GDPR Compliance
Last updated: August 14, 2026
General Data Protection Regulation
Café L'Aura is committed to complying with the General Data Protection Regulation (GDPR) and protecting the privacy rights of individuals in the European Union.
Data Controller
Café L'Aura acts as the data controller for personal information collected through our website and services.
Contact details:
Café L'Aura
47 Rue de Manchester
1080 Molenbeek-Saint-Jean
Brussels, Belgium
Email: [email protected]
Your GDPR Rights
Under the GDPR, you have the following rights regarding your personal data:
1. Right to Access
You have the right to request a copy of the personal data we hold about you. We will provide this information in a structured, commonly used, and machine-readable format.
2. Right to Rectification
If your personal data is inaccurate or incomplete, you have the right to request correction or completion.
3. Right to Erasure (Right to be Forgotten)
You may request deletion of your personal data when:
- The data is no longer necessary for the purposes it was collected
- You withdraw consent and there is no other legal basis for processing
- You object to processing and there are no overriding legitimate grounds
- The data has been unlawfully processed
4. Right to Restriction of Processing
You can request that we restrict processing of your personal data in certain circumstances, such as when you contest the accuracy of the data.
5. Right to Data Portability
You have the right to receive your personal data in a structured, commonly used format and transmit it to another controller.
6. Right to Object
You may object to processing of your personal data based on legitimate interests or for direct marketing purposes.
7. Rights Related to Automated Decision-Making
You have the right not to be subject to decisions based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects you.
How to Exercise Your Rights
To exercise any of these rights, please contact us at [email protected] with:
- A clear description of your request
- Proof of identity (to prevent unauthorized access)
- Any relevant reference numbers or account information
We will respond to your request within 30 days. If we need more time, we will notify you of the extension and reasons.
Lawful Basis for Processing
We process your personal data based on the following lawful grounds:
- Consent: For marketing communications and non-essential cookies
- Contract: To fulfill your subscription orders
- Legal obligation: To comply with accounting and tax requirements
- Legitimate interests: To improve our services and prevent fraud
Data Protection Principles
We adhere to the GDPR data protection principles:
- Lawfulness, fairness, and transparency
- Purpose limitation
- Data minimization
- Accuracy
- Storage limitation
- Integrity and confidentiality
- Accountability
Data Security Measures
We implement appropriate technical and organizational measures to ensure data security, including:
- Encryption of data in transit and at rest
- Access controls and authentication
- Regular security assessments
- Employee training on data protection
- Incident response procedures
Data Breach Notification
In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of the breach.
International Data Transfers
Your personal data is stored and processed within the European Union. If we transfer data outside the EU, we ensure appropriate safeguards are in place through:
- Standard contractual clauses approved by the European Commission
- Adequacy decisions
- Other legally approved mechanisms
Third-Party Processing
We work with carefully selected third-party processors who assist with delivery and service provision. All processors are required to:
- Process data only on our instructions
- Implement appropriate security measures
- Maintain confidentiality
- Comply with GDPR requirements
Right to Lodge a Complaint
If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with your local supervisory authority.
Belgian Data Protection Authority:
Rue de la Presse 35
1000 Brussels
Belgium
Website: www.dataprotectionauthority.be
Updates to This Information
We may update this GDPR compliance information periodically to reflect changes in our practices or legal requirements. Please check this page regularly.