Your data protection rights

Under the EU General Data Protection Regulation (GDPR) and German data protection law, you have the following rights regarding your personal data. This page summarises how you can exercise them in the Chacos Tacos Account service.

Last updated: March 2026

Right of access (Art. 15 GDPR)

You have the right to obtain confirmation as to whether we process your personal data and, if so, to receive a copy of that data.

How to exercise: Log in to your account → SettingsDownload my data. You will receive a JSON file containing your profile, addresses, consents, payment method metadata, orders, invoices, and (if applicable) staff-related data.

Right to rectification (Art. 16 GDPR)

You have the right to have inaccurate personal data corrected and incomplete data completed.

How to exercise: Log in → SettingsPersonal (or relevant section) to update your name, email, phone, and addresses. You can also contact us using the details in our Imprint.

Right to erasure (Art. 17 GDPR)

You have the right to request erasure of your personal data in certain circumstances (e.g. data no longer necessary, consent withdrawn, objection, or unlawful processing).

How to exercise: Log in → SettingsDelete account. You will be asked to confirm your password and to type "delete my account". This permanently deletes your account and associated data (profile, addresses, consents, orders, invoices, staff data, etc.). This action cannot be undone.

Right to data portability (Art. 20 GDPR)

You have the right to receive the personal data you provided to us in a structured, commonly used, machine-readable format, and to transmit it to another controller where technically feasible.

How to exercise: The same Download my data export (Settings → Download my data) provides your data in JSON format, which you can use or transfer as needed.

Right to restrict processing (Art. 18 GDPR)

In certain situations you have the right to request that we restrict the processing of your data (e.g. while accuracy is contested or you have objected and we are verifying grounds).

How to exercise: Contact us using the details in our Imprint. We will respond in line with the GDPR.

Right to object (Art. 21 GDPR)

You have the right to object to processing based on legitimate interest or for direct marketing. For marketing, we honour your consent preferences at all times.

How to exercise: Log in → SettingsConsent to turn off marketing emails and adjust order-related emails. For other objections, contact us via the Imprint.

Right to withdraw consent

Where processing is based on your consent, you can withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.

How to exercise: Settings → Consent to update marketing and order email preferences. For other consent-based processing, contact us.

Right to lodge a complaint

You have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your residence, place of work, or place of the alleged infringement. In Germany, you can contact the relevant state data protection commissioner (Landesdatenschutzbeauftragte/r). A list of German data protection authorities can be found at BfDI – Länder.

Contact

For any request regarding your data protection rights, please use the contact details in our Imprint. For full details on how we process your data, see our Privacy Policy.

← Back to homeLegal