Personal Data Processing Policy
We value the protection of your personal data and strictly comply with all legal requirements for its processing. Below is an overview of how we process your information.
Purpose of Personal Data Processing
- Processing and fulfillment of orders (payment, delivery, etc.)
- Establishing and maintaining contact with you
- Improving the quality of our services
- Providing loyalty programs in the physical store and on the website
- Fulfilling obligations to you as a customer under the terms of sale
The controller of personal data for the online store
irondust.eu is
IRON DUST OÜ, registration code
17177576, phone
+372 5880 6001, email
info@irondust.eu (hereinafter referred to as “the merchant”).
What Personal Data Will Be Processed
- Name
- Contact details such as phone number and email address
- Billing and delivery address
- Bank account number
- Value of goods and services and data related to payments (purchase history)
- Customer support data
- Other information related to customer surveys and/or offers
Purpose of Processing Personal Data
Personal data is processed to fulfill the contract concluded with the customer. Processing is also carried out to comply with legal obligations (for example, accounting and resolution of consumer disputes).
Customer data is used for order management and delivery of goods.
Purchase history data (purchase date, product, quantity, customer information) is used to provide an overview of purchased goods and services and to analyze customer preferences.
Bank account numbers are used for refunds.
Personal details such as email address, phone number, and customer name are used to resolve issues related to product and service delivery (customer support).
IP addresses or other network identifiers are processed to provide online services and generate web usage statistics.
Disclosure of Personal Data to Authorized Processors
The seller keeps the customer’s personal data confidential and discloses it to third parties only with the customer’s consent, unless disclosure is required or permitted by law.
The user of the online store agrees that the seller has the right to process their data for the purpose of providing relevant services, including sharing data with third parties involved in the provision of those services.
Authorized processors include:
Delivery service providers – for shipping orders to customers:
Payment intermediaries – for processing payments:
- Paysera
- Swedbank
- SEB
- Luminor
- LHV
- Coop Bank
- Maksekeskus
- PayPal
- Pocopay
Statistics collection – for improving the online store’s user experience:
Loyalty programs:- Loyalty program in the physical store
- Loyalty program on the website
Data Security and Access
Personal data is stored on servers of Zone, located within an EU member state or a country that is part of the European Economic Area. Data may be transferred to countries deemed to have adequate data protection levels by the European Commission, as well as to companies in the USA participating in the Privacy Shield framework.
The online store applies appropriate physical, organizational, and IT security measures to protect personal data from accidental or unlawful destruction, loss, alteration, unauthorized access, or disclosure.
Personal data is processed only under contracts between the online store and its authorized processors, who are required to ensure adequate security measures.
Access to and Correction of Personal Data
Customers can view and update their personal data through the account management section of the online store.
If a purchase was made as a guest (without creating an account), a data access request can be sent via email to
info@irondust.eu.
Data Retention
ёWhen a customer account is closed, personal data is deleted unless retention is required for accounting or consumer dispute purposes.
- Guest purchases: personalized purchase history is stored for 1 year.
- Payment and consumer dispute cases: personal data is stored until the claim is satisfied or the limitation period expires (3 years).
- Accounting data: stored for 7 years in accordance with legal requirements.
Data Deletion
Personal data stored in the online store, including user accounts, can be deleted upon request by sending an email to
info@irondust.eu.
You may also request the deletion of other personal data by contacting the same address.
Direct Marketing Messages
Email addresses and phone numbers may be used to send direct marketing messages if the customer has given consent.
If you no longer wish to receive marketing messages, please click the unsubscribe link provided in the email header or contact our customer support service.
If personal data is processed for direct marketing purposes (including profiling), the customer has the right to object to such processing at any time by notifying customer support via email.
Dispute Resolution
Disputes related to personal data processing are handled by our customer support service.
The supervisory authority is the
Estonian Data Protection Inspectorate (
info@aki.ee).
Consumers may also contact the Consumer Protection and Technical Regulatory Authority or the Online Dispute Resolution (ODR) platform.