{"id":2579,"date":"2026-01-10T21:15:17","date_gmt":"2026-01-10T20:15:17","guid":{"rendered":"https:\/\/kokitchen.berlin\/?page_id=2579"},"modified":"2026-01-10T21:15:18","modified_gmt":"2026-01-10T20:15:18","slug":"membership-privacy-policy","status":"publish","type":"page","link":"https:\/\/kokitchen.berlin\/en\/membership-privacy-policy\/","title":{"rendered":"KO KITCHEN PRIVACY POLICY"},"content":{"rendered":"\n<p><strong>Membership Card Program<\/strong><br><strong>Last Updated: January 10, 2026<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"1-information-controller\">1. INFORMATION CONTROLLER<\/h2>\n\n\n\n<p><strong>Company Name:<\/strong>&nbsp;Ko Kitchen<br><strong>Operator:<\/strong>&nbsp;Nico Borchert<br><strong>Address:<\/strong>&nbsp;Harzer Street 39, 12059 Berlin, Germany<br><strong>Email:<\/strong>&nbsp;<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"mailto:info@kokitchen.berlin\">info@kokitchen.berlin<\/a><br><strong>Tax ID (Steuernummer):<\/strong>&nbsp;16\/236\/03495<br><strong>VAT ID (USt-IdNr):<\/strong>&nbsp;DE368760326<\/p>\n\n\n\n<p>This Privacy Policy explains how Ko Kitchen (&#8220;Company,&#8221; &#8220;we,&#8221; &#8220;us,&#8221; or &#8220;our&#8221;) collects, uses, processes, and protects personal data collected through the Ko Kitchen Membership Card Program.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"2-legal-basis--regulatory-compliance\">2. LEGAL BASIS &amp; REGULATORY COMPLIANCE<\/h2>\n\n\n\n<p>Ko Kitchen complies with:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>GDPR (General Data Protection Regulation)<\/strong>\u00a0&#8211; EU Regulation 2016\/679<\/li>\n\n\n\n<li><strong>German Data Protection Act (BDSG)<\/strong>\u00a0&#8211; Bundesdatenschutzgesetz<\/li>\n\n\n\n<li><strong>German Telemedia Act (TMG)<\/strong>\u00a0&#8211; Telemediengesetz<\/li>\n\n\n\n<li><strong>German Civil Code (BGB)<\/strong>\u00a0&#8211; B\u00fcrgerliches Gesetzbuch<\/li>\n<\/ul>\n\n\n\n<p>All personal data processing is based on one or more of the following legal grounds:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Consent (Article 6(1)(a) GDPR)<\/li>\n\n\n\n<li>Contractual necessity (Article 6(1)(b) GDPR)<\/li>\n\n\n\n<li>Legal obligation (Article 6(1)(c) GDPR)<\/li>\n\n\n\n<li>Legitimate interests (Article 6(1)(f) GDPR)<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"3-data-we-collect\">3. DATA WE COLLECT<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">3.1 Information You Provide Directly<\/h3>\n\n\n\n<p><strong>During Registration &amp; Account Creation:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Full name<\/li>\n\n\n\n<li>Email address<\/li>\n\n\n\n<li>Phone number<\/li>\n\n\n\n<li>Residential address<\/li>\n\n\n\n<li>Date of birth (if required for age verification)<\/li>\n\n\n\n<li>Payment information (card details, bank account, etc.)<\/li>\n\n\n\n<li>Device identification (for mobile wallet integration)<\/li>\n<\/ul>\n\n\n\n<p><strong>During Membership Use:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Meal selections and redemption history<\/li>\n\n\n\n<li>Dates and times of meal claims<\/li>\n\n\n\n<li>Device information (phone model, operating system, etc.)<\/li>\n\n\n\n<li>Account activity logs<\/li>\n<\/ul>\n\n\n\n<p><strong>During Communication:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Messages, inquiries, and correspondence sent to Ko Kitchen<\/li>\n\n\n\n<li>Customer service interactions and support tickets<\/li>\n\n\n\n<li>Feedback and complaints<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">3.2 Information Collected Automatically<\/h3>\n\n\n\n<p><strong>Device &amp; Technical Data:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>IP address<\/li>\n\n\n\n<li>Device type and identifier<\/li>\n\n\n\n<li>Mobile wallet provider information (Apple Wallet, Google Pay, etc.)<\/li>\n\n\n\n<li>Browser or app type and version<\/li>\n\n\n\n<li>Operating system<\/li>\n\n\n\n<li>Geographic location (if enabled)<\/li>\n<\/ul>\n\n\n\n<p><strong>Usage Analytics:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Pages or features accessed<\/li>\n\n\n\n<li>Time and date of access<\/li>\n\n\n\n<li>Frequency of card usage<\/li>\n\n\n\n<li>Links clicked<\/li>\n\n\n\n<li>Actions taken within the app or platform<\/li>\n\n\n\n<li>Error logs and technical issues<\/li>\n<\/ul>\n\n\n\n<p><strong>Payment Data:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Transaction records<\/li>\n\n\n\n<li>Payment method (partial details for security)<\/li>\n\n\n\n<li>Billing history<\/li>\n\n\n\n<li>Refund records<\/li>\n\n\n\n<li>Failed payment attempts<\/li>\n<\/ul>\n\n\n\n<p>This data is collected through:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Cookies and similar tracking technologies<\/li>\n\n\n\n<li>Web server logs<\/li>\n\n\n\n<li>Analytics tools<\/li>\n\n\n\n<li>Third-party payment processors<\/li>\n\n\n\n<li>Mobile wallet providers<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">3.3 Data from Third Parties<\/h3>\n\n\n\n<p>Ko Kitchen may receive personal data from:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Payment processors (payment and billing information)<\/li>\n\n\n\n<li>Mobile wallet providers (installation and usage confirmation)<\/li>\n\n\n\n<li>Third-party analytics services<\/li>\n\n\n\n<li>Law enforcement (if legally required)<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"4-purpose-of-data-processing\">4. PURPOSE OF DATA PROCESSING<\/h2>\n\n\n\n<p>Ko Kitchen processes your personal data for the following purposes:<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">4.1 Core Membership Services<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Creating and maintaining your membership account<\/li>\n\n\n\n<li>Issuing your digital membership card<\/li>\n\n\n\n<li>Processing meal claims and redemptions<\/li>\n\n\n\n<li>Tracking meal allowances and validity periods<\/li>\n\n\n\n<li>Managing your membership plan<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">4.2 Billing &amp; Payment Processing<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Processing membership fees and payments<\/li>\n\n\n\n<li>Sending billing confirmations and invoices<\/li>\n\n\n\n<li>Managing payment methods and updates<\/li>\n\n\n\n<li>Handling refunds and chargebacks<\/li>\n\n\n\n<li>Detecting and preventing fraud<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">4.3 Communication<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Sending confirmation emails for registrations and transactions<\/li>\n\n\n\n<li>Providing membership renewal notices<\/li>\n\n\n\n<li>Notifying about billing dates and next billing information<\/li>\n\n\n\n<li>Responding to customer inquiries and support requests<\/li>\n\n\n\n<li>Sending service announcements and updates<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">4.4 Service Improvement<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Analyzing usage patterns to improve the membership program<\/li>\n\n\n\n<li>Understanding customer preferences and behavior<\/li>\n\n\n\n<li>Developing new features and enhancements<\/li>\n\n\n\n<li>Conducting anonymized statistical analysis<\/li>\n\n\n\n<li>Testing platform performance and reliability<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">4.5 Legal &amp; Compliance<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Complying with applicable laws and regulations<\/li>\n\n\n\n<li>Fulfilling tax and accounting obligations<\/li>\n\n\n\n<li>Preventing fraud, abuse, and unauthorized use<\/li>\n\n\n\n<li>Enforcing Terms and Conditions<\/li>\n\n\n\n<li>Responding to legal requests and law enforcement inquiries<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">4.6 Security<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Detecting unauthorized access and suspicious activity<\/li>\n\n\n\n<li>Protecting against malware, viruses, and cyber attacks<\/li>\n\n\n\n<li>Ensuring account security and integrity<\/li>\n\n\n\n<li>Preventing unauthorized use of membership cards<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">4.7 Marketing &amp; Promotions (if consented)<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Sending newsletters and promotional offers (only if you opt-in)<\/li>\n\n\n\n<li>Informing about special events and menu changes<\/li>\n\n\n\n<li>Conducting surveys and customer feedback requests<\/li>\n\n\n\n<li>Personalizing your experience based on preferences<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"5-legal-basis-for-processing\">5. LEGAL BASIS FOR PROCESSING<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">Processing Purpose<\/th><th class=\"has-text-align-left\" data-align=\"left\">Legal Basis<\/th><th class=\"has-text-align-left\" data-align=\"left\">Duration<\/th><\/tr><\/thead><tbody><tr><td>Membership account management<\/td><td>Contract (Article 6(1)(b) GDPR)<\/td><td>Duration of membership + 7 years (tax retention)<\/td><\/tr><tr><td>Payment processing &amp; billing<\/td><td>Contract + Legal obligation<\/td><td>Duration of membership + 10 years (tax records)<\/td><\/tr><tr><td>Communication &amp; support<\/td><td>Contract + Consent<\/td><td>Duration of membership + reasonable period<\/td><\/tr><tr><td>Fraud prevention &amp; security<\/td><td>Legitimate interest (Article 6(1)(f) GDPR)<\/td><td>Duration of membership + limited retention<\/td><\/tr><tr><td>Analytics &amp; improvement<\/td><td>Consent + Legitimate interest<\/td><td>Duration of membership + 12 months<\/td><\/tr><tr><td>Marketing communications<\/td><td>Explicit consent (Article 6(1)(a) GDPR)<\/td><td>Until withdrawal of consent<\/td><\/tr><tr><td>Legal compliance<\/td><td>Legal obligation (Article 6(1)(c) GDPR)<\/td><td>As required by law<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"6-data-retention\">6. DATA RETENTION<\/h2>\n\n\n\n<p>Ko Kitchen retains personal data based on the following periods:<\/p>\n\n\n\n<p><strong>Active Membership Data:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Retained for the duration of your membership<\/li>\n\n\n\n<li>Deleted within 30 days of account termination (unless legal obligations require retention)<\/li>\n<\/ul>\n\n\n\n<p><strong>Billing &amp; Financial Data:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Retained for 10 years (German tax law requirement &#8211; AStG, UStG)<\/li>\n\n\n\n<li>Includes transaction records, invoices, and payment receipts<\/li>\n<\/ul>\n\n\n\n<p><strong>Communication Records:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Retained for 2 years after membership termination<\/li>\n\n\n\n<li>May be extended if disputes are pending<\/li>\n<\/ul>\n\n\n\n<p><strong>Analytics &amp; Usage Data:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Anonymized data retained for 12 months<\/li>\n\n\n\n<li>Identifiable data deleted after 12 months (unless required for legal obligations)<\/li>\n<\/ul>\n\n\n\n<p><strong>Payment Method Details:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Deleted when payment method is updated<\/li>\n\n\n\n<li>Or within 30 days of membership termination<\/li>\n<\/ul>\n\n\n\n<p><strong>Marketing Data:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Retained only while you have consented to communications<\/li>\n\n\n\n<li>Deleted within 30 days of consent withdrawal<\/li>\n<\/ul>\n\n\n\n<p><strong>Legal &amp; Compliance Data:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Retained as required by applicable law (tax, regulatory, legal disputes)<\/li>\n\n\n\n<li>Minimum 7-10 years for financial records<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"7-data-sharing--recipients\">7. DATA SHARING &amp; RECIPIENTS<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">7.1 Internal Sharing<\/h3>\n\n\n\n<p>Personal data is shared internally only with Ko Kitchen personnel who require access to fulfill their roles:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Account management team<\/li>\n\n\n\n<li>Customer service representatives<\/li>\n\n\n\n<li>Finance and billing department<\/li>\n\n\n\n<li>Legal and compliance officers<\/li>\n\n\n\n<li>Technical support staff<\/li>\n<\/ul>\n\n\n\n<p>All internal personnel are bound by confidentiality obligations.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">7.2 Third-Party Processors &amp; Service Providers<\/h3>\n\n\n\n<p>Ko Kitchen shares personal data with the following categories of third parties (Data Processors under GDPR):<\/p>\n\n\n\n<p><strong>Payment Processors:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Credit card companies (Visa, Mastercard, etc.)<\/li>\n\n\n\n<li>SumUp<\/li>\n\n\n\n<li>Bank transfer systems<\/li>\n\n\n\n<li>Payment gateway providers<\/li>\n\n\n\n<li>These parties process payment information to process your fees<\/li>\n<\/ul>\n\n\n\n<p><strong>Digital Wallet Providers:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Apple Inc. (for Apple Wallet)<\/li>\n\n\n\n<li>Google LLC (for Google Pay)<\/li>\n\n\n\n<li>Other mobile wallet providers<\/li>\n\n\n\n<li>These parties assist in card delivery and management<\/li>\n<\/ul>\n\n\n\n<p><strong>Email &amp; Communication Services:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Email service providers (for sending confirmations and notifications)<\/li>\n\n\n\n<li>Customer service platforms<\/li>\n<\/ul>\n\n\n\n<p><strong>Analytics &amp; Service Providers:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Analytics tools (e.g., Google Analytics)<\/li>\n\n\n\n<li>Hosting providers<\/li>\n\n\n\n<li>Cloud storage services<\/li>\n\n\n\n<li>Technical support services<\/li>\n<\/ul>\n\n\n\n<p><strong>Payment Verification:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Identity verification services (age and fraud verification)<\/li>\n\n\n\n<li>Credit reporting agencies (if necessary)<\/li>\n<\/ul>\n\n\n\n<p>All third-party processors have signed Data Processing Agreements (DPA) ensuring GDPR compliance.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">7.3 Legal Obligations &amp; Law Enforcement<\/h3>\n\n\n\n<p>Ko Kitchen may disclose personal data if:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Required by law (court orders, government requests)<\/li>\n\n\n\n<li>Necessary to enforce Ko Kitchen&#8217;s legal rights<\/li>\n\n\n\n<li>Essential to protect the security or integrity of the platform<\/li>\n\n\n\n<li>Required to comply with tax, regulatory, or legal obligations<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">7.4 No Sale of Data<\/h3>\n\n\n\n<p><strong>Ko Kitchen does not sell personal data to third parties.<\/strong>&nbsp;Data is only shared as necessary to provide the membership service or as required by law.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"8-your-data-subject-rights\">8. YOUR DATA SUBJECT RIGHTS<\/h2>\n\n\n\n<p>Under GDPR and German data protection law, you have the following rights:<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">8.1 Right of Access (Article 15 GDPR)<\/h3>\n\n\n\n<p>You have the right to request and obtain a copy of all personal data Ko Kitchen holds about you in a structured, commonly used, and machine-readable format.<\/p>\n\n\n\n<p><strong>How to Exercise:<\/strong>&nbsp;Email&nbsp;<strong><a rel=\"noreferrer noopener\" target=\"_blank\" href=\"mailto:info@kokitchen.berlin\">info@kokitchen.berlin<\/a><\/strong>&nbsp;with the subject &#8220;Data Access Request&#8221;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">8.2 Right to Rectification (Article 16 GDPR)<\/h3>\n\n\n\n<p>You have the right to correct or update inaccurate or incomplete personal data.<\/p>\n\n\n\n<p><strong>How to Exercise:<\/strong>&nbsp;Log into your account to update information, or email&nbsp;<strong><a rel=\"noreferrer noopener\" target=\"_blank\" href=\"mailto:info@kokitchen.berlin\">info@kokitchen.berlin<\/a><\/strong><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">8.3 Right to Erasure (&#8220;Right to be Forgotten&#8221;) (Article 17 GDPR)<\/h3>\n\n\n\n<p>You have the right to request deletion of your personal data, except where:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Data is necessary to perform the membership contract<\/li>\n\n\n\n<li>Required by legal obligations (tax records, 7-10 years)<\/li>\n\n\n\n<li>Needed for legal claims or defenses<\/li>\n<\/ul>\n\n\n\n<p><strong>How to Exercise:<\/strong>&nbsp;Email&nbsp;<strong><a rel=\"noreferrer noopener\" target=\"_blank\" href=\"mailto:info@kokitchen.berlin\">info@kokitchen.berlin<\/a><\/strong>&nbsp;with &#8220;Deletion Request&#8221;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">8.4 Right to Restrict Processing (Article 18 GDPR)<\/h3>\n\n\n\n<p>You have the right to request that Ko Kitchen limit the processing of your data in specific circumstances, such as:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>If you dispute the accuracy of data<\/li>\n\n\n\n<li>If processing is unlawful but you request restriction rather than deletion<\/li>\n\n\n\n<li>If Ko Kitchen no longer needs the data, but you need it for legal claims<\/li>\n<\/ul>\n\n\n\n<p><strong>How to Exercise:<\/strong>&nbsp;Email&nbsp;<strong><a rel=\"noreferrer noopener\" target=\"_blank\" href=\"mailto:info@kokitchen.berlin\">info@kokitchen.berlin<\/a><\/strong>&nbsp;with &#8220;Restriction Request&#8221;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">8.5 Right to Data Portability (Article 20 GDPR)<\/h3>\n\n\n\n<p>You have the right to receive your personal data in a structured, commonly used, machine-readable format and have it transferred to another controller.<\/p>\n\n\n\n<p><strong>How to Exercise:<\/strong>&nbsp;Email&nbsp;<strong><a rel=\"noreferrer noopener\" target=\"_blank\" href=\"mailto:info@kokitchen.berlin\">info@kokitchen.berlin<\/a><\/strong>&nbsp;with &#8220;Data Portability Request&#8221;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">8.6 Right to Object (Article 21 GDPR)<\/h3>\n\n\n\n<p>You have the right to object to:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Processing based on legitimate interests<\/li>\n\n\n\n<li>Direct marketing and promotional communications<\/li>\n\n\n\n<li>Automated decision-making and profiling<\/li>\n<\/ul>\n\n\n\n<p><strong>How to Exercise:<\/strong>&nbsp;Email&nbsp;<strong><a rel=\"noreferrer noopener\" target=\"_blank\" href=\"mailto:info@kokitchen.berlin\">info@kokitchen.berlin<\/a><\/strong>&nbsp;with &#8220;Objection to Processing&#8221;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">8.7 Right to Withdraw Consent (Article 7(3) GDPR)<\/h3>\n\n\n\n<p>If processing is based on your consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing based on prior consent.<\/p>\n\n\n\n<p><strong>How to Exercise:<\/strong>&nbsp;Email&nbsp;<strong><a rel=\"noreferrer noopener\" target=\"_blank\" href=\"mailto:info@kokitchen.berlin\">info@kokitchen.berlin<\/a><\/strong>&nbsp;or adjust preferences in your account<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">8.8 Right to Lodge Complaints<\/h3>\n\n\n\n<p>You have the right to lodge a complaint with the applicable data protection authority:<\/p>\n\n\n\n<p><strong>German Data Protection Authorities:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Federal Level:<\/strong>\u00a0Bundesbeauftragte f\u00fcr den Datenschutz und die Informationsfreiheit (BfDI)<br>Website:\u00a0<a href=\"http:\/\/www.bfdi.bund.de\/\" target=\"_blank\" rel=\"noreferrer noopener\">www.bfdi.bund.de<\/a><\/li>\n\n\n\n<li><strong>Berlin:<\/strong>\u00a0Berliner Beauftragte f\u00fcr Datenschutz und Informationsfreiheit<br>Website:\u00a0<a href=\"http:\/\/www.datenschutz-berlin.de\/\" target=\"_blank\" rel=\"noreferrer noopener\">www.datenschutz-berlin.de<\/a><br>Email:\u00a0<a href=\"mailto:post@senbds.berlin.de\" target=\"_blank\" rel=\"noreferrer noopener\">post@senbds.berlin.de<\/a><\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"9-international-data-transfers\">9. INTERNATIONAL DATA TRANSFERS<\/h2>\n\n\n\n<p>Ko Kitchen operates within the European Union and primarily processes data within Germany. If data is transferred outside the EU\/EEA:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Transfers occur only to countries deemed to have adequate data protection<\/li>\n\n\n\n<li>Standard Contractual Clauses (SCCs) or other appropriate safeguards are implemented<\/li>\n\n\n\n<li>You will be notified of such transfers<\/li>\n<\/ul>\n\n\n\n<p>Third-party processors (like Google, Apple) may transfer data to their servers in the US or other countries. These companies comply with data protection regulations (e.g., Standard Contractual Clauses, Binding Corporate Rules).<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"10-data-security\">10. DATA SECURITY<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">10.1 Security Measures<\/h3>\n\n\n\n<p>Ko Kitchen implements industry-standard security measures to protect your personal data:<\/p>\n\n\n\n<p><strong>Technical Safeguards:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Encryption in transit (SSL\/TLS &#8211; HTTPS)<\/li>\n\n\n\n<li>Encryption at rest for sensitive data<\/li>\n\n\n\n<li>Secure payment processing (PCI DSS compliance)<\/li>\n\n\n\n<li>Firewalls and intrusion detection systems<\/li>\n\n\n\n<li>Regular security audits and vulnerability assessments<\/li>\n<\/ul>\n\n\n\n<p><strong>Organizational Safeguards:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Access controls and user authentication<\/li>\n\n\n\n<li>Employee confidentiality agreements<\/li>\n\n\n\n<li>Limited access to personal data (need-to-know basis)<\/li>\n\n\n\n<li>Incident response procedures<\/li>\n\n\n\n<li>Regular staff training on data protection<\/li>\n<\/ul>\n\n\n\n<p><strong>Mobile Wallet Security:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Digital cards are encrypted on your device<\/li>\n\n\n\n<li>Protected by your device&#8217;s security (passcode, biometrics)<\/li>\n\n\n\n<li>Tokenized card data to prevent exposure<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">10.2 Data Breach Notification<\/h3>\n\n\n\n<p>In the unlikely event of a data breach that compromises your personal data, Ko Kitchen will:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Notify you without undue delay (if breach poses high risk to your rights)<\/li>\n\n\n\n<li>Notify the German data protection authority if required<\/li>\n\n\n\n<li>Provide details of the breach, affected data, and remediation measures<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"11-cookies--tracking-technologies\">11. COOKIES &amp; TRACKING TECHNOLOGIES<\/h2>\n\n\n\n<p>Ko Kitchen uses cookies and similar tracking technologies to:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Analyze usage patterns<\/li>\n\n\n\n<li>Improve user experience<\/li>\n\n\n\n<li>Prevent fraud<\/li>\n<\/ul>\n\n\n\n<p><strong>Types of Cookies:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Essential Cookies:<\/strong>\u00a0Required for membership function (no consent needed)<\/li>\n\n\n\n<li><strong>Analytics Cookies:<\/strong>\u00a0Track usage for improvement (requires consent)<\/li>\n\n\n\n<li><strong>Marketing Cookies:<\/strong>\u00a0Personalized advertising (requires consent)<\/li>\n<\/ul>\n\n\n\n<p>You can control cookies through your browser settings. Disabling non-essential cookies may affect functionality.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"12-childrens-data\">12. CHILDREN&#8217;S DATA<\/h2>\n\n\n\n<p>Ko Kitchen&#8217;s membership program is only available to individuals aged 18 and older. We do not knowingly collect personal data from children under 18. If we discover we have inadvertently collected data from a minor, we will delete it promptly.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"13-updates-to-privacy-policy\">13. UPDATES TO PRIVACY POLICY<\/h2>\n\n\n\n<p>Ko Kitchen may update this Privacy Policy to reflect changes in data protection laws, business practices, or other developments. Updates will be communicated via:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Email notification<\/li>\n\n\n\n<li>Website announcement<\/li>\n\n\n\n<li>In-app notification<\/li>\n\n\n\n<li>Update to the &#8220;Last Updated&#8221; date at the top of this policy<\/li>\n<\/ul>\n\n\n\n<p>Continued use of the membership program after changes become effective indicates your acceptance of the updated Privacy Policy. We recommend reviewing this policy regularly.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"14-contact--data-protection-requests\">14. CONTACT &amp; DATA PROTECTION REQUESTS<\/h2>\n\n\n\n<p>For inquiries about your personal data, requests to exercise your data subject rights, or data protection concerns, please contact:<\/p>\n\n\n\n<p><strong>Ko Kitchen Data Protection Contact:<\/strong><br>Email:&nbsp;<strong><a rel=\"noreferrer noopener\" target=\"_blank\" href=\"mailto:info@kokitchen.berlin\">info@kokitchen.berlin<\/a><\/strong><br>Subject: &#8220;Data Protection Request&#8221; or &#8220;Privacy Inquiry&#8221;<\/p>\n\n\n\n<p><strong>Response Time:<\/strong>&nbsp;Ko Kitchen will respond to your request within&nbsp;<strong>30 days<\/strong>&nbsp;(extendable by 60 days for complex requests under GDPR Article 12(3)).<\/p>\n\n\n\n<p><strong>Information Required:<\/strong>&nbsp;To process your request, we may ask for:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Your full name and membership email<\/li>\n\n\n\n<li>Date of birth<\/li>\n\n\n\n<li>Any additional information necessary to verify your identity<\/li>\n\n\n\n<li>Clear specification of your request<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"15-third-party-links--services\">15. THIRD-PARTY LINKS &amp; SERVICES<\/h2>\n\n\n\n<p>Ko Kitchen&#8217;s platform may contain links to third-party websites or services. This Privacy Policy applies only to Ko Kitchen&#8217;s data processing. Third-party services have their own privacy policies, and Ko Kitchen is not responsible for their data practices.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"16-legal-basis--regulatory-compliance\">16. LEGAL BASIS &amp; REGULATORY COMPLIANCE<\/h2>\n\n\n\n<p>This Privacy Policy complies with:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>GDPR (EU Regulation 2016\/679)<\/strong>\u00a0&#8211; Effective May 25, 2018<\/li>\n\n\n\n<li><strong>German Federal Data Protection Act (BDSG-neu)<\/strong>\u00a0&#8211; Effective January 1, 2018<\/li>\n\n\n\n<li><strong>German Telemedia Act (TMG)<\/strong>\u00a0&#8211; Section 13 (cookie consent)<\/li>\n\n\n\n<li><strong>German Civil Code (BGB)<\/strong>\u00a0&#8211; Consumer protection provisions<\/li>\n<\/ul>\n\n\n\n<p>Where there is a conflict between this Privacy Policy and applicable law, the law takes precedence.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"17-entire-agreement\">17. ENTIRE AGREEMENT<\/h2>\n\n\n\n<p>This Privacy Policy, along with the Ko Kitchen Terms and Conditions, constitutes the entire agreement regarding data protection and privacy in the Ko Kitchen Membership Program.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n","protected":false},"excerpt":{"rendered":"<p>Membership Card ProgramLast Updated: January 10, 2026 1. INFORMATION CONTROLLER Company Name:&nbsp;Ko KitchenOperator:&nbsp;Nico BorchertAddress:&nbsp;Harzer Street 39, 12059 Berlin, GermanyEmail:&nbsp;info@kokitchen.berlinTax ID (Steuernummer):&nbsp;16\/236\/03495VAT ID (USt-IdNr):&nbsp;DE368760326 This Privacy &#8230; <a title=\"KO KITCHEN PRIVACY POLICY\" class=\"read-more\" href=\"https:\/\/kokitchen.berlin\/en\/membership-privacy-policy\/\" aria-label=\"Read more about KO KITCHEN PRIVACY POLICY\">Read more<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_kad_blocks_custom_css":"","_kad_blocks_head_custom_js":"","_kad_blocks_body_custom_js":"","_kad_blocks_footer_custom_js":"","footnotes":""},"class_list":["post-2579","page","type-page","status-publish"],"taxonomy_info":[],"featured_image_src_large":false,"author_info":{"display_name":"admin","author_link":"https:\/\/kokitchen.berlin\/en\/author\/admin\/"},"comment_info":0,"_links":{"self":[{"href":"https:\/\/kokitchen.berlin\/en\/wp-json\/wp\/v2\/pages\/2579","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/kokitchen.berlin\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/kokitchen.berlin\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/kokitchen.berlin\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/kokitchen.berlin\/en\/wp-json\/wp\/v2\/comments?post=2579"}],"version-history":[{"count":2,"href":"https:\/\/kokitchen.berlin\/en\/wp-json\/wp\/v2\/pages\/2579\/revisions"}],"predecessor-version":[{"id":2581,"href":"https:\/\/kokitchen.berlin\/en\/wp-json\/wp\/v2\/pages\/2579\/revisions\/2581"}],"wp:attachment":[{"href":"https:\/\/kokitchen.berlin\/en\/wp-json\/wp\/v2\/media?parent=2579"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}