backups. Technical and security records are retained only for as long as reasonably necessary for those purposes. Backup copies are removed according to our regular backup cycle.
4. Service Providers, Storage, and International Transfers
We use the following service providers to operate Co-Barista:
- Microsoft Azure: for cloud infrastructure, hosting, storage, and related technical services. We select EU regions for customer data where the relevant Azure service and configuration allow it. Some operational or support data may nevertheless be processed outside the EU/EEA.
- Google Firebase: for account authentication and related backend services. Firebase Authentication processes data in the United States. Depending on the Firebase service used, other data may be processed on Google’s global infrastructure.
Microsoft and Google process data on our behalf under contractual data protection obligations. Where personal data is transferred outside the EU/EEA, we rely on a lawful transfer mechanism as applicable, such as an adequacy decision (including the EU–US Data Privacy Framework for participating recipients) or the European Commission’s Standard Contractual Clauses, together with supplementary safeguards where required.
5. Sharing of Data
We do not sell or rent personal data and do not share it with third parties for their own advertising purposes. We disclose personal data only to service providers that need it to perform services for us, when required by law or a valid legal request, to protect rights and security, or in connection with a corporate transaction where permitted by law. Service providers may process the data only according to our instructions and applicable contractual and legal requirements.
6. Your Rights
Subject to the conditions and limitations of applicable law, you have the right to:
- receive information about how we process your personal data;
- request access to your personal data and obtain a copy;
- request correction of inaccurate or completion of incomplete personal data;
- request deletion of your personal data;
- request restriction of processing;
- receive personal data you provided in a structured, commonly used, machine-readable format and, where applicable, have it transmitted to another controller;
- object to processing based on legitimate interests and object at any time to processing for direct marketing;
- withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal;
- not be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects, subject to the exceptions provided by law; and
- lodge a complaint with the data protection authority responsible for your place of residence, place of work, or the place of the alleged infringement.
To access, correct, export, or delete your account-related personal data, or to exercise another right, contact us at info@brew-buddy.coffee. We may ask for information necessary to verify your identity. We will respond without undue delay and generally within one month, unless applicable law permits an extension. These rights are not absolute, and a legal exception may apply to a particular request.
7. Security
We use appropriate technical and organisational measures designed to protect personal data, including:
- encryption in transit and, where supported by the relevant service, at rest;
- access controls based on operational need and least-privilege principles;
- secure cloud configuration, monitoring, updates, and vulnerability management; and
- procedures for responding to security incidents and personal data breaches.
No method of transmission or storage is completely secure, but we review and improve our safeguards as appropriate.
8. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes to Co-Barista, our service providers, or legal requirements. We will publish the updated policy and revise the Effective Date. Where required, we will provide additional notice or request consent before a material change takes effect.
9. Contact Us
For questions about this Privacy Policy or our handling of personal data, or to exercise your data protection rights, contact us at:
Email: info@brew-buddy.coffee
This website itself sets no cookies and includes no tracking.