Legal
Privacy policy
This notice explains what personal data NORDICALPHA OÜ handles when you contact us or place an order, why we handle it, and what you can ask us to do about it.
Who we are
NORDICALPHA OÜ (“NordicAlpha”, “we”) is a company registered in Estonia. We supply furniture, appliances and interior fit-out from European manufacturers. For the personal data described in this notice we act as the data controller.
NORDICALPHA OÜRaua 34
10120 Tallinn, Estonia
You can reach us about any privacy matter at info@nordicalpha.eu. We have not appointed a Data Protection Officer, as we are not required to.
What personal data we handle
We only handle data that reaches us because you chose to contact us, or because it is needed to fulfil an order. This website has no registration, no user accounts and no contact forms.
- Contact and enquiry data — your name, company, email address, phone number, messenger handle, and whatever you choose to put in your message, including product lists, drawings, photographs and moodboards.
- Order and transaction data — delivery address, order contents, quotations, invoices, payment references and correspondence relating to an order.
- Technical data — our hosting provider records standard server information such as IP address, request time, requested page, and browser user-agent, for security and to keep the site running.
We do not ask for and do not want special categories of data (health, political opinions, and so on). Please do not send them to us.
Why we use it, and on what legal basis
Under the GDPR we must have a lawful basis for each use. Ours are:
- To answer your enquiry and prepare a quotation
- Article 6(1)(b) — steps taken at your request before entering into a contract.
- To place, pay for, quality-check and deliver your order
- Article 6(1)(b) — performance of our contract with you.
- To keep accounting and tax records
- Article 6(1)(c) — compliance with our legal obligations under Estonian law.
- To keep the website secure and available, and to defend legal claims
- Article 6(1)(f) — our legitimate interests, balanced against your rights.
- To send you commercial messages you asked for
- Article 6(1)(a) — your consent, which you may withdraw at any time.
We do not use your data for automated decision-making or profiling.
How long we keep it
We keep personal data only as long as there is a reason to.
- Enquiries that do not lead to an order — up to 24 months from our last exchange, so we can pick up a conversation you may return to.
- Order and accounting records — seven years from the end of the relevant financial year, as required by the Estonian Accounting Act.
- Server logs — a short rolling period held by our hosting provider, typically measured in days.
When a period ends, we delete the data or anonymise it.
Transfers outside the EEA
Our suppliers and service providers are primarily in the European Economic Area. Where a delivery address or a service provider is outside the EEA, the transfer takes place either because it is necessary to perform our contract with you (Article 49(1)(b)), or under a European Commission adequacy decision, or under Standard Contractual Clauses. You can ask us which applies in your case.
Two transfers happen only if you switch analytics on, and stop the moment you switch it off:
- Google — collected in the EU by Google Ireland Limited; Google LLC in the United States is certified under the EU–US Data Privacy Framework, with Standard Contractual Clauses in addition.
- Yandex — processed on Yandex servers including servers in the Russian Federation, for which there is no European Commission adequacy decision. The transfer rests on the safeguards in Yandex’s terms. Declining analytics prevents it entirely, and declining is one click.
Your rights
In relation to your personal data you may ask us to:
- Give you a copy of it, and tell you how we use it (Article 15).
- Correct anything inaccurate or incomplete (Article 16).
- Delete it, where we no longer have grounds to keep it (Article 17).
- Restrict how we use it while a dispute about it is resolved (Article 18).
- Send it on to you or another controller in a machine-readable form (Article 20).
- Stop processing based on our legitimate interests (Article 21).
- Withdraw consent at any time, where consent was the basis — this does not affect what we did before you withdrew it.
Write to info@nordicalpha.eu. We answer within one month, and will tell you if we need longer. Exercising these rights is free; we may charge only for manifestly unfounded or excessive repeat requests.
How we protect it
We keep personal data on services that require authentication and encrypt traffic in transit (HTTPS). Access is limited to the people who need it to do their work. No system is perfectly secure, but where a breach is likely to put your rights at risk we will notify the Estonian Data Protection Inspectorate, and you, as the GDPR requires.
Changes to this notice
If we change how we handle personal data we will update this page and move the “last updated” date at the top. Material changes affecting you will be communicated directly where we hold your contact details.
Contact and complaints
Please raise anything with us first at info@nordicalpha.eu — most things are quickest to fix directly.
You also have the right to complain to the Estonian supervisory authority:
Tatari 39, 10134 Tallinn, Estonia · info@aki.ee · www.aki.ee
If you live in another EU or EEA country, you may instead complain to the supervisory authority where you live or work.