Legal

Privacy Policy

This page explains, in plain language, what personal data Blueward Diaries processes, why, on what legal basis, and for how long. It reflects the website's actual current technical setup.

Last updated: 2 July 2026

1. Who is responsible (Controller)

The person responsible for processing your personal data on this website (the “controller” under the EU General Data Protection Regulation, GDPR) is the operator of Blueward Diaries:

  • Lea Sophie Gamsjäger
  • Pilgramgasse 8/2/35, 1050 Wien
  • General contact: hello@bluewarddiaries.com
  • Privacy enquiries: hello@bluewarddiaries.com

2. Hosting and website infrastructure

This website is built and hosted on the Lovable platform, using Lovable Cloud (which runs on Supabase) for the database, authentication and server-side functions. When you visit the site, requests are handled by this hosting infrastructure.

As with any website, the hosting and server layer may process standard technical request metadata to deliver pages and keep the service secure and stable. This can include:

  • IP address of the requesting device
  • browser type and user agent
  • date and time of the request
  • the page or resource requested and referring information

Purpose: delivering the website, ensuring technical stability, and protecting against abuse and attacks. Legal basis: our legitimate interest in a secure, functioning website (Article 6(1)(f) GDPR).

Detailed server-log content and retention periods at the hosting and infrastructure layer are managed by the platform provider in line with its own documentation.

3. Contact form

When you use the contact form, the following data is processed:

  • your name
  • your email address
  • the inquiry type you select
  • your message
  • the page URL you submitted from
  • the submission timestamp

Your name, email address, inquiry type and message are stored securely in our website database. The page URL and a human-readable submission timestamp are included in the notification email we receive, but the page URL is not stored as a separate field in our database.

Your IP address is used only transiently to apply rate limiting (to block spam and abuse). It is not stored in our database alongside your message.

To notify us of your message, the submitted data is transmitted securely, server-side, to our email delivery provider, Resend (see section 5), which sends the notification to our internal address.

Purpose: to receive and respond to your enquiry. Legal basis: where your message concerns a (potential) collaboration or contract, processing is based on steps taken at your request prior to, or in performance of, a contract (Article 6(1)(b) GDPR). For general messages, we rely on our legitimate interest in responding to enquiries directed to us (Article 6(1)(f) GDPR).

Retention: ordinary resolved enquiries are deleted six months after they are marked resolved, unless a contractual, evidentiary or legal retention requirement applies (in which case they are kept for as long as necessary). Deletion is currently performed manually.

4. Newsletter

If you subscribe to our newsletter, we process the following through our email service provider MailerLite:

  • your email address
  • your first name (optional)
  • your subscription and confirmation status, and the relevant registration and confirmation timestamps
  • your assignment to the Blueward Diaries newsletter group

Purpose: to send you the Blueward Diaries newsletter — travel stories, destination guides, new videos, lifestyle updates and occasional recommendations.

Legal basis: your consent (Article 6(1)(a) GDPR), which you give when subscribing.

Double opt-in: after you sign up, MailerLite sends a confirmation email. Your subscription becomes active only once you confirm via that email. You can withdraw your consent at any time using the unsubscribe link included in every newsletter email; withdrawal does not affect the lawfulness of processing before withdrawal.

No newsletter tracking: Blueward Diaries has disabled newsletter open tracking and link-click tracking in MailerLite. We do not use tracking pixels to determine whether an individual newsletter was opened, and we do not record which newsletter links an individual recipient clicks.

Service provider (processor): the newsletter is operated by MailerLite, acting as our processor. For customers in the EEA, UK and Switzerland, the relevant MailerLite legal entity is MailerLite Limited, an Irish registered company at 88 Harcourt Street, Dublin 2, D02 DK18, Ireland.

Retention: subscriber data is retained for as long as your subscription remains active. If you unsubscribe, your address may remain on a suppression list so that no further newsletter is sent to you. Where you request erasure, your data will be deleted unless limited retention is necessary to document consent, its withdrawal or compliance with legal obligations.

How the signup works: your subscription is submitted securely to MailerLite through a server-side connection. No MailerLite JavaScript, pop-up or embedded MailerLite form loads on this website. The credentials used for this connection are stored securely on the server and are never exposed in the website’s frontend code.

5. Email delivery (Resend)

We use Resend to deliver the notification email generated when you submit the contact form.

Data sent to Resend for this purpose: your name, email address, inquiry type, message, the page URL and the submission timestamp.

This happens server-side only. The credentials used for this connection are stored securely on the server and are never exposed in the website’s frontend code.

We do not use contact-form notification emails for marketing analytics. The provider may retain technical delivery and event information in accordance with its service settings and documentation.

Resend is operated by Resend, Inc., which is based in the United States, and processing of this data in the United States may occur. Please see section 13 regarding international transfers.

6. Fonts

All fonts used on this website (Anton, Prata, Dancing Script and Nunito Sans) are self-hosted and served directly from this website. No font files are requested from Google Fonts, and no connection is made to Google servers (such as fonts.googleapis.com or fonts.gstatic.com) to load fonts.

7. Social media links

We link to our profiles on Instagram, TikTok, Pinterest and YouTube. These are ordinary external links.

No social-media embeds, buttons with tracking, or social-media scripts load automatically on this website. Data is only transmitted to the relevant provider when you actively click a link and visit that platform, at which point that provider’s own privacy policy applies.

8. YouTube videos

This website can display YouTube videos embedded inside published blog posts, using the privacy-enhanced youtube-nocookie.com domain. Opening a post that contains an embedded YouTube video may establish a connection to YouTube/Google and transmit technical data such as your IP address and device or browser information, in order to load and play the video.

No YouTube embed is currently active on ordinary public pages. On pages without a video, no connection to YouTube/Google is made.

9. Cookies and browser storage

Ordinary visitors: based on the website’s current configuration, we do not intentionally set cookies for ordinary visitors and do not use analytics or advertising cookies. No non-essential cookies are intentionally placed by us.

Authenticated administrators: when an authorized administrator signs in to the private admin area, the authentication system (Supabase) stores the login session in the browser’s localStorage (for example, an entry such as sb-<project>-auth-token). This is strictly necessary to keep the administrator signed in and applies only after login — not to ordinary visitors.

No affiliate cookies or affiliate tracking technologies are currently active on this website. If a future affiliate programme places non-essential cookies or similar tracking technologies before or when a link is used, the website’s consent mechanism and cookie information will be updated before that technology is activated.

10. Administrator authentication

The website has a private authentication area for authorized administrators (for managing content). Sign-in uses Supabase authentication, and the session is stored in the browser’s localStorage as described above.

Public account registration is disabled. The sign-in page is available only to existing authorized administrators; there is no public self-service sign-up.

11. Comments and commerce

Comments: public comment submission is currently disabled on the website. No comment data is collected from visitors at this time.

Commerce: this website does not sell products directly and does not process any payments.

12. Affiliate links and commercial recommendations

Blueward Diaries may include clearly identified affiliate links in future articles, guides, newsletters and recommendation pages. If you click an affiliate link and subsequently make a purchase or booking, we may receive a commission from the relevant provider. The price you pay does not normally increase as a result.

Affiliate links will be clearly identified as advertising, affiliate links or commercial recommendations where required.

When you click an affiliate link, you are redirected to the relevant external provider or affiliate network. That provider may process technical information such as your IP address, browser or device information, the referring page, the clicked link, the time of the click and an affiliate identifier. The provider may use cookies, tracking links or similar technologies to attribute a later booking or purchase to Blueward Diaries.

No affiliate tracking technology is currently loaded automatically on this website. Until a specific affiliate programme is activated, clicking an ordinary external link does not involve affiliate attribution by Blueward Diaries.

The exact provider, data processing, storage period, cookies and international transfers depend on the affiliate programme used. This Privacy Policy will be updated before or when a specific affiliate programme or tracking technology is activated.

14. Data recipients and international transfers

We share personal data only with the following processors, for the purposes above:

  • Lovable / Lovable Cloud (Supabase) — website hosting, database, authentication and server functions.
  • MailerLite (MailerLite Limited, Ireland for EEA customers) — newsletter delivery.
  • Resend (Resend, Inc., United States) — contact-form notification emails.

Some of these providers, or their infrastructure, may process data outside the European Economic Area (EEA) — in particular Resend, Inc. in the United States. Where personal data is transferred outside the EEA, the relevant provider applies the transfer mechanism specified in its current data processing agreement, such as an adequacy decision or Standard Contractual Clauses, where applicable.

15. How long we keep your data

  • Active newsletter subscriptions — for as long as your subscription is active.
  • Unsubscribed newsletter addresses — may be kept on a suppression list to ensure you are not emailed again, unless you request erasure.
  • Contact enquiries — intended to be deleted six months after being marked resolved, unless a contractual or legal retention requirement applies (automated deletion is not yet active; see section 3).
  • Hosting/server logs — retained by the hosting infrastructure for a period controlled by the platform provider.
  • Administrator accounts — for as long as the person remains an authorized administrator.

16. Your rights

Under the GDPR you have the right to:

  • access your personal data
  • rectify inaccurate data
  • erasure of your data
  • restrict processing
  • object to processing based on legitimate interests
  • data portability
  • withdraw consent at any time (for the newsletter)

To exercise any of these rights, contact us at hello@bluewarddiaries.com.

You also have the right to lodge a complaint with the competent Austrian supervisory authority, the Austrian Data Protection Authority (Österreichische Datenschutzbehörde, Barichgasse 40-42, 1030 Vienna, dsb.gv.at).

17. Security

We use appropriate technical and organizational measures to protect your personal data, including access controls, secure server-side handling of credentials, input validation and rate limiting. However, no method of transmission or storage on the internet can be guaranteed to be completely secure, so we cannot provide an absolute guarantee of security.

18. Updates to this policy

This Privacy Policy was last updated on 2 July 2026. We may update it when our services, tools or legal requirements change. The current version is always available on this page.