Privacy Policy
Last updated: February 2026
This Privacy Policy describes how WitchaTea ("we", "us", "our") collects, uses, and protects your personal data when you use our website. We process your data in accordance with the EU General Data Protection Regulation (GDPR) and applicable national data protection laws.
1. Controller
Controller responsible for data processing:
WitchaTea
Sylwia Sakson
Neusiedlerstrasse 10/3/5
7111 Parndorf
Austria
VAT/Company ID: 0317-4329-0995
Email: info@witchatea.com
2. What data we collect
When you visit our website, we may collect:
- Usage data: Pages visited, date and time of access, referrer URL, browser type, device type, and approximate location (country/region) derived from your IP address.
- Contact data: If you contact us by email (e.g. via a mailto link), we process the data you provide in that email (name, email address, message content).
- Technical data: IP address, browser type and version, operating system — these may be stored temporarily in server logs.
3. Purposes and legal basis
We process your data for the following purposes and on the following legal bases (Art. 6 GDPR):
- Provision of the website: Legitimate interest (Art. 6(1)(f) GDPR) — to make our website available and ensure its security.
- Responding to enquiries: Legitimate interest (Art. 6(1)(f) GDPR) or, where a contract is being negotiated, performance of a contract (Art. 6(1)(b) GDPR).
- Compliance with legal obligations: Legal obligation (Art. 6(1)(c) GDPR) — e.g. retention for tax or accounting purposes.
4. Storage and retention
We retain your data only for as long as necessary to fulfil the purposes set out above or as required by law. Server logs are typically retained for a short period (e.g. 7–30 days). Contact correspondence is retained as needed to handle your enquiry and, where applicable, for the period required by tax or commercial law.
5. Recipients and third parties
We do not sell your personal data. Your data may be shared with:
- Hosting providers: Our website is hosted; the host may process data on our behalf as a processor under a data processing agreement.
- Font providers: We use Google Fonts; when your browser loads fonts, your IP address may be transmitted to Google. Please refer to Google's Privacy Policy for details.
If we use further third-party services (e.g. analytics, contact forms), we will update this policy and obtain consent where required.
6. Your rights under the GDPR
You have the following rights:
- Access (Art. 15 GDPR): Request a copy of the personal data we hold about you.
- Rectification (Art. 16 GDPR): Request correction of inaccurate data.
- Erasure (Art. 17 GDPR): Request deletion of your data in certain circumstances.
- Restriction of processing (Art. 18 GDPR): Request that we limit how we use your data.
- Data portability (Art. 20 GDPR): Request your data in a structured, commonly used format.
- Object (Art. 21 GDPR): Object to processing based on legitimate interests.
- Withdraw consent: Where processing is based on consent, you may withdraw it at any time.
- Complaint: Lodge a complaint with a supervisory authority. In Austria: Austrian Data Protection Authority (DSB).
To exercise these rights, contact us at info@witchatea.com.
7. International transfers
Where we transfer data to countries outside the EEA, we ensure appropriate safeguards (e.g. adequacy decisions, standard contractual clauses) as required by the GDPR.
8. Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or misuse.
9. Children
Our website is not directed at children under 16. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us so we can delete it.
10. Changes
We may update this Privacy Policy from time to time. The date of the last update is shown at the top. We encourage you to review this page periodically.
