1. General Terms
1.2. Personal data is any information related to an identified or identifiable natural person, i.e., the Data Subject. Processing includes any action related to personal data, such as obtaining, recording, transforming, using, viewing, deleting, or destroying.
1.3. The Data Controller adheres to the principles of data processing established by legislation and can confirm that personal data is processed in accordance with current legislation.
2. Acquisition, Processing, and Storage of Personal Data
2.1. The Data Controller obtains, processes, and stores personally identifiable information primarily using the website and email. (Note: If personal data is collected in other ways, such as in paper form, it needs to be added.)
2.4. The Data Controller is not responsible for losses incurred by the Data Subject or third parties if they arise due to falsely submitted personal data.
3. Processing of Customer Personal Data
3.1. The Data Controller may process the following personal data:
3.1.1. Name, surname
3.1.2. Date of birth
3.1.3. Contact information (email address and/or phone number)
3.1.4. Transaction data (purchased goods, delivery address, price, payment information, etc.).
3.1.5. Any other information submitted to us during the use of the website’s services or the purchase of goods or when contacting us.
3.2. In addition to the above, the Data Controller has the right to verify the accuracy of the submitted data using publicly available registers.
3.3. The legal basis for the processing of personal data is Article 6(1)(a), (b), (c), and (f) of the General Data Protection Regulation:
a) The data subject has given consent to the processing of their personal data for one or more specific purposes;
b) Processing is necessary for the performance of a contract to which the data subject is a party or for steps at the request of the data subject prior to entering into a contract;
c) Processing is necessary for compliance with a legal obligation to which the controller is subject;
f) Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject, especially if the data subject is a child.
3.4. The Data Controller stores and processes the data subject’s personal data as long as at least one of the following criteria exists:
3.4.1. Personal data are necessary for the purposes for which they were received;
3.4.2. Until, in accordance with external legislative acts, the Data Controller and/or the data subject can realize their legitimate interests, such as submitting objections or raising claims in court;
3.4.3. While there is a legal obligation to retain data, such as in accordance with the Accounting Law;
3.4.4. While the data subject’s consent to the respective processing of personal data is in force, if there is no other lawful basis for the processing of personal data.
Upon the expiration of the circumstances mentioned in this point, the storage period of the data subject’s personal data ends, and all relevant personal data are permanently deleted from computer systems and electronic and/or paper documents containing such personal data, or these documents are anonymized.
3.5. In order to fulfill its obligations to you, the Data Controller has the right to transfer your personal data to cooperation partners, data processors who perform the necessary data processing on our behalf, such as accountants, courier services, etc. A data processor is the controller of personal data. Payment processing is provided by the payment platform every-pay.com, so our company transfers the necessary personal data for payment execution to the platform owner EveryPay.
Upon request, we may disclose your personal data to state and law enforcement authorities to defend our legal interests by preparing, submitting, and defending legal claims if necessary.
3.6. When processing and storing personal data, the Data Controller implements organizational and technical measures to ensure the protection of personal data against accidental or unlawful destruction, alteration, disclosure, and any other unlawful processing.
4. Rights of the Data Subject
4.1. In accordance with the General Data Protection Regulation and the laws of the Republic of Latvia, you have the right to:
4.1.1. Access your personal data, receive information about its processing, and request a copy of your personal data in electronic format and the right to transfer this data to another controller (data portability);
4.1.2. Request the correction of incorrect, inaccurate, or incomplete personal data;
4.1.3. Erase your personal data (“be forgotten”), except in cases where the law requires data retention;
4.1.4. Withdraw your previously given consent to the processing of personal data;
4.1.5. Restrict the processing of your data – the right to request that we temporarily or permanently stop processing all your personal data;
4.1.6. Contact the Data State Inspectorate.
You can submit a request to exercise your rights by filling out a form in person at SIA “Radex-Europe”, Registration No.: 40003921407, address: “Lielcirši”, Vētras, Mārupe municipality, Mārupe parish, LV-2167, or by sending a request electronically by writing to the customer support email [email protected].
5. Final Provisions