Privacy & GDPR Supplement
Privacy & GDPR Supplement
Last updated: September 13, 2026
This Privacy & GDPR Supplement forms part of our Privacy Policy and provides additional information regarding the processing of personal data under applicable data protection laws, including the EU General Data Protection Regulation (GDPR).
Please read this Supplement together with our Privacy Policy.
Data Controller
For the purposes of applicable data protection laws, including the GDPR, the data controller is:
NOORDINARYLEAF, vl. Blanka Špehar i Damir Gašparović
Ulica Antuna Šoljana 37
10090 Zagreb
Croatia
Email: info@noordinaryleaf.com
Legal Bases for Processing
If you are located in the European Economic Area (EEA), we process your personal data under one or more of the following legal bases.
Performance of a Contract
We process personal data where necessary to enter into or perform our contract with you.
This includes processing necessary to:
- process and fulfil your order;
- process payments and payment confirmations;
- arrange shipping and delivery;
- send order and shipping notifications;
- process returns, refunds or cancellations;
- manage your customer account; and
- communicate with you regarding your order or other services you have requested.
Compliance with Legal Obligations
We process certain personal data where necessary to comply with applicable legal obligations, including:
- tax and accounting requirements;
- invoicing and record-keeping obligations;
- consumer protection requirements;
- regulatory obligations; and
- responding to legally valid requests from competent authorities.
Certain transaction and business records may therefore need to be retained even after your order has been completed or your account has been closed.
Legitimate Interests
Where permitted by applicable law, we may process personal data when necessary for our legitimate interests or those of a third party, provided that those interests are not overridden by your rights and freedoms.
Our legitimate interests may include:
- protecting our store, customers and business against fraud, abuse and security threats;
- maintaining the security and functionality of our website and Services;
- responding to customer inquiries where the processing is not already necessary for performance of a contract;
- maintaining appropriate business and transaction records;
- improving the reliability and operation of our Services; and
- establishing, exercising or defending legal claims.
Where processing is based on legitimate interests, you may have the right to object to that processing as described in our Privacy Policy.
Consent
Where required by applicable law, we rely on your consent for activities such as:
- non-essential cookies and similar tracking technologies;
- certain analytics and personalization activities;
- personalized or targeted advertising; and
- marketing communications.
You may withdraw your consent at any time.
For cookies and similar technologies, you can change or withdraw your choices using the Cookie Preferences controls available on our website.
Withdrawal of consent does not affect the lawfulness of processing carried out before consent was withdrawn.
Information Required to Complete a Purchase
Certain personal data is necessary for us to enter into and perform a contract with you.
Depending on your order, this may include your:
- name;
- email address and other contact details;
- billing address;
- shipping address;
- payment and transaction information; and
- information necessary to arrange delivery.
If you do not provide information that is required to process and fulfil an order, we may be unable to accept, process or deliver your purchase.
Fraud Prevention and Automated Processing
Shopify, payment providers and other service providers may use automated systems, including machine-learning technologies, to identify potentially fraudulent, suspicious or high-risk transactions.
Shopify may provide us with automated fraud-risk indicators relating to an order. These indicators can be used by us when reviewing transactions and deciding whether additional verification is appropriate.
Our own order-management process does not make decisions producing legal or similarly significant effects concerning you solely on the basis of automated processing.
Payment providers and other service providers may independently use automated fraud-prevention and risk-assessment technologies in accordance with their own privacy policies and legal obligations.
Shopify and Enhanced Services
Our online store is hosted by Shopify.
As described in our Privacy Policy, Shopify processes information relating to your use of our store in order to provide its platform and related services.
We have enabled Shopify Network Intelligence, which may allow Shopify to use information from interactions with our store together with information from interactions with Shopify and other Shopify merchants to provide certain enhanced services, such as personalization, analytics, fraud prevention and advertising-related features.
Where required by applicable law, non-essential processing for advertising, personalization or similar purposes is subject to your consent and privacy choices.
You can learn more about how Shopify processes personal information in the Shopify Consumer Privacy Policy and manage certain Shopify-specific privacy rights through the Shopify Privacy Portal:
Shopify Consumer Privacy Policy:
https://www.shopify.com/legal/privacy/app-users
Shopify Privacy Portal:
https://privacy.shopify.com/
Shopify specifically requires merchants using Network Intelligence in the EEA to inform customers about this processing and provide access to Shopify's privacy portal.
Data Retention
We retain personal data only for as long as reasonably necessary for the purposes for which it was collected and as required by applicable law.
Retention periods depend on the type of information and the purpose of processing.
In particular:
- order, invoice, payment and transaction information may be retained for the periods required by applicable tax, accounting and other legal requirements;
- customer account information may be retained while your account is active and for an appropriate period afterwards where necessary;
- customer service communications may be retained where necessary to resolve inquiries, document our communications or establish, exercise or defend legal claims;
- marketing information is generally processed until you unsubscribe, withdraw your consent or otherwise opt out, subject to information we may need to retain in order to respect your opt-out request; and
- certain information may be retained for longer where required by law or necessary for the establishment, exercise or defence of legal claims.
When personal data is no longer required, it will be deleted, anonymized or otherwise handled in accordance with applicable data protection requirements.
International Data Transfers
Some of our service providers, including Shopify and providers involved in payments, analytics, technology, communications or order fulfilment, may process personal data outside the EEA.
Where personal data is transferred to a country that has not been recognized by the European Commission as providing an adequate level of data protection, appropriate safeguards may be used in accordance with applicable data protection law.
These safeguards may include:
- European Commission Standard Contractual Clauses;
- approved Binding Corporate Rules;
- adequacy decisions; or
- other legally recognized transfer mechanisms.
You may contact us at info@noordinaryleaf.com if you would like further information about safeguards applicable to the transfer of your personal data.
Your GDPR Rights
Your data protection rights are described in greater detail in our main Privacy Policy.
Subject to the conditions and exceptions provided by applicable law, individuals in the EEA may have the right to:
- access their personal data;
- correct inaccurate or incomplete personal data;
- request deletion of personal data;
- restrict certain processing;
- object to processing based on legitimate interests;
- receive certain personal data in a portable format;
- withdraw consent at any time where processing is based on consent; and
- lodge a complaint with a competent data protection supervisory authority.
To exercise your rights in relation to personal data for which NOORDINARYLEAF is the controller, contact us at:
We may need to verify your identity before processing certain requests.
Complaints and Supervisory Authority
If you have concerns about how we process your personal data, we encourage you to contact us first at info@noordinaryleaf.com so that we can try to resolve the matter.
You also have the right to lodge a complaint with a competent data protection supervisory authority.
Our supervisory authority in Croatia is:
Croatian Personal Data Protection Agency (AZOP)
Ulica Metela Ožegovića 16
10000 Zagreb
Croatia
Email: azop@azop.hr
Telephone: +385 (0)1 4609-000
You may also lodge a complaint with the competent supervisory authority in the EEA country where you live, work or believe an infringement of data protection law has occurred.
AZOP's current official contact information confirms the address and contact details above.
Relationship With Our Privacy Policy
This Supplement provides additional GDPR and EEA-specific information and should be read together with our main Privacy Policy.
Our Privacy Policy contains further information about:
- the categories of personal information we collect;
- where personal information comes from;
- how we use and disclose personal information;
- Shopify's processing of personal information;
- cookies and similar technologies;
- your privacy rights and choices;
- security;
- international transfers; and
- how to contact us.
Contact
For questions regarding this Privacy & GDPR Supplement, our Privacy Policy, or the exercise of your data protection rights, please contact:
NOORDINARYLEAF, vl. Blanka Špehar i Damir Gašparović
Ulica Antuna Šoljana 37
10090 Zagreb
Croatia
Email: info@noordinaryleaf.com