Privacy Policy

1. Controller

The controller responsible for the processing of personal data on this website is:

Oskars Rullis
Self-employed person with registered economic activity in Latvia
Jāņu iela 8
Ikšķile, LV-5052
Latvia

Email: contact@oskarsrullis.com

The controller is the person who determines the purposes and means of processing personal data in connection with this website.

2. General Information on Data Processing

Personal data means any information relating to an identified or identifiable natural person. This may include, in particular, a name, email address, IP address and the content of a message.

Personal data is processed on this website only to the extent necessary to provide and secure the website, respond to enquiries, comply with legal obligations or pursue legitimate interests.

No automated decision-making, including profiling within the meaning of Article 22 of the General Data Protection Regulation (GDPR), takes place.

3. Hosting, Server Log Files and IONOS WebAnalytics

This website is hosted by:

IONOS SE
Elgendorfer Straße 57
56410 Montabaur
Germany

Provision of the Website and Server Log Files

When you access this website, IONOS processes technical access data. This may include, in particular:

  • the previously visited website or referrer,
  • the requested website or file,
  • browser type and browser version,
  • the operating system used,
  • the type of device used,
  • the time of access, and
  • the IP address in anonymised form.

The data is processed to provide the website securely, reliably and without technical errors, and to identify and prevent disruptions and abusive access. The legal basis is Article 6(1)(f) GDPR. The legitimate interest lies in the secure and reliable operation of this website.

According to IONOS, visitor data is stored for eight weeks. IONOS states that this data is not disclosed to third parties or transferred to countries outside the European Union.

IONOS WebAnalytics

IONOS WebAnalytics is used as part of the hosting agreement. The service statistically evaluates technical access data to provide an overview of how the website is used and to support the technical optimisation of the website.

Data is collected through server log files or a tracking pixel. IONOS WebAnalytics does not use cookies. The IP address is technically transmitted when a page is accessed, immediately anonymised and subsequently processed without being linked to an identifiable individual.

The data processed may include the website or file accessed, the previously visited website, browser type and browser version, operating system, device type, time of access and the anonymised IP address used to determine an approximate access location.

The processing is carried out for statistical evaluation and technical optimisation of the website on the basis of Article 6(1)(f) GDPR. The legitimate interest lies in understanding and improving the use and technical performance of the website. No individual visitor profiles are created.

Further information about data processing by IONOS is available under Data Processing by IONOS WebAnalytics and in the IONOS Privacy Notice.

4. Contact by Email

If you contact me by email, the information you provide will be processed. This may include, in particular, your email address, the content of your message and any other information you provide voluntarily.

The data is processed in order to respond to your enquiry and any follow-up questions. If the enquiry relates to the initiation or performance of a contract, the legal basis is Article 6(1)(b) GDPR. For other enquiries, processing is based on Article 6(1)(f) GDPR. The legitimate interest lies in responding to communications addressed to me.

Business email communications are processed using the technical infrastructure provided by IONOS.

Your message will be deleted once it is no longer required to respond to your enquiry and any follow-up communication. Statutory retention obligations and the retention of information required for the establishment, exercise or defence of legal claims remain unaffected.

5. Contact Forms

This website provides general contact forms and forms for business-related enquiries. The forms are provided using the Fluent Forms plugin installed locally in WordPress.

Depending on the form used, the following data may be processed in particular:

  • name,
  • email address,
  • company or type of organisation,
  • website or domain,
  • subject and content of the message,
  • the source URL of the form, browser and device information, and the date and time of submission.

Required fields are marked accordingly in the respective form. An enquiry submitted through a form cannot be processed without a valid email address and a message. Any additional information is provided voluntarily unless a field is expressly marked as required.

The data is processed in order to respond to the respective enquiry. If an enquiry relates to potential cooperation or a contractual relationship, the legal basis is Article 6(1)(b) GDPR. General enquiries are processed on the basis of Article 6(1)(f) GDPR.

The submitted information is stored in the WordPress database and additionally sent to me by email. It is deleted once it is no longer required to respond to the enquiry and any follow-up communication. Statutory retention obligations and the retention of information required for the establishment, exercise or defence of legal claims remain unaffected.

Data submitted through contact forms is not used for newsletters or other general advertising activities without a separate legal basis.

6. Anonymous Website Statistics with Statify

This website uses the locally installed Statify statistics plugin to obtain a basic overview of the number of page views, frequently visited pages and referral sources.

Statify does not store IP addresses, use cookies, create visitor profiles or transmit statistical data to an external analytics provider. The statistical data is stored exclusively in the local WordPress database and is automatically deleted after 30 days.

7. Website Security and Protection Against Abusive Access

Technical security measures are used to protect the website and its administration area. This may involve the processing of failed login attempts, IP addresses, usernames used, timestamps and other security-related technical information.

The processing is carried out to detect and prevent brute-force attacks, automated access attempts, malware and other abusive activities. The legal basis is Article 6(1)(f) GDPR. The legitimate interest lies in protecting the website, the data stored on it and the technical infrastructure.

Security logs and blocking records are deleted or overwritten once they are no longer required for the detection, prevention or investigation of security-related incidents.

8. Cookies and Language Selection

This website does not use cookies for advertising or marketing purposes.

Polylang is used to provide the website in multiple languages. In this context, the pll_language cookie is set. It stores the language code of the most recently selected or visited language version so that the website can be displayed in the appropriate language during subsequent visits.

The cookie is used exclusively for language selection, does not contain information such as a name or email address, and is not used for advertising, profiling or person-specific audience measurement. Its default storage period is one year.

You can delete the cookie at any time through your browser settings. In this case, you may need to select your preferred language again during a subsequent visit.

9. Backups

As part of the hosting service, IONOS also creates automatic backup copies of the website files and databases. These backups are used to restore data following technical errors or data loss, are retained only for a limited period depending on the type of backup, and are subsequently overwritten or deleted.

Technical backups are also created regularly to secure and restore the website. The WordPress plugin UpdraftPlus is used for this purpose.

Backups may generally contain all data stored in WordPress. This may include website files, media files, plugin and system settings, user accounts, form submissions and technical log data.

The backup copies are stored in an access-protected Google Drive account. The service provider is:

Google Ireland Limited
Gordon House
Barrow Street
Dublin 4
Ireland

The processing is based on Article 6(1)(f) GDPR. The legitimate interest lies in securing the website, restoring it following technical errors or security incidents, and ensuring business continuity.

Backups are retained in accordance with the configured backup schedule and are subsequently overwritten or deleted automatically. Data deleted from the active system may therefore remain in a time-limited backup until the respective backup is overwritten as part of the regular cycle. Backups are used only to restore the website.

In connection with Google Drive, it cannot be completely ruled out that Google may process data outside the European Economic Area, particularly in the United States. Where personal data is transferred to Google LLC in the United States, the transfer is based on the European Commission’s adequacy decision regarding the EU-US Data Privacy Framework. Google LLC is certified under this framework. Further information is available in the Google Privacy Policy.

10. Recipients of Personal Data

Personal data is disclosed to recipients only where this is necessary for the purposes described in this Privacy Policy, where disclosure is required by law or where another legal basis permits the disclosure.

Possible recipients may include, in particular:

  • IONOS as the hosting and email service provider,
  • Google in connection with the storage of backup copies in Google Drive,
  • technical service providers where their assistance is required for maintenance or security,
  • authorities, courts or other public bodies where disclosure is required by law.

11. General Retention Period

Unless a more specific retention period is stated in this Privacy Policy, personal data is deleted once the purpose for which it was processed no longer applies and no statutory retention obligations or other legal grounds require continued storage.

Where statutory retention obligations apply, the processing of the relevant data is restricted for the applicable retention period or the data is processed only for the purpose required by law. The data is deleted once the retention period has expired.

12. Your Rights

Subject to the applicable legal requirements, you have the following rights in particular:

  • Right of access: You may request information about the personal data I process concerning you.
  • Right to rectification: You may request the correction of inaccurate data or the completion of incomplete data.
  • Right to erasure: You may request the deletion of your personal data where the applicable legal requirements are met.
  • Right to restriction of processing: You may request that the processing of your personal data be restricted where the applicable legal requirements are met.
  • Right to data portability: Where processing is based on consent or a contract and is carried out by automated means, you may receive the relevant personal data in a structured, commonly used and machine-readable format.
  • Withdrawal of consent: You may withdraw consent at any time with effect for the future, without affecting the lawfulness of processing carried out before the withdrawal.
  • Right to object: You may object, on grounds relating to your particular situation, to processing based on Article 6(1)(f) GDPR.

To exercise your rights, you may contact me at contact@oskarsrullis.com. To prevent unauthorised disclosure of personal data, suitable proof of identity may be required in individual cases.

Objection to Direct Marketing

Where personal data is processed for direct marketing purposes, you have the right to object to such processing at any time. Following an objection, the relevant personal data will no longer be used for direct marketing purposes.

13. Right to Lodge a Complaint with a Supervisory Authority

You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data infringes the GDPR. In particular, a complaint may be lodged with the supervisory authority in the Member State of your habitual residence, place of work or the place of the alleged infringement.

The supervisory authority responsible for the controller in Latvia is:

Datu valsts inspekcija
Elijas iela 17
Rīga, LV-1050
Latvia

Telephone: +371 67223131
Email: pasts@dvi.gov.lv
Website: www.dvi.gov.lv

14. Encrypted Data Transmission

This website uses an encrypted HTTPS connection. This helps protect data transmitted between your browser and the server against interception and reading by third parties.

Despite appropriate technical and organisational security measures, data transmitted over the internet cannot be completely protected against every possible risk in all circumstances.

15. Changes to This Privacy Policy

This Privacy Policy will be updated if the services used, the processing of personal data or the applicable legal requirements change. The current version of the Privacy Policy is available on this website.