Effective Date: August 30, 2026
Ethiopian Food Stories (“We”, “Us”, “Our”) respects your privacy and is committed to protecting your personal data in full compliance with the EU General Data Protection Regulation (GDPR) (EU 2016/679) and applicable local data protection legislation.
1. Data Controller
For the purposes of the GDPR, the Data Controller responsible for your personal data is:
Ethiopian Food Stories
Email: info@ethiopianfoodstories.com
2. Information We Collect
We collect personal data to provide and improve our directory and platform services.
2.1 Information You Provide Directly
- Account & Listing Details: Name, email address, business address, phone number, business details, and passwords created when submitting a listing or registration.
- Community Contributions: Stories, photos, chef bios, and reviews submitted voluntarily.
- Contact Inquiries: Name, email, and message details when contacting us via forms or support chat.
2.2 Information Collected Automatically
- Log & Technical Data: IP address, browser type, device information, operating system, pages visited, and timestamps.
- Cookies & Tracking: Technical cookies necessary for website operation, analytics cookies (e.g., traffic patterns), and preference cookies (see Section 6).
3. Legal Basis for Processing (GDPR Article 6)
We process your personal data under the following legal bases:
- Consent (Art. 6(1)(a)): When you opt-in to marketing communications, cookie tracking, or voluntary story submissions.
- Performance of a Contract (Art. 6(1)(b)): To create your account, manage business listings, and deliver directory services.
- Legitimate Interests (Art. 6(1)(f)): To secure our platform, prevent fraud, and analyze directory usage to enhance community experience.
- Legal Obligation (Art. 6(1)(c)): To comply with European tax, legal, and regulatory obligations.
4. How We Use Your Personal Data
We use the collected information to:
- Publish and manage business directory listings and cultural stories.
- Verify listing ownership and respond to support inquiries.
- Maintain website security, prevent spam, and monitor platform performance.
- Send transactional emails (listing confirmation, account verification).
5. Data Sharing & International Transfers
5.1 Third-Party Service Providers
We do not sell your personal data. We share data only with trusted third-party service providers acting as Data Processors (e.g., website hosting, chat integrations, database infrastructure) bound by strict GDPR data processing agreements.
5.2 International Transfers Outside the EEA
If personal data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, such as EU Standard Contractual Clauses (SCCs) or adequacy decisions by the European Commission.
6. Cookie Policy & Tracking
Our website uses cookies and similar technologies:
- Essential Cookies: Required for basic site navigation, user sign-in, and security.
- Analytical Cookies: Help us understand site traffic and popular directory sections (processed anonymously).
You can manage or withdraw cookie consent at any time via your browser settings or our cookie consent banner.
7. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected:
- Account & Listing Data: Retained for as long as your account or venue listing remains active on the Platform.
- Inquiries & Correspondence: Retained for up to 24 months after resolution.
- Log Files: Retained for up to 90 days for technical security monitoring.
8. Your Rights Under GDPR
If you are located in the European Union or EEA, you possess the following rights regarding your personal data:
- Right of Access (Art. 15): Request a copy of the personal data we hold about you.
- Right to Rectification (Art. 16): Request correction of inaccurate or incomplete data.
- Right to Erasure / “Right to be Forgotten” (Art. 17): Request deletion of your personal data.
- Right to Restrict Processing (Art. 18): Request restriction of data processing under certain conditions.
- Right to Data Portability (Art. 20): Receive your data in a structured, machine-readable format.
- Right to Object (Art. 21): Object to processing based on legitimate interests.
- Right to Withdraw Consent: Withdraw consent at any time without affecting prior lawful processing.
To exercise any of these rights, please email us at info@ethiopianfoodstories.com.
Right to Complain
You also have the right to lodge a complaint with a Data Protection Authority (such as the Garante per la protezione dei dati personali in Italy or your local EU supervisory authority).
9. Security of Your Data
We implement appropriate technical and organizational security measures—including SSL encryption (HTTPS), access controls, and regular system monitoring—to protect your personal data from unauthorized access, loss, or disclosure.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements or platform operations. Updates will be posted on this page with an updated “Effective Date.”
11. Contact Details
For any privacy-related questions or data subject requests, please contact:
Data Protection Point of Contact
Ethiopian Food Stories
Email: info@ethiopianfoodstories.com
