GDPR Compliance
Last updated: August 4, 2026
Our Commitment to GDPR
Tea & Wind is committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR). This page outlines how we meet our obligations under GDPR and how you can exercise your data protection rights.
Data Controller
Tea & Wind acts as the data controller for the personal information we collect through our website and services.
Tea & Wind
Herengracht 282
1016 BX Amsterdam
Netherlands
Email: [email protected]
Lawful Basis for Processing
We process your personal data only when we have a lawful basis to do so under Article 6 of GDPR:
1. Consent (Article 6(1)(a))
We obtain your explicit consent before:
- Sending marketing communications
- Using non-essential cookies
- Processing special categories of data (if applicable)
You can withdraw consent at any time without affecting the lawfulness of processing based on consent before withdrawal.
2. Contract Performance (Article 6(1)(b))
We process data when necessary to fulfill our contract with you, including:
- Processing and delivering your orders
- Providing customer support
- Managing your account
3. Legal Obligation (Article 6(1)(c))
We process data when required by law, such as:
- Tax reporting requirements
- Accounting obligations
- Responding to lawful requests from authorities
4. Legitimate Interests (Article 6(1)(f))
We may process data based on our legitimate business interests, such as:
- Improving our products and services
- Detecting and preventing fraud
- Ensuring network and information security
We balance these interests against your rights and will not process data in ways you would not reasonably expect.
Your Rights Under GDPR
Right to Access (Article 15)
You have the right to obtain confirmation that we process your data and to access that data. You can request a copy of your personal information in a structured, commonly used format.
Right to Rectification (Article 16)
You have the right to correct inaccurate or incomplete personal data we hold about you.
Right to Erasure (Article 17)
You have the right to request deletion of your personal data when:
- The data is no longer necessary for the purposes it was collected
- You withdraw consent and there is no other legal basis for processing
- You object to processing and there are no overriding legitimate grounds
- The data has been unlawfully processed
This right is not absolute and may be limited by legal obligations to retain certain data.
Right to Restriction of Processing (Article 18)
You can request that we limit how we use your data when:
- You contest the accuracy of the data
- Processing is unlawful but you prefer restriction to erasure
- We no longer need the data but you need it for legal claims
- You have objected to processing pending verification of legitimate grounds
Right to Data Portability (Article 20)
You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller when processing is based on consent or contract and carried out by automated means.
Right to Object (Article 21)
You have the right to object to processing based on legitimate interests or for direct marketing purposes. We will stop processing unless we demonstrate compelling legitimate grounds that override your interests.
Right Not to Be Subject to Automated Decision-Making (Article 22)
You have the right not to be subject to decisions based solely on automated processing, including profiling, which produce legal effects or similarly significantly affect you. We do not currently engage in such automated decision-making.
How to Exercise Your Rights
To exercise any of your GDPR rights, please contact us at:
Email: [email protected]
We will respond to your request within one month. In complex cases, we may extend this period by two additional months and will inform you of the extension and reasons.
You will not be charged for exercising your rights unless your request is manifestly unfounded or excessive.
Data Security
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of data in transit and at rest
- Regular security assessments
- Access controls and authentication
- Staff training on data protection
- Incident response procedures
Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. If the breach is likely to result in a high risk to you, we will also notify you directly without undue delay.
Data Protection Officer
While we are not legally required to appoint a Data Protection Officer (DPO), you can contact us regarding any data protection matters at [email protected]
International Transfers
When we transfer personal data outside the EEA, we ensure appropriate safeguards are in place:
- Standard Contractual Clauses approved by the European Commission
- Transfers to countries with adequacy decisions
- Other legally approved transfer mechanisms
Complaints
If you are not satisfied with how we handle your data or your requests, you have the right to lodge a complaint with the supervisory authority:
Autoriteit Persoonsgegevens (Dutch DPA)
Postbus 93374
2509 AJ Den Haag
Netherlands
Website: autoriteitpersoonsgegevens.nl
Updates to This Information
We may update this GDPR information periodically to reflect changes in our practices or legal requirements. The date at the top indicates when this page was last updated.