EU Privacy Policy

This Privacy Policy applies to users located in the European Union (EU) and European Economic Area (EEA). It describes how TBDx Europe GmbH and TBDx Inc. process personal data under Regulation (EU) 2016/679 (EU General Data Protection Regulation / EU GDPR) when you visit europe.xbloom.com, use the xBloom mobile application, or operate our coffee machinery shipped from our EU central warehouse network (Germany & Netherlands).

1. DATA CONTROLLER & EU REPRESENTATIVE

Data Controller (Art. 4(7) EU GDPR):

TBDx Europe GmbH, c/o WeWork, Taunusanlage 8, 60329 Frankfurt am Main, Germany

Amtsgericht Frankfurt am Main | Email: privacy@tbdx.design

Designated EU Representative (Art. 27 EU GDPR):

De Posthoornstraat 1, 5048 AS Tilburg, Netherlands | Email: support@xbloom.com

2. CATEGORIES OF PERSONAL DATA COLLECTED

  • (1) Contact & Order Information: Full name, billing address, EU shipping address, email address, telephone number, account login credentials.
  • (2) xBloom App Recipe Parameters: Detailed coffee brewing data generated in Quick Mode and Get Created Mode (Pour Numbers, Grind Sizes, Water Volumes per pour, Temperature, Pour Pattern, Pauses, Vibration settings).
  • (3) Connected Device Diagnostics: Machine serial number, firmware logs, RFID pod scanner logs, error codes, total brew count, and Wi-Fi pairing parameters.
  • (4) Payment Information: Tokenized payment details processed by PCI-DSS certified partners (Shopify Payments, Klarna, Stripe).

3. LAWFUL BASES FOR DATA PROCESSING (ART. 6 EU GDPR)

Processing Activity Legal Basis under Art. 6(1) EU GDPR
Order fulfillment from DE/NL warehouses & invoicing Art. 6(1)(b) EU GDPR (Performance of a contract)
Executing App brewing modes (Quick Mode & Get Created Mode) Art. 6(1)(b) EU GDPR (Performance of a contract)
Statutory EU warranty (2 years) & customer service support Art. 6(1)(b) & (c) EU GDPR (Contract & Legal obligation)
Marketing newsletters & offers Art. 6(1)(a) EU GDPR (Explicit Consent)
Firmware updates (OTA) & IT security Art. 6(1)(f) EU GDPR (Legitimate Interests)

4. INTERNATIONAL DATA TRANSFERS OUTSIDE THE EEA

If personal data is transferred outside the EEA (e.g. cloud servers in the United States), safeguards under Art. 44 et seq. EU GDPR are enforced:

  • (1) Adequacy Decisions: Transfers to countries approved by the European Commission.
  • (2) Standard Contractual Clauses (SCCs): Execution of EU Commission Standard Contractual Clauses.
  • (3) EU-U.S. Data Privacy Framework (DPF): Transfers to certified U.S. entities.

5. YOUR RIGHTS UNDER EU GDPR

Under Articles 15 to 22 of the EU GDPR, you hold full statutory rights:

  • (1) Right of Access (Art. 15): Free confirmation and copy of personal data.
  • (2) Right to Rectification (Art. 16): Correction of inaccurate data.
  • (3) Right to Erasure (Art. 17): Deletion of data when legal purpose expires.
  • (4) Right to Revoke Consent (Art. 7(3)): Withdraw consent at any time.

To exercise your rights, email privacy@tbdx.design.

6. DATA RETENTION SCHEDULES

Fiscal & invoice records are stored for 10 years under EU national tax laws. App accounts are deleted within 30 days of deletion request.

Have Questions About Your Privacy?

Our Privacy Officer and Support Team are here to assist you with any questions regarding your personal data or exercising your data subject rights.

Contact Privacy Team