Last updated 7 September 2026 · Version 1.0
Privacy policy
What we collect, why we collect it, how long we keep it, and what you can make us do about it.
Template · pending legal review
1.Who we are
This website is operated by Nikola Tech Group SIA, registration No. 40203773109, registered address Rēzeknes nov., Feimaņu pag., Feimaņi, "5" - 5, LV-4623, Latvia, registered in the Commercial Register of the Republic of Latvia on 24 August 2026. For the purposes of this policy Nikola Tech Group SIA is the data controller of the personal data described here.
When we build or host software for a client, we generally act as a processor on that client's behalf, and the client's own contract and privacy notice govern that data rather than this policy.
2.What we collect
Information you give us
- Your name, email address and, if you provide them, company name and phone number.
- The content of your enquiry, including the project description, timeline and the service or care plan you are asking about.
- Correspondence with us, including any attachments you send.
- Billing details needed to issue an invoice, such as a company registration number and, where relevant, bank details.
Information collected automatically
- Server logs: IP address, browser type, referring page and timestamp, kept for security and availability.
- Browser storage as described in the cookies policy. Only strictly necessary storage is used unless you consent to more.
What we do not collect
We do not ask for or knowingly collect special-category data. We never see or store card details: services are paid by bank transfer against an invoice, and any card payment for a care plan is processed by a payment provider that does not share full card numbers with us.
3.Why we use it
Each use has a lawful basis under Article 6 of the GDPR.
| Purpose | Data used | Lawful basis |
|---|---|---|
| Replying to an enquiry and preparing a quote | Name, email, company, message | Art. 6(1)(b) — steps before a contract |
| Delivering a project or care plan | Contact and project data | Art. 6(1)(b) — contract |
| Invoices and accounts | Billing details, invoice records | Art. 6(1)(c) — legal obligation |
| Website security and availability | Server logs, IP address | Art. 6(1)(f) — legitimate interests |
| Optional analytics | Cookie identifiers | Art. 6(1)(a) — consent |
| Establishing or defending legal claims | Correspondence and records | Art. 6(1)(f) — legitimate interests |
Where we rely on consent you can withdraw it at any time; withdrawal does not affect processing that already took place. We do not make automated decisions with legal effects about you, we do not profile you, and we never sell personal data.
4.How long we keep it
- Enquiries that do not lead to a project: 12 months from the last message.
- Client project records and correspondence: 3 years after the engagement ends.
- Accounting records, including invoices: the period required by Latvian accounting law, currently around 5 years.
- Server logs: around 30 days.
- Your cookie choice: stored in your own browser until you clear it.
When a retention period ends the data is deleted or irreversibly anonymised.
6.International transfers
We prefer providers that store data inside the European Economic Area. Where a provider processes data outside the EEA, we rely on an adequacy decision or the European Commission's standard contractual clauses together with appropriate safeguards. We will tell you which providers are involved on request.
7.Your rights
- Access — a copy of the personal data we hold about you.
- Rectification — correction of inaccurate data.
- Erasure — deletion where there is no longer a lawful reason to keep it.
- Restriction — pausing processing while a question is resolved.
- Portability — data you gave us, in a structured, machine-readable format.
- Objection — to processing based on legitimate interests.
- Withdrawal of consent — at any time, for processing based on consent.
Write to the address in the last section. We respond within one month, free of charge unless a request is manifestly unfounded or excessive.
8.Security
HTTPS everywhere, least-privilege access to systems, a password manager and two-factor authentication on accounts, secrets kept outside source repositories, and regular updates to the software we run. Should a personal data breach occur that is likely to result in a risk to you, we will notify the supervisory authority within 72 hours and, where the risk is high, notify you directly.
9.Children
This is a business-to-business website not directed at children. We do not knowingly collect data from anyone under 16; if you believe we have, tell us and it will be deleted.
10.Changes to this policy
We update this policy when our business or the law changes. The version number and the date above always reflect the current text. Material changes will be brought to your attention on this page.
11.Contact and complaints
Questions and requests about personal data go to:
- Nikola Tech Group SIA
- Registration No. 40203773109, Commercial Register of the Republic of Latvia, 24 August 2026
- Rēzeknes nov., Feimaņu pag., Feimaņi, "5" - 5, LV-4623, Latvia
- Email: info@nikolatechgroup.com
You also have the right to complain to the Latvian Data State Inspectorate (Datu valsts inspekcija) or to the supervisory authority in your country of residence.