1. Controller
The controller is VIRELIX SIA, registration number 40203771235. Privacy enquiries: Virelixsia@outlook.com, +371 26 737 532.
2. Data we may process
- name, organisation and contact details;
- site city or country, premises type, area and access information;
- requested service, schedule, budget and scope information;
- correspondence, call notes, proposals, contracts, invoices and payment status;
- photographs voluntarily supplied for site assessment;
- technical information processed in operational and security logs by the hosting provider, such as IP address, browser type, time and requested page.
3. Purposes and lawful bases
- enquiry handling and proposals — steps requested before contract and legitimate interests in organising communication;
- contract performance — bookings, access, delivery, billing and quality matters;
- legal obligations — accounting, tax and lawful authority requests;
- security and claims — legitimate interests in protecting systems, property and legal interests;
- marketing — only with an appropriate lawful basis, including consent where required.
4. Whether data is required
Only information needed to prepare a response is mandatory in the enquiry form. If information required for a contract, invoice or access is not supplied, we may be unable to offer or deliver the service.
5. Data sources
We mainly receive data from you, an authorised person in your organisation or a property manager. Technical data may arise when you use the site. If another person supplies information needed to organise a contract, we process only what is necessary.
7. Transfers outside the EEA
Some technology providers may process data outside the European Economic Area. Where that occurs, we use an applicable transfer mechanism, such as an EU Commission adequacy decision or Standard Contractual Clauses, and provide available information on request.
8. Retention
An enquiry that does not become a contract is generally retained for up to 24 months unless a shorter or longer period is justified. Contracts, invoices and accounting information are retained for applicable accounting, tax and limitation periods. Security logs are retained for the limited period set by the hosting provider. Data is then deleted or anonymised.
9. Your rights
Where applicable, you may request access, correction, erasure, restriction and portability, and object to processing based on legitimate interests. Consent may be withdrawn for future processing where consent is the basis. We may reasonably verify identity before responding.
10. Supervisory authority
We invite you to contact us first. You also have the right to complain to the Latvian Data State Inspectorate: dvi.gov.lv.
11. Security
We use risk-appropriate organisational and technical measures, access controls and provider review. No internet transmission is entirely risk-free, so please do not place unnecessary sensitive data, passwords or identity-document copies in an enquiry.
12. Automated decisions and updates
We do not use website data for solely automated decisions producing legal or similarly significant effects. We may update this policy when processes or requirements change; the current version date appears above.