Privacy Policy

  1. General provisions.

1.1. This Privacy Policy describes how SIA Sarunāts, registration number: 40203388990, address: Liedes iela 28-35, Riga, LV-1029 (hereinafter also referred to as the "Data Controller") obtains, processes, and stores personal data obtained from its clients and individuals visiting the website www.myhero.lv (hereinafter referred to as the "Data Subject" or "You").

1.2. Personal data means any information relating to an identified or identifiable natural person, i.e., the Data Subject. Processing means any operation or set of operations performed on personal data, such as collection, recording, organization, use, viewing, deletion, or destruction.

1.3. The Data Controller complies with the legal data processing principles and can confirm that personal data is processed in accordance with applicable legislation.

    2.Collection, processing, and storage of personal data.

2.1. The Data Controller obtains, processes, and stores identifying information about individuals mainly using the online store website and email. (Note! It is necessary to supplement if personal data is also collected in other ways, such as in paper form).

2.2. By visiting and using the services of the online store, you agree that any information provided is used and managed in accordance with the purposes set out in the Privacy Policy.

2.3. The Data Subject is responsible for ensuring that the personal data provided is correct, accurate, and complete. Providing false information is considered a violation of our Privacy Policy. The Data Subject is obliged to immediately inform the Data Controller of any changes in the personal data provided.

2.4. The Data Controller is not responsible for any losses incurred by the Data Subject or third parties due to falsely provided personal data.

     3.Processing of customer personal data.

3.1. The Data Controller may process the following personal data:

3.1.1. Name, surname. 

3.1.2. Date of birth. 

3.1.3. Contact information (email address and/or phone number). 

3.1.4. Transaction data (purchased goods, delivery address, price, payment information, etc.). 

3.1.5. Any other information provided to us during the purchase of services and goods on the website or when contacting us.

3.2. In addition to the above, the Data Controller has the right to verify the accuracy of the data provided using publicly available registers.

3.3. The legal basis for the processing of personal data is Article 6(1)(a), (b), (c), and (f) of the General Data Protection Regulation:

a) the data subject has given consent to the processing of their personal data for one or more specific purposes; b) processing is necessary for the performance of a contract to which the data subject is a party or for taking pre-contractual steps at the data subject's request; c) processing is necessary for compliance with a legal obligation to which the controller is subject; f) processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.

3.4. The Data Controller stores and processes the personal data of the Data Subject as long as at least one of the following criteria is met:

3.4.1. Personal data is necessary for the purposes for which it was obtained; 

3.4.2. As long as the Data Controller and/or the Data Subject can pursue their legitimate interests in accordance with external regulatory acts, such as lodging objections or raising or defending claims in court; 

3.4.3. As long as there is a legal obligation to retain data, such as in accordance with the Accounting Law; 

3.4.4. As long as the Data Subject's consent to the relevant processing of personal data is valid, if there is no other lawful basis for processing personal data.

Upon expiration of the conditions mentioned in this paragraph, the storage period of the Data Subject's personal data expires, and all relevant personal data is permanently deleted from computer systems and electronic and/or paper documents containing such personal data, or these documents are anonymized.

3.5. To fulfill its obligations to you, the Data Controller has the right to transfer your personal data to cooperation partners, data processors performing the necessary data processing on our behalf, such as accountants, courier services, etc. A data processor is the data controller. Payment processing is provided by the payment platform makecommerce.lv, so our company transfers the necessary personal data to the owner of the platform, Maksekeskus AS, for payment execution. Upon request, we may transfer your personal data to state and law enforcement authorities to protect our legal interests, to compile, file, and defend legal claims.

3.6. When processing and storing personal data, the Data Controller implements organizational and technical measures to ensure the protection of personal data against accidental or unlawful destruction, alteration, disclosure, and any other unlawful processing.

     4.Data Subject's rights.

4.1. In accordance with the General Data Protection Regulation and Latvian legislation, you have the following rights: 4.1.1. Access to your personal data, receiving information about its processing, as well as requesting a copy of your personal data in electronic format and the right to transfer this data to another controller (data portability); 4.1.2. Request correction of incorrect, inaccurate, or incomplete personal data; 4.1.3. Delete your personal data ("to be forgotten"), except where required by law to retain data; 4.1.4. Withdraw your previously given consent to the processing of personal data; 4.1.5. Restrict the processing of your data - the right to request that we temporarily cease processing all of your personal data; 4.1.6. Contact the Data State Inspectorate. You can submit a request to exercise your rights by filling out a form in person at Liedes iela 28-35, Riga, LV-1029, or by sending a request electronically to the email address [email protected]

      5.Final provisions.

5.1. This Privacy Policy is developed in accordance with European Parliament and Council Regulation (EU) 2016/679 of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), as well as current legislation of the Republic of Latvia and the European Union.

5.2. The Data Controller has the right to make changes or additions to the Privacy Policy at any time and without prior notice. Amendments come into force upon their publication on the website www.myhero.lv.