Privacy · GDPR
What I collect, why, and how long I keep it
Briefly: thirteen brief fields, email correspondence and server logs. Nothing else — no cookie-based counters, no embedded video, no third-party fonts loaded from outside. Which is also why there is no cookie banner here.
This page is a prototype, not a signed legal text. The Latvian version is the binding one: the state language law requires consumer information in Latvian and does not allow the Latvian text to be shorter or narrower than any other. So the Latvian version is written rather than translated from the Russian, and a lawyer reads it before launch.
One person is responsible for the data
The controller is me. Not a department, not a «team», and not a legal entity with a shared inbox: the letters are read and the data is processed by the same person who builds the site.
I have no data protection officer and the law does not require one: the conditions of GDPR Article 37 are not met. Write about any data question to the same address as everything else.
Data controller
- Seller
- Vitālijs Pankovs
- studio@pankovs.com
The same details stand in the footer of every page and on the contact page. The registration number and registered address are not among them yet: the form of business is not chosen, and I am not going to invent them.
Five lines, and there is nothing else on the site
The list is short not because I left something out, but because there is no reason to collect more. Every line came from a specific task; a line without a task is not here.
What I collect, why, and on what basis. The basis is GDPR Article 6(1): (b) performance of a contract and steps before it at your request, (c) a legal obligation, (f) legitimate interest.
Scrolls sideways
| What | Why | Basis |
|---|---|---|
| Thirteen brief fields | To answer with an estimate and a date | 6(1)(b) |
| Email correspondence | To keep what was agreed | 6(1)(b) |
| Project data | To build and run the site | 6(1)(b) |
| Invoices and documents | To account to the state | 6(1)(c) |
| Server logs | To see failures and intrusions | 6(1)(f) |
The thirteen brief fields are: name, email, what you need, the deadline, care after launch, two questions about being found on Google, budget, a link to your current site, the domain and mailbox questions, a description of the project, and the consent tick. They have no other use: I answer the enquiry, and that is all. Project data means the domain, access credentials and contacts. The server log records the request address, the time and the response code.
Anonymised visit statistics — which pages are read and which sites people arrive from — are collected by a counter without cookies and without identifiers that could recognise you. It has no row in the table for a simple reason: it contains no personal data either.
Three periods are named exactly, one is not, and I say so
When a client leaves, I keep copies of their site and data for six months and then delete them. Six months is a buffer in case something does not come up at the new contractor. The same promise stands on the care page, and it is not in small print there.
I am required to keep accounting documents for as long as the Latvian accounting law says. The exact number of years is not confirmed in my sources, and I will not name it at random — it will appear here together with the Latvian version.
A brief that never became a project, and the correspondence around it, I keep for twelve months and then delete. The year is a buffer in case you come back saying «we are ready now» — so you do not have to tell the whole story again. Correspondence on a delivered project is kept for three years after delivery: it is the history of what we agreed — what the estimate included and what you approved at the gates — and it protects both sides while the claim and limitation periods run.
Who else sees the data, and in what role
Three roles without which the site does not work. Each processes data on my instructions and within the scope of its task, not «just in case».
Scrolls sideways
| Role | What it does | What it sees |
|---|---|---|
| Hosting | Holds the site, backups and logs | Everything stored on the server |
| Delivers and stores correspondence | Letters and addresses | |
| Stripe | Processes payment | Payment data |
Hosting sees the server contents technically, not by purpose: it is administrator access, not reading your correspondence. Stripe takes payment for the project and the care subscription — the card number never reaches me and is not stored on my server.
The roles are named, the specific vendors are not, and that is the more honest way round: a vendor can change, the role stays. I will finish the full list with names and countries before launch, together with the answer to whether data leaves the EEA and on what basis. Until there is an answer, I will not write here that everything stays in Europe.
Your rights and how to use them
There is no form for this. Write to studio@pankovs.com — in your own words, without citing articles.
Separately from data rights, there is the complaint procedure for the service: the reply period there is fifteen working days, and it is described on the contact page.
- Access
- Get a copy of what I hold about you
- Rectification
- Correct what is wrong or complete what is missing
- Erasure
- Delete it — except what I am required by law to keep
- Restriction
- Bar the use of the data until a dispute is settled
- Objection
- Object to processing based on legitimate interest
- Portability
- Take the data in a machine-readable form
- Withdrawing consent
- Where consent was the basis — withdraw it at any time
- Complaint
- Turn to the supervisory authority without asking me
In Latvia, compliance with personal data rules is supervised by Datu valsts inspekcija — the State Data Inspectorate. It is the body that takes complaints about those who process data and inspects them: dvi.gov.lv. You can approach it directly, and you do not need to tell me.
I would rather you wrote to me first: almost everything people write to the inspectorate about is settled with one email. But that is a preference, not a condition.
The data processing agreement is provided on request
When I hold your site, your visitors' data passes through it: enquiries, orders, messages from forms. That data is yours, not mine. In law you are the controller in this pairing and I am the processor, and there must be a written processing agreement between us — listing the data, the periods, the security requirements, the rules for engaging sub-processors, and the return or deletion of data at the end.
Publishing it as a page makes no sense: it is signed for a specific project. So — on request, by email, and without explaining why you need it. What care includes and what belongs to whom is written on the care page.
Ask about your data
A question about this page is the same kind of email as a question about price, and the same person answers it. If you need your copy of the data or its deletion, one line is enough.
The right of withdrawal has its own page.