🌱 NorixMedia
Your Data, Your Rights

Privacy Policy

This policy explains how NorixMedia Ltd collects, uses, stores, and protects your personal data when you visit our website or purchase our gardening products.

Last Updated: January 15, 2026

1. Introduction and Data Controller

NorixMedia Ltd ("NorixMedia", "we", "us", or "our") is committed to protecting your privacy and handling your personal data with transparency and care. This Privacy Policy describes how we collect, process, store, and share personal information when you interact with our website at norixmedia.com, place orders for our gardening kits and seedlings, sign up for communications, or contact our team.

NorixMedia Ltd is the data controller responsible for your personal data. We are a company registered in Ireland with company number 654321, and our registered office is located at:

NorixMedia Ltd

Unit 4, Ashbourne Business Park

Ashbourne, Co. Meath, A84 F6Y2

Ireland

Email: [email protected]

Phone: +353 1 802 4590

This policy applies to all personal data processed through our website, order forms, email communications, and any other channels through which you may share personal information with us. We process your data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the Irish Data Protection Act 2018, and the ePrivacy Directive 2002/58/EC as implemented in Irish law. We encourage you to read this policy in full so you understand how and why we use your data.

2. What Data We Collect

We collect different types of personal data depending on how you interact with our website and services. Below is a detailed list of the categories of personal data we may process:

Identity and Contact Data

  • Full name (first name and surname) as provided when placing an order or contacting us
  • Email address used for order confirmations, account communication, and optional marketing
  • Phone number (including country code) for delivery coordination and order-related queries
  • Delivery address including Eircode or equivalent postal code for shipping purposes

Technical and Usage Data

  • IP address assigned by your internet service provider when you access our website
  • Browser type and version (e.g., Chrome 120, Safari 17, Firefox 121)
  • Operating system and device type (desktop, tablet, or mobile)
  • Screen resolution and viewport dimensions
  • Pages visited on our website, time spent on each page, and navigation path
  • Referring website URL (the page that directed you to norixmedia.com)
  • Date, time, and timezone of each visit
  • Language preference set in your browser or selected on our site

Order and Transaction Data

  • Products selected and quantities ordered
  • Order date, order reference number, and order status
  • Payment method type (we do not store full card numbers; these are handled by our payment processor)
  • Delivery preferences and any special instructions you provide

Communication Data

  • Content of emails, messages, or enquiries you send to us
  • Your marketing preferences and consent status
  • Feedback, reviews, or testimonials you voluntarily provide

3. How We Collect Data

We collect personal data through the following methods and channels:

Directly from You

When you fill in our order form on the homepage or any product page, you provide us with your name, email, phone number, selected product, and Eircode. When you send us an email at [email protected] or use any contact form on our site, you provide the content of your message along with your contact details. When you opt in to receive gardening tips or promotional offers, you provide your email address and consent preference through a clearly labelled checkbox.

Automatically Through Technology

When you visit our website, certain technical data is collected automatically through server logs maintained by our hosting provider. This includes your IP address, browser type, operating system, referring URL, pages visited, and timestamps. We use cookies and similar tracking technologies to collect usage data that helps us understand how visitors navigate our site and to remember your preferences. Our cookie practices are described in detail in Section 10 of this policy and in our separate Cookie Notice.

From Third-Party Analytics Tools

We use Google Analytics to gather aggregated statistics about website usage, including page views, session duration, bounce rate, and approximate geographic location derived from IP addresses. Google Analytics uses cookies to collect this data. The data is processed by Google LLC under their data processing terms. We have configured Google Analytics to anonymise IP addresses before storage, meaning the full IP address is never written to disk by Google. If you have provided consent for marketing cookies, we may also receive aggregated insights from Meta Platforms Ireland Ltd (Facebook/Instagram) regarding the performance of advertising campaigns directed at our website.

4. Why We Collect Data (Legal Basis)

Under the GDPR (specifically Article 6), we must have a lawful basis for processing each category of your personal data. Below we set out the purposes of our data processing and the corresponding legal basis for each:

Purpose Legal Basis (GDPR Art. 6)
Processing and fulfilling your order for gardening kits, seedlings, or accessories Performance of a contract (Art. 6(1)(b))
Sending order confirmations, shipping updates, and delivery notifications Performance of a contract (Art. 6(1)(b))
Responding to your enquiries, support requests, or complaints Legitimate interest (Art. 6(1)(f)) - providing customer service
Sending promotional emails about new products, seasonal offers, or gardening tips Consent (Art. 6(1)(a)) - you can withdraw at any time
Analysing website usage to improve site design, navigation, and content Legitimate interest (Art. 6(1)(f)) - improving our services
Measuring the effectiveness of advertising campaigns Consent (Art. 6(1)(a)) - via cookie consent
Preventing fraud and ensuring website security Legitimate interest (Art. 6(1)(f)) - protecting our business
Complying with legal obligations such as tax, accounting, and consumer protection laws Legal obligation (Art. 6(1)(c))

Where we rely on legitimate interest as the legal basis, we have conducted a balancing test to ensure that our interests do not override your fundamental rights and freedoms. You have the right to object to processing based on legitimate interest at any time, and we will cease such processing unless we can demonstrate compelling legitimate grounds.

5. How We Use Your Data

We use the personal data we collect for the following specific purposes:

Service Delivery

Your name, email, phone number, and delivery address are used to process your order, coordinate delivery through our logistics partners (An Post and DPD Ireland), send you an order confirmation email, provide shipping tracking information, and contact you if there is an issue with your order. If a seedling replacement is requested under our 21-day sprouting guarantee, we use your order data to verify the claim and arrange the replacement shipment.

Marketing Communications

If you have explicitly opted in by ticking the consent checkbox on our order form, we will send you periodic emails containing gardening tips suited to the Irish growing season, information about new product releases, and occasional promotional offers. These emails are sent no more than twice per month. Every marketing email includes a clear "Unsubscribe" link at the bottom. You can withdraw your marketing consent at any time by clicking that link, by emailing us at [email protected], or by contacting us by phone. Withdrawal of consent does not affect the lawfulness of any processing carried out before you withdrew.

Website Analytics and Improvement

Aggregated, anonymised usage data collected through Google Analytics helps us understand which pages are most popular, where visitors drop off, what devices and browsers are most common, and how effective our content is. We use these insights to improve page layout, load times, product descriptions, and the overall user experience. No individual is identified through this analysis.

Legal Compliance

We may process your data to comply with applicable laws and regulations, including Irish tax law (requiring us to retain transaction records), consumer protection regulations (requiring us to handle complaints within prescribed timeframes), and any lawful requests from regulatory authorities or courts. We will only disclose your personal data to law enforcement or government bodies where we are legally required to do so.

6. Data Retention

We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. The specific retention periods for each category of data are as follows:

Data Category Retention Period
Order and transaction records (name, address, products, payment method type) 6 years from the date of the transaction, as required under Irish tax and accounting legislation (Taxes Consolidation Act 1997)
Contact form submissions and email correspondence 2 years from the date of last communication, unless an ongoing matter requires longer retention
Marketing consent records and email subscriber data Until you withdraw consent (unsubscribe). We retain a record of your withdrawal for 1 year to demonstrate compliance
Analytics cookies and usage data 13 months from the date of collection (aligned with Google Analytics data retention settings)
Server access logs (IP addresses, timestamps) 90 days from the date of access, after which they are automatically deleted
Cookie consent preferences (stored in your browser via localStorage) 12 months, after which you will be prompted to renew your consent choice

When data reaches the end of its retention period, it is securely deleted or anonymised so that it can no longer be linked to you as an individual. If you request deletion of your data before the retention period expires, we will comply unless retention is required by law (for example, tax records must be kept for 6 years regardless of a deletion request).

7. Data Sharing and Third Parties

We do not sell, rent, lease, or trade your personal data to any third party for their own marketing purposes. We share your data only with the following categories of service providers who assist us in operating our business, and only to the extent necessary for them to perform their function:

  • Delivery Partners

    An Post and DPD Ireland receive your name, delivery address, phone number, and order reference to fulfil shipments. They act as independent data controllers for the delivery process and have their own privacy policies.

  • Payment Processor

    Stripe Payments Europe Ltd processes card payments on our behalf. We do not store your full card number, CVV, or PIN. Stripe is PCI DSS Level 1 certified and processes payment data in accordance with their privacy policy. They act as a data processor on our behalf and as an independent controller for fraud prevention.

  • Hosting Provider

    Our website is hosted on servers within the European Economic Area (EEA). Our hosting provider processes server logs containing IP addresses and access timestamps as a data processor under a data processing agreement with us.

  • Analytics Providers

    Google Analytics (provided by Google Ireland Ltd) receives anonymised usage data through cookies, subject to your consent. We have entered into Google's Data Processing Amendment and have enabled IP anonymisation. If you consent to marketing cookies, Meta Platforms Ireland Ltd may receive limited interaction data through the Meta Pixel for ad performance measurement.

  • Email Service Provider

    Our email marketing platform stores your email address, name, and consent status to deliver marketing emails on our behalf. They act as a data processor and do not use your data for their own purposes. Servers are located within the EEA.

We may also disclose your personal data if required to do so by law, regulation, legal process, or enforceable governmental request, or to protect the rights, property, or safety of NorixMedia, our customers, or the public.

8. International Data Transfers

We prioritise keeping your data within the European Economic Area (EEA). Our website hosting, email marketing platform, and primary business operations are all based in the EEA.

However, some of our service providers (particularly Google LLC for analytics and Stripe Inc for payment processing) are headquartered in the United States. When data is transferred outside the EEA to these providers, the transfers are protected by one or more of the following safeguards as required under Chapter V of the GDPR:

  • EU-US Data Privacy Framework: Where the recipient is certified under the EU-US Data Privacy Framework (as recognised by the European Commission's adequacy decision of July 2023), transfers are made on the basis of that adequacy decision.
  • Standard Contractual Clauses (SCCs): Where the Data Privacy Framework does not apply, we rely on the European Commission's Standard Contractual Clauses (adopted June 2021) as the legal mechanism for the transfer, supplemented by additional technical and organisational measures where necessary.

You have the right to request a copy of the safeguards we have in place for any international data transfer by contacting us at the details provided in Section 13.

9. Your Rights Under GDPR

Under the General Data Protection Regulation and the Irish Data Protection Act 2018, you have the following rights regarding your personal data. These rights are not absolute in all circumstances, and certain exemptions may apply depending on the legal basis for processing and the nature of the data involved.

Right of Access (Article 15)

You have the right to request a copy of the personal data we hold about you, along with information about how it is being processed, the purposes of processing, and the categories of recipients. We will provide this information free of charge within one month of your request.

Right to Rectification (Article 16)

If any of the personal data we hold about you is inaccurate or incomplete, you have the right to request that we correct or complete it without undue delay. This includes updating your delivery address, phone number, or email address.

Right to Erasure (Article 17)

You have the right to request deletion of your personal data where it is no longer necessary for the purpose it was collected, where you withdraw consent (and no other legal basis applies), or where you object to processing based on legitimate interest. Please note that we may be required to retain certain data for legal compliance (such as tax records for 6 years).

Right to Restriction of Processing (Article 18)

You may request that we restrict the processing of your data while we verify its accuracy, if you believe our processing is unlawful but prefer restriction over deletion, if we no longer need the data but you need it for legal claims, or while we consider your objection to processing based on legitimate interest.

Right to Data Portability (Article 20)

Where processing is based on consent or contract performance and is carried out by automated means, you have the right to receive the personal data you provided to us in a structured, commonly used, and machine-readable format (e.g., CSV or JSON), and to request that we transmit it directly to another controller where technically feasible.

Right to Object (Article 21)

You have the right to object at any time to the processing of your personal data based on legitimate interest (Article 6(1)(f)). Upon receiving your objection, we will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms. You may object to direct marketing at any time, and we will cease such processing without exception.

Right to Withdraw Consent (Article 7(3))

Where we process your data based on consent (such as marketing emails or marketing cookies), you may withdraw that consent at any time. This can be done by clicking "Unsubscribe" in any marketing email, adjusting your cookie preferences on our site, or contacting us directly. Withdrawal does not affect the lawfulness of any processing carried out before you withdrew.

How to Exercise Your Rights

To exercise any of the rights described above, please contact us at [email protected] with the subject line "Data Subject Request". We may ask you to verify your identity before processing your request, to ensure we do not disclose data to the wrong person. We will respond to all valid requests within one calendar month. If your request is complex or we receive a large number of requests, we may extend this period by a further two months, in which case we will inform you within the initial one-month period and explain the reason for the extension.

Right to Lodge a Complaint

If you believe that we have not handled your personal data in accordance with the GDPR or Irish data protection law, you have the right to lodge a complaint with the Data Protection Commission of Ireland. Their contact details are:

Data Protection Commission

21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland

Phone: +353 1 765 0100 / 1800 437 737

Website: www.dataprotection.ie

10. Cookies and Tracking Technologies

Cookies are small text files placed on your device when you visit a website. They serve various purposes, from remembering your preferences to helping us understand how you use our site. Below we describe the types of cookies we use, their purpose, and how long they persist.

Essential Cookies

These cookies are necessary for the website to function properly and cannot be switched off. They are set in response to actions you take, such as setting your cookie consent preference or filling in a form. They do not track you across other websites.

Cookie Name Purpose Duration
norix_cookieConsent Stores your cookie consent preference (accepted/rejected) 12 months
norix_lang Stores your language preference 12 months

Analytics Cookies

These cookies help us understand how visitors interact with our website by collecting and reporting information anonymously. They are only set if you accept analytics cookies through our consent banner.

Cookie Name Purpose Duration
_ga Google Analytics: distinguishes unique users 13 months
_ga_[ID] Google Analytics: maintains session state 13 months

Marketing Cookies

Marketing cookies are used to track visitors across websites to allow us to display relevant advertisements. They are only set if you explicitly accept marketing cookies through our consent banner.

Cookie Name Purpose Duration
_fbp Meta Pixel: tracks visits for ad targeting 3 months
_fbc Meta Pixel: stores click identifier from ad 3 months

Managing Cookies

When you first visit our website, a cookie consent banner appears in the bottom-right corner of the screen, allowing you to accept or reject non-essential cookies. You can change your cookie preferences at any time by clearing your browser cookies and revisiting our site, which will trigger the consent banner again. You can also manage cookies through your browser settings. Most browsers allow you to block or delete cookies, though doing so may affect the functionality of certain website features. For more detail on our cookie practices, please refer to our Cookie Notice.

11. Children's Privacy

Our website and services are not directed at children under the age of 16. We do not knowingly collect or solicit personal data from anyone under 16 years of age. While many families enjoy our gardening kits as educational activities with their children, the order process and data submission should always be completed by a parent or guardian who is at least 18 years old.

If we become aware that we have inadvertently collected personal data from a child under 16 without verified parental consent, we will take immediate steps to delete that data from our records. If you believe that a child under 16 has provided us with personal data, please contact us at [email protected] so we can investigate and take appropriate action.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, services, legal requirements, or regulatory guidance. When we make changes, we will update the "Last Updated" date at the top of this page.

For significant changes that materially affect how we process your personal data or your rights, we will provide prominent notice on our website (such as a banner notification) at least 14 days before the changes take effect. If you have an account or are subscribed to our emails, we may also notify you directly via email.

We encourage you to review this policy periodically to stay informed about how we protect your personal data. Continued use of our website after changes have been posted constitutes your acceptance of the updated policy, except where your consent is specifically required under GDPR for the change in question.

13. Contact Details

If you have any questions about this Privacy Policy, wish to exercise your data protection rights, or want to raise a concern about how we handle your personal data, please contact us using the details below. We aim to respond to all privacy-related enquiries within 5 business days.

Privacy Contact

NorixMedia Ltd
Unit 4, Ashbourne Business Park, Ashbourne, Co. Meath, A84 F6Y2, Ireland
+353 1 802 4590
Monday to Friday, 9:00 to 17:30 (Irish Standard Time)

For data subject access requests, please email us with the subject line "Data Subject Request" and include enough information for us to verify your identity and locate your data (such as the email address or order number you used when interacting with us). We will acknowledge your request within 3 business days and provide a full response within one calendar month.

This Privacy Policy was last updated on January 15, 2026 and applies from that date forward.

Related Legal Documents