Ordeks
Privacy Policy Terms of Service
Eesti keeles

Privacy Policy

Last updated 20 August 2026

This policy explains what personal data Ordeks collects, why we collect it, who we share it with, and what you can do about it. It covers the Ordeks web application, the Ordeks mobile application and our website.

Ordeks is a business tool. Most of the personal data that passes through it is not ours — it belongs to the retailers who use Ordeks, and it describes their customers. Section 2 explains which parts of this policy apply to which data, because our obligations differ between the two.

If anything here is unclear, write to privacy@ordeks.ee and we will answer in plain language.

1. Who we are

Ordeks is operated by Ordeks OÜ, registry code 17031111, registered at Suurekase tee 3, Pukamäe küla, Kohila vald, Rapla maakond, Estonia.

For questions about this policy or about your personal data, contact privacy@ordeks.ee. For contractual matters, contact legal@ordeks.ee.

2. Two kinds of data, two different roles

We are the data controller for account data: the details of the people who sign in to Ordeks, their companies, and how they use the service. That data is described in section 3 and this whole policy governs it.

We are a data processor for order data: the customer names, addresses, contact details and order contents that a retailer imports into Ordeks from their own sales channels. The retailer decides what is imported and why; we only process it to run the service for them, on their documented instructions, under our Terms of Service and data processing terms.

If you are a shopper whose order appears in Ordeks and you want your data corrected, exported or erased, contact the retailer you bought from — they control that data. If you contact us instead, we will pass the request on to them and tell you we have done so, but we cannot act on it ourselves.

3. What we collect

DataExamplesWhere it comes from
Account and profileName, email address, hashed password, profile picture, language preference, role, personal fulfilment settingsYou, when you register, accept an invitation or edit your profile
CompanyCompany name, support email address, workspace settings, team membership and rolesThe company owner and administrators
Order data (as processor)Customer name, email, phone, billing and shipping address, order contents, order notes, payment method, any custom fields the retailer chooses to mapThe retailer's connected sales channels
Connection credentialsAPI keys, store URLs, account codes and secrets for connected systems, stored encryptedCompany administrators, when connecting a channel
Operational recordsWhich user picked or packed which order line, when, in which batch, on which application build and platformGenerated as work is done in the app
Device and technicalIP address, browser or device type, application version, push notification token, printer configurationAutomatically, when you use the service
BillingCompany billing name and email, subscription and invoice history, the last four digits and type of the payment cardYou and our payment processor
CorrespondenceEmails and support messages you send usYou

We do not collect payment card numbers. Card details are entered directly into our payment processor's hosted forms and never reach our servers.

We do not run advertising trackers, marketing pixels or third-party analytics inside the application.

4. Why we use it, and on what legal basis

We do not sell personal data, and we do not use it to make automated decisions that produce legal or similarly significant effects.

  • To provide the service you signed up for — accounts, order syncing, picking and packing, labels, reports. Legal basis: performance of a contract.
  • To bill you and keep accounting records. Legal basis: performance of a contract, and compliance with a legal obligation.
  • To keep the service secure, prevent abuse, diagnose faults and tie a bug report to the application build that caused it. Legal basis: our legitimate interest in a working, safe service.
  • To send you service messages — verification, password resets, invitations, trial and payment notices. Legal basis: performance of a contract.
  • To send push notifications about new orders to a device you have chosen to enable them on. Legal basis: consent, which you can withdraw at any time in your device or app settings.
  • To answer your support requests. Legal basis: performance of a contract and our legitimate interest in supporting our users.
  • To send occasional product news to business contacts. Legal basis: legitimate interest, and every such message carries an unsubscribe link.
  • To respond to lawful requests and defend legal claims. Legal basis: legal obligation and legitimate interest.

5. Cookies and local storage

We use only what the service needs to function. There are no advertising or analytics cookies, so there is no consent banner to click through.

Specifically we store: an authentication token so you stay signed in, your language preference, and a small amount of interface state such as your chosen filters. The mobile application additionally stores queued fulfilment work and a cached batch on the device, so it can keep working when the network drops.

You can clear this at any time through your browser or by signing out. Doing so will sign you out and reset your preferences.

6. Who we share it with

We use a small number of service providers to run Ordeks. Each is bound by a contract to process data only on our instructions.

ProviderWhat it doesData involved
Zone Media OÜApplication and database hostingAll service data
StripeSubscription payments and invoicingBilling contact details and payment records
Zone Media OÜSending service emailsRecipient name and email address
Expo (push notification service)Delivering push notifications to mobile devicesDevice push token and the notification text
wsrv.nlResizing product images for displayProduct image URLs from the retailer's own store, requested by your browser

We also transmit data to the systems a retailer has chosen to connect — their WooCommerce store, their Erply account, their Montonio account — because that is the point of the service. Those systems are controlled by the retailer, not by us, and their own terms and privacy policies apply.

Beyond that we share personal data only where the law requires it, to establish or defend a legal claim, or as part of a merger or sale of the business — in which case we will tell you before your data is transferred.

A current list of our service providers is available on request from privacy@ordeks.ee. We will give reasonable advance notice of any change to the providers processing order data.

7. Where your data is held

Our servers are located in the European Union. Some of our service providers may process data outside the European Economic Area. Where they do, the transfer is covered by an adequacy decision of the European Commission or by Standard Contractual Clauses together with the additional safeguards those clauses require.

You can ask us for a copy of the safeguards that apply to a particular provider.

8. How long we keep it

  • Account and profile data: for as long as your account exists, then deleted or anonymised within 30 days of the account being closed.
  • Order data: for as long as the retailer's workspace exists. The retailer can anonymise a customer's orders at any time through the application, and closing a workspace strips customer names and addresses from the orders it holds.
  • Operational records of who picked or packed what: retained with the workspace, because they are the audit trail of the work done.
  • Billing and accounting records: seven years, as Estonian accounting law requires.
  • Support correspondence: three years from the last message.
  • Server logs: up to 90 days.
  • Backups: rolling, and overwritten within 35 days. Data deleted from the live system persists in backups until they cycle out.

9. How we protect it

No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to people's rights, we will notify the Estonian Data Protection Inspectorate within 72 hours and, where the risk is high, tell the affected customers without undue delay.

  • All traffic between your browser or device and our servers is encrypted with TLS.
  • Passwords are stored hashed, never in a form we can read.
  • Sales channel credentials are stored encrypted at rest.
  • Every record belongs to exactly one company workspace, and requests are scoped to the workspace you are acting in.
  • Support access to a customer workspace is read-only, is shown to you in a persistent banner while it is happening, and cannot make changes in your connected stores.
  • Access to production systems is limited to the people who need it, and is protected by multi-factor authentication.

10. Your rights

Under the GDPR you have the right to:

  • Access the personal data we hold about you, and get a copy of it.
  • Have inaccurate data corrected.
  • Have your data erased, where we have no overriding obligation to keep it.
  • Restrict or object to our processing, including objecting to processing based on legitimate interest.
  • Receive your data in a portable, machine-readable format.
  • Withdraw consent at any time, where our processing rests on consent — for example push notifications.
  • Lodge a complaint with a supervisory authority.

11. Exercising your rights

You can export your own account data and delete your own account from the Account page in the application, without contacting us.

For anything else, write to privacy@ordeks.ee. We will respond within one month. If your request is complex we may extend that by two further months and will tell you why.

We may ask you to confirm your identity before acting on a request, so that we do not disclose someone's data to the wrong person.

If you are unhappy with how we have handled your data, you can complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, info@aki.ee, www.aki.ee — or to the supervisory authority where you live.

12. Children

Ordeks is a tool for businesses and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, contact privacy@ordeks.ee and we will delete it.

13. Changes to this policy

We may update this policy as the service changes. The date at the top always shows the current version. If a change materially affects how we handle your personal data, we will tell account owners by email at least 30 days before it takes effect.

Continuing to use Ordeks after a change takes effect means the updated policy applies to you.

14. Contact

General enquiries and support: info@ordeks.ee

Privacy questions and data subject requests: privacy@ordeks.ee

Contracts and legal notices: legal@ordeks.ee

Post: Ordeks OÜ, Suurekase tee 3, Pukamäe küla, Kohila vald, Rapla maakond, Estonia

Back to ordeks.ee

Product Pricing Privacy Policy Privaatsuspoliitika Terms of Service Kasutustingimused privacy@ordeks.ee
© Ordeks