Slokas iela 55, Rīga
Latvija, LV-1007
1. Purpose of the Personal Data Processing Policy
The purpose of the personal data processing policy is to provide a natural person (data subject) with information about the purpose, scope, protection, and duration of personal data processing at the time of data collection and during the processing of the data subject’s personal data.
2. Data Controller and Its Contact Information
The data controller for personal data processing is Darba Spars Ltd (hereinafter – DS), registration number 40003096564, with a registered address at Slokas iela 55, Riga, LV-1007, email: info@darbaspars.lv.
For matters related to personal data processing, DS’s contact point is the Customer Service Center. Questions about personal data processing can be sent to info@darbaspars.lv. Requests to exercise your rights can be submitted according to section 12 of this document.
3. Scope of the Document
Personal data is any information related to an identified or identifiable natural person. Definitions, explanations, and categories of personal data are provided in Annex No. 1.
The privacy policy is applied to ensure privacy and personal data protection for:
– natural persons – customers, employees, and other service users (including potential, former, and current users), as well as third parties who receive or provide any information related to the provision of services to a natural person (Client) to DS (including contact persons, payers, etc.);
– visitors of DS warehouses (Slokas iela 55, Riga, LV-1007) where video surveillance is conducted;
– visitors of DS-maintained websites (hereinafter – Clients).
DS takes care of the privacy and personal data protection of its Clients by respecting their rights to the lawful processing of personal data in accordance with applicable legislation – the Personal Data Protection Law, the European Parliament and Council Regulation (EU) 2016/679 of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (Regulation), and other applicable laws in the field of privacy and data processing.
The privacy policy applies to data processing regardless of the form and/or environment in which the Client provides personal data (on DS-owned websites, in paper form, or by phone) and in which company systems or paper format they are processed.
Additional specific rules may be set for specific types of data processing (e.g., processing of cookies, etc.), environments, or purposes, which the Client is informed about when providing relevant data to DS.
4. Purposes of Personal Data Processing
DS processes personal data for the provision of services and sale of goods:
– for customer identification and offer preparation;
– for preparing, concluding, amending, renewing, or terminating contracts;
– for customer service;
– for the delivery of goods and provision of services (fulfillment of contractual obligations);
– for ensuring/maintaining the operation of services;
– for improving goods and services, developing new goods and services;
– for promoting, advertising, and distributing services for commercial purposes;
– for reviewing and handling complaints;
– for measuring customer satisfaction, retention, and increasing loyalty;
– for administering payments;
– for assessing creditworthiness and monitoring loans;
– for debt collection and recovery;
– for maintaining and improving websites.
DS processes personal data for business planning and analysis:
– for accounting, planning, and statistics;
– for ensuring data quality and measuring efficiency;
– for conducting market and public opinion research;
– for preparing reports;
– for conducting customer surveys.
DS processes personal data for providing information to state administration institutions and operational entities in cases and to the extent specified by external regulatory acts, as well as for other specific purposes, which the Client is informed about when providing relevant data to DS.
5. Legal Basis for Personal Data Processing
DS processes Client’s personal data based on the following legal grounds:
– for concluding and fulfilling contracts – to conclude a contract based on the Client’s application and ensure its execution;
– for compliance with regulatory acts – to fulfill the obligations set out in external regulatory acts binding on DS;
– based on the consent of the Client – data subject;
– for legitimate interests – to realize DS’s legitimate interests arising from the obligations or contracts between DS and the Client or arising from the law.
DS’s legitimate interests are:
– to conduct business;
– to provide goods installation services;
– to provide urban equipment repair and maintenance services;
– to verify the Client’s identity before concluding a contract or during customer service – by phone, electronically, or in person;
– to ensure the fulfillment of contractual obligations;
– to prevent unreasonable financial risks to its business (including assessing credit risk before selling goods and services and during contract execution);
– to retain Client applications and requests for goods purchase and service provision, and other applications and requests, including those made verbally, by calling call centers, on websites, and in self-service environments;
– to analyze the operation of DS websites, internet sites, and mobile applications, and to develop and implement improvements;
– to administer the Client’s account on DS websites, internet sites, and mobile applications;
– to take actions for Client retention;
– to segment the Client database for more efficient service provision;
– to develop and enhance goods and services;
– to promote its goods and services by sending commercial notifications;
– to send other messages about the progress of contract execution and events important for contract execution, as well as to conduct Client surveys about goods and services and their usage experience;
– to inform about changes in the service provision procedure and price list;
– to inform Clients about news in the industry;
– to ensure environmental education activities;
– to prevent fraud;
– to ensure corporate governance, financial and business accounting, and analytics;
– to ensure efficient company management processes;
– to ensure the efficiency of service provision, goods sales, and delivery;
– to ensure and improve service quality;
– to administer payments;
– to administer overdue payments;
– to address state administration and operational institutions and courts for the protection of their legal interests;
– to inform the public about its activities.
6. Data Processing Rules from Controller to Another Data Controller
These data processing rules apply only to the processing of personal data arising from service agreements provided by DS to another legal entity.
Both Parties act as independent data controllers.
The Parties undertake appropriate technical and organizational measures to ensure the security of personal data processing.
The Parties shall promptly, but no later than within 2 (two) working days, inform the other Party of any received data subject request, if it concerns or affects the processing of personal data by the other Party (e.g., a request to restrict data processing) or affects personal data (e.g., a request to correct data). The Parties shall cooperate in good faith (e.g., by exchanging information about the processing of personal data) to fulfill reasonable data subject requests and ensure data accuracy throughout the data processing period.
7. Processing of Personal Data
DS processes Client data using modern technological capabilities, considering existing privacy risks and DS’s reasonably available organizational, financial, and technical resources.
Regarding the Client, DS may make automated decisions. The Client is separately informed about such DS actions in accordance with the regulatory acts. The Client may object to automated decision-making under the law, but it is understood that in certain cases, this may limit the Client’s right to use certain potentially available options (e.g., to receive commercial offers).
Automated decision-making that has legal consequences for the Client (e.g., approval or rejection of the Client’s application) may only be carried out in the course of concluding or fulfilling a contract between DS and the Client or based on the Client’s explicit consent.
To ensure the high-quality and prompt execution of the obligations of a contract concluded with the Client, DS may authorize DS group companies or its partners to carry out certain goods delivery or service provision activities, such as installation work or sending invoices. If DS group companies or partners process Client personal data held by DS when performing these tasks, the respective DS group companies or partners are considered DS data processors (processors), and DS is entitled to provide DS group companies and partners with the necessary Client personal data to the extent necessary for performing these tasks.
DS’s partners and DS group companies (in the status of personal data processors) shall ensure compliance with personal data processing and protection requirements in accordance with DS requirements and laws, and shall not use personal data for purposes other than for fulfilling obligations under the contract concluded with the Client on behalf of DS.
8. Protection of Personal Data
DS protects Client data using modern technological capabilities, taking into account existing privacy risks and DS’s reasonably available organizational, financial, and technical resources.
9. Categories of Data Recipients
DS does not disclose Client personal data or any information obtained during the provision of services and during the operation of the contract, including information about the services received, to third parties, except:
– if the data must be disclosed to a third party within the framework of a concluded contract to perform a function necessary for contract fulfillment or delegated by law (e.g., to a bank within the framework of settlements or to provide a service);
– for invoice delivery to the Client;
– for payment processing;
– for product delivery to the Client;
– for sending postal notifications to Clients about changes in contract content or price list;
– with the Client’s clear and explicit consent;
– to persons specified in external regulatory acts upon their justified request, in the manner and to the extent specified by external regulatory acts;
– in cases specified by external regulatory acts for the protection of DS’s legitimate interests, such as applying to a court or other state institutions against a person who has infringed on DS’s legitimate interests.
10. Access to Personal Data by Third Country Subjects
DS ensures compliance with the procedures set out in regulatory acts to guarantee a level of personal data processing and protection equivalent to that established by the Regulation.
11. Retention Period of Personal Data
DS retains and processes Client personal data as long as at least one of the following criteria applies:
– until the contract with the Client is valid;
– while DS or the Client may realize their legitimate interests according to the procedures prescribed in external regulatory acts (e.g., file objections or bring claims to court);
– as long as there is a legal obligation to retain data according to external regulatory acts;
– as long as the Client’s consent for the specific data processing is valid, unless another legal basis for data processing exists.
After the conditions referred to in this clause cease, Client personal data is deleted.
12. Access to Personal Data and Other Client Rights
The Client has the right to receive information as specified in the regulatory acts regarding the processing of their data, to access their data and to request their rectification, as well as to demand the deletion of data or to restrict its processing or to object to processing, insofar as this does not conflict with the purpose for which the data is processed.
Clients can obtain information about their data, rectify it, or delete it by submitting an appropriate request to DS. Information about the submission of requests can be found on the DS website or by contacting DS.
13. Client Consent for Data Processing and Right to Withdraw It
If data processing is based on Client consent, the Client has the right to withdraw their consent at any time, which does not affect the legality of data processing based on consent before its withdrawal.
Consent withdrawal is not valid if data processing is based on another legal basis, such as fulfilling a contract or compliance with the law.
14. Communication with the Client
DS communicates with the Client using the Client’s contact information (phone number, email address, mailing address, etc.).
15. Cookies
DS websites may use cookies. Cookies are files stored on Clients’ computers by websites to recognize Clients and facilitate the use of websites. DS websites may use cookies to store information about the Client’s actions on websites. The Client may choose whether to accept cookies in the browser settings.
16. Changes in the Privacy Policy
DS has the right to change the Privacy Policy by making the current version available on the DS website.