Privacy

This policy covers the FSS website and enquiries to SIA FLEXLAB. Processing in client projects depends on the task and separately agreed terms.

No advertising tracking

This version has no analytics, advertising pixels or session recording.

A clear purpose

Enquiry details are used to respond and discuss your task.

Direct contact

Privacy questions and outreach objections can be sent by email.

Who is responsible

The website operator and controller of enquiry data is SIA FLEXLAB, registration 40203617609, VAT LV40203617609, Katlakalna iela 9A, Rīga, LV-1073, Latvia.

Privacy contact: vladimir@fevralov.com, +371 2300 14 38. This is the company’s privacy contact, not a statement that a separate DPO has been appointed.

Data and purposes

When you browse, the server receives your IP address, request time and address, and technical browser information. This supports page delivery, diagnostics and protection against misuse. Basis: legitimate interests in reliable website operation, GDPR Article 6(1)(f).

When you email us, we receive your address, message and details you choose to share, such as your name, company and task. We use them to reply and prepare a proposal: Article 6(1)(b) where you are a prospective contracting party, or 6(1)(f) for communication with a company representative. Browsing does not require an enquiry.

Contract and accounting records support performance of a contract and applicable legal duties under Articles 6(1)(b) and 6(1)(c). Submitting an enquiry is not marketing consent.

Recipients and transfers

Access may be needed by people handling your enquiry, hosting, security and business email providers, and professional advisers or authorities where there is a legal basis.

The website is hosted through OpenAI Sites and the Cloudflare network. Domain email is served by Inbox.eu. The website has no separate enquiry database: emails arrive in the business mailbox. The website does not use a message submission form.

Storage locations and access from outside the EEA depend on the provider. Before connection, adequacy decisions or contractual safeguards, including EU standard contractual clauses and transfer assessments where needed, must be checked. Contact us for information about applicable recipients and safeguards.

Retention criteria

Enquiry correspondence is needed until the discussion and agreed follow-up are complete. If no project follows, data should not remain without a specific business or legal purpose. Retention is reviewed when the enquiry is closed.

Project terms define project retention. Working copies, the client’s report, mandatory accounting records and marketing objections serve different purposes and require different deletion rules. Outreach closure is described separately.

Technical logs and backups are handled under the relevant providers’ arrangements. You can email us for information about the retention of a specific enquiry or to request erasure. We do not claim automatic deletion of every copy.

Your rights

You may request access and a copy, correction, erasure or restriction. Portability applies to data you supplied that is processed automatically on the basis of consent or contract.

You may object to legitimate-interest processing. An objection to direct marketing ends processing for that purpose. Where consent applies, you may withdraw it without affecting the lawfulness of earlier processing.

Email your request to vladimir@fevralov.com. We respond without undue delay, normally within one month. If complexity requires up to two additional months, you will be told why within the first month. Extra identity evidence is requested only where there are reasonable doubts.

Complaints

You may complain to Latvia’s Datu valsts inspekcija (DVI) or the competent authority where you live, work or believe an infringement occurred. You do not have to contact us first.

Datu valsts inspekcija

AI and automated decisions

The website has no AI chat. Its code does not send visitor enquiries to AI models or make decisions with legal or similarly significant effects.

AI in a client project is assessed separately: allowed data, access, providers and verification of answers. AI processing does not itself anonymise data.

Changes

This policy must be updated before new analytics, collection methods or providers begin processing. Where consent is required, the new feature is enabled only after consent.

Version dated 15 September 2026