Last updated 10 October 2026
This privacy policy explains how Nori teenindus OÜ processes personal data when you use the Nori online shop and related services, and when you make purchases in our physical shop that involve the processing of personal data. It provides information about how we use data, our service providers, retention periods and your rights.
1. Who processes your data
The controller is Nori teenindus OÜ, registry code 12181610. Our postal and service address is Peterburi tee 2, T1 keskus, Tallinn 11415, Estonia. For data protection enquiries, email info@nori.ee or call +372 56727279.
This privacy policy provides information about data processing. Visiting the website, creating an account or placing an order does not in itself constitute consent to marketing or optional analytics. We ask for separate consent for these purposes.
2. What data we collect and where we obtain it
We obtain data from you when you place an order, create or use an account, request an invoice, contact us or request a notification. Our payment and delivery partners provide us with payment or delivery status information and information needed to provide the service. Technical data is also generated when you use the website.
- Contact details: first and last name, email address and phone number.
- Delivery and billing details: the selected delivery method, parcel locker or collection point, the delivery address for courier delivery, the billing address where needed, and any delivery instructions you provide.
- Purchases on behalf of a company: company name, registry code, VAT number, billing details and the contact person's details.
- Order and payment data: products purchased, quantities, prices, discounts, order date and time and order number, payment method, payment and delivery status, and information about returns or refunds. For bank transfers, this also includes the payment information shown on the bank statement.
- Account data: saved contact details and addresses, order history, wishlist, language and notification preferences, and technical data relating to login and password verification.
- Communications and optional requests: your questions, complaints and the information needed to resolve them; for product availability notifications, your email address, the selected product and the name you provide; for marketing, your consent and the information needed to demonstrate it.
- Technical data: IP address, request times, URLs visited, device and browser information, identifiers used by cookies and similar technologies, and consent choices. Optional analytics data depends on your consent.
We do not ask for your personal identification code, date of birth, gender or health data for an ordinary purchase. Please do not include this information in order notes or the contact form unless it is necessary to resolve a specific enquiry.
You can also place an order without creating an account. For parcel locker delivery or collection from our shop, we do not require your home address solely for delivery purposes; an address may be needed for an invoice or the selected payment service. Mandatory fields are marked on the form. Without the necessary data, we cannot fulfil the relevant order, delivery or service. Choosing not to provide optional data or consent to analytics does not prevent you from making a purchase.
If the person placing the order names someone else as the recipient of the goods, we obtain that person's name and the necessary contact or delivery details from the person placing the order. We use these details to hand over the goods and arrange delivery or collection. We provide the recipient with information about data processing no later than our first communication with them or the first disclosure of their data to a delivery partner, and in any event within one month, unless a statutory exception applies. We also ask the person placing the order to inform the recipient about this.
3. Why we use data and on what legal basis
| Purpose | Legal basis |
|---|---|
| Receiving orders, processing payments, preparing orders, delivery, returns and order-related notifications. | Entering into and performing a contract, Article 6(1)(b) of the GDPR. |
| Operating the account, address book and wishlist created at your request. | Performing the account service contract, Article 6(1)(b) of the GDPR. |
| Accounting, tax records and compliance with statutory requirements. | Legal obligation, Article 6(1)(c) of the GDPR. |
| Online shop security, prevention of abuse and fraud, defence of claims, responding to general enquiries, and serving company representatives and recipients other than the person placing the order. | Legitimate interests, Article 6(1)(f) of the GDPR: conducting business securely, responding to enquiries and handing over goods to the agreed recipient. We assess whether the processing is necessary and its impact on your rights. |
| The notification you request when a specific product is back in stock. | Your consent, Article 6(1)(a) of the GDPR. |
| Newsletters and offers, and optional analytics using Google Analytics. | Separate consent for each respective purpose, Article 6(1)(a) of the GDPR. |
| Retaining evidence of previous consent and minimal opt-out information after consent is withdrawn. | Legitimate interests, Article 6(1)(f) of the GDPR: demonstrating the lawfulness of previous processing and preventing unwanted marketing communications. We use this data only for these purposes. |
Order confirmations, invoices, payment or delivery information, and replies to your enquiries are service communications. They are not sent on the basis of marketing consent. Requesting a product availability notification does not subscribe you to a newsletter. You can opt out of marketing at any time, free of charge, using the option provided in the communication or by emailing info@nori.ee.
We do not make decisions about you based solely on automated processing that have legal or similarly significant effects. Compiling statistics on the use of the online shop is not such a decision. Information about a payment service provider's own security and fraud checks is available in its privacy policy.
4. Who we share data with
Our employees and service providers have access to data to the extent necessary to carry out their tasks. We do not sell your personal data. The payment and delivery methods you select determine which partners handle your order.
- Payments. Montonio Finance UAB is involved when you pay through Montonio. AS LHV Pank is involved when you pay through the LHV payment gateway, with AS LHV Paytech providing the technical service through the EveryPay platform. The service receives the payment or order reference, amount, currency and the customer, contact or billing details needed for the selected payment method. You enter your card details and online banking authentication details in the payment service provider's environment; we do not store your full card number, CVC/CVV security code or online banking login details.
- Delivery. Omniva shipments are handled by AS Eesti Post, Omniva SIA or Omniva LT, UAB, depending on the destination country and service. SmartPosti shipments are handled by SmartPosti OÜ and, for shipments to Finland, the relevant Posti delivery partner. The partner receives the recipient's name, necessary contact details, the selected collection point or delivery address, and the information needed to handle the shipment. For delivery by a Nori courier or collection from our shop, the relevant staff use the necessary information; an external delivery partner is involved only if one is used.
- Technical services. ZONE MEDIA OÜ provides web hosting. Our email, backup, IT maintenance and accounting service providers may also process data to the extent necessary. Google's services are described in the next section.
- Legal obligations. We may disclose data to a competent authority to the extent required by law, or to a legal adviser to resolve claims.
Service providers processing data on our behalf are subject to contractual data protection obligations. Banks, payment service providers and delivery companies may also act as independent controllers when providing their services, and their own privacy policies apply to that processing. Links to service providers' privacy policies are provided at the end of this policy.
5. Cookies Google Analytics and form protection
The online shop uses cookies and similar technologies to function and remember your choices. Strictly necessary technologies are used to provide the service you request. Optional analytics requires prior consent. The types, purposes and durations of cookies are described in more detail in a separate cookie policy.
With your consent, we use Google Analytics 4 to understand and improve the use of the online shop. The service provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Analytics may include cookie and client identifiers, pages visited, actions, device and browser information, approximate location and, where purchases are measured, information about products, purchase value, currency and a transaction reference that contains no directly identifying personal data. This data is not necessarily anonymous.
Our analytics configuration does not send your name, email address, phone number, postal address, bank account or card details, or the contents of the contact form or order notes to Google Analytics. In this configuration, we do not use advertising-based profiling or link analytics to your customer account.
Google Analytics starts only after you have consented to analytics. It does not start if you decline. You can give or withdraw consent in the website's cookie settings; if you are unable to change the settings, email info@nori.ee. Withdrawal does not affect the lawfulness of processing carried out before it.
We use Google reCAPTCHA to protect forms against spam and automated abuse. It may process your IP address, technical browser and device information, and interactions with the form to distinguish a person from an automated program. Personal data processing necessary for security is based on our legitimate interest in protecting the online shop and communication channels. The cookies used by this service and the conditions under which it is loaded are described separately in the cookie policy; consent to analytics does not automatically constitute consent for other purposes. Under Google Cloud agreements, EEA customers are usually served by Google Cloud EMEA Limited, 70 Sir John Rogerson's Quay, Dublin 2, Ireland.
6. Transfers outside the European Economic Area
Delivery arranged in Estonia, Latvia, Lithuania and Finland does not in itself involve a transfer outside the European Economic Area. However, when Google's services are used, data may also be processed outside the EEA, including in the United States.
Transfers must have a basis and safeguards that comply with the GDPR. For relevant Google transfers to the United States, the European Commission's adequacy decision under the EU–US Data Privacy Framework is used where the recipient is covered by that framework. Where this basis does not apply, appropriate safeguards are used, such as the European Commission's standard contractual clauses and, where necessary, supplementary measures. You can request more information about the safeguard used and a copy of the clauses by emailing info@nori.ee; links to further information about the services are provided at the end of this policy.
7. How long we retain data
We retain data for as long as necessary for its purpose. The same data may serve more than one purpose: for example, when an account is closed, an invoice must still be retained to meet accounting requirements.
| Data | Retention |
|---|---|
| Accounting source documents and data needed to reconstruct a transaction. | 7 years from the end of the financial year in which the transaction was recorded in the accounts; longer only where another valid legal basis applies. |
| Order fulfilment and delivery data, including guest orders and contact details of recipients other than the person placing the order. | Up to 3 years after the order is fulfilled or closed. The portion required for accounting is retained for the statutory period; data relating to a specific claim is retained until the dispute is finally resolved and the applicable limitation period has ended. |
| Customer account, address book and wishlist. | Until the account is closed or up to 3 years after the last login or purchase, whichever occurs first. Order history is retained for the period specified for orders. Data required by law or for the defence of claims is retained separately. |
| General enquiries and customer service correspondence. | Up to 3 years after the enquiry is resolved. For a claim or dispute, until its final resolution and the end of the applicable limitation period. |
| Product availability notification request. | Until the notification is sent or the request is cancelled, but for an unresolved request, no more than 12 months after it was submitted. |
| Marketing contact details and evidence of consent. | For marketing, until consent is withdrawn or 3 years have passed since it was given or renewed. Evidence of consent is retained for up to 3 years after it is no longer used; minimal opt-out information is retained for as long as needed to respect your choice. |
| Google Analytics user-level and event-level data. | 2 months; new activity does not restart the retention period for the user identifier. This setting does not cover standard aggregated reports, which may be retained for longer. |
| Routine web server and security logs. | Up to 90 days. Evidence relating to a specific security incident or dispute is retained only for as long as necessary to resolve that case and defend claims. |
| Backups. | Up to 30 days. Deleted data is removed as backups are replaced in the normal course; if data is restored, the relevant deletions are applied again. |
At the end of the retention period, data is deleted or anonymised so that the person can no longer be identified. The same principles apply to data migrated from the old Nori system: migration does not restart the lawful retention period or provide a basis for retaining all historical data indefinitely. Service providers' independent processing may be subject to the retention periods described in their privacy policies.
8. How we protect data
We use technical and organisational safeguards appropriate to the nature of the data and the risks, including encrypted web connections, restricted access and backups. People who process data are given access only to the extent needed for their tasks. Please keep your account password confidential and let us know if you suspect misuse of your account.
9. Your rights and how to contact us
Subject to the conditions set out in the GDPR, you have the right to receive information about the processing of your data and a copy of it, correct inaccurate data, request erasure or restriction of processing, and receive the data you have provided in a portable format where it is processed by automated means on the basis of a contract or consent.
You can withdraw consent at any time. This does not affect the lawfulness of processing carried out before withdrawal. You can change your contact details and saved addresses in your account; to close your account or exercise other rights, email info@nori.ee. Closing your account does not delete data that we must retain by law or for the justified defence of claims.
Right to object
You have the right to object, on grounds relating to your particular situation, to processing based on legitimate interests. In that case, we will stop processing unless we demonstrate compelling legitimate grounds that override your interests and rights, or the processing is necessary for legal claims.
You can object at any time to processing for direct marketing. In that case, we will stop processing your data for that purpose; you do not need to give a reason for your objection.
We generally respond to requests to exercise your rights within one month of receipt. Where necessary, we ask for proportionate information to verify your identity. For complex requests or a large number of requests, the deadline may be extended by up to two additional months; we will notify you of the extension and its reason within the first month. If we refuse a request, we will explain the reason and how you can challenge the refusal.
If you believe your data is being processed unlawfully, you can lodge a complaint with Andmekaitse Inspektsioon: www.aki.ee, info@aki.ee, Tatari 39, 10134 Tallinn. You can also contact the competent supervisory authority in the place where you live or work, or where the alleged infringement took place, and seek a judicial remedy.
10. Updates to this policy
We update this policy when our services, data processing or legal requirements change. The current version and its update date are available on the website. Where necessary, we will provide additional notice of significant changes. We will ask for separate consent for any new purpose that requires it.
Further information from service providers
- Montonio privacy policy
- LHV processing of customer data
- Omniva Estonia privacy policy
- Omniva Latvia privacy policy
- Omniva Lithuania privacy policy
- SmartPosti privacy policy
- Posti data protection
- Zone privacy notice
- Google Analytics data use
- Google Analytics international transfers
- Google reCAPTCHA data processing information
- Google Cloud data processing terms
- Andmekaitse Inspektsioon