— Legal information —
Privacy Policy
This notice explains how personal data is processed when you use this B2B platform. The legal basis is in particular the EU General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), the Digital Services Act (DDG) and the Telecommunications Digital Services Data Protection Act (TDDDG).
1. Controller
Cemil Caliskan, trading as COLIBRI Germany / COLIBRI Nexus, Hasenpfühlerweide 6, 67346 Speyer, Germany.
Phone: +49 162 9773765
Email: contact@colibri-nexus.com
No data protection officer has been appointed. For privacy requests please use the contact details above.
2. Principles
We process personal data only where necessary to operate the website, communicate with you, evaluate and onboard suppliers, verify origin and quality, prepare and execute contracts, coordinate export and logistics, ensure compliance and fraud prevention, and comply with legal obligations. Legal bases are Art. 6(1)(a), (b), (c) and (f) GDPR.
3. Hosting and server logs
When you access the site, technical access data is typically captured in server log files (IP address, date and time, requested URL, browser, operating system, referrer, data volume, HTTP status). Legal basis: Art. 6(1)(f) GDPR — secure and reliable operation of the site.
4. Encryption
The site uses SSL/TLS encryption. All HTTP requests are redirected to HTTPS. Forms are only submitted over encrypted connections.
5. Contact by email and phone
When you contact us we process your name, company, role, email, phone number, message content, any attachments and communication metadata. Legal basis: Art. 6(1)(b) GDPR for pre-contract or contract-related communication, otherwise Art. 6(1)(f) GDPR.
6. WhatsApp
On some pages we link out to WhatsApp to contact our partner in Brazil. Using WhatsApp may cause the provider to process message and metadata. No WhatsApp tracking scripts are loaded — the link is a plain external link. Please do not share confidential supplier documents via WhatsApp; use the secure supplier portal instead.
7. Supplier onboarding
During supplier onboarding we may process: company and producer name, legal form, trade/tax register data, business address, farm location and GPS coordinates, contact persons, country, region, coffee species, varieties, harvest windows, processing methods, production and available quantities, certifications, audit data, quality data (cupping scores, lab results), export/customs/logistics data, references, trade history, photos, videos, farm stories, uploaded documents and communication history.
Purposes include evaluation, onboarding, origin and quality verification, product assessment, contract preparation, matching suppliers and buyers, fraud prevention, compliance, traceability and documentation of business decisions. Legal bases: Art. 6(1)(b), (c) and (f) GDPR. For purely optional content (e.g. published producer portraits) we obtain separate consent under Art. 6(1)(a) GDPR.
8. Document uploads
Uploaded documents are stored privately and access-restricted. Access is only granted through authenticated user accounts and role-based permissions. Downloads use time-limited signed URLs; file names are replaced server-side by random identifiers. Please only upload documents strictly required for the review of your business activity.
9. AI and automated processing
Where AI tools are used to assist humans (e.g. translation, classification, extraction, summaries, recommendations), they support — but do not replace — human decisions. No solely automated decisions with legal or similarly significant effects under Art. 22 GDPR take place. Confidential or personal supplier data is not sent unfiltered to external public AI systems.
10. Cooperation with Brazil
COLIBRI cooperates with Andreia Galindo / Galindo International Business, Rua Júlia Maria Barbosa 80, Cambira – PR, CEP 86890-000, Brazil. We may exchange business contact data, supplier and producer information, product and quality data, offer, export and logistics data, and business correspondence.
The European Commission has adopted an adequacy decision for Brazil. Transfers to our partner in Brazil that fall within the scope of that decision are based on Art. 45 GDPR. Should the legal basis change, alternative transfer mechanisms (e.g. Standard Contractual Clauses under Art. 46 GDPR) will apply. Data minimisation, purpose limitation, access restrictions and appropriate technical and organisational measures continue to apply.
11. Recipients
Recipients may include: authorised internal users, our Brazilian cooperation partner, hosting/database/storage/email providers, logistics, customs and quality labs, certification bodies, legal and tax advisors, as well as authorities and courts where legally required.
12. Cookies and § 25 TDDDG
We only use technically necessary cookies to operate this site (session, security, language). Additional categories (preferences, statistics, marketing, external media) are only activated with your consent under § 25(1) TDDDG and Art. 6(1)(a) GDPR. You can withdraw your consent at any time via the "Cookie settings" link in the footer.
13. Third-party services
Currently we load web fonts from an external provider (Google Fonts). Migration to self-hosted fonts is under review. Additional third-party services (maps, videos, analytics, marketing, chat) are not loaded without prior consent.
14. Retention
We retain personal data only as long as necessary for the purposes described above or required by law. Separate retention rules apply to server logs, contact requests, supplier applications, approved suppliers, rejected applications, contracts, invoices, tax records, consent records, security logs and user accounts.
15. Your rights
Subject to the statutory requirements you have the right to:
- access (Art. 15 GDPR)
- rectification (Art. 16 GDPR)
- erasure (Art. 17 GDPR)
- restriction (Art. 18 GDPR)
- data portability (Art. 20 GDPR)
- object (Art. 21 GDPR)
- withdraw consent with effect for the future
- lodge a complaint with a supervisory authority
An informal message to contact@colibri-nexus.com is sufficient.
16. Supervisory authority
The competent supervisory authority is the State Commissioner for Data Protection and Freedom of Information of Rhineland-Palatinate (Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz).
17. Security
We use appropriate technical and organisational measures, in particular HTTPS, secure authentication, password hashing, role-based access control, least-privilege principle, rate limiting, protection against brute-force attacks, secure session management, CSRF/XSS/SQL-injection protection, input validation, secure file uploads, encrypted backups, security logging, regular updates and clean secret management via environment variables.
18. Changes
We may update this notice when legal requirements, technologies, processes or company structures change. The version published on this site applies.
Last updated: July 2026
The German version at Datenschutzerklärung is legally binding.