Privacy notice
How we handle the personal data of anyone who visits nordixstudio.ee, writes to us, buys a website or uses the client area.
Last updated: 10 October 2026
1. Who processes your data
Nordix Studio is a brand of Dokoyo Koyo Holding OÜ, based in Sakala tn 7-2, 10141 Tallinn, Eesti / Estonia, which is the data controller.
For anything concerning your data write to hello.nordixstudio@gmail.com. We reply within 30 days.
2. What we collect and why
Contact form: name, email and the message itself. We need them to reply and, where needed, prepare a quote.
Purchase and site brief: email, name, the business details you send us so we can build the site (company name, description, contact details, any logos) and billing details. Card data never passes through our servers: Stripe handles it.
Cookie-free statistics: we count page visits and button clicks together with the page, the language and the campaign tags (utm) of the link you arrived by. We do not store your IP address, any identifier or device fingerprint, and we cannot tell who you are.
Client area: email, name, the one-time access codes, the projects linked to your account and the content of the support requests you open.
Signing the terms: besides the signer's identity we record the date and time, the IP address and the browser used. They prove who signed and when, as a simple electronic signature requires.
Nordix assistant: what you type in the chat is sent to the AI model to generate the answer, and the conversation is kept on our servers. It serves two purposes: it lets the assistant remember what you discussed, and it lets the people at the studio read the conversation when they pick up your request. If you are signed in to the client area, the assistant can also look up your projects, your requests and your subscription status in order to answer you. It cannot change anything on its own: any action, such as opening a support request, is proposed to you and happens only if you confirm it.
3. On what legal basis
Enquiries, quotes, purchase, client area and contract: performance of a contract or pre-contractual steps taken at your request (Art. 6(1)(b) GDPR).
Platform security and keeping signature evidence: our legitimate interest (Art. 6(1)(f) GDPR).
Accounting records: legal obligation (Art. 6(1)(c) GDPR).
4. How long we keep it
One-time access codes: 10 minutes, after which the database deletes them automatically.
Enquiries that do not turn into a project: 24 months. Visit and click counters: 13 months.
Account, projects and support requests: for the whole length of the relationship and 3 years after it ends, the ordinary limitation period in Estonia.
Signed terms and accounting documents: 7 years, as the Estonian Accounting Act requires.
5. Who we share it with
We do not sell your data and we do not pass it to third parties for marketing.
We rely on suppliers who process data on our behalf as processors: Resend (sending email), Anthropic (chat assistant and first site drafts: what you write to the assistant and the information in your brief is processed through Anthropic's Claude API), MongoDB Atlas (database), Vercel (hosting) and Stripe (payments).
Payments are handled by Stripe, which processes card and transaction data as an independent controller under its own notice. We only receive the outcome, the plan chosen and the billing details.
Data may be shared with our accountant and, where necessary, with legal advisers or the competent authorities.
6. Transfers outside the European Union
Some suppliers are based in the United States, including Anthropic, which processes what you write to the assistant and the information in your brief. In that case the transfer relies on the standard contractual clauses approved by the European Commission or on an adequacy decision.
We host the database and the site in European regions whenever the supplier allows it.
7. Your rights
You can ask us for access to your data, correction, erasure, restriction of processing and portability, and you can object to processing based on legitimate interest.
Where processing relies on consent you can withdraw it at any time, without affecting what was done before.
To exercise these rights write to hello.nordixstudio@gmail.com.
8. Complaints
If you believe the processing breaches the GDPR you can contact the Estonian data protection authority, Andmekaitse Inspektsioon (Tatari 39, 10134 Tallinn, Eesti), or the authority of the country where you live.
9. Security
You enter the client area with a one-time code sent by email: we do not use passwords. The session travels in an encrypted cookie that JavaScript cannot read.
Access codes are stored only as hashes, the database is protected by dedicated credentials and backups are kept encrypted.
10. Changes
If we change how we handle data we update this page and the date at the top. Changes that matter to clients with an active contract are also announced by email.
Questions about this document?
Write to us at hello.nordixstudio@gmail.com.