Privacy Policy

Last updated: March 2026


Nordnatur Tech OÜ takes your privacy seriously. This policy explains what personal data we collect, why we collect it, and what we do with it, in plain language, without unnecessary complexity.

If you have questions or want to exercise any of your rights, you can reach us at office@nordnatur.com at any time.


Who We Are

Nordnatur Tech OÜ
Registry code: 16469064
Registered in Estonia, European Union
Website: dev.nordnatur.com/
Contact: office@nordnatur.com

We are the data controller for all personal data collected through this website.


What Data We Collect and Why

When You Place an Order

To fulfil your order and deliver your goods, we collect:

  • Name and delivery address
  • Email address and phone number
  • Order details (products, quantities, amounts)
  • Payment information — processed securely by our payment providers (see Third Parties below). We do not store full card details on our servers.

Lawful basis: Performance of a contract. We need this data to process and deliver your order, and to communicate with you about it.

We keep order records for seven years to meet Estonian accounting and tax obligations. After that period, data is deleted.

When You Sign Up for Our Newsletter

If you choose to join our mailing list — either during checkout or via a sign-up form on the site — we collect your email address. We use this to send you our content: Space Insights, material guides, product updates, and occasional offers.

Lawful basis: Consent. You can unsubscribe at any time using the link in any email we send, or by writing to office@nordnatur.com. Unsubscribing removes you from future mailings immediately.

We keep your email address on our mailing list until you unsubscribe.

When You Take Our Quiz

The quiz on our site is anonymous. It collects no personal data unless you choose, at the end, to join our mailing list — in which case, only your email address is collected, as described above.

When You Visit Our Website

Our website uses cookies — small text files stored on your device — to make the site function properly. These include:

  • Essential cookies: Required for the shop to work (your basket, your session, login state). These cannot be disabled without breaking site functionality.
  • Functional cookies: Remember your preferences (currency, language).

We do not currently use advertising or tracking cookies, and we do not share browsing data with third-party advertisers.

If you have questions about specific cookies in use, please write to office@nordnatur.com.


Third Parties We Share Data With

We share data with third parties only where necessary to operate our services. We do not sell personal data.

Payment Processing

PayPal (Europe) S.à r.l. et Cie, S.C.A. — When you pay by PayPal, you are directed to PayPal’s platform. PayPal processes your payment data under their own privacy policy, available at paypal.com/privacy.

Email Marketing

MailerLite (MailerLite UAB, Lithuania) — We use MailerLite to manage our mailing list and send newsletters. When you subscribe, your email address is transferred to MailerLite’s servers. MailerLite is GDPR-compliant and processes data within the EU. Their privacy policy is available at mailerlite.com/legal/privacy-policy.

Hosting and Website Infrastructure

Our website is hosted on servers within the European Union. WordPress and WooCommerce power the site. Standard server logs (including anonymised IP addresses) may be retained for security and troubleshooting purposes for up to 30 days.


Your Rights

Under the EU General Data Protection Regulation (GDPR), you have the following rights regarding your personal data:

Access — You can ask us to confirm whether we hold data about you and request a copy of it.

Correction — You can ask us to correct inaccurate or incomplete data.

Erasure — You can ask us to delete your data where we no longer have a legal basis to hold it. Note that we are required to retain order records for seven years for tax purposes; this data cannot be erased early.

Restriction — You can ask us to limit how we use your data while a dispute is resolved.

Portability — You can ask for your data in a structured, machine-readable format.

Objection — You can object to processing based on legitimate interests.

Withdrawal of consent — Where processing is based on consent (newsletter), you can withdraw it at any time. This does not affect the lawfulness of any processing before withdrawal.

To exercise any of these rights, write to office@nordnatur.com. We will respond within 30 days. We may ask you to verify your identity before acting on a request.


Supervisory Authority

If you believe we have handled your personal data incorrectly, you have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon):

Website: aki.ee Email: info@aki.ee Phone: +372 627 4135

You may also contact the data protection authority in your country of residence within the EU/EEA.


Changes to This Policy

We may update this policy from time to time — for example, if we add new services or our practices change. The “last updated” date at the top of this page will reflect any changes. For significant changes, we will notify active customers by email.


Contact

For any privacy-related question, request, or concern:

Nordnatur Tech OÜ
office@nordnatur.com

We aim to respond within five business days.