This privacy policy applies to teepapst.com. The controller is Teepapst GmbH, which also operates the aiya – THE TEA brand and the aiyatea.com webshop; teepapst.com itself does not operate its own webshop. Last updated: 8 September 2026.
Who We Are
The controller within the meaning of the General Data Protection Regulation (GDPR) and other data protection provisions is:
Teepapst GmbH
Rotenturmstraße 21/3
1010 Vienna
Austria
+43 1 997 40 25
info@teepapst.com
aiyatea.com
Contacting Our Data Protection Officer
The controller’s data protection officer is:
DataCo GmbH
Sandstr. 33
80335 Munich
Germany
+49 89 7400 45840
www.dataguard.de
General Information on Data Processing
On this page, we inform you about the processing of your personal data on this website. How we collect and use your personal data depends on how you interact with us or which services you use. We only collect, use, or share your personal data where we have a legitimate purpose and a legal basis for doing so.
What do we mean by legal basis? Consent (Art. 6(1)(a) GDPR) – You have given us your consent to process your personal data for the specific purpose we explained to you. You have the right to withdraw your consent at any time. Please contact our data protection officer using the contact details given below. Contract (Art. 6(1)(b) GDPR) – We need to use your data to fulfil a contract you have with us, or because you asked us to, or because you took certain steps before entering into that contract. Legal obligation (Art. 6(1)(c) GDPR) – We need to use your data to comply with the law. Vital interests (Art. 6(1)(d) GDPR) – Processing your data is necessary to protect your vital interests or those of another person, for example to protect you from serious physical harm. Public task (Art. 6(1)(e) GDPR) – Processing your data is necessary for the performance of a task carried out in the public interest, or one covered by a task laid down by law. Legitimate interests (Art. 6(1)(f) GDPR) – Processing your data is necessary to support a legitimate interest that we or another party have, only where your own interests do not override this.
Your Rights
If your personal data is processed, you are a data subject within the meaning of the GDPR and you have the following rights against the controller:
1. The Right to Access (Art. 15 GDPR)
You have the right to request confirmation from us as to whether personal data concerning you is being processed. If so, you have a right to access that data and to the following information:
- The purposes of processing
- The categories of personal data concerned
- The recipients or categories of recipients
- The envisaged storage period, or the criteria used to determine that period
- The existence of the rights to rectification, erasure, restriction, or objection
- The right to lodge a complaint with the competent supervisory authority
- Where applicable, the origin of the data (if not collected from you directly)
- Where applicable, the existence of automated decision-making, including profiling, with meaningful information about the logic involved, its significance, and its envisaged consequences
- Where applicable, the transfer of personal data to a third country or international organisation
2. Right to Rectification (Art. 16 GDPR)
If your personal data is inaccurate or incomplete, you have the right to request that it be corrected or completed without delay.
3. Right to Restriction of Processing (Art. 18 GDPR)
Where one of the following applies, you have the right to request that the processing of your personal data be restricted:
- You contest the accuracy of your personal data, for a period allowing us to verify its accuracy.
- The processing is unlawful and you oppose the erasure of the personal data, requesting the restriction of its use instead.
- We no longer need your personal data for the purposes of processing, but you need it to establish, exercise, or defend legal claims, or you have objected to the processing pending verification of whether our legitimate grounds override yours.
4. Right to Erasure (“Right to be Forgotten”) (Art. 17 GDPR)
Where one of the following grounds applies, you have the right to request the prompt erasure of your personal data:
- Your data is no longer necessary for the purposes for which it was originally collected.
- You withdraw your consent and there is no other legal basis for the processing.
- You object to the processing and there are no overriding legitimate grounds for it, or you object under Art. 21(2) GDPR.
- Your personal data has been processed unlawfully.
- Erasure is required to comply with a legal obligation under Union or Member State law to which we are subject.
- The personal data was collected in relation to information society services offered under Art. 8(1) GDPR.
Please note that the above grounds do not apply where processing is necessary:
- To exercise the right of freedom of expression and information;
- To comply with a legal obligation, or to perform a task carried out in the public interest to which we are subject.
- For reasons of public interest in the area of public health.
- For archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes.
- To establish, exercise, or defend legal claims.
5. Right to Data Portability (Art. 20 GDPR)
You have the right to receive your personal data in a structured, commonly used, and machine-readable format, or to request its transfer to another controller.
6. Right to Object to Certain Processing (Art. 21 GDPR)
For reasons arising from your particular situation, you have the right to object at any time to the processing of your personal data based on Art. 6(1)(e) or (f) GDPR, including profiling based on those provisions. Where your personal data is processed for direct marketing purposes, you have the right to object at any time to such processing, including any related profiling.
7. Right to Lodge a Complaint with a Supervisory Authority
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority if you consider that the processing of your personal data infringes the GDPR. The supervisory authority with which the complaint was lodged will inform you of the progress and outcome of the complaint, including the possibility of a judicial remedy under Art. 78 GDPR. A list of the competent supervisory authorities in Germany is available on the website of the Federal Commissioner for Data Protection at: https://www.bfdi.bund.de/DE/Service/Anschriften/Laender/Laender-node.html
Data Sharing and International Transfers
As explained in this privacy policy, we use various service providers who help us deliver our services and keep your data secure. Where we use these providers, it is necessary to share your personal data with them. We have entered into agreements with all providers we share your data with that oblige them to protect your data. Where your personal data is transferred outside the EU, we ensure it receives an equivalent level of protection, either because the destination country has an “adequate” level of data protection as determined by the European Commission, or because we apply another safeguard, such as an enhanced contractual arrangement, i.e. the Standard Contractual Clauses (SCCs) adopted by the European Commission. You can request a copy of the SCCs we have concluded with our service providers by sending an email to the email address given in this privacy policy.
Provision of the Website and Creation of Log Files
1. Description and Scope of Data Processing
Each time our website is accessed, our system automatically collects data and information from the accessing computer’s system. The following data is collected: information about the browser type and version used, the user’s operating system, the user’s internet service provider, the date and time of access, the website from which the user’s system reached our website, and the websites accessed via our website by the user’s system. This data is stored in our system’s log files. This data is not stored together with other personal data of the user.
2. Purpose of Data Processing
Temporary storage of the IP address by the system is necessary to enable the website to be delivered to the user’s computer. For this, the user’s IP address must remain stored for the duration of the session. Storage in log files takes place to ensure the functionality of the website. In addition, this data helps us optimise the website and ensure the security of our IT systems. The data is not evaluated for marketing purposes in this context.
3. Legal Basis for Data Processing
The legal basis for the temporary storage of the data and log files is Art. 6(1)(f) GDPR.
4. Duration of Storage
The data is deleted as soon as it is no longer required to achieve the purpose for which it was collected. In the case of data collected to provide the website, this is the case once the respective session has ended. In the case of data stored in log files, this is the case after seven days at the latest. Storage beyond this is possible; in that case, the users’ IP addresses are deleted or anonymised so that it is no longer possible to identify the accessing client.
5. Right to Object
The collection of data to provide the website and the storage of data in log files is essential for the operation of the website. The user therefore has no option to object. Whether such an objection would succeed would in any case be determined by a balancing of interests.
Hosting
Our website is hosted on external servers operated by a service provider we have commissioned. Our hosting provider is Bluehost.
Use of Cookies
1. Description and Scope of Data Processing
When you visit our website, we use technical tools for various functions, in particular cookies, which may be stored on your device. When you first visit our website, and at any time thereafter, you can choose whether to allow cookies generally or select individual additional functions. You can make changes at any time via the “Cookie Settings” link in our website’s footer, or in your browser settings.
Cookies are text files, or information stored in a database, saved on your hard drive and associated with the browser you use, allowing certain information to flow to the party that sets the cookie. We use technically necessary cookies required for the technical operation of the website, in particular to store your language preference and to manage your cookie consent. Without these cookies, our website cannot be displayed fully correctly.
Beyond these technically necessary cookies, we do not currently use any further cookies or tracking services. Should additional, non-essential cookies (e.g. for statistics or marketing) be used in future, we will inform you before their use and obtain your explicit consent via our cookie consent manager.
2. Purpose of Data Processing
The purpose of using technically necessary cookies is to ensure the functionality of our website. Some functions of our website cannot be offered without the use of cookies, in particular carrying over your language preference and storing your cookie consent.
3. Legal Basis for Data Processing
The provisions of the German Telecommunications-Digital-Services-Data Protection Act (Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz, TDDDG) apply to the storage of information on, and/or access to information already stored on, the end user’s device. Where the setting and reading of cookies is technically necessary, this is done to ensure the functionality of our website; in this case, the storage of and access to cookies on your device is based on § 25(2) No. 2 TDDDG. Cookies are generally deleted after the end of the session or after a set period has elapsed. Where non-essential cookies are used in future, this will be based on your explicit consent, given via the cookie banner. In that case, the basis for storage of and access to information is § 25(1) TDDDG in conjunction with Art. 6(1)(a) and Art. 7 GDPR.
4. Objection and Deletion
You can withdraw your consent to the use of cookies at any time and manage your settings via the “Cookie Settings” link in our website’s footer. Alternatively, you can prevent the storage of cookies through the appropriate settings in your browser software. Please note that any browser settings you make only apply to the browser you are using at the time.
Email Contact
1. Description and Scope of Data Processing
Our website allows you to contact us via the email address provided. In this case, the user’s personal data transmitted with the email is stored. The data is used exclusively to process the conversation.
2. Purpose of Data Processing
In the case of contact by email, this also constitutes the necessary legitimate interest in processing the data.
3. Legal Basis for Data Processing
The legal basis for processing data transmitted in the course of sending an email is Art. 6(1)(f) GDPR. Our legitimate interest lies in responding to your email enquiry as effectively as possible. If the email contact aims at the conclusion of a contract, the additional legal basis for processing is Art. 6(1)(b) GDPR.
4. Duration of Storage
The data is deleted as soon as it is no longer required to achieve the purpose for which it was collected. For personal data sent by email, this is the case once the respective conversation with the user has ended. A conversation is considered ended once it can be inferred from the circumstances that the matter concerned has been conclusively resolved.
5. Right to Object
If a user contacts us by email, they may object to the storage of their personal data at any time. In such a case, the conversation cannot be continued. All personal data stored in connection with the contact will be deleted in this case.
Contact Form
1. Description and Scope of Data Processing
Our website has a contact form that can be used for electronic contact. If a user makes use of this option, the data entered in the input form is transmitted to us and stored. At the time the message is sent, the following data is stored: first name, last name, email address, optionally company, your message, as well as the IP address of the accessing computer and the date and time.
2. Purpose of Data Processing
The processing of personal data from the contact form’s input fields serves solely to process your enquiry. The other personal data processed during the sending process helps prevent misuse of the contact form and ensures the security of our IT systems.
3. Legal Basis for Data Processing
The legal basis for processing data transmitted via the contact form is Art. 6(1)(f) GDPR. Our legitimate interest lies in responding to your contact form enquiry as effectively as possible. If the contact aims at the conclusion of a contract, the additional legal basis for processing is Art. 6(1)(b) GDPR.
4. Duration of Storage
The data is deleted as soon as it is no longer required to achieve the purpose for which it was collected. For personal data from the contact form’s input fields, this is the case once the respective conversation with the user has ended. A conversation is considered ended once it can be inferred from the circumstances that the matter concerned has been conclusively resolved.
5. Right to Object
If a user contacts us via the contact form’s input fields, they may object to the storage of their personal data at any time. Please send us an informal email to info@teepapst.com. All personal data stored in connection with the contact will be deleted in this case.
Social Media Presences
1. Description and Scope of Data Processing
Our website links to our profiles on Facebook, Instagram, TikTok, and YouTube. These links are plain hyperlinks, not embedded widgets or plug-ins. No data is transmitted to the respective platform unless you click the link. Only once you follow a link and visit the respective platform does that platform’s own privacy policy apply. If you take any action there (e.g. comments, posts, likes), you may make personal data public as a result.
2. Purpose of Data Processing
We use our social media profiles to communicate and exchange information with (potential) customers, for example regarding product information, promotions, and customer contact.
3. Legal Basis for Data Processing
The legal basis for processing personal data for the purpose of communicating with customers and prospective customers is Art. 6(1)(f) GDPR. Our legitimate interest lies in responding to your enquiry as effectively as possible and being able to provide the information requested.
4. Further Information
Further information on the processing of your data by the respective platform, and the corresponding options for objection, is available here: Facebook: https://de-de.facebook.com/policy.php · Instagram: https://help.instagram.com/519522125107875 · TikTok: https://www.tiktok.com/legal/privacy-policy · YouTube/Google: https://policies.google.com/privacy
Embedding of YouTube Videos
1. Description and Scope of Data Processing
We embed videos from YouTube (YouTube LLC, 901 Cherry Ave., San Bruno, CA 94066, USA, a Google company) on individual pages. We use the privacy-enhanced mode via youtube-nocookie.com. The video is initially displayed only as a thumbnail; no connection to YouTube’s servers is made at that point. Only once you actively click the video to play it is a connection established to YouTube’s servers, and data such as your IP address and device and browser information may be transmitted and stored. If you are logged into your Google account at that time, YouTube may associate this action with your account.
2. Purpose of Data Processing
Embedding YouTube videos serves to provide multimedia content on our website.
3. Legal Basis for Data Processing
The legal basis is your consent given by actively clicking the video (Art. 6(1)(a) GDPR).
4. Further Information
Further information on the processing of data by YouTube/Google is available here: https://policies.google.com/privacy
Use of Professional Network Presences
1. Scope of Data Processing
Our website links to our company presence on LinkedIn. The provider is LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland. This presence is used for information, PR, and communication with (potential) customers and business partners. If you take any action there (e.g. comments, posts, likes), you may make personal data public as a result. We have no information of our own regarding LinkedIn’s processing of your personal data; further information is available in LinkedIn’s privacy policy: https://www.linkedin.com/legal/privacy-policy
2. Legal Basis for Data Processing
The legal basis for processing personal data for the purpose of communicating with customers and prospective customers is Art. 6(1)(f) GDPR. Our legitimate interest lies in responding to your enquiry as effectively as possible and being able to provide the information requested.
3. Exercising Your Rights
You may object at any time to the processing of your personal data that we collect as part of your use of our company presence, and exercise your rights as a data subject as set out in the “Your Rights” section of this privacy policy. Please send us an informal email to info@teepapst.com.
Use of WPML
1. Scope of Personal Data Processing
We use WPML from On The Go Systems Limited, 22/F 3 Lockhart Road, Wanchai, Hong Kong (hereinafter: WPML). WPML is a multilingual plugin for WordPress. We use WPML to display our website in different languages. When you visit our website, WPML stores a cookie on your device to save your selected language setting. Further information on the processing of data by WPML is available here: https://wpml.org/de/documentation-3/privacy-policy-and-gdpr-compliance/
2. Purpose of Data Processing
The use of WPML enables us to display our website in multiple languages.
3. Legal Basis for Processing Personal Data
The legal basis for the data processing is Art. 6(1)(f) GDPR. Our legitimate interest lies in addressing visitors to our website in their preferred language.
4. Duration of Storage
WPML stores a cookie on your device. Information on the cookie’s storage period is available at: https://wpml.org/documentation/privacy-policy-and-DSGVO-compliance
5. Options for Objection and Removal
You can prevent the storage of the WPML cookie by disabling cookie storage in your browser. Further information on options for objection and removal regarding WPML is available at: https://wpml.org/de/documentation-3/privacy-policy-and-gdpr-compliance/
This privacy policy was created with the support of DataGuard.
