PRIVACY POLICY

1. General Provisions

1.1. This Privacy Policy describes how Sole Proprietor Dārta Eizentāle, registration number 06079412056, located at Ezermuižas iela 2, Berģi, Garkalnes pag., Ropažu nov., LV-1024 (hereinafter referred to as the “Data Controller”), collects, processes, and stores personal data obtained from clients and individuals visiting the website (hereinafter referred to as the “Data Subject” or “You”).

1.2. Personal data refers to any information relating to an identified or identifiable natural person, i.e., the Data Subject. Processing refers to any operation performed on personal data, such as collection, recording, modification, use, viewing, deletion, or destruction.

1.3. The Data Controller complies with the data processing principles stipulated by law and can confirm that personal data is processed in accordance with applicable legislation.

2. Collection, Processing, and Storage of Personal Data

2.1. The Data Controller collects, processes, and stores personal data primarily through the e-commerce website and email.

2.2. By visiting and using the services provided on the e-commerce website, you agree that any information provided may be used and managed in accordance with the purposes outlined in this Privacy Policy.

2.3. The Data Subject is responsible for ensuring that the submitted personal data is correct, accurate, and complete. Providing knowingly false information is considered a breach of this Privacy Policy. The Data Subject must immediately notify the Data Controller of any changes to the submitted personal data.

2.4. The Data Controller is not liable for any damages caused to the Data Subject or third parties resulting from the provision of false personal data.

3. Processing of Client Personal Data

3.1. The Data Controller may process the following personal data:

3.1.1. Name, surname

3.1.2. Date of birth

3.1.3. Contact information (email address and/or phone number)

3.1.4. Transaction data (purchased goods, delivery address, price, payment information, etc.)

3.1.5. Any other information provided to us during the use of the website's services and goods or through communication with us.

3.2. In addition to the aforementioned, the Data Controller has the right to verify the accuracy of the submitted data using publicly available registers.

3.3. The legal basis for processing personal data is the General Data Protection Regulation (GDPR) Article 6, paragraph 1, points a), c), and f):

a) the Data Subject has given consent for the processing of their personal data for one or more specific purposes;

c) processing is necessary for compliance with a legal obligation to which the Data Controller is subject;

3.4. The Data Controller retains and processes the personal data of the Data Subject as long as at least one of the following criteria is met:

3.4.1. The personal data is necessary for the purposes for which it was collected;

3.4.2. As long as the Data Controller and/or the Data Subject can exercise their legitimate interests according to external regulatory acts, such as submitting objections or initiating or defending a legal claim;

3.4.3. As long as there is a legal obligation to retain the data, such as in accordance with the Accounting Law;

3.4.4. As long as the Data Subject's consent for the relevant personal data processing is valid, provided there is no other legal basis for processing the personal data.

Once the conditions mentioned in this point are no longer met, the retention period of the Data Subject's personal data expires, and all relevant personal data is irreversibly deleted from computer systems and electronic and/or paper documents containing such personal data, or these documents are anonymized.

3.5. To fulfill its obligations towards You, the Data Controller has the right to transfer Your personal data to cooperation partners, data processors who perform necessary data processing on our behalf, such as accountants, courier services, etc. The data processor is also the data controller. Payment processing is provided by AS Swedbank or AS Citadele banka; therefore, our company transfers the necessary personal data for payment execution to the financial institution AS Swedbank or AS Citadele banka.

Upon request, we may transfer Your personal data to government and law enforcement authorities, if necessary, to defend our legal interests by preparing, submitting, and defending legal claims.

3.6. When processing and storing personal data, the Data Controller implements organizational and technical measures to ensure the protection of personal data against accidental or unlawful destruction, alteration, disclosure, and any other unlawful processing.

4. Rights of the Data Subject

4.1. In accordance with the General Data Protection Regulation and the laws of the Republic of Latvia, You have the right to:

4.1.1. Access your personal data, receive information about its processing, request an electronic copy of your personal data, and the right to transfer this data to another controller (data portability);

4.1.2. Request the correction of incorrect, inaccurate, or incomplete personal data;

4.1.3. Delete your personal data (“right to be forgotten”), except in cases where the law requires data retention;

4.1.4. Withdraw your previously given consent for personal data processing;

4.1.5. Restrict the processing of your data – the right to request that we temporarily cease processing all your personal data;

4.1.6. Lodge a complaint with the Data State Inspectorate.

You can exercise your rights by filling out a form that the company employee will send to you via email, and you can sign it with a secure electronic signature. You can request the form by writing to [email protected].

5. Final Provisions

5.1. This Privacy Policy has been developed in accordance with the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), as well as the laws of the Republic of Latvia and the European Union in force.

5.2. The Data Controller has the right to make changes or additions to the Privacy Policy at any time without prior notice. Amendments take effect upon their publication on the website www.eizenthal.lv.