Legal
Privacy Policy.
How E Kuprans Digitat IT, SIA handles personal data — what we collect, why, how long we keep it, and the rights the GDPR gives you over it.
1. Who we are
This website is operated by E Kuprans Digitat IT, SIA, a limited liability company registered in the Commercial Register of the Republic of Latvia. For the personal data described in this policy, we act as the data controller.
- Legal name: E Kuprans Digitat IT, SIA
- Registration number: 40203767598 (registered 05.08.2026)
- Legal address: Draudzības aleja 19-2, Jēkabpils, Jēkabpils nov., LV-5201, Latvia
- Board member: Elvis Kuprans
- Email: hello@example.com (placeholder — to be replaced with the live address)
We have not appointed a Data Protection Officer, as we are not required to under Article 37 of the GDPR. Privacy questions go directly to the address above.
2. What we collect
Information you give us
When you send a project brief through the contact form, or write to us directly, we receive whatever you choose to put in it — typically your name, email address, company name, the service you are interested in, an optional budget range, and your description of the project.
Information collected automatically
Our hosting provider records standard server logs when a page is requested. These usually contain the IP address, the time of the request, the page requested, the referring page and the browser's user-agent string. We use them only to keep the site running and secure.
What we deliberately do not do
- We do not run advertising or cross-site tracking on this website.
- We do not build profiles of visitors, and we make no automated decisions that produce legal effects for you.
- We do not knowingly collect special categories of personal data (health, beliefs, biometrics and similar). Please do not include them in a project brief.
The site does load web fonts from Google's servers, which means your IP address is visible to Google when a page loads. That is explained in the Cookies Policy, together with how to avoid it.
3. Why we use it, and on what legal basis
- To answer your enquiry and prepare a quote — Article 6(1)(b) GDPR, steps taken at your request before entering into a contract.
- To deliver a project you have commissioned — Article 6(1)(b), performance of a contract.
- To issue invoices and keep accounting records — Article 6(1)(c), compliance with Latvian accounting and tax law.
- To keep the website available and protect it from abuse — Article 6(1)(f), our legitimate interest in operating a secure service.
- To respond to a legal claim, should one arise — Article 6(1)(f), our legitimate interest in defending our position.
We do not send marketing email. If that ever changes, it will be on the basis of your explicit consent, and every message will carry a working unsubscribe link.
4. How long we keep it
- Enquiries that do not become projects: up to 12 months from the last message, then deleted.
- Project correspondence and deliverables: for the duration of the engagement and up to 3 years afterwards, so we can answer questions about work we did.
- Invoices and accounting records: as long as Latvian accounting law requires — currently 5 years — regardless of any deletion request, because the obligation overrides it.
- Server logs: short-term only, as configured by the hosting provider.
6. Transfers outside the EEA
Where a project is deployed on a cloud provider such as AWS, DigitalOcean or Google Cloud, we default to EU regions so data stays within the EEA. Some providers are US-headquartered, so a transfer may still occur; where it does, it is covered by the European Commission's Standard Contractual Clauses or another Chapter V safeguard.
If your project has a strict data-residency requirement, tell us before work begins — it affects which provider and region we recommend, and it is much cheaper to decide up front than to migrate later.
7. Security
The site is served over HTTPS. Access to enquiry data is limited to the people who need it to reply to you. Credentials for client systems are held under least-privilege access and are revoked at the end of a project.
No system is perfectly secure, and we will not claim otherwise. If a personal data breach occurs that is likely to result in a risk to your rights, we will notify the Data State Inspectorate within 72 hours as required by Article 33, and inform you directly where Article 34 applies.
8. Your rights
Under the GDPR you may:
- Access the personal data we hold about you, and get a copy of it.
- Rectify data that is inaccurate or incomplete.
- Erase data, where we have no overriding obligation to keep it.
- Restrict processing while a dispute about accuracy or legitimate interest is resolved.
- Object to processing based on our legitimate interests.
- Port data you provided to us, in a structured, machine-readable format.
- Withdraw consent at any time, where processing was based on consent. This does not affect processing already carried out.
Write to the contact address in section 1. We answer within one month; if a request is genuinely complex we may extend that by two further months and will tell you why. Exercising these rights is free — we will only charge for requests that are manifestly unfounded or excessive, and we will explain the reason first.
9. Personal data inside client projects
When we build a system for you — a contact form, a SaaS backend, an online store — that system will hold personal data about your customers. In that relationship you are the data controller and we are a processor, acting only on your documented instructions.
For those engagements we sign a separate data processing agreement covering scope, sub-processors, security measures, breach notification and what happens to the data at the end of the project. During development we work with test or minimised data wherever it is practical to do so, and at handover we delete any copies of live data we no longer need.
10. Children
This website is aimed at businesses and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has sent us personal data, contact us and we will delete it.
11. Changes to this policy
We may update this policy when our services, tools or legal obligations change. The date at the top of the page always reflects the current version. Where a change materially affects how we handle data we already hold, we will make that clear rather than quietly editing the text.
12. Contact and complaints
For anything in this policy, or to exercise a right, contact us at the address in section 1 or through the contact page.
If you are not satisfied with our response, you can lodge a complaint with the Latvian supervisory authority:
- Datu valsts inspekcija (Data State Inspectorate)
- Elijas iela 17, Rīga, LV-1050, Latvia
- www.dvi.gov.lv
You may also complain to the supervisory authority in the EU country where you live or work.