Privacy policy
Last updated: 8 September 2026 · Applies to aureocoffee.com
1 · Data controller
In compliance with Regulation (EU) 2016/679, the General Data Protection Regulation (GDPR), and Organic Law 3/2018, of 5 December, on the Protection of Personal Data and the guarantee of digital rights (LOPDGDD), the user is informed of the identifying details of the data controller:
- Controller: Marchitan Octavian (Áureo Coffee Bean Shop)
- Tax ID (NIF): ESX3567328M
- Registered address: Calle 102, N.º 8, 46182 La Cañada, València (Valencia), Spain
- Roastery and shop: Carrer de Pau Casals, 7, 43850 Cambrils (Tarragona), Spain
- Email: hola@aureocoffee.com
- Phone: +34 641 345 070
- Website: https://aureocoffee.com
Hereinafter, "Áureo", "the controller" or "we".
2 · Personal data we process
2.1. Data provided directly by the user
- Identification and contact data: first name, surname, NIF / NIE, postal address, email address, phone number.
- Customer account data (if you register): username, encrypted password, language and communication preferences.
- Billing and shipping data: billing address, shipping address, tax details.
- Payment data: depending on the method chosen. Full card details are not stored on our servers; they are handled by the contracted payment gateway (see section 5).
- Email for notifications and newsletter: if you sign up for "Notify me" or the newsletter, only your email address and the date of consent.
- Content of communications: information included in emails, contact forms or customer service messages.
2.2. Data collected automatically
- Browsing data: IP address, browser and device identifier, operating system, language, pages visited, date and time of access, referrer.
- Cookies and similar technologies: see the Cookie policy.
3 · Purposes of processing
| Purpose | Data categories |
|---|---|
| Manage the customer account and authentication | Identification, contact, account |
| Process orders, issue invoices and manage payments | Identification, billing, payment |
| Coordinate shipments with carriers | Identification, shipping address, phone |
| Handle queries, incidents and complaints | Identification, contact, content of the communication |
| Comply with legal obligations (tax, accounting, health) | Identification, billing |
| Notify the launch of the subscription, the decaf or new batches (only with consent) | |
| Send communications about similar products to customers (with the option to object) | Contact |
| Analyse use of the site to improve the service (only with cookie consent) | Browsing data, cookies |
| Fraud prevention and site security | Identification, browsing data |
4 · Legal basis
- Performance of a contract (Art. 6.1.b GDPR): managing orders, shipments, invoicing and customer service.
- Compliance with legal obligations (Art. 6.1.c GDPR): keeping invoices and complying with tax, commercial and food regulations.
- Legitimate interest (Art. 6.1.f GDPR): fraud prevention, basic statistical analysis and communications about similar products to existing customers, with the right to object at any time.
- Consent (Art. 6.1.a GDPR): email notifications ("Notify me"), newsletter and non-technical cookies.
The user may withdraw consent at any time, without affecting the lawfulness of the prior processing. Every email notification includes an unsubscribe link.
5 · Recipients of the data
5.1. Processors
Providers that process data on behalf of Áureo, under a processing agreement in accordance with Art. 28 GDPR:
- Web hosting: Hetzner Online GmbH (Germany, within the EEA).
- Payment gateways: Redsys (card and Bizum) and PayPal.
- Carriers: ASM and Loginser for shipments within Spain; international carriers (GLS, DHL, UPS or others) for shipments to the rest of the European Union. They process the recipient's data solely to deliver the order.
- Email: own SMTP server and Gmail (Google Ireland Limited).
- Web analytics: Google Analytics (Google Ireland Limited), only if the user accepts analytics cookies.
5.2. Disclosures to third parties
- Public authorities where there is a legal obligation (Tax Agency, health authorities, judicial authorities).
- Financial institutions for managing payments and refunds.
No other disclosures are made except under a legal obligation or with the user's express consent.
5.3. International transfers
Google (analytics and email) and PayPal may process data outside the European Economic Area. In those cases the safeguards provided for in Articles 46 et seq. of the GDPR apply (European Commission standard contractual clauses or adherence to the EU-US Data Privacy Framework). Hosting (Hetzner) and Redsys are provided entirely within the EEA.
6 · Retention periods
- Customer account: for as long as it remains active. If the user requests deletion, the data is blocked for the statutory periods and deleted afterwards.
- Orders and invoicing: the periods required by tax and commercial regulations (6 years under the Commercial Code; 4 years under tax regulations).
- Notification and newsletter emails: until the user unsubscribes or withdraws consent.
- Browsing and cookies: see the Cookie policy.
- Complaints: the time needed to handle them and the applicable limitation periods.
7 · User rights
The user may exercise the rights of access, rectification, erasure, objection, restriction of processing and portability, as well as withdraw consent and not be subject to automated decisions with legal effects.
7.1. How to exercise them
- Email to hola@aureocoffee.com, stating "Data protection" in the subject line and the right you wish to exercise.
- Postal request to: Marchitan Octavian, Carrer de Pau Casals, 7, 43850 Cambrils (Tarragona), Spain.
Attach a copy of a document proving your identity. We will reply within one month at most, extendable by two further months where the complexity so warrants.
7.2. Complaint to the supervisory authority
If you consider that the processing does not comply with the regulations, you may lodge a complaint with the Spanish Data Protection Agency (AEPD): https://www.aepd.es — C/ Jorge Juan, 6, 28001 Madrid.
8 · Security
We apply appropriate technical and organisational measures (Art. 32 GDPR): HTTPS / TLS encryption, passwords stored with secure hashing algorithms, access restricted to authorised staff and regular backups. No system is completely secure; we cannot guarantee the absolute inviolability of information transmitted over the Internet.
9 · Minors
The site is not aimed at children under 14. If we became aware that we had collected data from a minor without the consent of their parents or guardians, we would delete it.
10 · Social networks
Áureo may have a presence on social networks (Instagram, Facebook). The processing of followers' data is governed by the terms of each platform and its purpose is to share news about the roastery, the coffees and new releases.
11 · Changes
We may amend this policy to adapt it to new legislation or to changes in our activity. We will publish the updated version on the site with the new "Last updated" date.