Privacy Policy

Privacy Policy

Nordtradex OÜ / Andy Qi – Privacy Policy

1. Who we are
This website (https://andyqi.eu) is operated by Nordtradex OÜ, an Estonian company that owns and manages the Andy Qi natural cosmetics brand. We respect your privacy and process personal data in compliance with the General Data Protection Regulation (GDPR – EU 2016/679).
Contact: info@andyqi.eu.

2. What data we collect and how it is used
We only collect the data necessary to process and deliver your order. This includes:
– your name, email, phone number and delivery address (for shipping and customer communication),
– order and transaction details (for invoicing and logistics),
– technical cookies and analytics data (see “Cookies” below).
We do not store or access your payment details. All payments are handled securely through our payment service provider Maksekeskus AS, which processes your card or online banking data according to its own privacy and security policies.
Nordtradex OÜ receives only the confirmation that a payment has succeeded – no card, account, or banking details are ever visible to us.

3. Legal basis for processing
We process your data based on:
– fulfilment of a purchase contract (order delivery, invoicing, customer support);
– compliance with legal obligations (accounting, taxation);
– your consent, where required (for marketing or cookies).

4. Data sharing
Your data may be shared only with trusted partners necessary to provide our services:
Maksekeskus AS – payment processing,
– postal or courier companies – order delivery,
– IT and hosting providers – secure operation of our website,
– analytics tools (Google Analytics, RankMath) – website performance and security monitoring.
We do not sell, rent or otherwise share personal data with unrelated third parties.

5. Cookies and analytics
Our website uses cookies to ensure technical functionality and to improve user experience.
Essential cookies are required for the shopping cart and checkout to function.
Analytics cookies (e.g., Google Analytics) are used only with your consent and can be managed or withdrawn via our cookie banner. You may also disable cookies through your browser settings.

6. Data retention
Order and invoicing information is stored only as long as required by Estonian accounting and tax laws (typically 7 years). Technical data (cookies, analytics) is stored for shorter periods as defined in our cookie management tool.

7. Your rights
Under GDPR you have the right to:
– request access to your personal data,
– correct inaccurate or incomplete data,
– request deletion of your data where legally possible,
– restrict or object to certain processing,
– withdraw consent at any time (for marketing or cookies),
– file a complaint with the Estonian Data Protection Inspectorate.
To exercise your rights, contact info@andyqi.eu.

8. Data security
We apply appropriate technical and organisational measures – secure connections (SSL), limited access, encrypted hosting – to protect your personal data from unauthorised access, alteration, or misuse.

9. Policy updates
We may update this Privacy Policy to reflect changes in law or in our practices. The updated version will be published on this page with a revised date.

10. Contact
For any questions regarding privacy or data protection, please contact: info@andyqi.eu.