LONGSAL PRIVACY POLICY
1. General Information
SIA “Longsal”, registration No. 40203510883 (hereinafter – LONGSAL), acts as the data controller in relation to the personal data processing activities described in this Privacy Policy, in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (the General Data Protection Regulation, GDPR) and other applicable data protection laws.
This Privacy Policy explains what personal data LONGSAL may collect, the purposes for which such data are processed, the applicable legal bases, how long the data are retained, to whom they may be disclosed, and the rights available to data subjects.
This Privacy Policy applies to personal data collected and processed, including in connection with:
- LONGSAL websites and digital solutions;
- purchases of LONGSAL products or services;
- questionnaires and other data collection forms;
- testing services and related services;
- consultations;
- laboratory test results, medical documents, or other information submitted to LONGSAL;
- communication with LONGSAL by email, telephone, or other communication channels;
- the conclusion and performance of contracts;
- other situations in which a person uses LONGSAL services or otherwise interacts or cooperates with LONGSAL.
Certain LONGSAL services may be subject to additional privacy terms that provide more detailed information about the processing of personal data in connection with a specific service.
Such additional privacy terms supplement this Privacy Policy. Where a matter is not specifically addressed in the privacy terms applicable to a particular service, this Privacy Policy shall apply.
2. Personal Data LONGSAL May Process
Depending on the services used by the client and the nature of the relationship with LONGSAL, LONGSAL may process the following categories of personal data:
Identification and Contact Information
- first name and last name;
- date of birth and other identification information where necessary;
- email address;
- telephone number;
- delivery address or other address provided by the client.
Transaction and Service Information
- orders and services purchased;
- payment and invoice information;
- delivery information;
- LONGSAL services used by the client;
- information relating to consultations;
- customer service and communication records.
Information Provided by the Client
- answers provided in questionnaires and other data collection forms;
- documents submitted by the client to LONGSAL;
- information provided by the client during consultations or other communications.
Health-Related Information and Information Related to LONGSAL Personalised Services
- test and laboratory examination results;
- laboratory analysis results submitted by the client;
- information concerning health status;
- information concerning diet and lifestyle;
- information about medications and dietary supplements used;
- information concerning symptoms, well-being, and other health-related factors;
- medical opinions, reports, or other information provided by physicians or other healthcare professionals, where submitted by the client to LONGSAL;
- LONGSAL’s interpretation of results and personalised recommendations prepared for the client.
Depending on the specific service, LONGSAL may also process other categories of personal data where such data are necessary to provide the relevant service and the client has been appropriately informed about such processing.
3. Health Data
The provision of certain LONGSAL services requires the processing of information relating to the client’s health.
Health data are special categories of personal data under the GDPR and are subject to enhanced data protection requirements.
LONGSAL processes health data only where an appropriate legal basis exists under the GDPR, including, where required, the client’s explicit consent to the processing of such data.
In connection with LONGSAL services, a client may also provide additional health-related information, including:
- blood test results or other laboratory examination results;
- results of other tests;
- medical opinions or reports from physicians or other healthcare professionals;
- information concerning diagnoses, symptoms, or health status;
- information concerning the use of medications or dietary supplements;
- other information relevant to a consultation, interpretation of results, or the preparation of personalised recommendations.
Such information is processed only for the purpose of providing the relevant service and for other purposes that have been communicated to the client and are supported by an appropriate legal basis.
4. Purposes of Personal Data Processing
LONGSAL may process personal data for the following purposes:
- accepting and fulfilling client orders;
- entering into and performing contracts;
- providing LONGSAL products and services;
- providing testing services and managing related processes;
- assessing information provided by the client;
- receiving, processing, assessing, and interpreting test and laboratory examination results;
- providing consultations;
- preparing personalised recommendations;
- comparing previous and repeat test results, where relevant to the specific service;
- communicating with clients and providing customer support;
- sending notifications and reminders relating to orders, consultations, tests, or other services;
- administering payments, accounting, and invoicing;
- complying with LONGSAL’s legal obligations;
- protecting LONGSAL’s rights and legal interests;
- improving service quality, internal processes, and business operations;
- conducting statistical and business analysis, where supported by an appropriate legal basis;
- sending news, marketing communications, and information about LONGSAL products or services, where supported by an appropriate legal basis;
- preventing fraud, security incidents, and unauthorised use of systems;
- other specifically identified and legally justified purposes.
5. Legal Bases for Personal Data Processing
Depending on the specific processing activity, LONGSAL may process personal data on the basis of one or more legal grounds provided for under the GDPR.
Performance of a Contract
Where processing is necessary for the performance of a contract with the client or in order to take steps at the client’s request before entering into a contract.
Compliance with a Legal Obligation
Where LONGSAL is required to process or retain certain personal data in order to comply with applicable legal obligations.
Legitimate Interests
Where processing is necessary for the purposes of the legitimate interests pursued by LONGSAL or a third party, provided that such interests are not overridden by the interests or fundamental rights and freedoms of the data subject.
Consent
Where the data subject’s consent is required for a particular processing activity.
Where special categories of personal data are processed, including health data, LONGSAL also ensures that an appropriate condition under Article 9 of the GDPR applies, including, where applicable, the client’s explicit consent.
6. Recipients of Personal Data and Service Providers
LONGSAL does not disclose personal data to third parties without an appropriate legal basis.
Depending on the specific service, personal data may, to the extent necessary, be disclosed to:
- laboratories and testing service partners;
- IT, data storage, and technology service providers;
- payment service providers;
- accounting and financial service providers;
- delivery and logistics service providers;
- professional advisers where disclosure is necessary to protect LONGSAL’s rights or legal interests;
- public authorities, supervisory authorities, or law enforcement authorities where disclosure is required by applicable law;
- other persons or organisations where there is an appropriate legal basis or valid consent from the client.
LONGSAL discloses to recipients only the personal data necessary for the relevant task or service.
Where LONGSAL engages a data processor, LONGSAL takes appropriate measures to ensure that personal data are processed in accordance with applicable data protection requirements.
7. Transfers of Personal Data Outside the European Economic Area
As a result of using certain technology providers or other service providers, personal data may in some cases be transferred to, accessed from, or otherwise processed in countries outside the European Union or the European Economic Area.
Where such a transfer takes place, LONGSAL ensures that it is carried out in accordance with Chapter V of the GDPR and that an appropriate transfer mechanism is used.
Such mechanisms may include:
- a European Commission adequacy decision;
- European Commission-approved Standard Contractual Clauses;
- another lawful transfer mechanism recognised under the GDPR.
8. Retention of Personal Data
LONGSAL does not retain personal data for longer than necessary for the purposes for which the data were collected, unless a longer retention period is required by applicable law or another lawful basis for continued retention exists.
When determining the applicable retention period, LONGSAL takes into account:
- the purposes of the processing;
- the requirements of the specific service;
- applicable legal retention obligations;
- the need to establish, exercise, or defend legal claims;
- the nature and sensitivity of the personal data;
- the applicable legal basis for processing.
Where personal data are processed solely on the basis of consent and the client withdraws that consent, the relevant processing will cease unless another legal basis permits or requires continued processing.
Health-related information and documents submitted by the client are retained only for as long as necessary for the relevant processing purpose, provision of the service, compliance with applicable legal obligations, or the establishment, exercise, or defence of legal claims.
Specific LONGSAL services may be subject to specific retention periods. Where applicable, such retention periods are set out in the additional privacy terms relating to the relevant service.
9. Security of Personal Data
LONGSAL implements appropriate technical and organisational measures to protect personal data, taking into account the nature of the data, the scope and context of the processing, and the risks to the rights and freedoms of data subjects.
LONGSAL takes measures designed to protect personal data against:
- unauthorised access;
- unlawful disclosure;
- alteration;
- loss;
- destruction;
- other forms of unauthorised or unlawful processing.
Access to personal data is granted only to persons and service providers who require such access in order to perform their duties or provide the relevant service.
While no electronic transmission or storage system can guarantee absolute security, LONGSAL regularly assesses and, where appropriate, improves the technical and organisational measures used to protect personal data.
10. Cookies and Website Usage Data
LONGSAL websites may use cookies and similar technologies in order to:
- ensure the proper operation of the website and its functions;
- ensure security and user authentication;
- store user preferences;
- analyse website usage and improve performance;
- serve other purposes communicated to the user.
Depending on the type of cookie, its use may be strictly necessary for the operation of the website or may require the user’s consent.
Where applicable law requires consent for the use of particular cookies, such cookies will not be used before the relevant consent has been obtained.
More detailed information regarding the cookies used by LONGSAL, their purposes, retention periods, and options for managing cookie preferences may be provided in a separate Cookie Policy or through the website’s cookie management tool.
11. Marketing Communications
LONGSAL may send information concerning its products, services, news, and offers where an appropriate legal basis exists.
Where marketing communications are sent on the basis of consent, the data subject may withdraw their consent or opt out of receiving further marketing communications at any time.
Opting out of marketing communications does not affect the sending of essential communications relating to an order, consultation, test, or other service requested by the client.
12. Data Subject Rights
In accordance with the GDPR and other applicable data protection laws, the data subject may have the right to:
- receive information about the processing of their personal data;
- request access to their personal data;
- receive a copy of their personal data;
- request rectification of inaccurate or incomplete personal data;
- request erasure of personal data in the circumstances provided for under the GDPR;
- request restriction of processing in the circumstances provided for under the GDPR;
- exercise the right to data portability, where applicable;
- withdraw consent where processing is based on consent;
- object to the processing of personal data where the GDPR provides such a right;
- lodge a complaint with the competent supervisory authority.
In Latvia, the competent data protection supervisory authority is the Data State Inspectorate (Datu valsts inspekcija).
The right to erasure and other data subject rights are not absolute and are exercised subject to the conditions and limitations provided for under the GDPR and other applicable laws.
13. Withdrawal of Consent
Where the processing of personal data is based on the data subject’s consent, the data subject may withdraw that consent at any time.
Withdrawal of consent does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal.
Where, following withdrawal of consent, another lawful basis exists for processing or retaining the relevant personal data, LONGSAL may continue to process such data to the extent permitted or required under that legal basis.
Where withdrawal of consent means that LONGSAL no longer has a lawful basis to process information necessary for the provision of a particular service, LONGSAL may be unable to continue providing that service.
14. Submission of Data Subject Requests
Questions and requests relating to the processing of personal data may be submitted to LONGSAL by email at:
Before responding to or fulfilling a request, LONGSAL may take reasonable steps to verify the identity of the person making the request where necessary to ensure that personal data are not disclosed, amended, or otherwise processed at the request of an unauthorised person.
Where a client’s request concerns personal data that have also been disclosed to a partner involved in providing a LONGSAL service or to another recipient of personal data, LONGSAL will, in accordance with applicable data protection requirements, take the necessary steps to inform the relevant recipient and, where appropriate, coordinate the handling of the request.
LONGSAL will inform the data subject of the action taken in relation to their request without undue delay and within the time limits provided for under the GDPR.
15. Erasure of Personal Data
The data subject has the right, in the circumstances provided for under the GDPR, to request the erasure of their personal data.
Upon receiving an erasure request, LONGSAL assesses whether there is a legal obligation or another lawful basis requiring or permitting continued retention of the relevant personal data.
Where no such basis exists, LONGSAL will erase the relevant personal data.
Where the relevant personal data have also been disclosed to a partner involved in providing the service or to another recipient, LONGSAL will take the steps required under the GDPR to inform the relevant recipient of the erasure, where applicable.
Where personal data have been irreversibly anonymised so that the individual can no longer be identified, such information is no longer considered personal data within the meaning of the GDPR.
16. Automated Decision-Making
If LONGSAL uses automated individual decision-making, including profiling, which produces legal effects concerning the data subject or similarly significantly affects the data subject within the meaning of Article 22 of the GDPR, LONGSAL will provide the data subject with the information required under the GDPR.
The use of digital or automated tools by LONGSAL does not, by itself, mean that automated individual decision-making within the meaning of Article 22 of the GDPR is taking place.
17. Personal Data of Minors
Where a LONGSAL service is provided to a minor, personal data are processed in accordance with applicable requirements relating to the protection of minors’ personal data.
Where required, LONGSAL will obtain the consent or authorisation of a parent, guardian, or other legal representative, or take other measures required under applicable law.
18. Changes to this Privacy Policy
LONGSAL may update this Privacy Policy from time to time, including where LONGSAL services, personal data processing activities, technologies, or applicable legal requirements change.
The current version of this Privacy Policy will be made available on the LONGSAL website.
Where changes materially affect the processing of personal data or the rights of data subjects, LONGSAL will, where appropriate, also inform the relevant individuals through other suitable means.
19. Contact Information
For questions regarding this Privacy Policy, the processing of personal data, or the exercise of data subject rights, please contact:
SIA “Longsal”
Registration No. 40203510883
Email: [email protected]