Zinkmans / Privacy Policy

Privacy Policy

Last updated: 22 July 2026

This notice explains how SIA "Zinkmans" processes personal data when you visit zinkmans.com or contact us. It is written for the services currently detected on this website and should be reviewed if the technical setup changes.

1. Data controller

The controller responsible for the personal-data processing described in this notice is:

SIA "Zinkmans"

Registration No.
40203544470
Country of registration
Latvia
VAT status
Not registered for VAT

2. Personal data we collect

When you use the contact form, we receive the information you choose to provide and limited technical data needed to operate and protect the form:

  • Name and email address
  • Company or project name, if provided
  • Selected service and indicative budget, if provided
  • Message content
  • IP address used for short-term rate limiting
  • Basic request and server-log data recorded by the hosting environment

3. Purposes and legal bases

We use enquiry data to respond, prepare a proposal and take steps you request before a possible contract (GDPR Article 6(1)(b)). We use limited technical data to prevent abuse and maintain the website based on our legitimate interests in service security and availability (Article 6(1)(f)). If the law requires us to retain information, Article 6(1)(c) may apply. We do not use contact-form data for unrelated marketing, profiling or sale.

4. Retention

Contact messages are delivered to our business mailbox. Enquiries that do not lead to a project are normally deleted within 12 months. Information connected with a contract may be retained for the period required to perform the contract, handle claims and meet accounting or legal duties. Rate-limit files contain a hash derived from the IP address and recent timestamps; the active limit window is one minute and stale files are removed after about five minutes. Hosting logs may follow the host’s separate retention schedule.

5. Processors and recipients

Data may be processed by the website hosting provider and business email provider. Telegram notifications are not configured or enabled, so contact-form data is not currently sent to Telegram. Google Fonts is loaded from Google when the public site is opened, which can disclose technical request data such as an IP address and browser information to Google. We do not currently use public-site analytics, advertising pixels, payment processing or an external CAPTCHA.

6. International transfers

Some providers, including Google, may process data outside Latvia or the European Economic Area. Their applicable transfer safeguards and privacy terms govern those transfers. Telegram is not currently used. The owner should confirm the selected hosting and email providers before publication and update this notice if providers change.

7. Cookies and browser storage

The public site does not currently set analytics or advertising cookies. It stores a sessionStorage entry named boot_shown in your browser so the intro animation does not replay on every page; the entry is normally removed when the tab is closed. The admin_session cookie is used only when an authorised administrator signs in and is not set for ordinary visitors.

8. Spam prevention

The contact form uses a hidden honeypot field, a minimum completion time and short-term per-IP rate limiting. No external CAPTCHA service is currently used. If one is added, this policy and any required consent mechanism must be updated first.

9. Your rights

Depending on the circumstances, you may ask for:

  • Access to your personal data
  • Correction of inaccurate data
  • Deletion of data
  • Restriction of processing
  • Data portability
  • An objection to processing based on legitimate interests
  • Withdrawal of consent where consent is the legal basis
  • Information about how a request was handled

To exercise a right, email us using the controller contact shown on this page. We may need to verify your identity before acting on a request.

10. Security

We use proportionate technical and organisational measures, including access controls, rate limiting and data minimisation. Internet transmission and email delivery can never be guaranteed completely secure, so this notice does not make an absolute security promise.

11. Complaints

You may complain to the Latvian Data State Inspectorate if you believe your personal data has been processed unlawfully. You may also contact us first so we can investigate the concern.

Latvian Data State Inspectorate →

12. Changes and contact

We may update this notice when the website, providers or legal requirements change. The revision date above identifies the current version. For privacy questions or requests, use the business email or contact page below.