Privacy Policy
Last updated 20 August 2026
This policy explains what personal data Ordeks collects, why we collect it, who we share it with, and what you can do about it. It covers the Ordeks web application, the Ordeks mobile application and our website.
Ordeks is a business tool. Most of the personal data that passes through it is not ours — it belongs to the retailers who use Ordeks, and it describes their customers. Section 2 explains which parts of this policy apply to which data, because our obligations differ between the two.
If anything here is unclear, write to privacy@ordeks.ee and we will answer in plain language.
1. Who we are
Ordeks is operated by Ordeks OÜ, registry code 17031111, registered at Suurekase tee 3, Pukamäe küla, Kohila vald, Rapla maakond, Estonia.
For questions about this policy or about your personal data, contact privacy@ordeks.ee. For contractual matters, contact legal@ordeks.ee.
2. Two kinds of data, two different roles
We are the data controller for account data: the details of the people who sign in to Ordeks, their companies, and how they use the service. That data is described in section 3 and this whole policy governs it.
We are a data processor for order data: the customer names, addresses, contact details and order contents that a retailer imports into Ordeks from their own sales channels. The retailer decides what is imported and why; we only process it to run the service for them, on their documented instructions, under our Terms of Service and data processing terms.
If you are a shopper whose order appears in Ordeks and you want your data corrected, exported or erased, contact the retailer you bought from — they control that data. If you contact us instead, we will pass the request on to them and tell you we have done so, but we cannot act on it ourselves.
3. What we collect
| Data | Examples | Where it comes from |
|---|---|---|
| Account and profile | Name, email address, hashed password, profile picture, language preference, role, personal fulfilment settings | You, when you register, accept an invitation or edit your profile |
| Company | Company name, support email address, workspace settings, team membership and roles | The company owner and administrators |
| Order data (as processor) | Customer name, email, phone, billing and shipping address, order contents, order notes, payment method, any custom fields the retailer chooses to map | The retailer's connected sales channels |
| Connection credentials | API keys, store URLs, account codes and secrets for connected systems, stored encrypted | Company administrators, when connecting a channel |
| Operational records | Which user picked or packed which order line, when, in which batch, on which application build and platform | Generated as work is done in the app |
| Device and technical | IP address, browser or device type, application version, push notification token, printer configuration | Automatically, when you use the service |
| Billing | Company billing name and email, subscription and invoice history, the last four digits and type of the payment card | You and our payment processor |
| Correspondence | Emails and support messages you send us | You |
We do not collect payment card numbers. Card details are entered directly into our payment processor's hosted forms and never reach our servers.
We do not run advertising trackers, marketing pixels or third-party analytics inside the application.
4. Why we use it, and on what legal basis
We do not sell personal data, and we do not use it to make automated decisions that produce legal or similarly significant effects.
- To provide the service you signed up for — accounts, order syncing, picking and packing, labels, reports. Legal basis: performance of a contract.
- To bill you and keep accounting records. Legal basis: performance of a contract, and compliance with a legal obligation.
- To keep the service secure, prevent abuse, diagnose faults and tie a bug report to the application build that caused it. Legal basis: our legitimate interest in a working, safe service.
- To send you service messages — verification, password resets, invitations, trial and payment notices. Legal basis: performance of a contract.
- To send push notifications about new orders to a device you have chosen to enable them on. Legal basis: consent, which you can withdraw at any time in your device or app settings.
- To answer your support requests. Legal basis: performance of a contract and our legitimate interest in supporting our users.
- To send occasional product news to business contacts. Legal basis: legitimate interest, and every such message carries an unsubscribe link.
- To respond to lawful requests and defend legal claims. Legal basis: legal obligation and legitimate interest.
5. Cookies and local storage
We use only what the service needs to function. There are no advertising or analytics cookies, so there is no consent banner to click through.
Specifically we store: an authentication token so you stay signed in, your language preference, and a small amount of interface state such as your chosen filters. The mobile application additionally stores queued fulfilment work and a cached batch on the device, so it can keep working when the network drops.
You can clear this at any time through your browser or by signing out. Doing so will sign you out and reset your preferences.
6. Who we share it with
We use a small number of service providers to run Ordeks. Each is bound by a contract to process data only on our instructions.
| Provider | What it does | Data involved |
|---|---|---|
| Zone Media OÜ | Application and database hosting | All service data |
| Stripe | Subscription payments and invoicing | Billing contact details and payment records |
| Zone Media OÜ | Sending service emails | Recipient name and email address |
| Expo (push notification service) | Delivering push notifications to mobile devices | Device push token and the notification text |
| wsrv.nl | Resizing product images for display | Product image URLs from the retailer's own store, requested by your browser |
We also transmit data to the systems a retailer has chosen to connect — their WooCommerce store, their Erply account, their Montonio account — because that is the point of the service. Those systems are controlled by the retailer, not by us, and their own terms and privacy policies apply.
Beyond that we share personal data only where the law requires it, to establish or defend a legal claim, or as part of a merger or sale of the business — in which case we will tell you before your data is transferred.
A current list of our service providers is available on request from privacy@ordeks.ee. We will give reasonable advance notice of any change to the providers processing order data.
7. Where your data is held
Our servers are located in the European Union. Some of our service providers may process data outside the European Economic Area. Where they do, the transfer is covered by an adequacy decision of the European Commission or by Standard Contractual Clauses together with the additional safeguards those clauses require.
You can ask us for a copy of the safeguards that apply to a particular provider.
8. How long we keep it
- Account and profile data: for as long as your account exists, then deleted or anonymised within 30 days of the account being closed.
- Order data: for as long as the retailer's workspace exists. The retailer can anonymise a customer's orders at any time through the application, and closing a workspace strips customer names and addresses from the orders it holds.
- Operational records of who picked or packed what: retained with the workspace, because they are the audit trail of the work done.
- Billing and accounting records: seven years, as Estonian accounting law requires.
- Support correspondence: three years from the last message.
- Server logs: up to 90 days.
- Backups: rolling, and overwritten within 35 days. Data deleted from the live system persists in backups until they cycle out.
9. How we protect it
No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to people's rights, we will notify the Estonian Data Protection Inspectorate within 72 hours and, where the risk is high, tell the affected customers without undue delay.
- All traffic between your browser or device and our servers is encrypted with TLS.
- Passwords are stored hashed, never in a form we can read.
- Sales channel credentials are stored encrypted at rest.
- Every record belongs to exactly one company workspace, and requests are scoped to the workspace you are acting in.
- Support access to a customer workspace is read-only, is shown to you in a persistent banner while it is happening, and cannot make changes in your connected stores.
- Access to production systems is limited to the people who need it, and is protected by multi-factor authentication.
10. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you, and get a copy of it.
- Have inaccurate data corrected.
- Have your data erased, where we have no overriding obligation to keep it.
- Restrict or object to our processing, including objecting to processing based on legitimate interest.
- Receive your data in a portable, machine-readable format.
- Withdraw consent at any time, where our processing rests on consent — for example push notifications.
- Lodge a complaint with a supervisory authority.
11. Exercising your rights
You can export your own account data and delete your own account from the Account page in the application, without contacting us.
For anything else, write to privacy@ordeks.ee. We will respond within one month. If your request is complex we may extend that by two further months and will tell you why.
We may ask you to confirm your identity before acting on a request, so that we do not disclose someone's data to the wrong person.
If you are unhappy with how we have handled your data, you can complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, info@aki.ee, www.aki.ee — or to the supervisory authority where you live.
12. Children
Ordeks is a tool for businesses and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, contact privacy@ordeks.ee and we will delete it.
13. Changes to this policy
We may update this policy as the service changes. The date at the top always shows the current version. If a change materially affects how we handle your personal data, we will tell account owners by email at least 30 days before it takes effect.
Continuing to use Ordeks after a change takes effect means the updated policy applies to you.
14. Contact
General enquiries and support: info@ordeks.ee
Privacy questions and data subject requests: privacy@ordeks.ee
Contracts and legal notices: legal@ordeks.ee
Post: Ordeks OÜ, Suurekase tee 3, Pukamäe küla, Kohila vald, Rapla maakond, Estonia