Privacy Policy
As of: June 2026 | Mokka Milch GmbH
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) and other national data protection laws is:
Mokka Milch GmbH
Karl-Marx-Allee 35, 10178 Berlin, Germany
Commercial Register: HRB 281809, Amtsgericht Charlottenburg
Email: hallo@mokkamilch.de
Phone: 030 56293528
2. Data Protection Officer
Our Data Protection Officer is:
Alexander Neumann
Mokka Milch GmbH, Karl-Marx-Allee 35, 10178 Berlin, Germany
Email: hallo@mokkamilch.de
You may contact our Data Protection Officer at any time with questions regarding data protection law or to exercise your data subject rights.
3. General Information on Data Processing
We process personal data of our users only to the extent necessary to provide a functional website and our content and services. Data is processed on the basis of the following legal grounds:
Art. 6(1)(a) GDPR – Consent of the data subject
Art. 6(1)(b) GDPR – Performance of a contract or pre-contractual measures
Art. 6(1)(c) GDPR – Compliance with a legal obligation
Art. 6(1)(f) GDPR – Legitimate interests of the controller
4. Hosting & Server Log Files
Our website is hosted by Strato AG (Otto-Ostrowski-Straße 7, 10249 Berlin, Germany). A data processing agreement (DPA) pursuant to Art. 28 GDPR has been concluded with the provider.
Each time our website is accessed, the web server automatically records the following data: IP address of the requesting device, date and time of access, name and URL of the file retrieved, browser type and version, operating system, and referrer URL (previously visited page).
Legal basis: Art. 6(1)(f) GDPR. Retention period: maximum 7 days, then automatic deletion.
5. Cookies & Consent Management
Our website uses cookies. We distinguish between technically necessary cookies (legal basis: Art. 6(1)(f) GDPR) and analytics and marketing cookies, which are only set with your consent (legal basis: Art. 6(1)(a) GDPR).
To manage your cookie preferences, we use Klaro (KIProtect GmbH, Goethestr. 6, 10623 Berlin, Germany). Klaro is an open-source consent management tool. Your preferences are stored locally in your browser; no consent data is transferred to external servers. A DPA has been concluded with KIProtect GmbH.
Klaro Privacy Policy: https://klaro.org/privacy
6. Google Tag Manager
We use Google Tag Manager (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). The Tag Manager itself does not process personal data other than the IP address required to deliver the script. The tools integrated via the Tag Manager process data as described in the respective sections of this policy.
Google Privacy Policy: https://policies.google.com/privacy
7. Google Analytics
With your consent, we use Google Analytics 4 (Google Ireland Limited). Data that may be processed includes: truncated IP address, pages visited, time on site, referral source, device and browser type, approximate location.
Data is transferred to Google servers in the USA. We have concluded a DPA and Standard Contractual Clauses (SCCs) with Google. Legal basis: Art. 6(1)(a) GDPR. Retention period: 14 months.
Opt-out browser add-on: https://tools.google.com/dlpage/gaoptout
8. Google Ads & Remarketing
a) Conversion Tracking
When you reach our website via a Google ad and complete a booking or contact us, Google stores a cookie on your device that allows us to measure the effectiveness of our ads.
b) Remarketing
With your consent, we display personalised ads to you on other websites (Google Display Network). Legal basis: Art. 6(1)(a) GDPR.
Deactivate personalised ads: https://adssettings.google.com
9. Contact & Email
When you contact us by email, the data you provide (in particular your email address and message content) is stored by us to process your enquiry. Legal bases: Art. 6(1)(b) GDPR (where the enquiry relates to a contract) or Art. 6(1)(f) GDPR. Data is deleted once your enquiry has been fully processed, unless statutory retention obligations apply.
10. Newsletter
We use two tools for newsletter and member communications, depending on the purpose:
a) Brevo (External Newsletter)
For our general newsletter, we use Brevo (Sendinblue SAS, 7 rue de Madrid, 75008 Paris, France). Brevo is an EU-based provider. Data processed includes your email address, name, and interaction data (opens, clicks). Registration is via a double opt-in process. A DPA pursuant to Art. 28 GDPR has been concluded with Brevo. Legal basis: Art. 6(1)(a) GDPR. Retention period: until unsubscribe; proof of consent for a maximum of 3 years.
You may withdraw your consent at any time via the unsubscribe link in any newsletter or by emailing hallo@mokkamilch.de.
Brevo Privacy Policy: https://www.brevo.com/legal/privacypolicy/
b) Nexudus (newsletter, member & booking communication)
We use the Nexudus platform (NÉXUDUS Ltd., Company Registration Number 09772435, England and Wales) for sending newsletters and for transactional and member-related communication (e.g. booking confirmations, membership updates). This applies to both members and non-members who sign up for the newsletter via our website. Sign-up is via a double opt-in process. The data processed includes email address, name, and, where applicable, interaction data. Since Nexudus is also our booking and membership management system, communication takes place within the same platform. A DPA pursuant to Art. 28 GDPR has been concluded with Nexudus. The United Kingdom is recognised as a safe third country under the European Commission's adequacy decision (June 2021), so data transfers are legally safeguarded. Legal basis: Art. 6(1)(a) GDPR (newsletter consent) or Art. 6(1)(b) GDPR (transactional communication). You can withdraw your newsletter consent at any time via the unsubscribe link in the respective email or by emailing hallo@mokkamilch.de.
11. Online Bookings: Co-Working, Event Spaces & Reservations
We use Nexudus (NÉXUDUS Ltd., Company Registration Number 09772435, England and Wales) for bookings of coworking spaces, event spaces, and table reservations made via our website. The booking process may involve processing the following data: first and last name, email address, phone number (optional), booking date, time period, room booked, payment data, and event-related information. Legal basis: Art. 6(1)(b) GDPR. A DPA has been concluded with Nexudus. Storage period: 10 years pursuant to German commercial and tax law retention obligations.
12. Food & Beverage: Reservations, Orders & Payment Processing
We use two systems for restaurant table reservations:
a) Gastronovi
We use Gastronovi (Gastronovi GmbH, An der Weide 14, 28195 Bremen) for table reservations and orders at the restaurant. The data processed includes name, email address, phone number (optional), date, time, number of guests, special requests, and order data. Gastronovi is a German company; all data is processed within the EU. A DPA pursuant to Art. 28 GDPR has been concluded with Gastronovi. Legal basis: Art. 6(1)(b) GDPR. Storage period: 10 years pursuant to German commercial and tax law retention obligations.
b) Adyen (payment processing)
Payment processing at the restaurant is carried out via Adyen (Adyen N.V., Simon Carmiggeltstraat 6–50, 1011 DJ Amsterdam, Netherlands). Adyen processes payment data such as card number (tokenised), transaction amount, and date and time of the transaction. Adyen is an EU-based, publicly listed company; all payment data is processed within the EU and secured in accordance with PCI-DSS standards. A DPA pursuant to Art. 28 GDPR has been concluded with Adyen. Legal basis: Art. 6(1)(b) GDPR. Storage period: 10 years pursuant to German commercial and tax law retention obligations. Adyen privacy policy: https://www.adyen.com/legal/privacy-policy
c) Stripe (payment processing)
We use Stripe (Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin 2, Ireland) for online payments (e.g. bookings, memberships). Stripe processes payment data such as card number (tokenised), transaction amount, date and time of the transaction, and billing address. Stripe is an EU-based company; payment data is secured in accordance with PCI-DSS standards. In certain cases, data may be transferred to Stripe, Inc. (USA); this is based on EU Standard Contractual Clauses (SCCs). A DPA pursuant to Art. 28 GDPR has been concluded with Stripe. Legal basis: Art. 6(1)(b) GDPR. Storage period: 10 years pursuant to German commercial and tax law retention obligations. Stripe privacy policy: https://stripe.com/de/privacy
13a Events: Photography, Video Recording & Data Sharing with Co-Creators
a) Photography and video recording at community events
Photos and videos may be taken at public MOKKA*MILCH community events for documentation and marketing purposes. Attending an event constitutes consent to the creation and publication of photo and video material in which you are recognisable. You can withdraw this consent at any time — either on-site with staff or by email to hallo@mokkamilch.de. Material already published will be removed promptly after withdrawal, to the extent technically feasible. Legal basis: Art. 6(1)(a) GDPR (consent). Storage period: image material is stored for the duration of its marketing use and deleted upon withdrawal of consent or after 5 years at the latest.
b) Photography at private events
At private events (e.g. corporate celebrations, trade fairs), MOKKA*MILCH may take its own photos and videos of the premises and the event atmosphere for marketing and communication purposes. Recordings in which individuals are identifiable are only published with their explicit consent. The event organiser is responsible for informing their guests of this. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in showcasing our premises and events).
c) Data sharing with co-creators
For certain events, MOKKA*MILCH works with external co-creators (e.g. workshop facilitators, artists, speakers). To carry out the event, the following data may be shared with the relevant co-creator: first and last name, email address, and, where applicable, attendance status. This data is shared exclusively for the purpose of running the event. Co-creators are contractually bound to confidentiality and may not use the data for their own marketing purposes. Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
13b Video Surveillance
To protect our premises, the people and property within them, and to prevent vandalism, we operate a video surveillance system at Karl-Marx-Allee 35, 10178 Berlin. The following areas are monitored: exterior areas of the building (cameras serve to deter and document vandalism; as the building is a listed structure, there is a particular legitimate interest in protecting it from damage) and corridors and common areas (cameras in indoor hallways serve to ensure the safety of people and to monitor access to non-public areas). Data subjects are informed of the video surveillance by clearly visible notice signs at the entrance and in the monitored areas (Art. 13 GDPR). Legal basis: Art. 6(1)(f) GDPR (legitimate interests). Technical service provider: SecFire GmbH (Rheinsberger Str. 18b, 16909 Wittstock; Möllendorffstraße 49, 10367 Berlin). Recordings are stored via a cloud recording solution with servers located in Germany, operated in compliance with the GDPR. A DPA pursuant to Art. 28 GDPR has been concluded with SecFire. Storage period: recordings are automatically overwritten after 7 days at the latest. In the event of a specific incident (e.g. vandalism, burglary), relevant recordings may be retained longer for the purpose of investigating the incident and for any related legal proceedings. You have the right to access recordings relating to you (Art. 15 GDPR), the right to erasure (Art. 17 GDPR), and the right to object (Art. 21 GDPR), unless overriding legitimate interests apply. Please contact: hallo@mokkamilch.de
14 Accounting & Tax
For accounting and tax purposes, we export relevant business data (including transaction data that may contain personal information such as names and billing addresses) to DATEV (DATEV eG, Paumgartnerstr. 6–14, 90429 Nuremberg). DATEV is a German cooperative; all data is processed exclusively within the EU. A DPA pursuant to Art. 28 GDPR has been concluded with DATEV. Legal basis: Art. 6(1)(c) GDPR (compliance with tax and commercial law retention obligations under the German Commercial Code (HGB) and Fiscal Code (AO)). Storage period: 10 years.
15. Social Media Presences
We maintain presences on social media platforms. When visiting our profiles, we are jointly responsible for data processing with the respective platform operator (joint controllership, Art. 26 GDPR). Legal basis: Art. 6(1)(f) GDPR.
Instagram — Meta Platforms Ireland Ltd., 4 Grand Canal Square, Dublin 2 — https://privacycenter.instagram.com/policy
Facebook — Meta Platforms Ireland Ltd., 4 Grand Canal Square, Dublin 2 — https://www.facebook.com/privacy/policy/
LinkedIn — LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2 — https://www.linkedin.com/legal/privacy-policy
X (Twitter) — X Corp., 1355 Market Street, San Francisco, CA 94103, USA — https://twitter.com/privacy
Please note that visiting our profiles on these platforms may result in personal data being transferred to third countries, in particular the USA.
16. Disclosure of Data / Data Processing Agreements
We only disclose personal data where consent has been given (lit. a), for the performance of a contract (lit. b), where we are legally obliged to do so (lit. c), or where there is a legitimate interest (lit. f). External service providers acting as processors are carefully selected and data processing agreements (DPAs) pursuant to Art. 28 GDPR are concluded.
17. International Data Transfers
Some of the services we use (in particular Google and OpenTable) transfer personal data to third countries, especially the USA. Appropriate safeguards pursuant to Art. 46 GDPR are in place in the form of EU Standard Contractual Clauses (SCCs). Nexudus (UK) is covered by the European Commission's adequacy decision for the United Kingdom.
Copies of the applicable safeguards are available on request at: hallo@mokkamilch.de
18. Retention Periods
Some of the services we use (in particular Google and Stripe) transfer personal data to third countries, in particular the USA. EU Standard Contractual Clauses (SCCs) serve as appropriate safeguards pursuant to Art. 46 GDPR. For Nexudus (UK), the European Commission's adequacy decision for the United Kingdom applies. Copies of the applicable safeguards are available upon request at: hallo@mokkamilch.de
19. Your Rights as a Data Subject
You have the following rights with respect to your personal data:
Right of access (Art. 15 GDPR): You may request information about the personal data we process.
Right to rectification (Art. 16 GDPR): You may request correction of inaccurate or incomplete data.
Right to erasure (Art. 17 GDPR): You may request deletion of your data under certain conditions.
Right to restriction (Art. 18 GDPR): You may request that processing of your data be restricted.
Right to data portability (Art. 20 GDPR): You may request your data in a structured, machine-readable format.
Right to object (Art. 21 GDPR): You may object to processing based on Art. 6(1)(f) GDPR.
Right to withdraw consent: Consent may be withdrawn at any time with effect for the future.
To exercise your rights, please contact: hallo@mokkamilch.de — We will respond within one month (Art. 12(3) GDPR).
20. Right to Lodge a Complaint with a Supervisory Authority
You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The competent authority for Mokka Milch GmbH is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit
Friedrichstr. 219, 10969 Berlin, Germany
Phone: +49 30 13889-0
Email: mailbox@datenschutz-berlin.de
Web: https://www.datenschutz-berlin.de
21. Changes to this Privacy Policy
We update this Privacy Policy when our processing activities, the services we use, or the legal framework change. The current version is always available on this page.
© 2026 Mokka Milch GmbH | As of: June 2026 | www.mokkamilch.de