Privacy Policy
This Privacy Policy explains how SIA DM grupa collects, uses, stores, and protects personal data of our customers, website visitors, and buyers of fiberglass products and services, as well as the rights available to data subjects under the General Data Protection Regulation (GDPR).
1. Data Controller and Contact Information
Controller: SIA DM grupa (Registration No. 42403043645)
Legal address: Mazā Stacijas iela 6-3, Riga, LV-1083, Latvia
Email: info@dmgrupa.lv
Phone: +371 26166380
Website: dmgrupa.lv
2. Scope of Application
This Privacy Policy applies to the processing of personal data of:
- Natural persons – buyers and clients purchasing goods (such as hot tub shells, cellars, accessories, fiberglass products) and ordering construction or custom manufacturing services from SIA DM grupa;
- Visitors and users of the online store and website dmgrupa.lv;
- Third parties communicating with or involved in order fulfillment (e.g. contact persons, authorized recipients, payers).
SIA DM grupa respects your privacy and processes personal data strictly in compliance with Regulation (EU) 2016/679 (GDPR) and other applicable privacy regulations.
3. Purposes of Personal Data Processing
We process your personal data for the following purposes:
For the sale of goods and provision of services:
- Customer identification and registration;
- Processing of orders, preparation and conclusion of distance sale agreements;
- Manufacturing, dispatch, logistics, and delivery of ordered products;
- Invoicing, payment processing, and accounting administration;
- Warranty commitments, after-sales service, and defect inspection;
- Customer support and communication regarding order status;
- Handling inquiries, reviews, requests, and claims.
For business operations, quality, and website maintenance:
- Maintaining website security, stability, and functionality;
- Customer satisfaction surveys and product improvement;
- Sales statistics and internal analytics;
- Protection of legal rights and prevention of fraudulent activities.
4. Legal Bases for Processing
SIA DM grupa processes personal data based on the following legal grounds under Article 6 of the GDPR:
- Performance of a contract (Art. 6(1)(b)): to conclude and execute the product purchase agreement, deliver goods, and handle payments upon your request;
- Legal obligation (Art. 6(1)(c)): to fulfill mandatory accounting, tax, commercial, and consumer protection laws;
- Consent (Art. 6(1)(a)): where you have explicitly given consent (e.g., newsletter subscriptions or optional cookies);
- Legitimate interests (Art. 6(1)(f)): to conduct commercial operations, ensure IT security, protect company assets, and defend legal claims.
5. Data Protection and Security
We implement modern organizational, physical, and technical security measures to protect your personal data from unauthorized access, accidental loss, alteration, or disclosure, including:
- Encrypted data transmission (SSL/TLS certificates);
- Firewalls and intrusion detection systems;
- Strict role-based access control to administrative systems.
6. Personal Data Retention Periods
Personal data is retained only as long as necessary for the purpose it was collected, or to comply with statutory retention requirements:
- Accounting documents and invoices: retained for at least 5 years in accordance with tax and accounting legislation;
- Contract and warranty records: retained during the validity of the contract and for the statutory limitation period (up to 10 years) for resolving disputes or claims;
- Consent-based data (e.g. newsletter): processed until you withdraw your consent;
- Customer inquiries: retained until the inquiry is resolved and for a reasonable period thereafter (up to 2 years).
7. Recipients of Personal Data and Transfers
To ensure high-quality product delivery and store functionality, data may be disclosed to trusted service providers who act as data processors:
- Courier, transportation, and logistics providers for product delivery;
- Licensed payment institutions and banks for transaction settlement;
- IT hosting, cloud infrastructure, and technical maintenance partners;
- Accounting and legal service providers;
- State institutions, tax authorities, or law enforcement when mandated by legal acts.
Personal data is processed within the European Union / European Economic Area (EU/EEA) and is not transferred to third countries without adequate protection safeguards.
8. Rights of the Data Subject
Under the GDPR, you have the right to:
- Access: access your personal data and receive information about its processing;
- Rectification: rectify inaccurate or incomplete personal data;
- Erasure: erase your personal data ("right to be forgotten"), subject to statutory retention obligations;
- Restriction of processing: restrict processing under certain statutory conditions;
- Data portability: receive your data in a structured, commonly used format;
- Object: object to data processing based on legitimate interests;
- Withdraw consent: withdraw consent at any time without affecting the lawfulness of prior processing;
- Lodge a complaint: lodge a complaint with the supervisory authority (Data State Inspectorate / Datu valsts inspekcija, www.dvi.gov.lv or the data protection authority of your EU member state).
To exercise your rights, please submit a written request to: info@dmgrupa.lv.
Appendix: Categories of Processed Personal Data
For additional questions about personal data protection or our cookie policy, please check our Cookie Policy or contact us at info@dmgrupa.lv.