COQUUS
COQUUS

Privacy Policy

Effective: 1 January 2025Last Updated: January 2025

COQUUS AB ("COQUUS", "we", "us", "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, and protect your data in accordance with the EU General Data Protection Regulation (GDPR).

1. Data Controller

COQUUS AB is the data controller for personal data collected through the Platform. Contact: info@coquus.se.

2. Information We Collect

We collect the following personal data:

  • Name and contact details (email, phone number)
  • Profile information (address, profile photo)
  • Booking information and history
  • Payment data (processed by third-party providers; we do not store card details)
  • Communications sent through the Platform
  • Technical data (IP address, browser type, device information)
  • Usage data (pages visited, features used)

For chefs, we may also collect identity verification documents, bank account details (for payouts), and culinary credentials.

3. How We Use Your Data

We use personal data to:

  • Create and manage user accounts
  • Facilitate bookings between customers and chefs
  • Process payments and manage payouts
  • Send booking confirmations, reminders, and service notifications
  • Verify chef identity and credentials
  • Improve and personalise the Platform
  • Ensure platform safety and prevent fraud
  • Comply with legal obligations

4. Legal Basis for Processing

We process your data on the following legal bases:

  • Contract performance: to fulfil bookings and platform services
  • Legitimate interests: platform security, fraud prevention, service improvement
  • Legal obligation: compliance with applicable laws
  • Consent: for marketing communications (where applicable)

5. Data Sharing

We may share personal data with:

  • Chefs or customers as required to fulfil a booking
  • Payment processors (e.g. Stripe) to process transactions
  • Identity verification providers
  • Analytics and infrastructure providers supporting the Platform
  • Law enforcement or regulatory authorities where required by law

We do not sell personal data to third parties.

6. Data Retention

We retain personal data for as long as necessary to provide our services and comply with legal obligations. Account data is retained for a minimum of 3 years after account closure for legal and accounting purposes. You may request deletion of your data subject to legal retention requirements.

7. Your Rights Under GDPR

Under GDPR you have the right to:

  • Access your personal data
  • Correct inaccurate or incomplete information
  • Erase your data ("right to be forgotten")
  • Restrict processing in certain circumstances
  • Data portability in a structured, machine-readable format
  • Object to processing based on legitimate interests
  • Withdraw consent at any time where processing is based on consent

To exercise any of these rights, contact us at info@coquus.se. We will respond within 30 days. You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY) at imy.se.

8. Cookies

We use cookies and similar technologies to operate the Platform. For full details, see our Cookie Policy.

9. Data Security

COQUUS implements appropriate technical and organisational measures to protect personal data against unauthorised access, loss, or destruction. These include encryption, access controls, and regular security reviews.

10. International Transfers

Personal data is processed within the EU/EEA. Where data is transferred outside the EU/EEA, we ensure appropriate safeguards are in place in accordance with GDPR requirements.

11. Updates

This Privacy Policy may be updated periodically. We will notify you of material changes via the Platform or email. Continued use of the Platform constitutes acceptance of the updated policy.

12. Contact

For privacy-related enquiries or to exercise your rights, contact: info@coquus.se.