DATA PROTECTION
Privacy Policy
A clear account of the data we collect, why we need it, how long we keep it and the choices available to you.
Controller and contact
The controller is Antons Vasiljevs, trading under the eWriti name in Latvia (“eWriti”, “we”, “us”). Privacy requests may be submitted through the contact form on the eWriti homepage. We may ask for proportionate information to verify the requester’s identity before disclosing or deleting personal data.
The site is in a pre-launch phase and does not yet conclude sales. Full statutory trader contact details will be displayed before a binding checkout is made available.
Data we collect
- Purchase-interest data: name, email, optional phone number, desired quantity, language and message.
- Contact data: name, email, subject and the content of your message.
- Technical and security data: IP-derived pseudonymous fingerprint, browser type, page URL, timestamps, request timing and error details.
- If checkout is enabled later, order, delivery and payment-status data. Card details are entered directly with Stripe and are not stored by eWriti.
Please do not include sensitive personal data or card details in free text fields.
Purposes and legal bases
- To answer a request and take steps requested before a possible contract — GDPR Article 6(1)(b).
- To perform and administer an accepted order and provide support — Article 6(1)(b).
- To comply with tax, accounting, consumer-protection and legal obligations — Article 6(1)(c).
- To secure, debug and improve the service, prevent abuse and defend legal claims — our legitimate interests under Article 6(1)(f).
- Marketing email, if introduced, will require a separate opt-in and may be withdrawn at any time.
Recipients and international transfers
Data is disclosed only when necessary to service providers acting under appropriate terms: OpenAI/ChatGPT Sites for hosting, Cloudflare for edge delivery and storage, and Stripe for checkout and payment processing when enabled. Delivery providers receive the minimum data needed to deliver an accepted order.
Some providers may process data outside the EEA. Where required, we rely on an adequacy decision or appropriate safeguards such as the European Commission’s Standard Contractual Clauses. We do not sell personal data.
Retention
- Purchase-interest requests: normally up to 24 months.
- General contact messages: normally up to 12 months.
- Technical and error logs: normally up to 90 days.
- Order and accounting records: for the period required by applicable Latvian tax and accounting law.
- Data needed for disputes or security investigations may be retained until the matter and relevant limitation period end.
Records may be deleted or anonymised earlier when they are no longer needed.
Cookies and local storage
The public site uses browser storage only to remember language and temporary order-form preferences. The protected admin area uses a strictly necessary, secure, HttpOnly session cookie. No advertising or cross-site tracking cookies are intentionally used.
Your rights
Depending on the circumstances, you may request access, correction, erasure, restriction, portability, or object to processing based on legitimate interests. You may withdraw consent without affecting earlier lawful processing. We normally respond within one month.
You may complain to Latvia’s Data State Inspectorate (Datu valsts inspekcija) or the supervisory authority in your habitual EU residence. These rights are subject to lawful exceptions.
Security and changes
We use encrypted transport, access controls, rate limiting, isolated storage, input limits, server-side authorisation and security logging. No online system can be guaranteed absolutely secure. Material policy changes will be dated here; changes do not retrospectively reduce rights already acquired.