Effective date: 30 August 2026
1. Introduction
This Privacy Policy explains how personal data is processed in connection with the whitepeony.eu website, White Peony digital services and the White Peony mobile application.
The Website and related services are operated by two Czech companies with clearly defined areas of responsibility:
Luxusní Čaje s.r.o.
IČO: 21495572
Korunní 2569/108, Vinohrady, 101 00 Prague 10, Czech Republic
und
BIOTEA s.r.o.
IČO: 17996651
Poděbradská 634/98, Hloubětín, 198 00 Prague 14, Czech Republic.
The applicable company responsible for processing personal data depends on the particular service and purpose of processing.
2. Data Controllers
2.1 B2C activities
For personal data processed in connection with consumer purchases, consumer orders, B2C customer accounts, consumer customer service, consumer complaints and other B2C e-commerce activities, the data controller is:
Luxusní Čaje s.r.o.
IČO: 21495572
Korunní 2569/108
Vinohrady, 101 00 Prague 10
Czech Republic
2.2 B2B activities
For personal data processed in connection with B2B customers, wholesale customers, business partners, corporate accounts, wholesale enquiries and other B2B commercial activities, the data controller is:
BIOTEA s.r.o.
IČO: 17996651
Poděbradská 634/98
Hloubětín, 198 00 Prague 14
Czech Republic
2.3 Website, application and technology
Biotea s.r.o. also operates and/or provides technological services relating to the Website and the White Peony mobile application.
Depending on the particular processing activity, Biotea s.r.o. may act as an independent data controller or as a processor acting on documented instructions of another controller.
Where Biotea s.r.o. processes personal data on behalf of Luxusní Čaje s.r.o., the parties will regulate such processing in accordance with Article 28 GDPR and applicable Czech data protection legislation.
3. Categories of Personal Data
Depending on the service used, we may process:
- name and surname;
- billing and delivery address;
- email address;
- telephone number;
- company name and business identification details;
- information relating to orders, purchases and contractual relationships;
- payment and transaction information;
- customer-service communications;
- account credentials and account-related information;
- information submitted through contact forms;
- technical information such as IP address, browser type, device information and security logs;
- information concerning the use of the Website or application;
- cookie and similar technology data where applicable;
- marketing preferences and consent records.
We do not intentionally request special categories of personal data unless processing is specifically necessary and legally permitted.
4. Purposes and Legal Bases
Personal data may be processed for the following purposes:
Contractual performance
Processing may be necessary to:
- create and administer customer accounts;
- process and deliver orders;
- provide requested products and services;
- communicate with customers;
- process payments;
- provide customer support;
- administer contractual relationships.
The legal basis is generally Article 6(1)(b) GDPR.
Legal obligations
Personal data may be processed where necessary to comply with legal obligations, including accounting, tax, consumer protection and other statutory requirements.
The legal basis is Article 6(1)(c) GDPR.
Legitimate interests
Personal data may be processed where necessary for legitimate interests, including:
- website and information-security;
- fraud prevention;
- protection of legal rights;
- internal administration;
- improvement and maintenance of services;
- direct marketing where permitted by applicable law;
- business-to-business communications where legally permitted.
The legal basis is Article 6(1)(f) GDPR, taking into account the rights and interests of the data subject.
Consent
Where required by law, personal data will be processed on the basis of the user’s consent.
Consent may be withdrawn at any time without affecting the lawfulness of processing carried out before withdrawal.
5. Cookies
The Website may use essential and non-essential cookies and similar technologies.
Essential technologies may be used where necessary to provide the Website or requested service.
Non-essential analytics, advertising or similar technologies will be used in accordance with applicable legislation and, where required, only after obtaining the user’s consent.
Users can manage their cookie preferences through the Website’s cookie-consent mechanism.
6. Recipients and Processors
Personal data may be made available to service providers that support the operation of the Website and business, including providers of:
- hosting and cloud services;
- website and application infrastructure;
- payment services;
- logistics and delivery;
- customer support;
- accounting and tax services;
- email and communication services;
- analytics;
- marketing and advertising;
- cybersecurity and fraud prevention.
Where a third party processes personal data on behalf of a controller, the relationship will be governed by the requirements applicable to processors under GDPR.
7. International Transfers
Where personal data is transferred outside the European Economic Area, such transfer will only take place where permitted by applicable data protection legislation and where the relevant safeguards required by GDPR are in place.
Such safeguards may include an adequacy decision of the European Commission, Standard Contractual Clauses or another legally recognized transfer mechanism.
8. Retention
Personal data will be retained only for as long as necessary for the purposes for which it was collected, unless a longer retention period is required or permitted by law.
Different categories of information may therefore be retained for different periods depending on the purpose of processing, contractual requirements, statutory obligations and the establishment, exercise or defence of legal claims.
9. Rights of Data Subjects
Subject to the conditions established by GDPR, data subjects may have the right to:
- obtain confirmation as to whether their personal data is being processed;
- access their personal data;
- request correction of inaccurate or incomplete data;
- request erasure of personal data;
- request restriction of processing;
- object to processing based on legitimate interests;
- receive personal data in a structured, commonly used and machine-readable format where the right to data portability applies;
- withdraw consent where processing is based on consent;
- lodge a complaint with the competent supervisory authority.
10. Exercising Your Rights
Requests concerning personal data should be sent to:
Where necessary, the request may be forwarded to the company responsible for the relevant processing activity.
We may request reasonable information necessary to verify the identity of the person making the request.
11. Data Security
Appropriate technical and organizational measures are implemented to protect personal data against unauthorized access, loss, destruction, alteration or other unlawful processing.
The measures applied take into account the nature, scope, context and purposes of processing and the risks to the rights and freedoms of individuals.
12. Changes to this Privacy Policy
This Privacy Policy may be updated from time to time to reflect changes in our services, corporate structure, technology or applicable legal requirements.
The current version will be published on the Website together with its effective date.
13. Supervisory Authority
The competent Czech supervisory authority for personal data protection is:
Úřad pro ochranu osobních údajů (Office for Personal Data Protection)
Pplk. Sochora 27
170 00 Prague 7
Czech Republic
Website: uoou.gov.cz
Users may lodge a complaint with the competent supervisory authority if they believe that their personal data has been processed in violation of applicable data protection legislation.
