Privacy policy


Effective Date: November 11, 2024.



1. General Provisions.

1.1. This Privacy Policy outlines how SIA "Krone Art", Registration No. 40203501522, registered at "Dzīles" - 9, Jaunpils, Jaunpils parish, Tukums Municipality, LV-3145 (hereinafter referred to as the "Data Controller"), collects, processes, and stores personal data obtained from clients and visitors of the website www.kroneart.com (hereinafter referred to as the "Data Subject" or "You").

1.2. Personal data refers to any information relating to an identified or identifiable natural person. Processing encompasses any operation performed on personal data, such as collection, recording, modification, use, viewing, deletion, or destruction.

1.3. The Data Controller adheres to data processing principles as stipulated by law and ensures that personal data is processed in accordance with applicable legislation.


2. Collection, Processing, and Storage of Personal Data.

2.1. The Data Controller primarily collects, processes, and stores personally identifiable information through the online store's website and email.

2.2. By visiting and utilizing the services provided on the online store, you consent to the use and management of any provided information in accordance with the purposes outlined in this Privacy Policy.

2.3. The Data Subject is responsible for ensuring that the submitted personal data is accurate, precise, and complete. Providing knowingly false information is considered a violation of our Privacy Policy. The Data Subject must promptly notify the Data Controller of any changes to the submitted personal data.

2.4. The Data Controller is not liable for any losses incurred by the Data Subject or third parties resulting from the submission of false personal data.


3. Processing of Client Personal Data

3.1. The Data Controller may process the following personal data:

  • 3.1.1. First and last name
  • 3.1.2. Contact information (email address and/or phone number)
  • 3.1.3. Transaction details (purchased services, project address, price, payment information, etc.)
  • 3.1.4. Any other information submitted to us during the purchase of services offered on the website or through communication with us.

3.2. Additionally, the Data Controller has the right to verify the accuracy of the submitted data using publicly available registers.

3.3. The legal basis for processing personal data is Article 6(1)(a), (b), (c), and (f) of the General Data Protection Regulation (GDPR):

  • (a) The Data Subject has given consent to the processing of their personal data for one or more specific purposes;
  • (b) Processing is necessary for the performance of a contract to which the Data Subject is a party or to take steps at the request of the Data Subject prior to entering into a contract;
  • (c) Processing is necessary for compliance with a legal obligation to which the Data Controller is subject;
  • (f) Processing is necessary for the purposes of the legitimate interests pursued by the Data Controller or a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of personal data, especially if the Data Subject is a child.

3.4. The Data Controller retains and processes the Data Subject's personal data as long as at least one of the following criteria is met:

  • 3.4.1. The personal data is necessary for the purposes for which it was collected;
  • 3.4.2. As long as the Data Controller and/or the Data Subject can exercise their legitimate interests in accordance with the procedures specified in external regulatory enactments, such as submitting objections or bringing or defending legal claims;
  • 3.4.3. There is a legal obligation to retain the data, such as under the Accounting Law;
  • 3.4.4. The Data Subject's consent to the respective personal data processing is valid, unless there is another legal basis for data processing.

Upon the cessation of the circumstances mentioned above, the retention period for the Data Subject's personal data ends, and all relevant personal data is irreversibly deleted from computer systems and electronic and/or paper documents containing the respective personal data, or such documents are anonymized.

3.5. To fulfill its obligations to you, the Data Controller has the right to transfer your personal data to cooperation partners, data processors who perform necessary data processing on our behalf, such as accountants, courier services, etc. The data processor is the controller of personal data. Payment processing is provided by the payment platform Stripe.com; therefore, our company transfers the necessary personal data for payment execution to the platform owner, Stripe Inc. Upon request, we may transfer your personal data to state and law enforcement authorities to defend our legal interests, if necessary, by preparing, submitting, and defending legal claims.

3.6. When processing and storing personal data, the Data Controller implements organizational and technical measures to protect personal data against accidental or unlawful destruction, alteration, disclosure, and any other unlawful processing.


4. Rights of the Data Subject

4.1. In accordance with the General Data Protection Regulation and the laws of the Republic of Latvia, you have the right to:

  • 4.1.1. Access your personal data, receive information about its processing, and request a copy of your personal data in electronic format, as well as the right to data portability;
  • 4.1.2. Request the correction of incorrect, inaccurate, or incomplete personal data;
  • 4.1.3. Delete your personal data ("right to be forgotten"), except in cases where the law requires data retention;
  • 4.1.4. Withdraw your previously given consent to the processing of personal data;
  • 4.1.5. Restrict the processing of your data—the right to request that we temporarily stop processing all your personal data;
  • 4.1.6. Contact the Data State Inspectorate.



5. Final Provisions

5.1. This Privacy Policy is developed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (April 27, 2016) on the protection of natural persons concerning the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), as well as the applicable laws of the Republic of Latvia and the European Union.

5.2. The Data Controller has the right to make changes or additions to the Privacy Policy at any time without prior notice. Amendments take effect upon their publication on the website www.kroneart.com.


6. Contact Us

If you have any questions or concerns about this Privacy Policy or our data processing practices, please contact us at: info@kroneart.com


7. Updates to the Privacy Policy

We may update this Privacy Policy from time to time. The current effective date will be displayed at the beginning of the Privacy Policy page. You are responsible for periodically reviewing this Privacy Policy to stay informed about any changes.