Last updated: January 2024
Kaffee Röstung Zürich is committed to complying with the General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection (FADP). This page provides information about how we ensure compliance and how you can exercise your rights.
If you are a resident of the European Economic Area (EEA) or Switzerland, you have the following rights regarding your personal data:
You have the right to request a copy of the personal data we hold about you. We will provide this information within 30 days of receiving a valid request.
You have the right to request that we correct any inaccurate or incomplete personal data we hold about you.
You have the right to request that we delete your personal data in certain circumstances, including when the data is no longer necessary for the purposes for which it was collected.
You have the right to request that we limit the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data.
You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit that data to another controller.
You have the right to object to processing of your personal data based on our legitimate interests. We will stop processing unless we can demonstrate compelling legitimate grounds that override your interests.
You have the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects. We do not currently engage in such automated decision-making.
To exercise any of your rights, please contact us at:
Email: [email protected]
Address: Röstgasse 47, 8004 Zurich, Switzerland
We will respond to your request within 30 days. We may request verification of your identity before processing your request.
While we are not legally required to appoint a Data Protection Officer due to the nature and scale of our processing activities, we take data protection seriously. All data protection inquiries should be directed to our management team at the contact details above.
We process personal data only when we have a lawful basis to do so. The lawful bases we rely on include:
When we transfer personal data outside Switzerland or the EEA, we ensure appropriate safeguards are in place. These may include:
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. If the breach is likely to result in a high risk to your rights, we will also notify you directly.
You have the right to lodge a complaint with a supervisory authority. In Switzerland, this is the Federal Data Protection and Information Commissioner (FDPIC). For EEA residents, you may contact your local data protection authority.
We may update this GDPR information page periodically. The date of the last update is shown at the top of this page.