CUSTOMER SERVICE
PRIVACY POLICY
1. Who We Are
This website is operated by SONDER COFFEE DOO, a coffee roastery registered in the Republic of Serbia (PIB: 114924139, MB: 22091328 / Srbija, Beograd (Stari Grad), Zorza Klemansoa 27v). We are the data controller for all personal data collected through this website.
Contact: info@sondercoffeeroastery.com
2. What Data We Collect
We may collect and process the following categories of personal data:
Identity data: full name, company name
Contact data: email address, phone number, delivery address, billing address
Order data: products ordered, quantities, order history, payment method (we do not store card numbers; payments are handled by a third-party processor)
Account data: username, password (hashed), preferences
Usage data: IP address, browser type and version, pages visited, time spent, referring URL
Cookie data: session cookies, analytics cookies, preference cookies (see Section 7)
Communication data: contents of messages sent via contact forms or email
Subscription data: email address and preferences if you subscribe to our newsletter
3. How We Use Your Data
We process your data on the following legal bases:
Purpose
Legal basis
Processing and fulfilling orders
Performance of a contract (Art. 6(1)(b) GDPR)
Creating and managing your account
Performance of a contract
Sending transactional emails (order confirmation, shipping)
Performance of a contract
Sending the newsletter
Consent (Art. 6(1)(a) GDPR)
Analytics and improving the website
Legitimate interests (Art. 6(1)(f) GDPR)
Responding to inquiries
Legitimate interests
Compliance with legal obligations (invoicing, tax records)
Legal obligation (Art. 6(1)(c) GDPR)
4. Sharing Your Data
We do not sell your personal data. We may share it with:
Delivery and logistics partners — to ship your order
Payment processors — to handle transactions securely
Email service providers — to send transactional and marketing emails
Analytics providers (e.g. Google Analytics) — to understand website usage
Hosting and IT service providers — to operate the website
Public authorities — if required by law
All third-party processors are bound by data processing agreements and are required to handle your data in accordance with applicable law.
5. International Transfers
Some of our service providers are located outside Serbia and the EEA. Where data is transferred internationally, we ensure appropriate safeguards are in place (Standard Contractual Clauses or adequacy decisions under GDPR).
6. How Long We Keep Your Data
Order and billing records: 10 years (Serbian Accounting Law)
Account data: for the duration of the account, plus 2 years after deletion request
Newsletter subscriptions: until you unsubscribe
Analytics data: up to 26 months
Inquiry data: 2 years from last contact
7. Cookies
We use the following categories of cookies:
Strictly necessary: required for the website to function; cannot be disabled
Functional: remember your preferences (language, cart contents)
Analytics: help us understand how visitors use the site (e.g. Google Analytics)
Marketing: used to show relevant ads (only if you consent)
You can manage your cookie preferences via our cookie banner or your browser settings. Withdrawing consent does not affect lawfulness of prior processing.
8. Your Rights
Under the Serbian Law on Personal Data Protection (ZZPL) and GDPR, you have the right to:
Access — obtain a copy of the data we hold about you
Rectification — correct inaccurate data
Erasure — request deletion ("right to be forgotten")
Restriction — limit how we process your data
Portability — receive your data in a machine-readable format
Objection — object to processing based on legitimate interests
Withdraw consent — at any time, where processing is based on consent
Lodge a complaint — with the Commissioner for Information of Public Importance and Personal Data Protection of the Republic of Serbia (www.poverenik.rs)
To exercise your rights, contact us at: info@sondercoffeeroastery.com . We will respond within 30 days.
9. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, loss, or disclosure, including SSL encryption, access controls, and regular security reviews.
10. Children
Our website is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected such data, please contact us for immediate deletion.
11. Changes to This Policy
We may update this policy from time to time. The current version is always available on this page. For material changes, we will notify you by email or prominent website notice.
QUICK LINKS
CUSTOMER SERVICE