Privacy Policy

Privacy Policy

Last Updated: June 15, 2026

Chocolate Studio FERI operates this shop and website, including all associated information, content, features, tools, products, and services, to provide you, the customer, with a personalized shopping experience (the "Services"). Chocolate Studio FERI is powered by Shopify, which enables us to provide you with the Services. This Privacy Policy describes how we collect, use, or share personal data when you visit or use the website, make a purchase or other transaction using the Services, or otherwise communicate with us. If there is a conflict between our terms and conditions and this Privacy Policy, this Privacy Policy shall prevail with respect to the collection, processing, and disclosure of your personal data.

Please read this Privacy Policy carefully. By using and accessing any of the Services, you confirm that you have read this Privacy Policy and agree to the collection, use, and sharing of your data as described in this Privacy Policy.

Course Booking System

We operate a course booking system at booking.feri-chocolates.de. When you book a course through this system, we collect the following data:

  • Name
  • Email Address
  • Phone Number (optional)

This data is used exclusively to process your course booking, especially for sending the booking confirmation and a reminder email before the course starts.

Legal Basis: Art. 6 para. 1 lit. b GDPR (performance of a contract)

For the operation of the course booking system, we use the following data processors:

  • IONOS SE (Web Hosting, Germany) – DPA available
  • Supabase Inc. (Database, Frankfurt/EU) – DPA available
  • Resend Inc. (Email Sending, USA) – Data transfer based on EU Standard Contractual Clauses (Art. 46 para. 2 lit. c GDPR)

Booking data will be deleted after the tax retention periods (10 years) have expired. At your request, we will delete your data prematurely, provided there are no legal retention obligations. Please contact info@feri-chocolates.de for this purpose.

What personal data do we collect or process?

When we use the term "personal data," we refer to information that identifies or can be directly associated with you or another person. Personal data does not include information that has been collected anonymously or anonymized in such a way that identification or attribution to you is not possible. Depending on how you interact with the Services, where you reside, and as permitted or required by applicable law, we may collect or process the following categories of personal data, including inferences drawn from that personal data:

  • Contact Information including name, mailing address, billing address, shipping address, phone number, and email address.
  • Financial Information including credit, debit card, and financial account numbers, payment card information, financial account information, transaction details, payment method, payment confirmation, and other payment details.
  • Account Information including username, password, security questions, configurations, and settings.
  • Transaction Information including items you view, add to cart, wishlist, or purchase, return, exchange, or cancel, as well as your past transactions.
  • Communications with us including information you provide when communicating with us, for example, when you submit a customer support request.
  • Device Information including information about your device, browser, or network connection, IP address, and other unique identifiers.
  • Usage Information including information about your interaction with the Services, including how and when you interact with or browse them.

Sources of personal data

We may collect personal data through the following sources:

  • Directly from you We collect data, among other things, when you create an account, access or use the Services, communicate with us, or otherwise provide us with your personal data.
  • Automatically via the Services We collect data, among other things, from your device or when you use our products or services or visit our website, as well as through the use of cookies and similar technologies.
  • From our service providers We collect data, among other things, when we engage service providers to enable certain technologies and when they collect or process your personal data on our behalf.
  • From our partners and other third-party providers

How do we use your personal data?

Depending on how you interact with us or which of the Services you use, we may use personal data for the following purposes:

  • Providing, customizing, and improving the Services. We use your personal data to provide you with the Services. This includes, among other things, fulfilling our contract with you, processing your payments, fulfilling your orders, storing your configurations and the items you are interested in, organizing shipping, facilitating returns and exchanges, enabling you to submit reviews, and creating a personalized shopping experience for you, for example, by recommending products based on your purchases. This may also include using your personal data to better customize and improve the Services.
  • Marketing and advertising. We use your personal data for marketing and advertising purposes, for example, to send marketing and promotional communications via email, SMS, or postal mail and to display online advertisements for products or services for the Services or other websites, including based on items you previously purchased or added to your cart, as well as other activities related to the Services.
  • Security and fraud prevention. We use your personal data to authenticate your account, provide a secure payment and shopping experience, detect, investigate, or take action against possible fraudulent, illegal, unsafe, or malicious activities, protect public safety, and ensure the security of our Services.
  • Communication with you. We use your personal data to provide you with customer support and effective services, respond to your inquiries in a timely manner, and maintain our business relationship with you.
  • Legal reasons. We use your personal data to comply with applicable law or respond to legal process, including requests from law enforcement or regulatory authorities, to investigate or participate in civil investigations, potential or actual litigation, or other adversarial proceedings, and to investigate potential violations of our terms or policies or to enforce the terms and policies.

How do we share personal data?

Under certain circumstances, we may share your personal data with third parties for legitimate purposes in accordance with this Privacy Policy. Such circumstances may include:

  • With Shopify, these are providers and other third parties who provide services on our behalf (e.g., IT management, payment processing, data analysis, customer support, cloud storage, fulfillment, and shipping).
  • We share personal data with business and marketing partners who provide marketing services to you and display advertisements to you.
  • If you request or otherwise consent to share certain information with third parties.
  • We share personal data with our affiliates or otherwise within our corporate group.
  • In connection with a business transaction such as a merger or insolvency, to comply with applicable legal obligations, to enforce applicable terms of service or policies, and to protect or defend the Services, our rights, and the rights of our users or others.

Relationship with Shopify

The Services are hosted by Shopify, where Shopify collects and processes personal data about your access to and use of the Services to provide and improve them to you. To protect, expand, and improve our business, we also use certain advanced Shopify features that incorporate data and information from your interactions with our shop, with other merchants, and with Shopify. For more information on how Shopify uses your personal data and what rights you have, please see the Shopify Consumer Privacy Policy. Depending on where you reside, you can exercise certain rights regarding your personal data listed here: Shopify Privacy Portal.

Social Media

We are present on the following social media platforms:

  • Instagram (Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland)
  • Facebook (Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland)

Our website contains simple links to our profiles on these platforms. Only when you click on such a link and visit the respective platform do Meta's data protection regulations apply.

In addition, Instagram posts may be embedded on individual pages of our website. These contents are not loaded automatically. Only when you actively click on "Load content" will data (in particular your IP address and browser information) be transferred to Meta Platforms Ireland Limited and the Instagram post displayed. By clicking, you consent to the data transfer to Meta.

Legal basis: Art. 6 para. 1 lit. a GDPR (consent). You can withdraw your consent at any time for the future by revisiting the relevant page and not reloading the content.

Information on data processing by Meta can be found at: https://www.facebook.com/privacy/policy/. Meta may collect and process personal data even if you do not have an account with Instagram or Facebook. We have no influence on this data processing.

Third-Party Websites and Links

The Services may provide links to websites or other online platforms operated by third parties. If you follow links to websites that are not affiliate websites or not controlled by us, you should review their privacy and security policies and other terms and conditions. We do not guarantee and are not responsible for the privacy or security of such websites, including the accuracy, completeness, or reliability of the information located on these websites. Our inclusion of such links does not imply endorsement of the content of these platforms or their owners or operators, unless explicitly stated in the Services.

Children's Data

The Services are not intended for use by children, and we do not knowingly collect personal data from children who are not yet of legal age in your country. If you are the parent or guardian of a child who has provided us with their personal data, you can contact us using the contact details provided below to request the deletion of this data.

Security and Retention of Your Data

Please note that no security measures are perfect or impenetrable, and therefore we cannot guarantee "perfect security." In addition, information you send to us may be subject to risks during transmission. We recommend that you do not use insecure channels when submitting sensitive or confidential information to us.

How long we retain your personal data depends on various factors. These include, for example, whether we need the data to manage your account, provide you with Services, comply with legal obligations, resolve disputes, or enforce other applicable contracts and policies.

Your Rights and Options

Depending on where you reside, you may have some or all of the rights listed below regarding your personal data. However, these rights are not absolute, may apply only under certain circumstances, and in certain cases, we may deny your request to the extent permitted by law.

  • Right to Access/Information. You may have the right to request access to the personal data we hold about you.
  • Right to Erasure. You may have the right to request that we delete the personal data we hold about you.
  • Right to Rectification. You may have the right to request that we correct inaccurate personal data we hold about you.
  • Right to Data Portability. You may have the right to receive a copy of the personal data we hold about you and to request that we transmit it to a third party under certain circumstances and with certain exceptions.
  • Managing communication settings. We may send you promotional emails. You can object to receiving these emails at any time by using the unsubscribe option included in our emails to you.

If your residence is in the United Kingdom or the European Economic Area, subject to the exceptions and limitations of local law, you may additionally exercise the following rights:

  • Right to Object and Right to Restriction of Processing. You may have the right to request that we cease or restrict the processing of personal data for certain purposes.
  • Withdrawal of Consent. Where we rely on consent to process your personal data, you have the right to withdraw that consent.

You can exercise these rights where indicated in the Services, or by contacting us using the contact details provided below. For more information on how Shopify uses your personal data and what rights you have, please visit https://privacy.shopify.com/en.

Complaints

If you have any complaints about how we process your personal data, please contact us using the contact details provided below. Depending on where you reside, you have the right to object to our decision by contacting us or by lodging your complaint with the competent data protection authority. For the European Economic Area, you can find the competent data protection supervisory authorities here.

International Transfers

Please note that we may transfer, store, and process your personal data outside the country in which you reside.

When we transfer your personal data outside the European Economic Area or the United Kingdom, we rely on recognized transfer mechanisms such as the European Commission's Standard Contractual Clauses or equivalent agreements issued by the respective competent authority of the United Kingdom, unless the data transfer takes place to a country that demonstrably provides an adequate level of protection.

Changes to this Privacy Policy

We may update this Privacy Policy from time to time, for example, to reflect changes in our practices, or for other operational, legal, or regulatory reasons. We will publish the revised Privacy Policy on this website and adjust the "Last Updated" date accordingly.

Contact

Should you have any questions about our data protection practices or this privacy policy, or if you wish to exercise any of your rights, please contact us by phone at +49 89 80 03 86 77, by email at info@feri-chocolates.de, or by mail at Marktstraße 15, Munich, 80802, DE. For the purposes of applicable data protection laws, we are the data controller for your personal data.

Subscribe to the newsletter

Receive exclusive offers and early access to new products, workshops, and events.