Test Privacy Policies
At Kaicao (“we”, “us”, “our”) we want you to feel comfortable in our online shop and not have to worry about the security of your data. That is why data protection is an important part of our philosophy.
Responsible for the collection and processing of your personal data is
Kaicao Fabrica de Chocolate, Sociedad Limitada (“Kaicao”)
Plaza Castilla, 3 - ESC DR 6 C 1,
Madrid, 28046, Spain
The competent data protection authority in Spain is:
The Spanish Agency for Data Protection (AEPD)
C/ Jorge Juan, 6.
Madrid, 28001, Spain
What is personal data?
According to the Spanish Data Protection and Digital Rights Act 3/2018 (“DPA”) and the EU`s General Data Protection Regulation (GDPR), personal data are "any information relating to an identified or identifiable natural person. This is, for example, name or address data, telephone number, mobile number, bank details or insurance number. However, personal data also includes online identifiers such as your device identifier and IP address.
General information on data processing
All personal data that we obtain from you via the website will be processed for the purposes described in more detail below. This is done within the framework of the DPA and GDPR or with your consent. And of course, only when data processing is permitted and if:
We process and store your personal data only for the period of time required to achieve the respective processing purpose or for as long as a legal retention period (in particular commercial and tax law) exists. Once the purpose has been achieved or the retention period has expired, the corresponding data is routinely deleted.
What data does Kaicao process?
Kaicao offers you a wide range of products and services and in the process, various data are always collected. Most of the data we process is provided by you when you use our services or contact us. As soon as you register, you provide us with your name and e-mail address or your postal address.
Further, we also automatically collect technical device and access data that occur during your interaction with our website. And we collect further data through website analyses in order, for example, to optimize our offers for you personally (e.g., to optimize our offers for you).
Even if you do not log in or register on our website, but simply browse our website, data is collected and stored and processed by us. Specifically, this requires the IP address of your computer, Date and time of access, Name and URL of the accessed file, Browser used, Number of bytes transferred, Status of the page retrieval, Session ID, Referrer URL.
You can easily contact us via our contact form, e-mail, or social media. In this case, we store and process the following data from you: Name, e-mail address, telephone number as well as other personal data that you provide when contacting us.
This data is collected and processed exclusively for the purpose of contacting you and processing your request and then deleted, provided there is no legal obligation to retain it. The legal bases for processing are contract and our legitimate interest.
To use our services, you can register and log in to Kaicao. Here, too, we store data in order to create a User account for you: Name, E-mail address, chosen password.
We store this data as long as you are registered with us. If you delete your account, we will delete your data unless there is a legal retention period on our part. In this case, we must store your data for longer.
The data that you provide to us via your account will be stored until you delete the data from your account. In addition, we process data that is required for the services we offer or your membership. The legal bases for processing are contract and our legitimate interest.
You can order our offers via the online shop. In doing so, we process your personal data that is required for processing your order and for customer care, as well as the data that you also provide to us voluntarily. When you order via the online shop, for example, we have to ask for your name, e-mail address and shipping address. We will process this data for order processing: Name, Address(es), E-mail address, Order data, Payment data, Telephone number, IP address
The processing of this personal data is necessary for the ordering process. We process this data insofar as this is necessary for the processing of the contract, and for the assertion of possible claims on our part. The legal bases for processing are contract and our legitimate interest.
To ensure that you receive your ordered products, we pass on the necessary data to the selected service provider for order and order processing. In this case, we transmit your e-mail address and in some cases also your telephone number to the logistics service provider. In this way, they can inform you that your parcel is being sent. With the parcel notification, you can influence the parcel delivery if necessary and change the delivery day or delivery location.
We use the store system Shopify of the service provider Shopify International Limited, for the purpose of hosting and displaying the shop on the basis of processing on our behalf. All data collected on our website is processed on Shopify's servers. As part of Shopify's services, data may also be transferred to Shopify Inc, 150 Elgin St, Ottawa, ON K2P 1L4, Canada, Shopify Data Processing (USA) Inc, Shopify Payments (USA) Inc or Shopify (USA) Inc as part of further processing on our behalf. In the event that data is transferred to Shopify Inc. in Canada, the appropriate level of data protection is guaranteed. Further processing on servers other than the aforementioned of Shopify will only take place within the framework communicated below. The legal basis for the data processing is our legitimate interest in providing an appealing website and shop.
Integration of third-party services and content
We use content or service offers of third-party providers on the basis of our legitimate interests in order to integrate their content and services (hereinafter uniformly referred to as "content").
This always requires that the third-party providers of this content are aware of the IP address of the user, as without the IP address they would not be able to send the content to their browser. The IP address is therefore necessary for the display of this content.
Third-party providers may also use so-called pixel tags (invisible graphics, also known as "web beacons") for statistical or marketing purposes. The "pixel tags" can be used to evaluate information such as visitor traffic on the pages of our website. The pseudonymous information may also be stored in cookies on the user's device and may contain, among other things, technical information about the browser and operating system, referring websites, time of visit and other information about the use of our website, as well as being linked to such information from other sources.
The following provides an overview of third-party providers and their content, together with links to their privacy policies, which contain further information on the processing of data and so-called opt-out measures, if any:
The legal basis for the data processing is your consent and our legitimate interest.
Analytics and Advertising
We would like to show you interesting advertising outside of our website and use various third-party tools and cookies for this purpose. These collect and process information about your activities on our website - for example, which products you are interested in or which Kaicao pages you visit. By knowing what you are looking for and how you use our website, we can adapt our advertising to your needs. And thus increase the likelihood that you will also be shown suitable and interesting advertising outside our website.
We also analyze this data to evaluate the relevance of the advertisements and to optimize the advertisements for you. Through the tools, your browser regularly establishes a connection to the server of the tool provider when you visit our website. For some tools, we have no direct influence on what data is processed by the providers. The following personal data may be processed by third-party providers:
Authorities and other third parties
In the event of certain legal incidents, we are obliged to pass on our customers' data to law enforcement authorities or other third parties. This may be the case, for example, for official and court decisions or for legal and criminal prosecution.
How is my data protected?
We want you to feel and be safe on our website. Therefore, we take various measures to meet both the legal requirements and our own very high standards of data protection and data security.
Kaicao takes the protection of your personal data seriously. All data is handled and processed in accordance with the DPA and GDPR, which ensures the highest standards of data protection.
Our data processing is subject to the principle that we only process the personal data that is necessary for the sensible and economic use of our offer. In doing so, we take great care to ensure that your privacy and the confidentiality of all personal data are always guaranteed.
All transmitted data is protected by TLS encryption. Transport Layer Security (TLS) is a protocol used to ensure secure data transmission on the Internet. The public-private key procedure is used here. This means that data encrypted with a publicly accessible key can only be decrypted again with a separate private key.
We stand for high security when shopping online. Kaicao uses technical and organizational security measures (TOMs) throughout the company to protect the data we manage from you against accidental or intentional manipulation, loss, destruction or against access by unauthorized persons. For example, we regularly train all employees on current IT security topics.
Duration of data storage
We store personal data on our secure server and only for as long as it is necessary for the purposes for which it is processed or for as long as any consent you have given us has been revoked by you. Insofar as statutory retention obligations must be observed, the storage period for certain data may be up to 6 years, irrespective of the processing purposes.
Insofar as you have also given us your separate consent to process your data for marketing and advertising purposes, we are entitled to contact you for these purposes via the communication channels you have given your consent to.
You may give us your consent in a number of ways including by selecting a box on a form where we seek your permission to send you marketing information, or sometimes your consent is implied from your interactions or contractual relationship with us. Where your consent is implied, it is on the basis that you would have a reasonable expectation of receiving a marketing communication based on your interactions or contractual relationship with us.
Direct Marketing generally takes the form of e-mail but may also include other less traditional or emerging channels. These forms of contact will be managed by us, or by our contracted service providers. Every directly addressed marketing sent or made by us or on our behalf will include a means by which you may unsubscribe or opt out.
Your data subject rights
These rights are standardized in the DPA and GDPR. These include:
Please contact us at any time with questions and suggestions regarding data protection and to enforce your rights as a data subject.
We encourage you to contact us if you have any information requests, requests for information or objections about data processing or concerns. However, you also have the right to file a complaint with your local supervisory authority. However, we would appreciate it if you would contact us with your concern before turning to a supervisory authority.
Online presence in social media
Based on our legitimate interests, we maintain online presences within social networks and platforms in order to communicate with the active, interested parties and users there and to inform them about our services there. When calling up the respective networks and platforms, the terms and conditions and data processing policies of their respective operators apply.
Updating your information
If you believe that the information, we hold about you is inaccurate or that we are no longer entitled to use it and want to request its rectification, deletion, or object to its processing, please do so by contacting us. For your protection and the protection of all of our users, we may ask you to provide proof of identity before we can answer the above requests.
Keep in mind, we may reject requests for certain reasons, including if the request is unlawful or if it may infringe on trade secrets or intellectual property or the privacy of another user. Also, we may not be able to accommodate certain requests to object to the processing of Personal Data, notably where such requests would not allow us to provide our service to you anymore.
Withdraw your consent
You may withdraw your consent and request us to stop using and/or disclosing your Personal Data for any or all of the Purposes by submitting your request to us. Should you withdraw your consent to the collection, use or disclosure of your Personal Data, it may impact our ability to proceed with your transactions, agreements, or interactions with us. Prior to you exercising your choice to withdraw your consent, we will inform you of the consequences of the withdrawal of your consent. Please note that your withdrawal of consent will not prevent us from exercising our legal rights (including any remedies) or undertaking any steps as we may be entitled to at law.
Personal Data and children
Our services are aimed at people aged 18 and over. We will not knowingly collect, use or disclose Personal Data from minors under the age of 18 without first obtaining consent from a legal guardian through direct offline contact.
Do you have any questions?
Please contact us if you have any comments or questions about this policy and/or our use of your Personal Data.