Privacy policy

Effective date: 30 August 2026

1. Introduction

This Privacy Policy explains how personal data is processed in connection with the whitepeony.eu website, White Peony digital services and the White Peony mobile application.

The Website and related services are operated by two Czech companies with clearly defined areas of responsibility:

Luxusní Čaje s.r.o.
IČO: 21495572
Korunní 2569/108, Vinohrady, 101 00 Prague 10, Czech Republic

und

BIOTEA s.r.o.
IČO: 17996651
Poděbradská 634/98, Hloubětín, 198 00 Prague 14, Czech Republic.

The applicable company responsible for processing personal data depends on the particular service and purpose of processing.

2. Data Controllers

2.1 B2C activities

For personal data processed in connection with consumer purchases, consumer orders, B2C customer accounts, consumer customer service, consumer complaints and other B2C e-commerce activities, the data controller is:

Luxusní Čaje s.r.o.
IČO: 21495572
Korunní 2569/108
Vinohrady, 101 00 Prague 10
Czech Republic

2.2 B2B activities

For personal data processed in connection with B2B customers, wholesale customers, business partners, corporate accounts, wholesale enquiries and other B2B commercial activities, the data controller is:

BIOTEA s.r.o.
IČO: 17996651
Poděbradská 634/98
Hloubětín, 198 00 Prague 14
Czech Republic

2.3 Website, application and technology

Biotea s.r.o. also operates and/or provides technological services relating to the Website and the White Peony mobile application.

Depending on the particular processing activity, Biotea s.r.o. may act as an independent data controller or as a processor acting on documented instructions of another controller.

Where Biotea s.r.o. processes personal data on behalf of Luxusní Čaje s.r.o., the parties will regulate such processing in accordance with Article 28 GDPR and applicable Czech data protection legislation.

3. Categories of Personal Data

Depending on the service used, we may process:

  • name and surname;
  • billing and delivery address;
  • email address;
  • telephone number;
  • company name and business identification details;
  • information relating to orders, purchases and contractual relationships;
  • payment and transaction information;
  • customer-service communications;
  • account credentials and account-related information;
  • information submitted through contact forms;
  • technical information such as IP address, browser type, device information and security logs;
  • information concerning the use of the Website or application;
  • cookie and similar technology data where applicable;
  • marketing preferences and consent records.

We do not intentionally request special categories of personal data unless processing is specifically necessary and legally permitted.

4. Purposes and Legal Bases

Personal data may be processed for the following purposes:

Contractual performance

Processing may be necessary to:

  • create and administer customer accounts;
  • process and deliver orders;
  • provide requested products and services;
  • communicate with customers;
  • process payments;
  • provide customer support;
  • administer contractual relationships.

The legal basis is generally Article 6(1)(b) GDPR.

Legal obligations

Personal data may be processed where necessary to comply with legal obligations, including accounting, tax, consumer protection and other statutory requirements.

The legal basis is Article 6(1)(c) GDPR.

Legitimate interests

Personal data may be processed where necessary for legitimate interests, including:

  • website and information-security;
  • fraud prevention;
  • protection of legal rights;
  • internal administration;
  • improvement and maintenance of services;
  • direct marketing where permitted by applicable law;
  • business-to-business communications where legally permitted.

The legal basis is Article 6(1)(f) GDPR, taking into account the rights and interests of the data subject.

Consent

Where required by law, personal data will be processed on the basis of the user’s consent.

Consent may be withdrawn at any time without affecting the lawfulness of processing carried out before withdrawal.

5. Cookies

The Website may use essential and non-essential cookies and similar technologies.

Essential technologies may be used where necessary to provide the Website or requested service.

Non-essential analytics, advertising or similar technologies will be used in accordance with applicable legislation and, where required, only after obtaining the user’s consent.

Users can manage their cookie preferences through the Website’s cookie-consent mechanism.

6. Recipients and Processors

Personal data may be made available to service providers that support the operation of the Website and business, including providers of:

  • hosting and cloud services;
  • website and application infrastructure;
  • payment services;
  • logistics and delivery;
  • customer support;
  • accounting and tax services;
  • email and communication services;
  • analytics;
  • marketing and advertising;
  • cybersecurity and fraud prevention.

Where a third party processes personal data on behalf of a controller, the relationship will be governed by the requirements applicable to processors under GDPR.

7. International Transfers

Where personal data is transferred outside the European Economic Area, such transfer will only take place where permitted by applicable data protection legislation and where the relevant safeguards required by GDPR are in place.

Such safeguards may include an adequacy decision of the European Commission, Standard Contractual Clauses or another legally recognized transfer mechanism.

8. Retention

Personal data will be retained only for as long as necessary for the purposes for which it was collected, unless a longer retention period is required or permitted by law.

Different categories of information may therefore be retained for different periods depending on the purpose of processing, contractual requirements, statutory obligations and the establishment, exercise or defence of legal claims.

9. Rights of Data Subjects

Subject to the conditions established by GDPR, data subjects may have the right to:

  • obtain confirmation as to whether their personal data is being processed;
  • access their personal data;
  • request correction of inaccurate or incomplete data;
  • request erasure of personal data;
  • request restriction of processing;
  • object to processing based on legitimate interests;
  • receive personal data in a structured, commonly used and machine-readable format where the right to data portability applies;
  • withdraw consent where processing is based on consent;
  • lodge a complaint with the competent supervisory authority.

10. Exercising Your Rights

Requests concerning personal data should be sent to:

[email protected]

Where necessary, the request may be forwarded to the company responsible for the relevant processing activity.

We may request reasonable information necessary to verify the identity of the person making the request.

11. Data Security

Appropriate technical and organizational measures are implemented to protect personal data against unauthorized access, loss, destruction, alteration or other unlawful processing.

The measures applied take into account the nature, scope, context and purposes of processing and the risks to the rights and freedoms of individuals.

12. Changes to this Privacy Policy

This Privacy Policy may be updated from time to time to reflect changes in our services, corporate structure, technology or applicable legal requirements.

The current version will be published on the Website together with its effective date.

13. Supervisory Authority

The competent Czech supervisory authority for personal data protection is:

Úřad pro ochranu osobních údajů (Office for Personal Data Protection)
Pplk. Sochora 27
170 00 Prague 7
Czech Republic

Website: uoou.gov.cz

Users may lodge a complaint with the competent supervisory authority if they believe that their personal data has been processed in violation of applicable data protection legislation.

de_DEGerman