Privacy Policy – Ideas from the Wood

Effective Date: 28/06/2025
Last Updated: 28/06/2025

1. Introduction

At Ideas from the Wood, we respect and protect your privacy. This Privacy Policy explains how we collect, use, share, and protect your personal data when you use our website and services, in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the Austrian Data Protection Act (Datenschutzgesetz – DSG).

2. Data Controller

Ideas from the Wood
Geblergasse 63/9
1170 Vienna, Austria
Email: ideasfromthewood@proton.me

You may contact us at any time if you have questions about your data or this policy.

3. Personal Data We Collect

When you visit our website, place an order, or contact us, we may collect the following types of personal data:

  • Identity Information – name, billing address, shipping address

  • Contact Information – email address, phone number

  • Payment Information – your payment details are handled securely by Stripe, our third-party payment processor. We do not store your full payment card data.

  • Order Details – products purchased, order value, delivery method

  • Technical Data – IP address, browser type, device type, referring URLs, access times

  • Communication Data – emails and messages sent to our customer support

We do not collect or store sensitive personal data (e.g. racial or ethnic origin, health data, etc.).

4. How We Use Your Data

We use your personal data only for the purposes permitted under the GDPR:

  • To process and deliver your order

  • To manage payments and refunds

  • To provide customer service and support

  • To communicate order updates and account-related notifications

  • To maintain security and prevent fraud

  • To comply with legal obligations (e.g., recordkeeping under Austrian law)

  • To analyze and improve our website and services (only with your consent for analytics cookies)

5. Legal Basis for Processing

We process your data on the following lawful bases:

  • Contractual necessity – processing your orders and fulfilling our agreement with you

  • Legal obligation – complying with accounting, tax, and legal requirements

  • Legitimate interest – fraud prevention, service improvement, marketing analytics

  • Consent – sending newsletters or placing optional cookies (which you can withdraw at any time)

6. Data Sharing

We share your data only when necessary and in accordance with the GDPR. This includes sharing with:

  • Stripe – Our payment processor, which securely handles all payment transactions. Stripe’s privacy policy is available at: https://stripe.com/privacy

  • Shipping providers – such as Österreichische Post or UPS, to deliver your order

  • Service providers – e.g., hosting services, email providers, IT support

  • Authorities – if required by law or for legal proceedings

All third parties are contractually required to protect your data and use it only for specified purposes.

7. Cookies and Tracking Technologies

We use cookies to:

  • Enable essential website functions (e.g., cart, checkout)

  • Improve user experience

  • Analyze site usage (only with your consent)

You will be prompted to accept or reject non-essential cookies via a cookie banner when visiting our site.

8. Data Retention

We retain personal data only as long as necessary:

  • For order and transaction records: 7 years, as required by Austrian tax law

  • For customer support records: up to 3 years after your last contact

  • For marketing (with consent): until you unsubscribe

Once retention periods expire, data is securely deleted or anonymized.

9. Your Rights Under GDPR

As a data subject, you have the following rights:

  • Access – request a copy of your personal data

  • Rectification – correct inaccurate or incomplete data

  • Erasure – request deletion of your data (“right to be forgotten”)

  • Restriction – limit processing under certain conditions

  • Objection – to data processing for legitimate interests or direct marketing

  • Data portability – receive your data in a structured, machine-readable format

  • Withdraw consent – at any time, without affecting previous processing

To exercise your rights, email us at: [your contact email]

10. Complaints

If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Austrian Data Protection Authority:

Österreichische Datenschutzbehörde
Barichgasse 40–42
1030 Vienna, Austria
Website: https://www.dsb.gv.at

11. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in law or our services. We will post the updated version on our website and revise the “Last Updated” date above. We recommend reviewing this page regularly.

12. Contact Us

If you have any questions about this Privacy Policy or how we handle your data, please contact us:

Ideas from the Wood
Geblergasse 63/9
1170 Vienna, Austria
Email: ideasfromthewood@proton.me