— Legal information —

Privacy Policy

Courtesy translation. This English text is provided for convenience. Legally binding is the German version at Datenschutzerklärung. In case of any discrepancy the German version prevails, to the extent legally permitted.

This notice explains how personal data is processed when you use this B2B platform. The legal basis is in particular the EU General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), the Digital Services Act (DDG) and the Telecommunications Digital Services Data Protection Act (TDDDG).

1. Controller

Cemil Caliskan, trading as COLIBRI Germany / COLIBRI Nexus, Hasenpfühlerweide 6, 67346 Speyer, Germany.

Phone: +49 162 9773765
Email: contact@colibri-nexus.com

No data protection officer has been appointed. For privacy requests please use the contact details above.

2. Principles

We process personal data only where necessary to operate the website, communicate with you, evaluate and onboard suppliers, verify origin and quality, prepare and execute contracts, coordinate export and logistics, ensure compliance and fraud prevention, and comply with legal obligations. Legal bases are Art. 6(1)(a), (b), (c) and (f) GDPR.

3. Hosting and server logs

When you access the site, technical access data is typically captured in server log files (IP address, date and time, requested URL, browser, operating system, referrer, data volume, HTTP status). Legal basis: Art. 6(1)(f) GDPR — secure and reliable operation of the site.

4. Encryption

The site uses SSL/TLS encryption. All HTTP requests are redirected to HTTPS. Forms are only submitted over encrypted connections.

5. Contact by email and phone

When you contact us we process your name, company, role, email, phone number, message content, any attachments and communication metadata. Legal basis: Art. 6(1)(b) GDPR for pre-contract or contract-related communication, otherwise Art. 6(1)(f) GDPR.

6. WhatsApp

On some pages we link out to WhatsApp to contact our partner in Brazil. Using WhatsApp may cause the provider to process message and metadata. No WhatsApp tracking scripts are loaded — the link is a plain external link. Please do not share confidential supplier documents via WhatsApp; use the secure supplier portal instead.

7. Supplier onboarding

During supplier onboarding we may process: company and producer name, legal form, trade/tax register data, business address, farm location and GPS coordinates, contact persons, country, region, coffee species, varieties, harvest windows, processing methods, production and available quantities, certifications, audit data, quality data (cupping scores, lab results), export/customs/logistics data, references, trade history, photos, videos, farm stories, uploaded documents and communication history.

Purposes include evaluation, onboarding, origin and quality verification, product assessment, contract preparation, matching suppliers and buyers, fraud prevention, compliance, traceability and documentation of business decisions. Legal bases: Art. 6(1)(b), (c) and (f) GDPR. For purely optional content (e.g. published producer portraits) we obtain separate consent under Art. 6(1)(a) GDPR.

8. Document uploads

Uploaded documents are stored privately and access-restricted. Access is only granted through authenticated user accounts and role-based permissions. Downloads use time-limited signed URLs; file names are replaced server-side by random identifiers. Please only upload documents strictly required for the review of your business activity.

9. AI and automated processing

Where AI tools are used to assist humans (e.g. translation, classification, extraction, summaries, recommendations), they support — but do not replace — human decisions. No solely automated decisions with legal or similarly significant effects under Art. 22 GDPR take place. Confidential or personal supplier data is not sent unfiltered to external public AI systems.

10. Cooperation with Brazil

COLIBRI cooperates with Andreia Galindo / Galindo International Business, Rua Júlia Maria Barbosa 80, Cambira – PR, CEP 86890-000, Brazil. We may exchange business contact data, supplier and producer information, product and quality data, offer, export and logistics data, and business correspondence.

The European Commission has adopted an adequacy decision for Brazil. Transfers to our partner in Brazil that fall within the scope of that decision are based on Art. 45 GDPR. Should the legal basis change, alternative transfer mechanisms (e.g. Standard Contractual Clauses under Art. 46 GDPR) will apply. Data minimisation, purpose limitation, access restrictions and appropriate technical and organisational measures continue to apply.

11. Recipients

Recipients may include: authorised internal users, our Brazilian cooperation partner, hosting/database/storage/email providers, logistics, customs and quality labs, certification bodies, legal and tax advisors, as well as authorities and courts where legally required.

12. Cookies and § 25 TDDDG

We only use technically necessary cookies to operate this site (session, security, language). Additional categories (preferences, statistics, marketing, external media) are only activated with your consent under § 25(1) TDDDG and Art. 6(1)(a) GDPR. You can withdraw your consent at any time via the "Cookie settings" link in the footer.

13. Third-party services

Currently we load web fonts from an external provider (Google Fonts). Migration to self-hosted fonts is under review. Additional third-party services (maps, videos, analytics, marketing, chat) are not loaded without prior consent.

14. Retention

We retain personal data only as long as necessary for the purposes described above or required by law. Separate retention rules apply to server logs, contact requests, supplier applications, approved suppliers, rejected applications, contracts, invoices, tax records, consent records, security logs and user accounts.

15. Your rights

Subject to the statutory requirements you have the right to:

  • access (Art. 15 GDPR)
  • rectification (Art. 16 GDPR)
  • erasure (Art. 17 GDPR)
  • restriction (Art. 18 GDPR)
  • data portability (Art. 20 GDPR)
  • object (Art. 21 GDPR)
  • withdraw consent with effect for the future
  • lodge a complaint with a supervisory authority

An informal message to contact@colibri-nexus.com is sufficient.

16. Supervisory authority

The competent supervisory authority is the State Commissioner for Data Protection and Freedom of Information of Rhineland-Palatinate (Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz).

17. Security

We use appropriate technical and organisational measures, in particular HTTPS, secure authentication, password hashing, role-based access control, least-privilege principle, rate limiting, protection against brute-force attacks, secure session management, CSRF/XSS/SQL-injection protection, input validation, secure file uploads, encrypted backups, security logging, regular updates and clean secret management via environment variables.

18. Changes

We may update this notice when legal requirements, technologies, processes or company structures change. The version published on this site applies.

Last updated: July 2026

The German version at Datenschutzerklärung is legally binding.