+371 26003120 On working days 10-19, on weekends 10-17

Privacy policy

SIA Zinva, a company registered in the Republic of Latvia with registration number 40003946631, legal address: Latgales iela 418B, Rīga, LV-1063, Latvia (hereinafter – the Data Controller), is committed to properly protecting your personal data. This Privacy Policy (hereinafter – the Policy) is a document that provides individuals with information on how personal data is processed on this website and its associated domains (hereinafter – the Website). Please take the time to review this Policy to understand our practices regarding your personal data and how we process it.

How We Obtain Information

We may obtain data about you in the following cases:

  • Information you provide when filling out forms or documents on our Website or in our physical store.
  • If you contact us, we may retain these correspondences and the information provided therein (including details and order information).
  • Detailed information regarding your visits to our Website and the resources you access.
  • Information you indicate in your consents or applications addressed to us.

IP Addresses and Cookies

We may collect information about your computer (terminal device), including your IP address, operating system, and browser type for system administration. This is statistical data about browsing actions and patterns and does not identify any individual.

Additionally, the Data Controller may obtain information about general internet usage using cookies stored on the terminal device used to access the Website. You can learn more about cookie rules, types, and managing your consent in our Cookie Settings section.

List of Used Cookies:

 

Where We Store Your Personal Data

We carry out our operations and process data within the territory of the European Union. At the same time, in individual cases, if you consent to third-party cookies and these cookies are managed by a third party located outside the EU/EEA (e.g., the USA), data may be transferred to and stored outside the European Economic Area (EEA). In such cases, data transfer takes place using European Commission Standard Contractual Clauses (SCC) or other GDPR-compliant safeguards.

Security and Retention Periods of Personal Data

The Data Controller implements and maintains appropriate administrative, technical, and organizational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.

The Data Controller stores personal data no longer than is reasonably necessary for the purposes for which the specific personal data is processed. Retention periods for personal data are determined based on applicable legal acts or the legitimate interests of the Data Controller. Upon expiration of the storage period, personal data is deleted.

  • Transaction documents: stored for 5 years after the transaction is processed in accordance with the Accounting Law.
  • Warranty documents: stored for the entire duration of the warranty and statutory liability period (usually 2 to 5 years).
  • Proof of consent: stored during its validity period and for another 5 years after withdrawal.
  • CCTV recordings: stored for no longer than 3 months.

Categories of Processed Personal Data and Purposes

1. Sale of Goods in the Online Store and Administration of Related Processes

  • Purpose: Conclusion and execution of the purchase contract, invoicing, payment processing, delivery of goods, and communication regarding the order.
  • Data Categories: Name, surname, contact information (email, phone, address), order and payment details, delivery address.
  • Legal Basis: Performance of a contract (Point (b) of Article 6(1) of the General Data Protection Regulation), Legal obligation (Point (c) of Article 6(1)), and Legitimate interest (Point (f) of Article 6(1)).

2. Administration of Product Quality and Warranty Obligations

  • Purpose: Ensuring consumers' right of withdrawal, commercial warranties, and product returns.
  • Data Categories: Identification and contact information, transaction and purchase data, payment details for refunds.
  • Legal Basis: Legal obligation (Point (c) of Article 6(1) of the Regulation and Consumer Rights Protection Law) and Performance of a contract (Point (b) of Article 6(1) of the Regulation).

3. Management of Customer Communication and Requests

  • Purpose: Reviewing customer requests, feedback, complaints, and providing responses.
  • Data Categories: Name, surname, contact information, content of communication.
  • Legal Basis: Legal obligation (Point (c) of Article 6(1) of the Regulation) and Legitimate interest (Point (f) of Article 6(1) of the Regulation).

4. Direct Marketing and Newsletters

  • Purpose: Sending news, special offers, and marketing communications.
  • Data Categories: Name, email, phone number.
  • Legal Basis: Consent (Point (a) of Article 6(1) of the Regulation). Consent can be withdrawn at any time by clicking the unsubscribe link in the email or contacting us.

5. Video Surveillance

  • Purpose: Ensuring the safety of the Data Controller's property, employees, and visitors, and the prevention and detection of criminal offenses.
  • Data Categories: Personal image (video image), location, time, and behavior in the video surveillance area.
  • Legal Basis: Legitimate interest (Point (f) of Article 6(1) of the Regulation). Video surveillance is conducted at the goods pickup point at Latgales iela 418B, Rīga.

Cases When Data May Be Disclosed to Third Parties

To provide services, personal data may be transferred to the following processors:

  • Courier services for delivery of goods: Latvijas Pasts VAS, Venipak Latvija SIA, DPD Latvija SIA, Omniva SIA, Unisend Latvija SIA, Itella Logistics SIA, Velokurjers SIA, HRX SIA, and other suppliers.
  • SMS service providers: NESS SIA.
  • CRM and IT system maintainers: NORGATE.LV SIA and other IT service providers.
  • Payment service providers: "Paysera LT" UAB and other licensed payment institution partners.

Data may also be transferred to state or local government institutions and law enforcement agencies in cases specified by normative acts.

Rights of the Data Subject

Regarding the processing of their personal data, the user has the following rights:

  • To request access to their personal data and receive information about its processing.
  • To request rectification of inaccurate or incomplete data.
  • To request erasure of their personal data ("right to be forgotten").
  • To request restriction of data processing.
  • To object to data processing based on legitimate interests.
  • To request data portability.
  • To withdraw provided consent for data processing at any time.
  • To lodge a complaint with the supervisory authority – Data State Inspectorate (Datu valsts inspekcija, www.dvi.gov.lv) if you believe that data processing violates your rights.

Data Controller and Contact Information

The Personal Data Controller is SIA Zinva, reg. No. 40003946631, legal address: Latgales iela 418B, Rīga, LV-1063, Latvia.

If you have any questions, comments, or requests regarding this Privacy Policy or the processing of your personal data, please contact us by email at: [email protected] or by sending a letter to: Latgales iela 418B, Rīga, LV-1063.

 

Version 1.1.

April 20, 2021