Privacy policy

Privacy Policy

Last updated: 16 July 2026

1. Controller

The controller responsible for the processing of personal data on this website is:

WAKABA Matcha & Tea GmbH
Hansaallee 113
40549 Düsseldorf
Germany

Represented by its Managing Director:
Asuka Ohashi

Email: info@matcha-wakaba.com

2. General information on data processing

We process personal data exclusively in accordance with applicable data protection laws, in particular the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG) and the German Telecommunications Digital Services Data Protection Act (TDDDG).

Personal data means any information relating to an identified or identifiable natural person. This may include, in particular, names, business contact details, IP addresses, order information and communication content.

Although our products and services are offered exclusively to business customers, we may process personal data relating to contact persons, managing directors, employees, sole traders and other natural persons in the course of business relationships.

3. Hosting and shop system provided by Shopify

We use Shopify’s e-commerce platform to operate this website and our B2B online store.

For merchants established in the European Economic Area, the relevant Shopify contracting entity is generally:

Shopify International Limited
Ireland

Shopify processes data on our behalf, particularly where this is necessary to provide the online store, maintain technical security, administer customer accounts, process enquiries and orders, and facilitate payments and deliveries.

The data processed may include:

  • IP addresses and technical device information;

  • browser and operating system information;

  • pages accessed and access times;

  • names and business contact details;

  • company and billing information;

  • customer account and order information;

  • payment and shipping information;

  • communication and support data.

Depending on the processing activity, the legal basis is Article 6(1)(b) GDPR for pre-contractual measures or the performance of a contract, Article 6(1)(c) GDPR for compliance with legal obligations, or Article 6(1)(f) GDPR based on our legitimate interest in operating a secure and commercially efficient B2B online store.

Shopify may also process personal data outside the European Economic Area. According to Shopify, appropriate safeguards are used for such transfers, including binding corporate rules and, where applicable, the European Commission’s standard contractual clauses.

4. Server log files

When you access our website, Shopify and, where applicable, other technical service providers automatically process certain technical information.

This information may include:

  • IP address;

  • date and time of access;

  • page or file accessed;

  • referring URL;

  • browser type and browser version;

  • operating system;

  • device type;

  • amount of data transferred;

  • internet service provider;

  • status and error messages.

The data is processed to provide the website, maintain technical security, analyse errors and prevent abusive or unauthorised access.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure, stable and functional operation of our website.

The data is deleted when it is no longer required for these purposes, unless security incidents, legal obligations or other legitimate reasons require longer storage.

5. Contact by email

If you contact us by email, we process the information you provide, which may include:

  • your name;

  • your business email address;

  • your company;

  • your telephone number, where provided;

  • the content of your message;

  • any other information you submit.

Where the contact relates to the preparation or performance of a contract, the processing is based on Article 6(1)(b) GDPR.

Other business enquiries are processed on the basis of Article 6(1)(f) GDPR. Our legitimate interest is to process and respond to business enquiries.

Where processing is based on consent, the legal basis is Article 6(1)(a) GDPR. Consent may be withdrawn at any time with effect for the future.

6. Contact, sample and wholesale enquiry forms

When you use a contact form, request a sample or price information, or apply for a B2B account, we process the information entered in the relevant form.

This may include:

  • first and last name;

  • company name and legal form;

  • business address;

  • country;

  • business email address;

  • telephone number;

  • website or social media profile;

  • VAT identification number;

  • commercial register or business registration information;

  • type of business and industry;

  • anticipated order volumes;

  • products of interest;

  • content of the enquiry.

The data is processed to review your enquiry, prepare an offer, assess a potential business relationship, verify your status as a business customer and take steps prior to entering into a contract.

The legal basis is Article 6(1)(b) GDPR.

Where the processing relates to verifying business status, preventing misuse or assessing business risks, the data may also be processed on the basis of Article 6(1)(f) GDPR.

Our legitimate interest is to ensure that our B2B store is available only to eligible business customers and to prevent abusive or fraudulent registrations.

7. B2B customer accounts

If you apply for or use a B2B customer account, we process the data required to create and administer the account.

This may include:

  • name of the contact person;

  • company name;

  • billing and delivery addresses;

  • business email address;

  • telephone number;

  • VAT identification number;

  • customer-specific prices and discounts;

  • order history;

  • payment and delivery terms;

  • account status and internal approval notes.

The legal basis for the processing is Article 6(1)(b) GDPR.

Data used for fraud prevention, credit assessment or account security may be processed on the basis of Article 6(1)(f) GDPR, where this is necessary and proportionate.

We reserve the right to manually review and reject B2B account applications if the applicant’s business status cannot be sufficiently verified.

8. Orders and contract processing

When an order is placed, we process the information required to process and perform the contract.

This may include:

  • name and contact details of the contact person;

  • company name;

  • billing and delivery addresses;

  • VAT identification number;

  • products and quantities ordered;

  • prices, discounts and payment terms;

  • payment status;

  • shipping and delivery information;

  • invoice and accounting information;

  • communications relating to the order.

The legal basis is Article 6(1)(b) GDPR.

Where we are required to issue and retain invoices, comply with tax obligations, maintain food traceability records or fulfil other legal requirements, the processing is based on Article 6(1)(c) GDPR.

9. Payment processing

Where electronic payment methods are offered on our website, we transmit the information required for payment processing to the payment service provider selected by the customer.

The information transmitted may include:

  • name and company;

  • billing address;

  • order number;

  • invoice amount;

  • currency;

  • payment status;

  • other information required for payment verification.

The legal basis is Article 6(1)(b) GDPR.

Where payment service providers process personal data for their own purposes, such as fraud prevention, identity verification or compliance with anti-money laundering obligations, they may act as independent controllers.

The payment methods actually available are displayed during the checkout process.

10. Shipping and logistics

To deliver ordered goods, we provide the necessary information to the appointed parcel service, freight forwarder, warehouse provider or fulfilment provider.

This information may include:

  • name of the contact person;

  • company name;

  • delivery address;

  • telephone number;

  • email address;

  • order number;

  • type, number and weight of the shipment;

  • requested delivery options.

The legal basis is Article 6(1)(b) GDPR.

Where an email address or telephone number is used exclusively for delivery notifications or delivery scheduling, it will only be disclosed where this is necessary for proper delivery or where the relevant person has consented.

11. Newsletter

If you subscribe to our newsletter, we process your email address and, where applicable, your name, company and business interests.

The legal basis is your consent pursuant to Article 6(1)(a) GDPR.

We may use a double opt-in procedure to verify the subscription. In this case, we may store the date and time of registration and confirmation and, where applicable, the IP address used, so that we can demonstrate that valid consent was provided.

You may withdraw your consent at any time with effect for the future, in particular by using the unsubscribe link in the newsletter or by contacting us.

After withdrawal, your email address will be removed from the active newsletter distribution list unless legal grounds require further storage.

12. Direct marketing to existing business customers

Where legally permitted, we may use the business contact details of existing customers to provide information about our own similar products and services.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is to maintain existing business relationships and carry out direct marketing.

You may object to the use of your data for direct marketing at any time with effect for the future.

Following an objection, we will no longer use your data for this purpose.

13. Cookies and similar technologies

Our website uses cookies and similar technologies.

Technically necessary cookies and local storage technologies may be used where they are strictly required to provide the website, shopping cart, login functions, security features, language settings or other services expressly requested by the user.

Access to information stored on your device or the storage of information on your device is based on Section 25(2) TDDDG in the case of technically necessary technologies.

Where personal data is subsequently processed, the legal basis is Article 6(1)(b) or Article 6(1)(f) GDPR, as applicable.

Cookies, analytics, marketing and tracking technologies that are not technically necessary are used only after you have provided prior consent through our consent management system.

The legal bases are Section 25(1) TDDDG and Article 6(1)(a) GDPR.

You may withdraw or change your consent at any time with effect for the future through the cookie or privacy settings available on our website.

Rejecting non-essential cookies will not prevent you from using the basic functions of the online store.

14. Shopify analytics and marketing functions

Shopify provides technical, statistical and, where applicable, marketing-related functions.

Where these functions are used exclusively for technical operation, security, error detection or basic store statistics, processing may be based on Article 6(1)(f) GDPR.

Where optional analytics, personalisation, advertising or cross-site functions are used and involve cookies, local storage technologies or similar identifiers, they will only be activated after you have provided consent.

The legal bases are Section 25(1) TDDDG and Article 6(1)(a) GDPR.

You may withdraw your consent at any time through the privacy settings available on our website.

15. Links to social networks

Our website may contain links to our profiles on social networks such as Instagram, TikTok or LinkedIn.

Where the website contains only a link, a connection to the relevant platform provider is generally established only when you click that link.

After clicking the link, the privacy terms of the relevant platform provider apply. We do not have complete control over the personal data subsequently processed by the platform provider.

16. Recipients of personal data

Where necessary for the purposes described in this Privacy Policy, personal data may be disclosed to the following categories of recipients:

  • Shopify and technical hosting providers;

  • providers of store apps and IT services;

  • payment service providers and banks;

  • parcel services, freight forwarders, warehouses and fulfilment providers;

  • tax advisers, accountants and auditors;

  • legal advisers;

  • public authorities and government bodies where legally required;

  • email, CRM and newsletter service providers;

  • other processors.

Where required, we enter into data processing agreements with processors in accordance with Article 28 GDPR.

17. Transfers to third countries

When using Shopify and other international service providers, the processing of personal data outside the European Union or European Economic Area cannot be completely excluded.

Personal data will only be transferred where the applicable legal requirements are satisfied.

Safeguards may include:

  • an adequacy decision issued by the European Commission;

  • binding corporate rules;

  • the European Commission’s standard contractual clauses;

  • supplementary technical and organisational safeguards;

  • explicit consent, where legally permitted.

18. Storage periods

We retain personal data only for as long as necessary for the relevant processing purpose or for as long as statutory retention obligations apply.

Data relating to general enquiries is generally deleted once the enquiry has been fully processed and no further business relationship is established, unless legitimate interests or legal obligations justify longer storage.

Contract, order, invoice and accounting data is retained in accordance with applicable commercial and tax-law retention requirements. Depending on the type of document, the relevant retention period may generally be six, eight or ten years.

Data relating to outstanding claims or legal disputes may be retained until the relevant proceedings have been completed and the applicable limitation periods have expired.

19. Your rights

Where the applicable legal requirements are met, you have the following rights in particular:

  • the right of access pursuant to Article 15 GDPR;

  • the right to rectification pursuant to Article 16 GDPR;

  • the right to erasure pursuant to Article 17 GDPR;

  • the right to restriction of processing pursuant to Article 18 GDPR;

  • the right to data portability pursuant to Article 20 GDPR;

  • the right to object pursuant to Article 21 GDPR;

  • the right to withdraw consent pursuant to Article 7(3) GDPR;

  • the right to lodge a complaint with a supervisory authority pursuant to Article 77 GDPR.

To exercise your rights, please contact us at info@matcha-wakaba.com.

20. Right to object

Where we process personal data on the basis of Article 6(1)(f) GDPR, you have the right to object to such processing at any time on grounds relating to your particular situation.

Where personal data is processed for direct marketing purposes, you may object at any time.

Following an objection, the data will no longer be processed for direct marketing purposes.

21. Right to lodge a complaint with a supervisory authority

You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data is unlawful.

The supervisory authority generally responsible for our company is:

State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen

You may also contact another competent supervisory authority, in particular the authority responsible for your habitual residence or place of work.

22. Requirement to provide personal data

The provision of personal data is generally voluntary.

However, certain information is required in order to assess a B2B enquiry, create a customer account, prepare an offer, enter into a contract or perform a contract.

If the required information is not provided, we may be unable to process the relevant enquiry, registration or order.

23. Automated decision-making

As a general rule, we do not carry out solely automated decision-making that produces legal effects concerning you or similarly significantly affects you.

Where technical procedures are used for fraud detection or risk assessment, the final decision regarding the establishment of a business relationship will generally involve human review.

24. Data security

We implement appropriate technical and organisational measures to protect personal data against loss, manipulation, unauthorised access and other unlawful processing.

Our security measures are reviewed and adjusted in accordance with technological developments and the relevant level of risk.

25. Changes to this Privacy Policy

We may update this Privacy Policy if our website, the services we use, our business processes or the applicable legal requirements change.

The current version published on this website applies.