Privacy Policy
I. Controller
The controller of personal data pursuant to Article 4(7) of Regulation (EU) 2016/679 (GDPR) is:
Tereza Ehrenbergerová
Company ID: 06350607
Address: Kuršova 985/10, 635 00 Brno
Czech Republic
Email: tereza@littlestitchatelier.com
Website: www.littlestitchatelier.com
The controller processes personal data in accordance with applicable data protection laws.
Personal data means any information relating to an identified or identifiable natural person.
II. Categories of Personal Data
The controller processes personal data provided by the customer when placing an order, including:
- name and surname
- email address
- billing address (if required for invoicing)
- any other information necessary to complete the order
Because the shop sells digital products only, no shipping address is required unless needed for invoicing.
III. Purpose and Legal Basis for Processing
Contract performance
Personal data is processed to process orders and fulfill contractual obligations
(Art. 6(1)(b) GDPR).
Legal obligations
Data may be processed to comply with accounting and tax obligations
(Art. 6(1)(c) GDPR).
Marketing
If the customer consents, email may be used for newsletters or updates
(Art. 6(1)(a) GDPR).
Consent can be withdrawn at any time by emailing:
tereza@littlestitchatelier.com
Personal data is not used for automated decision-making or profiling.
IV. Data Retention
Personal data is stored:
- for the duration necessary to fulfill the contract and handle any claims (maximum 10 years after the end of the contractual relationship)
- for marketing purposes until consent is withdrawn,
- no longer than 5 years from the last interaction
After this period, data will be deleted or anonymized.
V. Recipients of Personal Data
Personal data may be shared with:
- e-shop platform providers
- payment processing providers
- accounting service providers
- email marketing providers (if applicable)
Data is not sold to third parties.
If data is transferred outside the EU, appropriate safeguards are applied (e.g. Standard Contractual Clauses).
VI. Rights of the Data Subject
The customer has the right to:
- access personal data
- request correction or deletion
- restrict processing
- data portability
- object to processing
- withdraw consent for marketing
- file a complaint with a supervisory authority
Requests can be sent to:
tereza@littlestitchatelier.com
Supervisory authority:
Czech Data Protection Authority (www.uoou.cz)
VII. Data Security
The controller has implemented appropriate technical and organizational measures to protect personal data, including:
- secure data storage
- restricted access
- protection of electronic systems
- password protection
VIII. Final Provisions
By placing an order or submitting personal data through the website, the customer confirms that they have read and accept this Privacy Policy.
The controller may update this policy.
The current version will always be published on the website.
Effective date: 1 February 2026