SMAIDA
Services Salary calculator Pricing About Contact
LV / EN
Apply

Privacy Policy

Effective from: 5 August 2026

This privacy policy explains what personal data SMAIDA collects, why it is collected, how long it is kept, and what rights you have.

Data protection matters to me. I work with companies' financial data, and confidentiality is the foundation of this work.


1. Data controller

The controller responsible for processing your personal data is:

SMAIDA Solutions, SIA
Registration number: 40203760180
VAT number: LV40203760180
Registered address: Kurpnieku iela 11, Mārupe, Mārupes nov., LV-2167, Latvia
Email: info@smaida.eu
Phone: +371 26 306 284

If you have questions about how your data is processed, write to info@smaida.eu. I will answer personally.


2. What data I process and why

2.1. Service enquiry form on the website

Data: email address; if you choose to provide them — name, company name, phone number, message content.

Purpose: to respond to your enquiry, prepare a proposal and communicate about the service.

Legal basis: GDPR Article 6(1)(b) — steps taken at your request prior to entering into a contract.

Retention: up to 12 months after the last contact if no engagement follows. If an engagement begins — see section 2.4.

The website enquiry form collects your email address. It is stored in my email and contact tool (Brevo), and you receive an automated confirmation email. If you later share further details (name, company, phone, message) by email, those are processed as described in section 2.3.

2.2. Booking an introductory call

Data: name, email address, chosen time slot and any information you provide about your company.

Purpose: to schedule and hold the introductory call.

Legal basis: GDPR Article 6(1)(b) — pre-contractual steps.

Retention: up to 12 months after the call if no engagement follows.

Bookings are handled through Google Calendar's appointment scheduling. Google acts as a data processor in this process.

2.3. Communication by email and phone

Data: contact details and the content of correspondence.

Purpose: to answer your question and maintain a record of communication.

Legal basis: GDPR Article 6(1)(f) — my legitimate interest in responding to enquiries and documenting communication.

Retention: up to 24 months, where the correspondence does not relate to a contract or accounting records.

2.4. Providing accounting services to clients

Once an engagement begins, a broader set of data is processed.

Client contact person data (name, position, email, phone) — processed by me as a controller, in order to perform the contract.
Legal basis: GDPR Article 6(1)(b) and (f).

Client employee and business partner data (payroll data, personal identity numbers, bank accounts, data contained in supporting documents) — processed by me as a processor on the client's instructions. The client is the controller of this data, and the processing is governed by a contract between us meeting the requirements of GDPR Article 28.
Legal basis: GDPR Article 28; processing takes place only on the client's documented instructions.

Retention follows Section 28 of the Latvian Accounting Law:

  • supporting documents — no less than 5 years;
  • accounting registers, inventory lists and accounting organisation documents — 10 years;
  • payroll documents — 10 years (75 years for documents dated before 1 January 1999);
  • annual reports — until the reorganisation or termination of the company.

These periods are set by law, and during them I cannot delete the data even on request.

2.5. Technical data and website operation

Data: IP address, browser and device type, pages visited, time of visit.

Purpose: to keep the website running, secure, and protected from misuse.

Legal basis: GDPR Article 6(1)(f) — legitimate interest in the secure operation of the website.

Retention: server logs — up to 12 months.


3. Cookies

The website uses two types of cookies:

Technically necessary cookies — required for the website's basic operation and security. These do not require consent.

Analytics cookies (Google Analytics). The website uses Google Analytics to understand how visitors use the site (pages viewed, approximate location, device and browser type) so I can improve it. Google Analytics sets cookies (for example _ga and _ga_<id>) and processes data including your IP address; Google acts as a data processor. These cookies are not loaded until you give consent.

Your choice. On your first visit, a cookie banner lets you accept or decline analytics cookies — Google Analytics loads only if you accept. You can change or withdraw your choice at any time via the Cookie settings link in the footer, or by clearing cookies in your browser. Declining does not affect how the website works.

Legal basis for analytics cookies: your consent (GDPR Article 6(1)(a)).


4. Who receives the data

I do not sell personal data or share it with third parties for marketing purposes.

The following categories of recipients may have access to data:

RecipientPurpose
Vercel Inc. (website hosting)Website operation, security and server logs
Brevo (Sendinblue SAS)Sending the confirmation email and managing contacts submitted via the website enquiry form
Google (Analytics, Fonts, Calendar)Website analytics (only with consent), web fonts, and appointment scheduling
Accounting and document processing software providersService delivery
State Revenue Service, Register of Enterprises and other authoritiesCompliance with statutory obligations
Auditors, legal advisersWhere necessary, subject to confidentiality

Contracts meeting the requirements of GDPR Article 28 are in place with all service providers that process personal data on my behalf.


5. Transfers outside the European Union

Some service providers used (for example, Google) may process data outside the European Economic Area.

Where this happens, transfers are based on:

  • a European Commission adequacy decision (including the EU–US Data Privacy Framework), or
  • Standard Contractual Clauses approved by the European Commission.

Where possible, I choose providers that store data on servers within the European Union.


6. Use of artificial intelligence

SMAIDA uses automation and artificial intelligence for routine work — for example, extracting data from documents and classifying transactions.

Two things I want to state clearly:

No automated decision-making. I do not carry out automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you (GDPR Article 22). Every decision is reviewed and approved by a human, who is also accountable for it.

Client data is not used to train AI models. When using AI tools, I select solutions and settings that prevent submitted data from being used to train the provider's models.


7. Data security

I apply appropriate technical and organisational measures to protect personal data, including:

  • encrypted data transmission (HTTPS);
  • access limited to those who need it to perform their work;
  • multi-factor authentication on the systems used;
  • regular backups;
  • selection of service providers based on an assessment of their security standards.

In the event of a personal data breach likely to result in a risk to your rights and freedoms, I will notify the Data State Inspectorate within 72 hours and, where the risk is high, notify you as well.


8. Your rights

In relation to your personal data, you have the right to:

  • Access your data — find out what data I process about you (GDPR Article 15).
  • Rectification — correct inaccurate or incomplete data (Article 16).
  • Erasure — the "right to be forgotten", where there is no longer a basis for processing (Article 17).
  • Restriction of processing — in certain circumstances (Article 18).
  • Data portability — receive your data in a structured format (Article 20).
  • Object to processing — where processing is based on legitimate interests (Article 21).
  • Withdraw consent — at any time, where processing is based on consent. Withdrawal does not affect the lawfulness of processing carried out beforehand.

How to exercise your rights: write to info@smaida.eu. I will respond within one month. If the request is complex, this period may be extended by a further two months, and I will inform you if that happens.

Please note: some rights are limited where retention is required by law. For example, accounting supporting documents cannot be deleted before the end of the period set by the Accounting Law.


9. Lodging a complaint

If you believe your personal data is being processed unlawfully, please contact me first — most questions can be resolved quickly.

You also have the right to lodge a complaint with the supervisory authority:

Data State Inspectorate (Datu valsts inspekcija)
Address: Elijas iela 17, Riga, LV-1050, Latvia
Phone: +371 67223131
Email: pasts@dvi.gov.lv
Website: www.dvi.gov.lv


10. Changes to this policy

This policy may be updated if services, systems used, or regulatory requirements change.

The current version is always available on this page. The date at the top shows when it was last updated. Existing clients will be informed of any material changes.


Questions about this policy? Write to info@smaida.eu — I will answer personally.

SMAIDA Solutions, SIA Accounting outsourcing Salary calculator Privacy Policy Cookie settings © 2026 · Smart AI Accounting