PRIVACY POLICY
THE BETTER COFFEE ENDEAVOUR
Last updated: July 17, 2026
Version: 1.0
1. SCOPE
This Privacy Policy explains how personal data is processed in connection with The Better Coffee Endeavour communication infrastructure available at:
https://endeavour.thebettercoffee.org
The service is based on self-hosted Matrix, Element, Matrix Authentication Service, MatrixRTC, Element Call, LiveKit, and related open-source components.
This Policy applies to account registration, authentication, messaging, rooms, Spaces, files, calls, support, security, and use of the service website.
2. DATA CONTROLLER
The controller responsible for the processing of personal data is:
Kbcoffee, Krzysztof Blinkiewicz Tax Identification Number (NIP): 7743006883 Słowackiego 23/38 09-400 Płock Poland
Email:
office@thebettercoffee.org
The Better Coffee is the name of a project and a trade designation used within the Controller’s business activity. It does not constitute a separate legal entity.
The Better Coffee Office is a support and coordination function within The Better Coffee Endeavour, performed by the Controller. It does not constitute a separate legal entity or a separate data controller.
The Better Coffee Office serves as the operational contact point for privacy requests, account administration, moderation, and support.
The software projects Matrix, Element, LiveKit, and their developers are not the controller of data stored on the self-hosted The Better Coffee Endeavour server merely because their software is used.
3. DATA WE PROCESS
Depending on how you use the service, we may process the following categories of data.
A. Account and profile data
This may include:
• Matrix user ID and username;
• verified email address;
• encrypted or hashed password credentials;
• display name;
• profile image;
• account status;
• language and account preferences;
• recovery and encryption configuration;
• information about connected devices and sessions.
We do not store your password in readable form.
B. Authentication and security data
This may include:
• login and logout timestamps;
• IP address;
• device and client information;
• browser and operating system information;
• access tokens and session identifiers;
• authentication attempts;
• email verification activity;
• password reset activity;
• security alerts;
• administrative and abuse-prevention logs.
C. Communication content
Depending on the rooms and features you use, this may include:
• messages;
• files and images;
• reactions;
• replies;
• room names and descriptions;
• room membership;
• invitations;
• read receipts;
• typing notifications;
• profile information;
• moderation events;
• encryption-related events and keys stored in encrypted form.
Private rooms are intended to use end-to-end encryption where supported and enabled.
When end-to-end encryption is active, the server generally stores encrypted message content and does not possess the device keys required to read it. Room membership, timestamps, sender information, event types, delivery information, IP addresses, and other technical metadata may still be visible to or processed by the server.
The encryption status should be checked in the Matrix client.
D. Voice and video call data
When you participate in a voice or video call, the service may process:
• Matrix user and device identifiers;
• room and call identifiers;
• participant information;
• connection timestamps;
• IP address;
• network diagnostics;
• client and device information;
• audio and video streams necessary to transmit the call.
Calls are not recorded on the server by default.
Other participants may independently record calls or take screenshots using their own devices. Such activity is outside the direct technical control of the Controller.
E. Support and administrative communication
When you contact the Controller, The Better Coffee Office, report abuse, request support, appeal a moderation decision, or exercise a data protection right, we may process:
• your name and contact details;
• the contents of the request;
• relevant account, room, or event information;
• correspondence and actions taken;
• evidence necessary to investigate the matter.
F. Limited website analytics
The service uses a self-hosted instance of Umami for limited, privacy-oriented website analytics.
Analytics may include:
• visited page;
• visit time;
• referring website;
• browser type;
• device type;
• operating system;
• approximate country or region;
• an anonymous session identifier generated from technical data.
Umami is not used to create advertising profiles, track users across unrelated websites, or identify account holders.
The analytics system does not use advertising cookies.
Essential cookies, local storage, or session data may still be used by Matrix Authentication Service, Element, or your chosen Matrix client for login, security, preferences, and service operation.
4. PURPOSES OF PROCESSING
We process personal data to:
• create and manage accounts;
• verify email addresses;
• authenticate users and devices;
• provide messaging, rooms, Spaces, file sharing, voice calls, and video calls;
• synchronize encrypted and unencrypted Matrix events;
• enable Matrix federation;
• provide account recovery and security functions;
• maintain service security and stability;
• prevent spam, fraud, abuse, impersonation, and unauthorized access;
• investigate technical problems and user reports;
• moderate rooms and enforce the Terms of Service;
• communicate about the service;
• comply with legal obligations;
• defend legal claims;
• understand general use of the public service interface through limited analytics;
• develop and improve the infrastructure.
5. LEGAL BASES
Where the General Data Protection Regulation applies, personal data is processed on the following legal bases:
A. Performance of a contract
Processing necessary to create an account and provide the communication service is based on Article 6(1)(b) GDPR.
B. Legitimate interests
Processing necessary for security, abuse prevention, moderation, service administration, technical diagnostics, limited analytics, continuity, and protection of the infrastructure is based on Article 6(1)(f) GDPR.
The legitimate interests are operating a secure and functional independent communication service and protecting its users and infrastructure.
C. Legal obligations
Processing required by applicable law is based on Article 6(1)(c) GDPR.
D. Consent
Where we explicitly request consent for optional processing, the basis is Article 6(1)(a) GDPR.
Consent may be withdrawn at any time without affecting processing that occurred before withdrawal.
E. Legal claims and vital interests
Where necessary, information may be processed to establish, exercise, or defend legal claims or to protect a person’s vital interests in accordance with applicable law.
6. WHETHER DATA IS REQUIRED
A valid email address, username, password, and basic technical processing are necessary to create and operate an account.
Without this information, we cannot provide an account.
Providing optional profile information is voluntary.
Messages, files, calls, profile details, and participation in particular rooms are generally voluntary, subject to any separate operational requirements connected with a specific project, course, license, or cooperation process.
7. SOURCES OF DATA
We receive data:
• directly from you;
• automatically from your browser, device, or Matrix client;
• from other users who invite, mention, contact, or report you;
• from other Matrix homeservers through federation;
• from room administrators and moderators;
• from integrations or clients that you authorize;
• from security and server logs.
8. MATRIX FEDERATION
Matrix is a decentralized and federated communication protocol.
When you participate in a federated room or communicate with a user on another homeserver, relevant Matrix events may be transmitted to and stored by independent homeservers.
This may include:
• your Matrix user ID;
• display name and profile image;
• room membership;
• messages and files;
• encrypted message content;
• timestamps;
• reactions and replies;
• encryption events;
• moderation events;
• other room data necessary for federation.
An independent homeserver acts under its own responsibility, terms, privacy practices, and legal jurisdiction.
The Controller cannot fully control data stored by another homeserver or guarantee that it will delete copies following deletion of your local account.
9. RECIPIENTS AND SERVICE PROVIDERS
Personal data may be available to or processed by:
• persons authorized by the Controller to administer The Better Coffee Endeavour infrastructure;
• room administrators and moderators, within their technical permissions;
• users and rooms selected by you;
• independent Matrix homeservers participating in federated rooms;
• Hetzner Online GmbH as infrastructure hosting provider;
• email infrastructure providers used to deliver verification and security messages;
• technical service providers used to maintain the service;
• public authorities where disclosure is legally required;
• legal or security advisers where necessary to protect rights or respond to incidents.
The primary infrastructure is self-managed and hosted in Germany within the European Economic Area.
We do not sell personal data.
We do not provide personal data to advertisers.
10. THIRD-PARTY MATRIX CLIENTS
You may use Element X, Element Desktop, another Matrix client, an application store, or an operating-system notification service.
Those third parties may process technical or account-related data independently under their own privacy policies.
The Controller does not control the independent data practices of software, stores, notification systems, integrations, bridges, or services selected by the user.
11. INTERNATIONAL DATA TRANSFERS
The primary server infrastructure is located within the European Economic Area.
Because Matrix is federated, data may be transmitted to homeservers or users located outside the EEA when you join federated rooms or communicate with external users.
The location and legal safeguards of an external homeserver are determined by its independent operator.
Before sharing sensitive information in a federated room, users should consider who participates in the room and which homeservers are involved.
12. DATA RETENTION
Personal data is retained only for as long as reasonably necessary for the purposes described in this Policy.
The following criteria apply:
• account information is generally retained while the account remains active;
• room events and messages may remain as part of room history;
• security and technical logs are retained according to configured log rotation, security needs, and incident investigation requirements;
• support and moderation records are retained while necessary to resolve the matter and document actions;
• legal records may be retained for the period required by law or necessary to defend claims;
• backups are retained according to the applicable backup rotation and are deleted or overwritten as they expire;
• analytics data is retained only for operational analysis and is not used for advertising profiles.
Following account deletion, some information may remain:
• in room history;
• on other users’ devices;
• in files downloaded by recipients;
• in quotations, replies, exports, or screenshots;
• on federated Matrix homeservers;
• in technical logs;
• in protected backups until their scheduled expiry.
Where technically possible, account identifiers may be deactivated or anonymized while historic room events remain necessary for conversation integrity.
13. END-TO-END ENCRYPTION
End-to-end encryption is designed so that encrypted content can be decrypted only by authorized participant devices holding the necessary keys.
The Controller may be unable to recover:
• encrypted messages;
• encrypted files;
• encryption keys;
• secure backups;
• content lost after all verified devices and recovery credentials are lost.
Users should:
• verify their devices;
• protect their recovery key or recovery passphrase;
• use secure passwords;
• keep their clients updated;
• review room encryption status;
• remove devices they no longer control.
Encryption protects message content but does not eliminate all communication metadata.
14. SECURITY
We use technical and organizational measures intended to protect personal data, including:
• self-managed infrastructure;
• encrypted network connections;
• end-to-end encryption where enabled;
• access controls;
• account authentication;
• verified email registration;
• system logs and security monitoring;
• software updates;
• backups;
• restricted administrative access.
No online system can guarantee absolute security.
Users remain responsible for the security of their devices, passwords, recovery keys, email accounts, clients, and local copies of data.
15. SPECIAL CATEGORIES OF DATA
The service is not designed to require health data, political opinions, religious beliefs, trade-union membership, sexual-orientation data, biometric data, or other special categories of personal data.
Users may voluntarily disclose sensitive information in conversations.
Before doing so, users should consider:
• who is present in the room;
• whether the room is encrypted;
• whether the room is federated;
• whether disclosure is necessary;
• whether another person’s information may be involved.
16. AUTOMATED DECISION-MAKING
We do not use personal data to make decisions producing legal or similarly significant effects solely through automated processing.
Automated security systems may identify unusual login attempts, spam, or technical abuse. Significant account actions are subject to human review where reasonably possible.
17. YOUR RIGHTS
Subject to applicable law, you may have the right to:
• obtain information about the processing of your personal data;
• access your personal data;
• correct inaccurate data;
• request deletion;
• request restriction of processing;
• object to processing based on legitimate interests;
• receive portable data where the right applies;
• withdraw consent;
• lodge a complaint with a supervisory authority;
• challenge a decision based solely on automated processing.
Some requests may be limited by:
• the rights of other users;
• end-to-end encryption;
• legal obligations;
• security requirements;
• the decentralized nature of Matrix;
• data already transmitted to independent homeservers;
• the need to preserve room-event integrity.
To exercise your rights, contact:
office@thebettercoffee.org
We may need to verify your identity before acting on a request.
18. COMPLAINTS
You may lodge a complaint with the President of the Personal Data Protection Office in Poland or with the competent supervisory authority in your country of residence, work, or the place of the alleged infringement.
Before filing a complaint, you may contact the Controller through The Better Coffee Office so that the matter can be reviewed directly.
19. CHILDREN
The service is not specifically directed at children.
A person who has not reached the age at which they may independently consent or enter into the relevant agreement under applicable law may use the service only with authorization from a parent or legal guardian.
20. CHANGES TO THIS POLICY
This Policy may be updated when:
• the service changes;
• new features or providers are introduced;
• legal requirements change;
• security or operational practices change.
The current version and last updated date will be published on this page.
Material changes may also be communicated through the service or by email.
21. CONTACT
Questions, privacy requests, complaints, and security reports may be sent to:
Kbcoffee, Krzysztof Blinkiewicz
Tax Identification Number (NIP): 7743006883
Słowackiego 23/38
09-400 Płock
Poland
Email:
office@thebettercoffee.org
Service:
https://endeavour.thebettercoffee.org