Personal Data Processing

We attach great importance to the protection of your personal data and comply with all legal requirements regarding its processing. Below is a description of how we process your data:

Purpose of personal data processing:

  • Processing and fulfilling orders (payment, delivery, etc.)

  • Establishing and maintaining contact with you

  • Improving the quality of our services

  • Providing a loyalty program in the physical store and on the website

  • Fulfilling obligations to you as a customer, in accordance with the terms of sale

The controller of personal data for the online store irondust.eu is IRON DUST OÜ, registration code 17177576, phone +372 5880 6001, email info@irondust.eu (hereinafter referred to as the “merchant”).


Which personal data will be processed?

  • Name

  • Contact information, such as phone number and email address

  • Billing and delivery address

  • Bank account number

  • Cost of goods and services and payment-related data (purchase history)

  • Customer support data

  • Other information related to customer surveys and/or offers


Purpose of processing personal data

Personal data is processed for the purpose of fulfilling the contract concluded with the customer, as well as for fulfilling legal obligations (e.g., accounting and resolving consumer disputes).

Personal data is used to manage customer orders and deliver goods.
Purchase history data (purchase date, product, quantity, customer data) is used to create an overview of purchased goods and services and to analyze customer preferences.
Bank account numbers are used for refunding payments.
Personal data, such as email address, phone number, and customer name, is processed for handling matters related to the provision of goods and services (customer support).
IP addresses or other network identifiers of the online store user are processed to provide online services and to compile website usage statistics.


Transfer of personal data to authorized processors

The merchant keeps the customer’s personal data confidential and discloses it to third parties only with the customer’s consent, except where disclosure is required by law.
The online store user agrees that the merchant has the right to process the customer’s data to provide the relevant services, including transferring the data to parties involved in providing services.

List of authorized processors:

Delivery service providers:

  • DPD

  • Itella

  • Omniva

  • Venipak

Payment intermediaries:

  • Paysera

  • Swedbank

  • SEB

  • Luminor

  • LHV

  • Coop Pank

  • Maksekeskus

  • PayPal

  • Pokopay

Statistics collection – to improve user experience:

  • Google Analytics

  • Facebook

  • Loyalty program in physical store

  • Loyalty program on website


Security and access to data

Personal data is stored on Zone servers located in an EU member state or an EEA country. Data may be transferred to countries with an adequate level of protection recognized by the European Commission, as well as to U.S. companies participating in the Privacy Shield program.

The online store implements physical, organizational, and technological security measures to protect personal data from accidental or unlawful destruction, loss, alteration, or unauthorized access.

Processing of personal data by authorized processors is carried out under contracts that require appropriate security measures.


Access to and correction of personal data

Stored personal data can be viewed and corrected through the online store account management section.
If a purchase was made as a guest (without an account), a request for personal data can be sent by email to info@irondust.eu.


Retention

Upon closing a user account, personal data is deleted except where retention is required for accounting purposes or for resolving consumer disputes.
Data from guest purchases is retained for 1 year.
In case of disputes, data is retained until the claim is resolved or the limitation period expires (3 years).
Data required for accounting purposes is retained for 7 years.


Deletion

Personal data stored in the online store, including your account, can be deleted by sending a request to info@irondust.eu.
Requests to delete other personal data can also be made by email.


Direct marketing

Email addresses and phone numbers are used for direct marketing only with the customer’s consent.
Customers who do not wish to receive direct marketing messages can unsubscribe via a link in the email or contact customer support.
If personal data is processed for direct marketing purposes (including profiling), the customer has the right to object at any time to the initial and further processing, including profiling related to direct marketing, by notifying customer support via email.


Dispute resolution

Disputes regarding personal data processing are resolved through customer support.
Supervisory authority: Estonian Data Protection Inspectorate (info@aki.ee).
Consumer disputes can also be addressed via the ODR platform.