datenschutz

Privacy Policy

This statement informs you, in accordance with the revised Swiss Federal Act on Data Protection (revFADP) and the EU GDPR, about the processing of your personal data.

Stand · 19.04.2026

Questa pagina è attualmente disponibile solo in tedesco e inglese. Di seguito è riportata la versione inglese.

1. Controller

Yourantai GmbH Via Naccio 50, 6614 Brissago, Switzerland Email: hello@yourantai.ch

2. What data we process

• Booking enquiries: name, email, phone (optional), requested dates, party size, message. • Experience requests (tea ceremony, zen, spa): as above. • Guest portal access: email address for magic-link authentication. • Technical data: anonymised server logs (IP, user-agent, timestamp) for abuse prevention — deleted after 30 days. • Cookies: strictly necessary cookies only (session, language preference). No tracking, no profiling, no advertising cookies.

3. Purpose and legal basis

Processing is carried out for the initiation and fulfilment of contracts (Art. 31 para. 2 lit. a revFADP; Art. 6 para. 1 lit. b GDPR), to comply with statutory obligations (notably tax and accounting retention obligations of 10 years) and on the basis of our legitimate interest in operating a secure website.

4. Processors and recipients

We use the following service providers under GDPR-compliant data processing agreements: • Hosting & database: Supabase (EU region, Frankfurt). • Web hosting: Lovable / Cloudflare Workers (EU region). • Email delivery: [TODO: e.g. Resend, once active. Currently no automated emails are sent — see note below.] Your data is never shared with third parties for advertising purposes.

5. Retention

Booking and contract data: 10 years (statutory tax retention). Enquiries without a booking: max. 12 months. Server logs: 30 days.

6. Your rights

You have the right of access, rectification, erasure, restriction of processing, data portability and objection at any time. An informal email to hello@yourantai.ch is sufficient. Right of complaint: you may lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC, Bern) and — where the GDPR applies — with the supervisory authority of your country of residence.

7. Security

The website uses encrypted connections (HTTPS / TLS) exclusively. Database access is protected by row-level security rules. Administrative functions are accessible only via separate admin accounts with role-based permissions.

Note on current email delivery

Booking confirmations and portal invitations are technically prepared but not yet sent automatically — the personal confirmation is sent manually by email. Once the sending domain is active, this statement will be updated accordingly.