What personal data we collect when you contact or trade with the Oromia Coffee Farmers' Cooperative Union, why we hold it, and the rights you have over it.
// Last updated: 14 May 2026 · Effective across all OCFCU web properties
The Oromia Coffee Farmers' Cooperative Union ("OCFCU", "we", "us" or "our") is committed to protecting the privacy of everyone who contacts us or uses this website. This policy explains what personal data we collect, why we collect it, how we use and safeguard it, and the rights you have over it. It applies to oromiacoffeeunion.com and to any business correspondence that arises from it.
Because we trade internationally, we aim to meet the expectations of the EU/UK General Data Protection Regulation (GDPR) for the visitors and buyers who reach us from those regions, in addition to Ethiopian law.
OCFCU is the data controller for the information described here.
We only collect what we need to answer your enquiry and, where relevant, to trade with you.
We do not intentionally collect special-category data (such as health or political data), and we ask that you do not send it to us. This site is intended for business users and is not directed at children.
| Purpose | Legal basis (GDPR) |
|---|---|
| Responding to enquiries and providing samples, quotes and information | Steps taken at your request prior to a contract; our legitimate interest in answering enquiries |
| Negotiating and performing a coffee supply contract | Performance of a contract |
| Sending trade updates about harvests and availability (only if you ask us to) | Consent — withdrawable at any time |
| Measuring and improving how the website performs | Consent (analytics cookies) |
| Meeting accounting, tax, export and other legal obligations | Legal obligation |
| Protecting our rights and preventing fraud or misuse | Legitimate interest |
We never sell your personal data. We share it only where necessary, with:
OCFCU is based in Ethiopia and our buyers are worldwide, so your data may be processed outside your home country — including outside the European Economic Area. Where we transfer personal data from the EEA or UK, we rely on an appropriate safeguard such as the European Commission's Standard Contractual Clauses, together with additional measures where needed to ensure a comparable level of protection.
Subject to applicable law, you may ask us to:
To exercise any of these, email [email protected]. We will respond within one month. If you are in the EEA or UK and believe we have not handled your data properly, you may also complain to your local data-protection authority — but we would welcome the chance to resolve it with you first.
We apply appropriate technical and organisational measures — including encryption in transit, access controls and staff confidentiality obligations — to guard against loss, misuse or unauthorised access. No method of transmission over the internet is completely secure, so we cannot guarantee absolute security, but we take these obligations seriously and review our measures regularly.
We may update this policy to reflect changes in our practices or in the law. The "last updated" date above shows the current version; significant changes will be highlighted on this page.
Questions about this policy or your data? Write to [email protected] or to OCFCU, Bole Road, Addis Ababa, Ethiopia.