Privacy policy

Dragonfly Water Solutions B.V., Gijsbrecht van Amstelstraat 240, 1215 CR Hilversum, Netherlands. KvK 76489256, BTW NL860642574B01. Referred to below as "Dragonfly" or "we".

Version 1.0, effective 1 September 2026. This policy explains what personal data we collect when you visit dragonflywatersolutions.com or buy from us, why we collect it, who else sees it, and what you can make us do about it. It is written under the General Data Protection Regulation, Regulation (EU) 2016/679.

1. Who is responsible

Dragonfly Water Solutions B.V. is the controller of the personal data described here. Write to info@dragonflywater.com or to the postal address above. You can also call +31 6 20037980.

We are not required to appoint a data protection officer and we have not appointed one. Your questions go to the address above and a director answers them.

2. What we collect, why, and on what legal basis

When What Why Legal basis
You place an order Name, billing and delivery address, email, telephone, what you bought, order value, payment status To take payment, ship the order, handle returns, and keep the accounts Performance of a contract, art. 6(1)(b). Legal obligation, art. 6(1)(c), for the tax records
You pay Payment reference and outcome. We never see or store your full card number To collect the money and to detect fraud Performance of a contract, art. 6(1)(b). Legitimate interest in preventing fraud, art. 6(1)(f)
You contact us Your message, your contact details, our reply To answer you and to keep a record of what was agreed Performance of a contract, or legitimate interest in answering enquiries, art. 6(1)(f)
You create an account Email, password (stored hashed by Shopify), order history, saved addresses To let you sign in and see your orders Performance of a contract, art. 6(1)(b)
You join a waitlist Email and the product you asked about To send you one message when it is back Consent, art. 6(1)(a)
You subscribe to our emails Email, name if you gave it, what you opened and clicked To send you our newsletter and offers, and to see what people read Consent, art. 6(1)(a). For existing customers, the soft opt-in in article 13(2) of Directive 2002/58/EC as implemented in article 11.7 of the Dutch Telecommunicatiewet
You leave a checkout unfinished Email or phone if you entered it, and what was in the cart To send you a reminder Consent, art. 6(1)(a). We only send this where you gave marketing consent
You leave a review The name you give, the review, your order reference, any photograph To publish it on the product page Consent, art. 6(1)(a)
You visit the site IP address, browser, device, pages viewed, referring site, cart and session identifiers To keep the shop working and secure Legitimate interest in a working, secure shop, art. 6(1)(f), for the strictly necessary part only
You arrive through a partner link and analytics or marketing cookies are switched on Referral identifier, pages viewed, whether you bought, order value To measure the site and to pay the right partner the right commission Consent, art. 6(1)(a). Nothing here is set before you agree

You do not have to give us anything. Without a name, address and payment we cannot sell you anything and cannot form a contract. Everything else is optional and refusing it costs you nothing.

3. Who else sees your data

We use a small number of companies to run the shop. They process your data on our instructions under a written agreement, and only for what is listed here. We do not give your data to anyone else, and we do not share it for anyone else's marketing.

Who What they do What they get Where
Shopify International Limited, Ireland Runs the store, the checkout, your account and our order records Everything you give us in an order or an account Ireland, with group companies in Canada and the United States
Our payment providers Take the payment Payment and billing data. We do not see your card number iDEAL, card (Visa, Mastercard, Maestro, American Express), PayPal, Klarna, Bancontact, Apple Pay, Google Pay and Shop Pay. Handled by Shopify Payments and the provider you choose; we never see your full card number.
PostNL and their partner carriers Deliver your parcel Name, delivery address, email or phone for the tracking notice Netherlands, and the destination country's carrier for international parcels
Judge.me Collects and publishes product reviews Your email to ask for a review, and what you write Judge.me Ltd. We could not confirm its country of establishment from its own published documents; its data processing addendum states that it relies on standard contractual clauses.
Enlistly Runs our affiliate programme and works out which partner referred an order Referral identifier, order reference and order value. See section 4 Enlistly, operated from the United States. It does not publish a data processing addendum. We are asking them for one.
SmartPush Sends order and marketing email Email, name, order data, what you opened and clicked SmartPush, operated by Starling Labs Limited, Hong Kong, which is outside the European Economic Area. It does not name a transfer mechanism in its published policy. We are asking them for one.
Ecomail Sends marketing email Email, name, what you opened and clicked ECOMAIL.CZ, s.r.o., Czech Republic, inside the European Economic Area.
Our accountant, and the Belastingdienst Books and tax Invoice data Netherlands

Where a provider processes data outside the European Economic Area, the transfer rests on an adequacy decision by the European Commission or on the Commission's standard contractual clauses. Ask us and we will tell you which one applies to which provider and send you the relevant terms.

4. Affiliate tracking, and being straight about it

We run an affiliate programme. When you arrive through a partner's link, a tracking identifier records that partner so they get paid if you buy. We use that identifier for commission and for our own reporting, and for nothing else.

We do not sell personal data, and we do not use it for targeted advertising. This store runs no advertising or retargeting trackers: there is no Meta pixel, no Google Ads tag, no TikTok pixel and no retargeting network on it, and you can confirm that from the page source. The only third parties that receive anything are the service providers listed above, each for the single purpose stated next to it.

5. How long we keep it

  • Orders and invoices: seven years, which is the retention period Dutch tax law requires.
  • Customer accounts: while the account exists, and two years after your last order if you leave it dormant.
  • Waitlist entries: until we send the notification, or twelve months, whichever comes first.
  • Marketing subscription and engagement data: until you unsubscribe, and then a suppression record so we do not email you again by mistake.
  • Correspondence: two years after the matter is closed.
  • Reviews: for as long as the review is published, unless you ask us to remove it.
  • Consent records: five years, so we can show what you agreed to and when

6. Your rights

Under the GDPR you can ask us to give you a copy of your data, correct it, delete it, restrict what we do with it, or send it to you or another provider in a portable format. You can object to processing based on our legitimate interests.

You can object to direct marketing at any time and we stop, with no balancing and no questions. That is article 21(2). Use the unsubscribe link in any message or email us.

Where we rely on your consent you can withdraw it at any time. Withdrawing does not make what we did beforehand unlawful.

Email info@dragonflywater.com. We answer within one month. There is no charge.

If you are not satisfied with how we handled it, you can complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens, at autoriteitpersoonsgegevens.nl, or to the supervisory authority in your own EU country.

7. Automated decisions

We do not make decisions about you by automated means alone, and we do not profile you in a way that produces legal effects or anything similar. Fraud screening at checkout is done by our payment provider and a human reviews anything it stops.

8. Children

The store is not aimed at children and we do not knowingly collect data from anyone under 16. If you think we hold data about a child, tell us and we will delete it.

9. Security

The store runs on platforms that encrypt data in transit and at rest. Access is limited to the people who need it to do their work. If a breach ever puts your data at risk, we notify the Autoriteit Persoonsgegevens within 72 hours and tell you directly where the risk to you is high.

10. Cookies

Cookies and similar technologies have their own page. See our Cookie Policy.

11. Changes

If we change this policy we publish a new version number and date at the top. If a change matters to you, we say so on the site rather than leaving you to notice.