Privacy Policy

Preamble

With the following privacy policy, we would like to inform you about the types of personal data (hereinafter also briefly referred to as “data”) that we process for what purposes and to what extent. The privacy policy applies to all personal data processing carried out by us, both in the context of providing our services and in particular on our websites, mobile applications and within external online presences such as our social media profiles (hereinafter collectively referred to as the “online offer”).

The terms used are not gender-specific.

Effective date: 6 September 2026

Table of contents

Responsible party

Florian Lenz
c/o flexdienst – #21989
Kurt-Schumacher-Straße 74
67663 Kaiserslautern
Germany

E-mail address: privacy@drinkhub.app

Overview of processing

The following overview summarises the types of data processed and the purposes of that processing and refers to the data subjects involved.

Types of data processed

  • Master data.
  • Employment data.
  • Location data.
  • Contact data.
  • Content data.
  • Usage data.
  • Meta-, communication and procedural data.
  • Log data.

Categories of affected persons

  • Service recipients and clients.
  • Employees.
  • Communication partners.
  • Users.
  • Third parties.
  • Whistleblowers.

Purposes of processing

  • Provision of contractual services and fulfilment of contractual obligations.
  • Communication.
  • Security measures.
  • Direct marketing.
  • Organisational and administrative procedures.
  • Feedback.
  • Registration procedures.
  • Provision of our online offer and user-friendliness.
  • IT infrastructure.
  • Whistleblower protection.
  • Public relations.

Relevant legal bases

Relevant legal bases under the GDPR: In the following, you will find an overview of the legal bases of the GDPR on which we process personal data. Please note that in addition to the GDPR, national data protection provisions in your or our place of residence or establishment may also apply. If, in individual cases, more specific legal bases are relevant, we will inform you in this privacy policy.

  • Consent (Art. 6(1)(a) GDPR) – The data subject has given consent to the processing of their personal data for one or more specific purposes.
  • Contract performance and pre-contractual inquiries (Art. 6(1)(b) GDPR) – Processing is necessary for the performance of a contract to which the data subject is a party, or for the implementation of pre-contractual measures requested by the data subject.
  • Legal obligation (Art. 6(1)(c) GDPR) – Processing is necessary to comply with a legal obligation to which the controller is subject.
  • Legitimate interests (Art. 6(1)(f) GDPR) – Processing is necessary to protect the legitimate interests of the controller or a third party, provided that these interests do not override the rights and freedoms of the data subject requiring protection of personal data.

National data protection regulations in Germany: In addition to the GDPR, national data protection regulations apply in Germany. These include, in particular, the Federal Data Protection Act (BDSG). The BDSG contains special provisions on the right to information, right to deletion, right to objection, processing of special categories of personal data, processing for other purposes, transmission and automated individual decision-making including profiling. State data protection laws may also apply.

Security measures

We take appropriate technical and organisational measures in accordance with legal requirements, taking into account the state of the art, implementation costs, the type, scope, circumstances and purposes of processing, and the varying likelihood and severity of the threat to the rights and freedoms of natural persons, in order to ensure an appropriate level of security.

These measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access to the data as well as the associated access, input, transfer, availability and separation. We have also established procedures that ensure data subject rights, deletion of data and responses to data breaches. In addition, we consider data protection already in the development and selection of hardware, software and processes, in line with the privacy-by-design principle and default settings that are privacy-friendly.

Transfer of personal data

In the course of processing personal data, it may be transmitted to other locations, companies, legally independent organisational units or persons. Recipients may include, for example, IT service providers or providers of services and content embedded in a website. In such cases we comply with the legal requirements and conclude appropriate contracts or agreements that protect your data.

International data transfers

Data processing in third countries: If we transfer data to a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)), or if this occurs in the course of using third-party services or disclosing or transferring data to other persons, entities or companies, this always takes place in accordance with the legal requirements.

For transfers to the US, we primarily rely on the Data Privacy Framework (DPF), recognised by the EU Commission’s adequacy decision of 10 July 2023 as a secure legal framework. We also concluded standard contractual clauses with the respective providers, which correspond to the requirements of the EU Commission and set contractual obligations for the protection of your data.

General information about data storage and deletion

We delete personal data that we process in accordance with the legal provisions as soon as the underlying consent is revoked or there are no further legal bases for processing. This applies where the original purpose of processing no longer applies or the data is no longer needed. Exceptions apply where legal obligations or special interests require longer storage or archiving of the data.

In particular, data that must be retained for commercial or tax reasons, or whose storage is necessary for legal proceedings or to protect the rights of other natural or legal persons, must be archived accordingly.

Rights of data subjects

As a data subject, you have various rights under the GDPR, in particular under Articles 15 to 21 GDPR:

  • Right to object: You may object at any time on grounds relating to your particular situation to the processing of personal data concerning you based on Article 6(1)(e) or (f) GDPR. This also applies to profiling based on those provisions.
  • Right to withdraw consent: You have the right to withdraw consent at any time.
  • Right of access: You have the right to request confirmation as to whether personal data is being processed and to obtain access to that data and further information accordingly.
  • Right to rectification: You have the right to request the completion or correction of inaccurate personal data concerning you.
  • Right to erasure and restriction of processing: You have the right to request the erasure of personal data concerning you or, alternatively, the restriction of processing.
  • Right to data portability: You have the right to receive your personal data in a structured, commonly used and machine-readable format or to request its transmission to another controller.
  • Right to lodge a complaint: You also have the right to lodge a complaint with a supervisory authority.

Provision of the online offer and web hosting

We process user data in order to provide our online services. For this purpose, we process the user’s IP address, which is necessary in order to transmit the content and functions of our online services to the user’s browser or device.

  • Data types processed: Usage data, metadata, communication data, log data, content data.
  • Affected persons: Users.
  • Purposes and legitimate interests: Provision of our online offer, user-friendliness, IT infrastructure and security.
  • Storage and deletion: Deleted according to the information in the section “General information about data storage and deletion”.
  • Legal basis: Legitimate interests (Art. 6(1)(f) GDPR).

Use of cookies

Cookies are functions that store and retrieve information on users’ devices. We use cookies in accordance with legal requirements and, where necessary, obtain prior consent. If consent is not required, we rely on our legitimate interests, such as the essential functionality and security of our online offer. Consent may be withdrawn at any time.

Storage duration: Temporary cookies are deleted when the browser is closed. Permanent cookies remain stored on the device and may be kept for up to two years. Users can manage or withdraw their consent at any time via their browser settings.

Registration, login and user account

Users may create a user account. In the course of registration, we process the required mandatory information in order to provide the account on the basis of contractual obligations. This includes, in particular, login information such as a username, password and email address.

We store the IP address and the time of the relevant user action in order to protect against misuse and unauthorised usage. This is processed on the basis of our legitimate interests and the interests of users in security.

  • Processed data types: Master data, contact data, content data, usage data, log data.
  • Data subjects: Users.
  • Purposes and legal basis: Contract performance, security, provision of services, legitimate interests.

Community functions

The community functions we provide allow users to communicate with each other or otherwise interact. Community usage is only permitted in compliance with applicable law, our terms and guidelines and the rights of other users and third parties.

Single sign-on login

Single sign-on allows users to register or log in using an account from a third-party provider such as Apple or Google. The authentication is performed directly with that provider. We receive a user ID and, depending on the provider and the chosen permissions, additional information such as email address or username. We do not see or save the password entered with the third-party provider.

Contact and request management

When you contact us by post, contact form, email, phone or social media, we process the information you provide in order to answer your request or otherwise handle your inquiry.

Newsletter and electronic notifications

We send newsletters and electronic notifications only with the consent of recipients or on another valid legal basis. The content of the newsletter is defined by the information provided in the registration process. You can revoke consent at any time via the link in each newsletter or by contacting us directly.

Presences in social networks

We maintain online presences in social networks and process user data in this context in order to communicate with users or provide information about us. We also point out that user data may be processed outside the EU/EEA, which may affect the enforceability of user rights.

Plug-ins, embedded functions and content

We embed functions and content elements from third-party providers into our online offer, such as graphics, videos or maps. The providers of that content process the user’s IP address in order to deliver the content to the browser. We do our best to use only providers that process the IP address only for the purpose of delivering the content. In some cases, they may also use cookie-based measurement or marketing technologies.

Changes and updates

We ask you to regularly check the contents of our privacy policy. We update the policy whenever the changes to our data processing make it necessary. We will inform you if the changes require your cooperation (for example, consent) or another individual notification.

Definitions

In this section, you will find an overview of the terms used in this privacy policy. Where the terms are defined by law, their legal definitions apply. The explanations below are intended primarily to aid comprehension.

  • Personal data: Any information relating to an identified or identifiable natural person.
  • Controller: The natural or legal person that determines the purposes and means of processing personal data.
  • Processing: Any operation or set of operations performed on personal data, whether automated or not.
  • Master data: Basic information required to identify and manage contractual partners, accounts or profiles.
  • Contact data: Information that enables communication, such as email addresses, phone numbers and addresses.
  • Content data: Information generated in the creation, editing and publication of content such as text, images and video.
  • Usage data: Information about how users interact with digital products or services.
  • Location data: Data indicating the geographic position of a device or person.
  • Meta-, communication and procedural data: Information about how data is processed, transmitted and managed.
  • Log data: Information about system events and activity such as timestamps, IP addresses and access records.

Created with the free privacy policy generator by Dr. Thomas Schwenke