NL Back to site

Pablo Beer

Privacy statement

This page explains how the current Pablo Beer website handles information.

Last updated 13 September 2026

Privacy at a glance

We only use information needed to operate and secure this website, apply its 18+ access check and load its embedded video after the check. We do not run analytics or advertising tracking on the Pablo website.

Controller and contact

Adventures beers B.V.
Beekzicht 9a
4881 GM Zundert
The Netherlands
Chamber of Commerce (KVK): 93800312

Adventures beers B.V. is the controller for the personal-data processing described in this statement. For a privacy question or rights request, write to this address and mark the letter “Privacy”. This website has no contact form and no separate privacy email address.

No separate data protection officer has been appointed for the processing described here. If that changes, this statement will be updated.

Hage Hosting, Oude Moolweg 3, 4325 EA Renesse, KVK 86151762, provides hosting. Hage Hosting acts as our processor for hosting data under a processing agreement. Hage may separately be a controller for its own customer administration and infrastructure security; see its privacy statement (opens in a new tab).

Age check and browser storage

The date of birth you enter is checked locally in your browser to restrict access to this alcohol advertising to adults aged 18 and over. The date is not sent to or stored by Adventures beers B.V. or Hage Hosting.

After a successful check, this site stores only pablo-age-verified=true in the browser's temporary session storage. It lets the current browser tab remember that the check passed. It is not used to identify, profile or follow you across websites or browser sessions. The browser controls when session storage is removed.

The legal basis for the controller's website operation and responsible age restriction is our legitimate interest under Article 6(1)(f) GDPR. You can leave the site without completing the check.

Cookies and tracking

The Pablo website's static code does not set HTTP cookies and does not use analytics or advertising pixels. The browser session key described above is web storage, not a cookie, and is used only for the age-check function.

After the age check, the page initializes one embedded Vimeo video. The player URL uses Vimeo's dnt=1 setting. Vimeo says this blocks new session and analytics cookies for that viewing session, although essential security cookies may still be used. Your browser connects directly to Vimeo, which can receive technical request data such as your IP address, browser and device details, the requested video and referrer. Vimeo is an independent controller; read its privacy policy (opens in a new tab) and player-cookie information (opens in a new tab).

Our legal basis for initializing this embedded player after the age check is our legitimate interest under Article 6(1)(f) GDPR in presenting the Pablo Beer video. Vimeo determines the purposes and legal basis of its own processing as an independent controller.

We do not intentionally add other cookies or tracking technologies. If hosting, CDN or security configuration changes, the cookie and data description will be updated before that change is used for a new purpose.

Server data

When you request a page, Hage Hosting's infrastructure can process technical data such as your IP address, requested URL, date and time, browser and operating system, referrer and security or error-log data. This is needed to deliver, maintain, secure and troubleshoot the website.

For this hosting activity, Adventures beers B.V. is controller and Hage Hosting is processor. The legal basis is our legitimate interest under Article 6(1)(f) GDPR in a reliable and secure website. Hage's published retention schedule lists log files for a maximum of 12 months; backups follow the selected backup package and retention policy. Hage deletes hosted data after termination in accordance with the processing agreement, subject to legal requirements.

Hage describes measures including encryption in transit and at rest where possible, least-privilege access control, logging, TLS/SSL, firewall and malware protection, intrusion detection, monitoring, patching, server hardening, DDoS protection, backups and physical access controls. No security measure eliminates every risk.

Purposes and legal bases

We use the limited information described above to deliver the pages and assets you request, apply the 18+ access restriction, protect the service against abuse and attacks, diagnose technical problems, and answer privacy correspondence. We process information only for these stated purposes and for legal obligations or the establishment, exercise or defence of legal claims where necessary.

The age-check value is not transmitted to us. For server data, our legitimate interest is the secure and functional operation of the website. If you send a rights request, we process the contact details and the contents you provide under our legal obligation to respond and, where necessary, our legitimate interest in documenting and defending the request.

Recipients and international transfers

Recipients or categories of recipients can include Hage Hosting and its authorised hosting, cloud, backup, security and infrastructure subprocessors; authorities where disclosure is legally required; Vimeo when its player is initialized after the age check; and a browser's direct connection to Drankgigant after you follow the webshop link. We do not sell personal data.

Hage's processing agreement provides for subprocessors within the European Union or with appropriate safeguards and says a subprocessor list is available on request. The actual Hage data-centre and subprocessor configuration is not controlled by this page. Vimeo may process data outside the European Economic Area under its own terms and transfer safeguards. Consult the linked provider information for those details.

External webshop

Links to Drankgigant (opens in a new tab) open an external website. Drankgigant is a separate controller and handles information, cookies, orders and payments under its own privacy and cookie information. Review that information before purchasing.

Retention

We do not receive or retain the date of birth entered in the age check. The session-storage value remains under your browser's session-storage rules. Hage log files are listed as retained for a maximum of 12 months, and Hage backups follow the selected package and retention policy. Privacy correspondence is kept only for as long as needed to handle the request and establish, exercise or defend legal claims, or for any longer period required by law.

We review retention against the purpose and delete or anonymise information when it is no longer needed, subject to legal, security and backup constraints.

Your rights

Subject to the GDPR conditions and exceptions, you may ask for access to your personal data, correction, erasure, restriction of processing, data portability and object to processing based on our legitimate interest. Where processing is based on consent, you may withdraw consent at any time without affecting earlier lawful processing. The age date is not held by us, so we cannot provide or erase a date that never reached our systems.

Send a request to Adventures beers B.V., Beekzicht 9a, 4881 GM Zundert, The Netherlands, marked “Privacy”. We may ask for information reasonably necessary to verify identity. We do not ask you to send more personal information than needed. We normally respond within one month; if a request is complex, we may extend that period by up to two further months and will explain why.

Automated decisions

We do not use profiling or automated decision-making that produces legal effects or similarly significantly affects you. The age gate performs a local technical comparison with the 18+ threshold; it does not create a profile or a server-side decision record.

Security incidents

Hage Hosting's processing agreement requires it to notify us without unreasonable delay and assist with data-breach investigation, impact assessment and legally required notifications. Adventures beers B.V. assesses incidents and, where required by the GDPR, notifies the Dutch supervisory authority within the applicable period and affected people when the risk is high.

Complaints

Please contact Adventures beers B.V. first so we can investigate. You also have the right to complain to the Dutch supervisory authority, the Autoriteit Persoonsgegevens (opens in a new tab). Its postal address is Autoriteit Persoonsgegevens, Postbus 93374, 2509 AJ Den Haag, The Netherlands.

Changes to this statement

We may update this statement when the website, providers or processing purposes change. The latest version and date are published on this page.