Privacy Policy
Last updated: July 15, 2026
1. Data Controller
SIA HA Group Registration number: 40203724866 VAT payer: LV40203724866 Email: info@hagroup.lv Registered office: Valdeķu iela 1, Rīga, LV-1058, Latvia SIA HA Group is the controller of personal data processed through this website.
2. Scope and Sources
This policy applies to personal data processed through hagroup.lv. We receive data directly from you when you submit a form or communicate with us, and limited technical data when your browser connects to and uses the website. If you provide another person's data, you must be entitled to do so and should make this policy available to that person.
3. Data We Process
Project and contact inquiries: full name, company (optional), work email, selected project budget (optional), project details, privacy-policy acknowledgement, browser language, page URL, submission time, and form-mode indicators. Career applications: full name, email, phone (optional), LinkedIn or portfolio URL (optional), position (optional), cover letter (optional), privacy-policy acknowledgement, browser language, page URL, and submission time. Storage-notice acknowledgements: a necessary-storage choice, notice version, interface language, server creation and expiry times, and a random Firestore document ID saved locally as a receipt. We do not attach a name, email address, user agent, page URL, or persistent visitor identifier to this record. Technical data: website hosting and security providers may process IP address, browser/device information, request time, requested page, and similar connection-log data. Your browser also stores the necessary preference and form-protection values listed in our Cookie Policy.
4. Purposes and Legal Bases
We process data for the following purposes under Article 6 GDPR: • To answer project inquiries, prepare proposals, and take steps requested before a possible contract — Article 6(1)(b), or our legitimate interest in managing business communications where that basis does not apply — Article 6(1)(f). • To assess applications and manage recruitment — steps before a possible employment relationship under Article 6(1)(b) and our legitimate interest in selecting candidates and defending legal claims under Article 6(1)(f). • To deliver and secure the website, prevent rapid repeat submissions, diagnose faults, and maintain service integrity — our legitimate interests under Article 6(1)(f). • To keep a limited record that the necessary-storage notice was acknowledged, so we can demonstrate transparent notice delivery without tracking visitors — our legitimate interest under Article 6(1)(f). This acknowledgement is not consent under Article 6(1)(a). • To keep records or disclose information where required by law — Article 6(1)(c), and to establish, exercise, or defend legal claims — Article 6(1)(f). The privacy checkbox confirms that you have read this policy. We do not treat it as blanket consent. If we ask for consent for a separate optional purpose, Article 6(1)(a) applies and you may withdraw that consent at any time without affecting earlier lawful processing.
5. Required and Optional Information
Fields marked as required are needed to identify your request, reply to you, and understand the matter. If you do not provide them, we cannot process the form. Other fields are optional. Please do not submit special-category data (for example, health, biometric, political, religious, or trade-union information) or other information that is not necessary for your inquiry or application.
6. Recipients and Service Providers
Access is limited to authorised HA Group personnel who need the data for the relevant purpose. We use the following processors on our behalf, under contractual and security obligations: • Google Firebase / Cloud Firestore — receives and stores form submissions and storage-notice acknowledgements. • Google Cloud Functions (europe-north1) — runs the code that turns a submission into a notification message. • Google Cloud Secret Manager — holds the credentials that code uses. • Gmail (Google) — delivers each submission to our own mailbox as an email. Your message and contact details travel through Google's mail infrastructure. • Amazon Web Services (S3 and CloudFront) — hosts and delivers the website. • Google Fonts and the Iconify CDN — serve the fonts and icons this page uses. Your browser requests these files directly, so your IP address and browser details reach those services when a page loads. Data may also be disclosed to professional advisers, courts, regulators, law-enforcement bodies or other authorities where necessary and lawful. We do not sell personal data or share it with advertisers.
7. International Transfers
Some service providers may process data outside Latvia or the European Economic Area. Where personal data is transferred to a country without an applicable European Commission adequacy decision, we rely on safeguards permitted by Chapter V GDPR, such as the European Commission's Standard Contractual Clauses, together with supplementary measures where required. You may contact us for information about the relevant safeguards.
8. Retention
We keep personal data only for as long as needed for the stated purpose: • Project and contact inquiries: normally up to 24 months after the last substantive communication. • Career applications: normally up to 12 months after submission. Longer talent-pool retention requires a separate legal basis, such as your specific consent. • Storage-notice acknowledgement records: up to 12 months, after which the Firestore TTL expiry field makes them eligible for automatic deletion. • Hosting and security logs, if generated: for the period reasonably necessary for security, troubleshooting, and provider operations. • Browser-stored values: for the periods described in our Cookie Policy. Data may be kept longer where required by law or reasonably necessary to establish, exercise, or defend legal claims. It is then deleted or anonymized when the applicable period ends.
9. Security
We apply appropriate technical and organisational measures designed to protect personal data, including access controls, encrypted connections, service-provider security controls, and limiting access by purpose. No internet transmission or storage system can be guaranteed completely secure.
10. Your GDPR Rights
Subject to the conditions and exceptions in the GDPR, you may request access to and a copy of your data, correction, deletion, restriction of processing, and data portability. You may object to processing based on legitimate interests, including by explaining your particular situation. Where processing is based on consent, you may withdraw it at any time without affecting processing carried out before withdrawal. You also have the right to lodge a complaint with a supervisory authority.
11. Exercising Rights and Complaints
Send requests to info@hagroup.lv. We may ask for information reasonably necessary to verify your identity. We will respond without undue delay and normally within one month; the GDPR permits an extension of up to two further months for complex or numerous requests, in which case we will inform you. In Latvia, the supervisory authority is Datu valsts inspekcija, Elijas iela 17, Riga, LV-1050, Latvia; email pasts@dvi.gov.lv; website www.dvi.gov.lv. You may also complain to the supervisory authority in the EU/EEA country where you live, work, or believe an infringement occurred.
12. Automated Decisions and Children
We do not use website data for solely automated decisions that produce legal or similarly significant effects, and we do not carry out advertising profiling. The website and its forms are intended for business contacts and job applicants, not for children.
13. Policy Changes
We may update this policy to reflect changes in our processing or legal obligations. The current version and its effective date will be published on this page. Where a change materially affects how we use existing data, we will provide additional notice or obtain consent if required by law.
