1. Introduction
SIA "3A princips", registration No. 40103843255, registered address: Valentīna iela 16 k-3 - 33, Riga, LV-1083, Latvia (hereinafter – the Controller), processes personal data obtained from the data subject – the user of the website www.darbaguru.lv (hereinafter – the Website) (hereinafter – the User).
The Controller is committed to protecting the User's privacy and personal data and respects the User's right to lawful processing of personal data in accordance with the applicable legal acts, including Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (the General Data Protection Regulation or GDPR), as well as other applicable laws governing privacy and personal data processing.
Accordingly, the Controller has developed this Privacy Policy in order to provide the User with the information required under the GDPR.
This Privacy Policy applies to the processing of personal data regardless of the form and/or medium in which the User provides personal data (via the Website, in paper form, or by telephone).
2. Identity and Contact Details of the Controller
Controller: SIA "3A princips"
Registration No.: 40103843255
Registered address: Valentīna iela 16 k-3 - 33, Riga, LV-1083, Latvia
Website: www.darbaguru.lv
E-mail: info@darbaguru.lv
Telephone: +371 29554294
3. Contact Details of the Data Protection Specialist
The Controller's Data Protection Specialist is Lauris Klagišs.
E-mail: lauris@klagiss.lv
Telephone: +371 29470425
4. Purposes of Processing and Legal Basis for Processing
If the User submits personal data to the Controller, such as their first name, surname, personal identity number, e-mail or postal address, telephone number, personal messages, or other information, through the Website's contact forms, e-mail, or any other form of correspondence, the Controller stores and uses such information for the purpose of performing or concluding the relevant service agreement.
The processing of such data is necessary for identifying the client, preparing, concluding, and proving the conclusion of a contract, ensuring and maintaining the provision of services, customer service, reviewing and processing applications and objections, administering payments, and for other purposes directly related to the conclusion or performance of a contract.
The legal basis for such processing is Article 6(1)(b) of the GDPR, which provides that processing is lawful where it is necessary for the performance of a contract to which the data subject is a party or in order to take steps at the request of the data subject prior to entering into a contract.
5. Categories of Personal Data
The categories of personal data processed include: First name;Surname; Personal identity number; E-mail address; Postal address; IP address; Telephone number; Contents of messages or correspondence; Other information voluntarily provided by the User.
6. Categories of Recipients of Personal Data
Personal data is disclosed only to those employees of the Controller who require such data for the performance of their direct duties in order to conclude or perform the relevant service agreement.
When obtaining and processing personal data, the Controller partly uses the services of external service providers who, under contractual obligations, strictly comply with the Controller's instructions. The Controller evaluates such service providers before engaging them and continuously monitors their compliance thereafter.
7. Categories of Data Subjects
The categories of data subjects include: Existing clients of the Controller; Former clients of the Controller; Potential clients of the Controller.
8. Transfer of Personal Data Outside Latvia
The personal data received is not and will not be transferred outside Latvia, the European Union, or the European Economic Area, nor will it be transferred to any international organisation.
9. Data Retention Period
Unless otherwise specified in the data protection provisions, the Controller deletes personal data no later than three months after the original reason for retaining the data no longer exists, except where the Controller is legally obliged to retain such data for a longer period (including, but not limited to, accounting or legal proceedings).
10. Access to Personal Data
The data subject has the right to obtain access to their personal data within one month from the date of submitting the relevant request.
The User may submit a written request to exercise their rights either:
in person at the Controller's registered address (upon presentation of an identity document);
or
electronically by e-mail, provided that the request is signed with a secure electronic signature.
Upon receiving a request from the User to exercise their rights, the Controller verifies the User's identity, assesses the request, and fulfils it in accordance with the applicable legal requirements.
The User has the right to receive the information prescribed by law regarding the processing of their personal data, to request access to their personal data, and to request the Controller to supplement, rectify or erase such data, restrict processing, or object to processing, insofar as these rights do not conflict with the purposes of the data processing (the conclusion or performance of contracts).
The data subject shall not have the right to obtain information where disclosure is prohibited by law in the interests of national security, national defence, public security, criminal law enforcement, the protection of the State's financial interests in tax matters, the supervision of financial market participants, or macroeconomic analysis.
11. Right to Lodge a Complaint with the Supervisory Authority
The data subject has the right to lodge a complaint with the supervisory authority:
Data State Inspectorate (Datu valsts inspekcija)
Blaumaņa iela 11/13
Riga, Latvia
The Data State Inspectorate also accepts electronic submissions sent to e-mail: info@dvi.gov.lv