Legal

Privacy Policy

How we use your personal data.

English translation — pending legal review. This page is a translation of the Greek original. In case of any discrepancy, the Greek text takes precedence. Neither the original nor this translation has been reviewed by a lawyer yet.

Bridge Urban Coffee Roasters respects your privacy. This page explains what data we collect through bridgecoffeeroasters.com , why, and what rights you have.

Data controller

The data controller is Bridge Urban Coffee Roasters. For any request about your data, contact us at info@bridgecoffeeroasters.com.

What data we collect

Contact and franchise forms

The contact and franchise forms don't send data to any server of ours — they open your own email program (mailto:) with the details you filled in, and the message reaches our inbox directly through your own email account.

Newsletter sign-up

When you sign up for the newsletter, your email address is sent to our server, recorded in a database we maintain, and forwarded to Mailchimp, the service we use to send the newsletter. Sign-up is completed with double opt-in: Mailchimp sends you an email with a confirmation link, and you receive nothing else until you click it.

Legal basis: your consent (Article 6(1)(a) GDPR). You can withdraw it at any time via the unsubscribe link in every email you receive, or by messaging us.

Recording your cookie choice

When you click "Accept all" or "Reject" on the cookie banner, your choice is stored locally on your device and additionally recorded on our server as proof of consent. This record contains: a random identifier generated by your browser (it isn't your IP and doesn't identify you by name), your two choices (analytics / advertising), your browser's user-agent, and the time.

Legal basis: our obligation to be able to demonstrate that consent was given (Article 7(1) GDPR). Details in the Cookie Policy.

Accessibility preferences

Accessibility settings (font size, contrast, reduced motion) are stored only locally on your device (browser localStorage) and are never sent to our servers.

Analytics

We use Vercel Web Analytics, a service that doesn't use cookies or store a persistent visitor identifier.

Abuse protection

To prevent the newsletter form from being abused (e.g. mass-sending confirmation emails to third parties), we limit how many submissions we accept from the same connection. For this we temporarily keep a cryptographic code (HMAC) of your IP — not the IP itself, which is never stored anywhere — together with a counter. This record is automatically deleted once the time window (one hour) expires.

Legal basis: our legitimate interest in protecting the service from abuse (Article 6(1)(f) GDPR).

Who it's shared with

We don't sell or rent personal data. The data described above is accessible only to the providers needed to run the site, as processors acting on our behalf:

  • Vercel Inc. (USA) — site hosting and cookieless analytics.
  • Neon Inc. (USA) — the database where newsletter sign-ups and consent records are stored. The server is currently located in the USA (us-east-1).
  • Intuit Mailchimp (USA) — sending the newsletter, only for those who sign up.

Because these providers are based in the USA, data is transferred outside the EEA. These transfers are covered by the Standard Contractual Clauses (SCCs) included in each provider's data processing terms.

How long we keep it

  • Newsletter sign-ups: until you unsubscribe or request deletion. Addresses recorded in our database that never made it to the sending list (e.g. due to a technical error) are automatically deleted after 12 months.
  • Cookie consent records: kept for 24 months from each choice, which is how long the consent itself lasts, and then deleted.
  • Messages from the contact/franchise forms: remain in our inbox for as long as needed to respond to your request.

Your rights

Under the General Data Protection Regulation (GDPR), you have the right to:

  • Access the data concerning you
  • Correct inaccurate data
  • Erasure ("the right to be forgotten")
  • Restrict or object to processing
  • Data portability
  • Lodge a complaint with the Hellenic Data Protection Authority (HDPA)

To exercise any of these, email us at info@bridgecoffeeroasters.com and we'll reply within one month. To unsubscribe from the newsletter, just use the unsubscribe link at the bottom of every email.

Our stores

Our physical stores (Drapetsona, Keratsini, Piraeus, Nikaia, Peristeri) may process data separately (e.g. security cameras, point-of-sale system) — this policy covers the website only.

Changes

We may update this policy. Draft last updated: 29/07/2026.