Privacy Policy

Last updated: 14 March 2026

Controller

Maximilian Schubert Sole proprietorship – Makanji Matcha Jakob-Engel Straße 16 91171 Greding Germany

Email: contact@makanji-matcha.de Imprint: www.makanji-matcha.de/imprint

Relevant legal bases

Relevant legal bases under the GDPR: Below you will find an overview of the legal bases of the GDPR on the basis of which we process personal data. Please note that, in addition to the provisions of the GDPR, national data protection requirements may apply in your or our country of residence or domicile. Should more specific legal bases be relevant in an individual case, we will inform you of these in this privacy policy.

Legal bases under the GDPR

  • Consent (Art. 6 (1) sentence 1 lit. a GDPR) – The data subject has given consent to the processing of their personal data for one or more specific purposes.
  • Legal obligation (Art. 6 (1) sentence 1 lit. c GDPR) – Processing is necessary for compliance with a legal obligation to which the controller is subject.
  • Legitimate interests (Art. 6 (1) sentence 1 lit. f GDPR) – Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, provided that the interests, fundamental rights, and freedoms of the data subject that require the protection of personal data do not override those interests.

National data protection regulations in Germany

In addition to the data protection provisions of the GDPR, national data protection regulations apply in Germany. These include, in particular, the Act on Protection against Misuse of Personal Data in Data Processing (Federal Data Protection Act – BDSG). The BDSG contains, in particular, special provisions on the right of access, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes, and transmission as well as automated decision-making in individual cases including profiling. Furthermore, the data protection laws of the individual federal states may apply.

Security measures

In accordance with the legal requirements and taking into account the state of the art, the implementation costs, and the nature, scope, circumstances, and purposes of the processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, we take appropriate technical and organisational measures to ensure a level of protection appropriate to the risk.

These measures include, in particular, safeguarding the confidentiality, integrity, and availability of data by controlling physical and electronic access to the data as well as the access, input, disclosure, availability, and separation relating to it. Furthermore, we have established procedures that ensure the exercise of data subjects’ rights, the erasure of data, and responses to threats to the data. We also take the protection of personal data into account as early as the development or selection of hardware, software, and procedures, in accordance with the principle of data protection by design and by default.

Securing online connections with TLS/SSL encryption technology (HTTPS)

To protect the data of users transmitted via our online services from unauthorised access, we rely on TLS/SSL encryption technology. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are the cornerstones of secure data transmission on the internet.

These technologies encrypt the information transmitted between the website or app and the user’s browser (or between two servers), thereby protecting the data from unauthorised access. TLS, as the more advanced and secure version of SSL, ensures that all data transmissions meet the highest security standards.

When a website is secured by an SSL/TLS certificate, this is signalled by the display of HTTPS in the URL. This serves as an indicator to users that their data is transmitted securely and in encrypted form.

Transfer of personal data

In the course of our processing of personal data, it may happen that the data is transferred to, or disclosed to, other bodies, companies, legally independent organisational units, or persons.

Recipients of this data may include, for example, service providers commissioned with IT tasks, or providers of services and content embedded in a website.

In such cases, we observe the legal requirements and, in particular, conclude corresponding contracts or agreements with the recipients of your data that serve to protect your data.

General information on data storage and erasure

We erase the personal data that we process in accordance with the legal provisions as soon as the underlying consents are withdrawn or there are no further legal bases for the processing. This applies to cases in which the original purpose of the processing no longer applies or the data is no longer required. Exceptions to this rule exist where legal obligations or special interests require longer retention or archiving of the data.

In particular, data that must be retained for commercial or tax-law reasons, or whose storage is necessary for legal prosecution or to protect the rights of other natural or legal persons, must be archived accordingly.

Our privacy notices contain additional information on the retention and erasure of data that applies specifically to certain processing operations.

Where several statements on retention periods or erasure deadlines apply to a given piece of data, the longest period is always decisive. Data that is no longer retained for the originally intended purpose, but rather due to legal requirements or other reasons, is processed exclusively for the reasons that justify its retention.

Retention and erasure of data

The following general periods apply to retention and archiving under German law:

  • 10 years – Retention period for books and records, annual financial statements, inventories, management reports, opening balance sheets, and the work instructions and other organisational documents required to understand them (§ 147 (1) no. 1 in conjunction with (3) AO, § 14b (1) UStG, § 257 (1) no. 1 in conjunction with (4) HGB).
  • 8 years – Accounting vouchers, such as invoices and cost receipts (§ 147 (1) no. 4 and 4a in conjunction with (3) sentence 1 AO and § 257 (1) no. 4 in conjunction with (4) HGB).
  • 6 years – Other business documents: received commercial or business letters, copies of dispatched commercial or business letters, and other documents insofar as they are relevant for taxation, e.g. hourly wage slips, cost-accounting sheets, calculation documents, price labels, as well as payroll documents insofar as they are not already accounting vouchers, and cash-register receipts (§ 147 (1) nos. 2, 3, 5 in conjunction with (3) AO, § 257 (1) nos. 2 and 3 in conjunction with (4) HGB).
  • 3 years – Data required to consider potential warranty and damage claims or similar contractual claims and rights, and to process related enquiries, based on past business experience and customary industry practice, is stored for the duration of the regular statutory limitation period of three years (§§ 195, 199 BGB).

Provision of the online offering and web hosting

This website is hosted on the servers of an external service provider in order to ensure reliable and secure use of this online offering. The data processing by the hosting provider takes place pursuant to Art. 6 (1) lit. f GDPR, as the controller has a legitimate interest in providing a stable and secure website. Should it be necessary to obtain the user’s consent (for example, for the use of certain cookies or tracking technologies), the data processing is based on the user’s consent pursuant to Art. 6 (1) lit. a GDPR and § 25 (1) TTDSG. You can withdraw your consent at any time with effect for the future.

The hosting provider is:

Cloudflare, Inc. 101 Townsend St. San Francisco, CA 94107 USA

Cloudflare has an establishment in the EU:

Cloudflare Germany GmbH Rosenheimer Str. 143c/8th floor

Details on the data processing and data protection can be found in the hosting provider’s privacy policy.

To ensure that your data is processed in accordance with the applicable data protection regulations, a data processing agreement (DPA) has been concluded with the hosting provider.

This contract obliges the hosting provider to process the personal data of website visitors exclusively in accordance with the controller’s instructions and in compliance with the GDPR. The hosting provider guarantees comprehensive protection of your data through technical and organisational measures.

Collection of access data and log files

Access to our online offering is logged in the form of so-called "server log files". The server log files may include the address and name of the web pages and files accessed, the date and time of access, the volume of data transferred, notification of successful access, browser type and version, the user’s operating system, the referrer URL (the previously visited page), and, as a rule, IP addresses and the requesting provider.

The server log files may be used, on the one hand, for security purposes, e.g. to avoid overloading the servers (in particular in the case of abusive attacks, so-called DDoS attacks), and, on the other hand, to ensure server utilisation and stability.

Legal bases: Legitimate interests (Art. 6 (1) sentence 1 lit. f GDPR).

Erasure of data: Log file information is stored for a maximum of 30 days and then erased or anonymised. Data whose further retention is required for evidentiary purposes is exempt from erasure until the respective incident has been finally resolved.

Newsletter and electronic notifications

We send newsletters, emails, and other electronic notifications (hereinafter "newsletter") exclusively with the consent of the recipients or on the basis of a legal permission. Insofar as the contents of a newsletter are specifically described upon registration, they are decisive for the users’ consent. To register for our newsletter, it is generally sufficient to provide your email address. However, in order to offer you a personalised service, we may ask you to provide your name for a personal salutation in the newsletter, or for further information if this is necessary for the purpose of the newsletter.

Erasure and restriction of processing: We may store unsubscribed email addresses for up to three years on the basis of our legitimate interests before erasing them, in order to be able to prove consent previously given. The processing of this data is restricted to the purpose of a potential defence against claims. An individual request for erasure is possible at any time, provided that the former existence of consent is confirmed at the same time. In the case of obligations to permanently observe objections, we reserve the right to store the email address solely for this purpose in a blocklist.

Brevo

The newsletter is sent via the provider Brevo.

Sendinblue GmbH Köpenicker Str. 126 10179 Berlin Germany

Brevo is a service of Sendinblue GmbH, Köpenicker Str. 126, 10179 Berlin, Germany. The email addresses of newsletter recipients, as well as other data described in these notices, are stored on Brevo’s servers in the EU. Brevo uses this information to send and evaluate the newsletters on behalf of the controller. In addition, according to its own information, Brevo may use this data to optimise or improve its own services, e.g. for the technical optimisation of dispatch and the presentation of the newsletters, or for economic purposes to determine which countries the recipients come from. However, Brevo does not use the data of the newsletter recipients to contact them itself or to pass it on to third parties.

Further information on data protection at Brevo can be found at: https://www.brevo.com/en/legal/privacypolicy/

In addition, technical and organisational security measures are used to protect your personal data against manipulation, loss, destruction, or access by unauthorised persons. These security measures are continuously improved in line with technological developments.

Measurement of open and click rates

Our newsletters contain so-called web beacons for the statistical evaluation of open and click rates.

Changes and updates

We adapt this privacy policy as soon as changes to our data processing make this necessary.

Please check the content of this privacy policy regularly.

Created with the free privacy-policy generator by Dr. Thomas Schwenke.