1. General Provisions.

1.1. The purpose of this Privacy Policy is to provide information on how SIA MM Building, 40103937796, registered address: Ganibu dambis 27 k-6, Riga, LV-1005 (hereinafter referred to as the “Data Controller” or “we”) collects, processes, and stores personal data obtained from its clients and visitors to the website www.havenpoint.eu (hereinafter referred to as the “Data Subject” or “you”).

1.2. Personal data is any information relating to an identified or identifiable natural person, i.e., the Data Subject. Processing means any operation performed on personal data, such as collection, recording, alteration, use, viewing, deletion, or destruction.
1.3. The Data Controller complies with the principles of data processing established by law and can confirm that personal data is processed in accordance with applicable legislation.

2. Collection, Processing, and Storage of Personal Data

2.1. The Data Controller collects, processes, and stores personally identifiable information primarily through the online store website and email, in exceptional cases in paper form.

2.2. By visiting and using the services provided by the online store, you agree that any information provided will be used and managed according to the purposes specified in the Privacy Policy.

2.3. The Data Subject is responsible for ensuring that the submitted personal data is accurate, precise, and complete. Deliberately providing false information is considered a violation of our Privacy Policy. The Data Subject must promptly inform the Data Controller of any changes to the submitted personal data.

2.4. The Data Controller is not responsible for any damages incurred by the Data Subject or third parties due to the submission of inaccurate personal data.

3. Processing of Client Personal Data

3.1. The Data Controller may process the following personal data:
3.1.1. Name, surname

3.1.2. Personal identification number / date of birth
3.1.3. Contact information (email address and/or phone number)
3.1.4. Transaction data (purchased goods, delivery address, price, bank account, payment information, etc.)
3.1.5. Any other information provided to us during the purchase of goods or services offered on the website, communication with us, or subscription to receive updates.

3.2. Additionally, the Data Controller has the right to verify the accuracy of the submitted data using publicly available registers.
3.3. The legal basis for the processing of personal data is Article 6(1)(a), (b), (c), and (f) of the General Data Protection Regulation:

a) the Data Subject has given consent for the processing of their personal data for one or more specific purposes;
b) the processing is necessary for the performance of a contract to which the Data Subject is a party or to take steps at the request of the Data Subject prior to entering into a contract;
c) the processing is necessary for compliance with a legal obligation to which the Controller is subject;
f) the processing is necessary for the legitimate interests pursued by the Controller or a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject, particularly if the Data Subject is a child.

3.4. The Data Controller stores and processes personal data of the Data Subject as long as at least one of the following criteria applies:

3.4.1. The personal data is necessary for the purposes for which it was collected;
3.4.2. As long as the Data Controller and/or the Data Subject may exercise their legitimate interests, such as filing objections or submitting or defending claims in court, in accordance with external regulatory acts;
3.4.3. As long as there is a legal obligation to retain the data, such as under the Accounting Law;

3.4.4. As long as the Data Subject’s consent for the respective personal data processing is valid, if there is no other legal basis for the processing.
When the conditions mentioned in this clause cease to exist, the storage period for the personal data of the Data Subject also ends, and all relevant personal data is permanently deleted from computer systems and electronic and/or paper documents containing the respective data, or these documents are anonymized.

3.5. To fulfill its obligations to you, the Data Controller has the right to transfer your personal data to partners, data processors who perform necessary data processing on our behalf, such as accountants, banking and payment card centers, courier services, etc. The data processor is the controller of personal data. Payments are made outside the online store environment, in a secure payment environment at the respective bank or service provider.
Upon request, we may transfer your personal data to state and law enforcement authorities to defend our legal interests, prepare, submit, and defend legal claims if necessary.
3.6. While processing and storing personal data, the Data Controller implements organizational and technical measures to ensure the protection of personal data against accidental or unlawful destruction, alteration, disclosure, and any other unlawful processing.

4. Rights of the Data Subject

4.1. In accordance with the General Data Protection Regulation and the laws of the Republic of Latvia, you have the following rights:

4.1.1. To access your personal data, receive information about its processing, request a copy of your personal data in electronic format, and transfer your data to another controller (data portability);

4.1.2. To request the correction of incorrect, inaccurate, or incomplete personal data;
4.1.3. To delete your personal data (“right to be forgotten”), except in cases where the law requires data retention;

4.1.4. To withdraw your previously given consent for the processing of personal data;
4.1.5. To restrict the processing of your data—the right to request that we temporarily suspend all processing of your personal data;

4.1.6. To lodge a complaint with the Data State Inspectorate.

You can submit a request to exercise your rights by filling out a form and sending it electronically to the email address: info@havenpoint.eu.

5. Final Provisions

5.1. This Privacy Policy has been developed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (April 27, 2016) on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, repealing Directive 95/46/EC (General Data Protection Regulation), as well as the applicable laws of the Republic of Latvia and the European Union.
5.2. The Data Controller reserves the right to make changes or additions to the Privacy Policy at any time and without prior notice. Amendments take effect upon their publication on the website www.havenpoint.eu

Payment processing is provided by the payment platform makecommerce.lv, therefore our company transfers the personal data necessary for payment execution to the platform owner Maksekeskus AS.