Privacy Policy
🔒 Privacy Policy
Last Updated: 15 October 2025
HUB 92 SL (referred to as “the Company,” “we,” “us,” or “our”) operates the baristaemporium.com/ website. We are committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website and purchase products from us.
1. 🆔 Data Controller Information
The Company is the Data Controller responsible for the processing of your personal data under the terms of the General Data Protection Regulation (GDPR).
| Detail | Information |
| Legal Entity (Data Controller): | HUB 92 SL |
| Registered Address: | Calle Príncipe de Asturias, 11, 28006 Madrid, Spain |
| Data Protection Contact: | privacy@baristaemporium.com (For all data rights inquiries) |
2. 🗃️ Data We Collect and How We Use It
We collect and process personal data based on specific legal grounds provided by the GDPR (e.g., Contractual Necessity, Legal Obligation, Legitimate Interest, or Explicit Consent).
2.1. Data Collected for Contract Fulfillment (Orders)
This data is necessary to process your order and deliver your machine.
| Data Type | Purpose & Legal Basis | Retention |
| Identity Data (Name, Email, Phone) | To communicate order status and track the shipment. (Contractual Necessity) | Kept as required by Spanish tax and consumer law. |
| Transaction Data (Shipping/Billing Address, Purchase History) | To fulfill the order, calculate VAT, and ensure correct delivery. (Contractual Necessity) | Kept as required by Spanish tax and consumer law (usually 6 years). |
2.2. Usage Data & Analytics
This data is collected automatically to improve your experience and our site performance.
| Data Type | Purpose & Legal Basis | Retention |
| Technical Data (IP address, Browser Type, Pages Visited) | To diagnose server problems, prevent fraud, and analyze site usage. (Legitimate Interest) | Varies based on the tool (e.g., Google Analytics). |
| Marketing Data (Tracking via Google Analytics/Facebook Pixel) | To measure the effectiveness of our advertising and target relevant offers. (Consent or Legitimate Interest) | Varies based on the tool. |
3. 🤝 Disclosure of Your Personal Data (Third Parties)
We may share your personal data with the following third-party service providers who act as Data Processors to us. We ensure all processors comply with GDPR.
Payment Processor: We use a secure third-party payment processor to handle all card transactions. We do not store or directly process credit card numbers on our servers.
Shipping Couriers: We share your Name, Address, and Phone Number with carriers like DHL, FedEx, or Correos to ensure delivery of your espresso machine.
Analytics Providers: We use tools such as Google Analytics and the Facebook Pixel to understand site traffic and measure marketing effectiveness. These tools may process data outside the EU/EEA, subject to robust legal safeguards (e.g., Standard Contractual Clauses).
Legal and Regulatory Authorities: We may disclose your data where legally required to comply with Spanish law, court orders, or other legal processes.
4. 🔒 Data Security and Retention
4.1. Data Security
We have implemented appropriate security measures, including SSL encryption for all data transfer and secure servers, to prevent your personal data from being accidentally lost, used, or accessed in an unauthorized way.
4.2. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which we collected it, including for the purposes of satisfying any legal, accounting, or reporting requirements (e.g., Spanish tax law generally requires keeping transaction records for up to six years).
5. 🇪🇺 Your Rights Under GDPR
Under GDPR, you have the following rights regarding your personal data. You can exercise these rights at any time by contacting our Data Protection Contact at privacy@baristaemporium.com.
| Right | Description |
| Right of Access | The right to request a copy of the personal data we hold about you. |
| Right to Rectification | The right to have any incomplete or inaccurate data we hold corrected. |
| Right to Erasure | The right to ask us to delete or remove personal data where there is no good reason for us to continue processing it (the “Right to be Forgotten”). |
| Right to Restrict Processing | The right to suspend the processing of your personal data. |
| Right to Data Portability | The right to receive your personal data in a structured, commonly used, and machine-readable format. |
| Right to Object | The right to object to the processing of your personal data (e.g., for direct marketing). |
| Right to Lodge a Complaint | The right to complain to a supervisory authority, such as the Spanish Data Protection Agency (AEPD). |
Pay Securely
