Privacy Policy
How PixelForge Technologies SIA handles personal data — what we collect, why, how long we keep it, and what you can require us to do about it.
Version 1.0 · In force from 14 August 2026 · Last reviewed 14 August 2026
The short version. We only collect what we need to answer your message and do the work you hire us for. We do not sell data, we do not run advertising trackers, and analytics cookies are loaded only if you accept them. You can ask us at any time what we hold about you and require us to delete it.
01Who we are
This website is operated by PixelForge Technologies SIA, a private limited company registered in the Republic of Latvia. For the purposes of the General Data Protection Regulation (Regulation (EU) 2016/679, the "GDPR"), we are the data controller for the personal data described in this policy.
| Controller | PixelForge Technologies SIA |
|---|---|
| Registration number | 40203770583 |
| Registered address | Tautas iela 85 - 11, Daugavpils, LV-5417, Latvia |
| order@pixelforge-tech.com | |
| Phone | +36 20 464 3315 |
We are not required to appoint a Data Protection Officer. Data protection questions are handled directly by the company's management at the email address above.
02What this policy covers
This policy applies to personal data we process when you:
- visit this website;
- send us an enquiry through the contact form, by email, by phone or through WhatsApp;
- enter into or perform a contract with us for development services;
- receive an invoice from us or send us one.
It does not cover websites we have built for our clients. Those sites are operated by the client, who is the controller for the data collected there and publishes its own privacy notice. Where we maintain such a site on the client's behalf, we act as a processor under a separate written agreement — see section 11.
03Personal data we collect
3.1 Data you give us
When you contact us, you choose what to tell us. Typically that is:
- your name;
- your email address;
- your phone number, if you provide one;
- your company name, if you provide one;
- the content of your message, including anything you decide to write about your project, budget or deadlines.
The enquiry form on this site does not transmit anything to us or to a third party by itself. It assembles the text and opens your own email programme, from which you send the message. Nothing reaches us until you press Send there.
3.2 Data we collect automatically
Our web server, like any web server, records technical information in its access logs when a page is requested: the IP address, the date and time, the address of the requested page, the referring page, and the browser and operating system identification string. These logs exist so we can keep the site running, investigate errors and detect abuse.
If — and only if — you accept analytics cookies, we also receive aggregated statistics about how the site is used. See section 5 and the Cookies Policy.
3.3 Data arising from a contract
If you become a client, we additionally process the contact details of the people we work with at your organisation, your company's billing and registration details, correspondence about the project, and the records required for accounting.
3.4 What we do not collect
We do not knowingly collect special categories of personal data (health, biometric, political, religious or similar), we do not build advertising profiles, and we do not buy contact lists.
04Why we use your data, and on what legal basis
| Answering your enquiry | To reply, prepare an estimate and discuss your project. Legal basis: steps taken at your request prior to entering a contract (Art. 6(1)(b)), or our legitimate interest in responding to business correspondence (Art. 6(1)(f)). |
|---|---|
| Performing a contract | To deliver the services you have ordered, communicate about the work, provide support and hand over the result. Legal basis: performance of a contract (Art. 6(1)(b)). |
| Invoicing & accounting | To issue invoices and keep the records Latvian law requires. Legal basis: compliance with a legal obligation (Art. 6(1)(c)). |
| Security & error logging | To keep the site available, investigate faults and prevent abuse. Legal basis: our legitimate interest in operating a secure service (Art. 6(1)(f)). |
| Analytics | To understand which pages are useful and improve them. Legal basis: your consent (Art. 6(1)(a)), which you may withdraw at any time. |
| Legal claims | To establish, exercise or defend legal claims if a dispute arises. Legal basis: our legitimate interest (Art. 6(1)(f)). |
We do not send marketing emails and we do not operate a newsletter. If that ever changes, it will be on the basis of consent that you give separately and can withdraw with one click.
05Cookies and analytics
This site sets a small number of strictly necessary items in your browser's local storage — your cookie choice and your motion preference — so that the site behaves the way you asked it to. These are required for the site to function as you have configured it and are not used to track you.
Analytics are loaded only after you press "Accept all" in the cookie notice. If you press "Essential only", or simply ignore the notice, no analytics scripts run at all.
The full list, with retention periods and instructions for changing your mind, is in the Cookies Policy.
06Who we share data with
We do not sell personal data and we do not disclose it for anyone else's marketing. We share it only in these situations:
- Hosting and infrastructure providers — the companies that run the servers on which this site and our email operate. They process data strictly on our instructions.
- Our accountant — for invoices and statutory bookkeeping.
- Analytics provider — only if you have consented to analytics cookies.
- Professional advisers — lawyers or auditors, where genuinely necessary and under a duty of confidence.
- Public authorities — where we are legally required to disclose information, for example to the State Revenue Service or a court.
Every processor we use is bound by a written agreement meeting the requirements of Article 28 of the GDPR.
07Transfers outside the EEA
We prefer providers based in the European Economic Area, and our hosting and email are located within the EU. Where a service we rely on transfers data outside the EEA — for example an analytics provider — the transfer takes place under an adequacy decision of the European Commission or under Standard Contractual Clauses together with supplementary safeguards. You can ask us which providers are currently in use and on what basis.
08How long we keep data
| Enquiries that do not lead to a contract | Up to 12 months, then deleted |
|---|---|
| Project correspondence | Duration of the contract plus 2 years |
| Contracts & accounting records | 5 years from the end of the financial year, as required by Latvian accounting law; contracts may be kept for the length of the applicable limitation period |
| Server access logs | Normally 30 days, longer only where a specific security incident is under investigation |
| Analytics data | Up to 14 months, in aggregated form |
| Consent records (cookie choice) | Up to 12 months, stored in your own browser |
When a retention period ends, data is deleted or irreversibly anonymised.
09How we protect data
- All traffic to this site is encrypted with TLS (HTTPS).
- Access to systems containing personal data is limited to the people who need it, protected by strong unique credentials and two-factor authentication where the service supports it.
- Backups are encrypted and stored separately from live systems.
- Software and dependencies are kept up to date and security advisories are monitored.
- Client project data is kept separated per client, never mixed into shared environments.
No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Data State Inspectorate within 72 hours and inform you directly where the law requires it.
10Your rights
Under the GDPR you have the right to:
- Access — obtain confirmation of whether we process your data, and a copy of it.
- Rectification — have inaccurate or incomplete data corrected.
- Erasure — have your data deleted where there is no longer a lawful reason to keep it.
- Restriction — require us to pause processing while a dispute about accuracy or legitimacy is resolved.
- Portability — receive data you provided to us in a structured, machine-readable format.
- Objection — object to processing based on our legitimate interests, on grounds relating to your particular situation.
- Withdraw consent — at any time, where processing is based on consent. Withdrawal does not affect the lawfulness of processing carried out beforehand.
To exercise any of these, write to order@pixelforge-tech.com. We respond within one month. If a request is unusually complex we may extend that by two further months and will tell you why within the first month. There is no charge, unless a request is manifestly unfounded or excessive.
We may need to verify your identity before acting on a request — this protects you from someone else obtaining your data.
11Personal data inside client projects
When we build or maintain a system that processes personal data belonging to our client's own customers, our client is the controller and we act as a processor. In those engagements:
- we sign a data processing agreement before any access is granted;
- we process data only on the client's documented instructions;
- we use real personal data in testing only where unavoidable, and prefer anonymised or synthetic data;
- we return or delete the data at the end of the engagement, at the client's choice;
- we notify the client without undue delay if we become aware of a breach affecting their data.
If you are a customer of one of our clients and want to exercise your rights, contact that company directly — they hold the relationship and the legal responsibility. We will assist them in responding.
12Children
Our services are directed at businesses and we do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
13Changes to this policy
We may update this policy when our services, our providers or the law change. The version number and date at the top of the page always show the current edition. Where a change materially affects how we use data about you, and we have your contact details, we will tell you directly rather than relying on you noticing the update.
14Contact and complaints
For any question about this policy or about how we handle your data:
PixelForge Technologies SIA
Tautas iela 85 - 11, Daugavpils, LV-5417, Latvia
order@pixelforge-tech.com · +36 20 464 3315
We would always rather hear from you first. If you are not satisfied with our response, you have the right to lodge a complaint with the Latvian supervisory authority:
Datu valsts inspekcija (Data State Inspectorate)
Elijas iela 17, Rīga, LV-1050, Latvia
www.dvi.gov.lv
If you live in another EU or EEA country, you may instead complain to the supervisory authority where you live or work.
Related documents
This policy sits alongside two other documents that govern your use of this site and our services.