Legal
Privacy
Policy
Last updated: September 2026
1. Introduction
This Privacy Policy explains how RIEK&DOL ("we", "our", "us") collects, uses, stores and protects the personal data of visitors to this website and clients who engage our design services.
We are committed to handling your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and applicable Latvian data protection legislation.
2. Data Controller
The data controller responsible for your personal data is:
Trading as: RIEK&DOL
Email: riekndol@gmail.com
3. What Personal Data We Collect
We may collect and process the following categories of personal data:
3.1 Data you provide directly
- Inquiry form: name, email address, message content, and any project details you share.
- Account registration: name and email address if you create an account on this website.
- Email correspondence: any personal data contained in emails you send to us.
3.2 Data collected automatically
- Session data: a session identifier stored in a cookie to keep you logged in if you have an account.
- Server logs: IP address, browser type, pages visited, and timestamps, retained temporarily by our hosting provider for security and operational purposes.
We do not use advertising cookies, behavioural tracking, or third-party analytics tools on this website.
4. How and Why We Process Your Data
| Purpose | Data used | Legal basis |
|---|---|---|
| Responding to your inquiry or project request | Name, email, message | Legitimate interest (Art. 6(1)(f) GDPR); or pre-contractual steps (Art. 6(1)(b)) |
| Fulfilling a service contract | Name, email, project information | Performance of a contract (Art. 6(1)(b) GDPR) |
| Maintaining your website account | Name, email, session token | Legitimate interest; performance of contract (Art. 6(1)(b) & (f)) |
| Security and fraud prevention | IP address, session data | Legitimate interest (Art. 6(1)(f) GDPR) |
| Legal obligations (e.g. invoicing, tax records) | Name, address, financial data | Legal obligation (Art. 6(1)(c) GDPR) |
5. Data Retention
We retain your personal data only as long as necessary:
- Inquiry messages: up to 2 years from the date of last contact, unless a project contract follows.
- Client project data: up to 5 years after project completion for legal and business record-keeping purposes.
- Account data: for as long as you maintain an account, plus a reasonable period after deletion for security purposes.
- Server logs: typically 30–90 days, as determined by our hosting infrastructure provider.
6. Third-Party Data Processors
We use the following third-party services that may process personal data on our behalf. All processors are required to handle data in accordance with GDPR.
| Processor | Purpose | Location |
|---|---|---|
| Neon (Neon Inc.) | Database hosting (stores account and inquiry data) | EU / USA (SCCs apply) |
| Uploadcare | File and image hosting | EU / USA (SCCs apply) |
| Google LLC (if Google sign-in used) | Authentication via Google OAuth | USA (SCCs apply) |
| [EMAIL SERVICE PROVIDER, IF USED] | Transactional email delivery | [LOCATION] |
We do not sell, rent or share your personal data with third parties for marketing purposes.
7. International Data Transfers
Some of our service providers are based outside the European Economic Area (EEA), including in the United States. Where personal data is transferred to countries not deemed adequate by the European Commission, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission to ensure an equivalent level of data protection.
8. Your Rights Under GDPR
As a data subject located in the EU/EEA, you have the following rights:
- Right of access (Art. 15): request a copy of the personal data we hold about you.
- Right to rectification (Art. 16): request correction of inaccurate or incomplete data.
- Right to erasure (Art. 17): request deletion of your personal data, where no legal obligation requires us to retain it.
- Right to restriction of processing (Art. 18): request that we limit how we process your data in certain circumstances.
- Right to data portability (Art. 20): receive your data in a structured, machine-readable format where processing is based on consent or contract.
- Right to object (Art. 21): object to processing based on legitimate interests.
- Right to withdraw consent: where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, please contact us at riekndol@gmail.com. We will respond within 30 days. You also have the right to lodge a complaint with the Latvian Data State Inspectorate (www.dvi.gov.lv).
9. Cookies
We use a limited number of cookies. Essential cookies are required for the website to function and do not require your consent. We do not use advertising or analytics cookies.
For full details, please read our Cookie Policy.
10. Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss or destruction. These include encrypted database connections, access controls, and secure session handling.
No transmission of data over the internet is 100% secure. While we take all reasonable steps to protect your data, we cannot guarantee absolute security.
11. Changes to This Policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page will reflect any changes. Where changes are material, we will make reasonable efforts to notify you.
12. Contact
For any questions, concerns or requests relating to your personal data, please contact:
RIEK&DOL
Email: riekndol@gmail.com