1. General Terms
This Privacy Policy establishes the procedure by which SIA “NKK TRADE”, registration number 40203295205, processes personal data of individuals in connection with the operation of the online store frequencies.lv, merchandise trading, customer service, user account maintenance, loyalty program administration, delivery organization, payment processing, and website security. This Policy applies to all persons who visit the website, create a user account, place orders, subscribe to newsletters, participate in loyalty or referral programs, contact the seller, or otherwise provide their data to the Data Controller.
The purpose of this Policy is to provide clear, complete, and transparent information about the categories of data processed, the purposes of processing, legal bases, data recipients, retention periods, data subject rights, and cookies use. The Policy has been prepared in accordance with the Regulation (EU) 2016/679 of the European Parliament and of the Council, the data protection regulatory acts in force in the Republic of Latvia, as well as consumer protection rules applicable to e-commerce.
Users are obligated to familiarize themselves with this Policy before placing an order or creating an account. If a person does not use frequencies.lv services and does not provide their data, this Policy does not apply to them. If a person continues to use the website, creates an account, or places an order, it is considered that the person has familiarized themselves with this Policy and understands what personal data and for what purpose will be processed. This Policy should be interpreted in conjunction with the distance contract terms, delivery and return terms, cookie settings, and other legal texts published on the website.
If frequencies.lv is used in multiple languages, the legally binding version is the Latvian language version, unless the seller has clearly specified otherwise in a particular situation. Translations in other languages are provided for users’ convenience. If interpretation differences arise between language versions, the Latvian language version applies with priority.
2. Personal Data Controller
The Personal Data Controller is SIA “NKK TRADE”, registration number 40203295205, VAT payer number LV40203295205, legal address Mazcenu aleja 10-39A, Jaunmārupe, Mārupes Parish, Mārupes Municipality, LV-2166, email info@frequencies.lv, telephone +371 27474539. The Controller determines the purposes and means of personal data processing, insofar as such processing has not been entrusted to another Controller or joint Controller in accordance with regulatory requirements.
A Data Protection Officer has not been separately appointed. Data protection matters are monitored by a member of the company’s Management Board because, given the nature and scope of the company’s activities, the company is not subject to the mandatory obligation to appoint a Data Protection Officer in accordance with Article 37 of the GDPR. The company does not conduct large-scale regular and systematic monitoring of data subjects as a main activity and does not process special categories of data on a large scale as a main activity.
In case of questions, requests, or complaints about personal data processing, a person may contact the Controller by writing to info@frequencies.lv or sending a written submission to the legal address. To protect other persons’ data and prevent unauthorized access, the Controller has the right to verify the identity of the requester before providing information by requesting additional information or identity verification documents.
3. Categories of Personal Data Processed
3.1. Order and Purchase Data
To conclude and fulfill the distance contract, the Controller processes data provided during order placement, including the buyer’s name, surname, email address, telephone number, delivery address, billing address, order content, selected goods type and quantity, order number, order history, product price, delivery method, applied discounts, payment status, payment method, and communication about order fulfillment. If the order contains a personalized product, the Controller also processes information necessary for its manufacture, such as engraving text, desired crystal combinations, personalization instructions, or other customer specifications.
This data is necessary to verify the transaction content, prepare the order, organize delivery, prepare accounting documents, process refunds, consider complaints, and, if necessary, prove the fact of contract conclusion and its fulfillment. If the buyer does not provide the minimum necessary data, the seller cannot accept and fulfill the order.
3.2. User Account and Profile Data
If a person creates a user account, the Controller processes the username, email address, password stored in encrypted form, account technical identifiers, language preference, purchase history, wishlist information, persistent shopping cart content, and the user’s chosen virtual crystal avatar, which is stored in the system as freq_crystal_avatar. In certain cases, the user’s saved delivery and billing data may also be processed to facilitate repeat purchases.
This data is processed to ensure account functionality, authentication, personalized user experience, order history viewing, wishlist and language preference storage, as well as convenient repeat ordering. The password is not stored in plain text but in encrypted or hash form, in accordance with WordPress and WooCommerce technical architecture.
3.3. “Crystal Circle” Loyalty Program Data
If a person participates in the “Crystal Circle” loyalty or referral program, the Controller processes program participant identification data, unique referral code, reward balance accumulated in the system, referred customer history and usage activity, and technical fraud prevention data, including IP address, which may be stored in the system as fka_last_ip. The system may also use other technical identifiers to prevent unauthorized reward allocation, multiple account use, or automated malicious activities.
To ensure program operation, the Controller also processes information about whether rewards have been granted, used, canceled, or frozen for verification purposes. If there is reasonable suspicion of fraud, the Controller may conduct additional verification by linking referral activities with order and session information, insofar as necessary to protect the Controller’s legitimate interests.
3.4. Technical and Web Browsing Data
When visiting the website, the Controller may automatically process the user’s IP address, approximate geographic information, browser type and version, device and operating system information, visit time, duration, viewed pages, click stream, referring pages, session identifiers, and cookie data. This data is processed to ensure website technical operation, security, session maintenance, language selection, shopping cart storage, access control, and error diagnostics.
The Website uses Google Analytics 4 (Google Ireland Limited / Google LLC) to collect visit statistics. Analytics cookies are activated only after the user has given consent in the cookie banner (Google Consent Mode), and consent can be withdrawn at any time in the cookie settings. IP addresses are processed in truncated form, and the data is used in aggregated form to improve the operation and content of the Website.
If you consent to marketing cookies in the cookie banner, the website uses Meta Pixel (Meta Platforms Ireland Limited) to measure the results of Facebook and Instagram ads and to show ads to website visitors. Information about your actions on the website (pages and products viewed, adding to cart, checkout and purchase amount), browser and device data and your IP address are transmitted to Meta. SIA “NKK TRADE” and Meta are joint controllers for the collection and transmission of this data; the legal basis is your consent (Article 6(1)(a) GDPR), which you can withdraw at any time in the cookie settings. Meta processes the data further under its own privacy policy: facebook.com/privacy/policy.
4. Processing Purposes and Legal Bases
4.1. Distance Contract Conclusion and Fulfillment
The processing of order, delivery, communication, and refund data primarily occurs to conclude and fulfill the distance contract between the buyer and seller. The legal basis for this processing is Article 6(1)(b) of the GDPR, namely, processing is necessary for the performance of a contract or for taking steps at the request of the data subject before entering into a contract. Without this processing, the seller could not accept and fulfill the order, prepare products, organize delivery, or ensure communication about the transaction’s fulfillment.
4.2. Payment Processing
Payment processing occurs to receive payment for the order, verify transaction status, confirm order placement, and, if necessary, process refunds. The legal basis is Article 6(1)(b) of the GDPR. Payment processing is provided by external service providers. Mandatory notice: Payment processing is provided by the payment platform makecommerce.lv, therefore our company transfers the personal data necessary for payment execution to the platform owner Maksekeskus AS.
The Controller does not receive or store complete payment card data unless necessary for a separate refund or dispute process in accordance with the payment partner’s technical requirements. Payment partners operate as independent Data Controllers or processors depending on the nature of the specific processing.
4.3. Accounting Records and Regulatory Compliance
The Controller processes transaction data to fulfill legal obligations in the fields of accounting, taxation, financial reporting, consumer rights, and dispute resolution. The legal basis is Article 6(1)(c) of the GDPR, namely, processing is necessary for compliance with a legal obligation applicable to the Controller. This processing is based, inter alia, on the Accounting Law, Consumer Rights Protection Law, and other applicable regulatory acts.
4.4. User Profile Maintenance
The maintenance of user accounts, wishlists, language preferences, virtual crystal avatar, and persistent shopping cart is performed to ensure a personalized, convenient, and uninterrupted website usage experience. The legal basis is Article 6(1)(f) of the GDPR, namely, the Controller’s legitimate interest in ensuring quality e-commerce services, account functionality, and customer convenience. The Controller has assessed that such processing is reasonably expected in the context of online store operations and does not exceed the data subject’s interests, rights, and freedoms.
4.5. Loyalty Program Administration
The administration of the “Crystal Circle” loyalty program occurs to allocate and record rewards, maintain the referral system, ensure compliance with rules, and prevent misuse. In this section, the legal basis for processing may be Article 6(1)(a) of the GDPR, insofar as a person voluntarily signs up for program participation, as well as Article 6(1)(f) of the GDPR, insofar as the Controller has a legitimate interest in maintaining a safe and fair reward system, including fraud prevention and duplicate reward allocation prevention.
4.6. Direct Marketing
If a person separately provides consent, the Controller may process the email address and minimal technical data related to communication to send newsletters, special offers, information about new products, or marketing content. The legal basis is Article 6(1)(a) of the GDPR. Consent is voluntary, and its non-provision does not affect the ability to make purchases. Consent may be withdrawn at any time free of charge.
4.7. Customer Service and Complaint Handling
The Controller processes communication data, requests, complaints, warranty or conformity claims, technical support information, and other related information to respond to customer inquiries, handle applications, resolve problems, and provide evidence of communication. The legal basis is typically Article 6(1)(b) of the GDPR if communication directly relates to contract fulfillment, or Article 6(1)(f) of the GDPR if communication is necessary to ensure the quality of customer service and protect the Controller’s legal interests.
4.8. Website Security and Technical Operation
The processing of IP addresses, sessions, authorization cookies, security logs, and server technical data is performed to ensure website operation, user authentication, prevention of security incidents, restriction of unauthorized access, proper cache operation, and system stability. The legal basis is Article 6(1)(f) of the GDPR. The Controller’s legitimate interest is to ensure a secure and functioning e-commerce environment.
4.9. Fraud Prevention
The Controller processes IP addresses, session data, referral activities, and other technical indicators when necessary to prevent fraudulent order placement, payment risks, referral system misuse, or unauthorized access to user accounts. The legal basis is Article 6(1)(f) of the GDPR. Such processing is carried out proportionally and only to the extent necessary to protect security and property interests.
5. Personal Data Recipients
The Controller does not share personal data with third parties without a legal basis. However, data sharing may be necessary to ensure order fulfillment, payment processing, delivery, hosting, accounting, or regulatory compliance.
Maksekeskus AS receives data necessary for payment processing if the buyer chooses the appropriate MakeCommerce-provided solutions, such as card payments, internet banking, Apple Pay, Google Pay, Revolut, Wise, N26, or “buy now, pay later” functionality, insofar as it is available at that time.
Swotzy for WooCommerce as a logistics aggregator receives information necessary for delivery to provide it to the selected carrier and generate delivery orders. Depending on the selected delivery method, data may be received by DPD Latvia SIA, Omniva SIA, Latvia Post VAS, Venipak SIA, or another delivery partner that provides delivery in that territory.
Hostinger International Ltd. provides website hosting, data storage, and technical services related to server maintenance. WordPress, WooCommerce, LiteSpeed Cache, Yoast SEO, WP Smush, Polylang, and other technical solutions used in website operation may technically process or generate data on behalf of the Controller, insofar as necessary for the website’s functioning.
The accounting outsourcing service provider receives only the data necessary to fulfill accounting and tax obligations. State institutions, supervisory bodies, law enforcement bodies, or courts may receive personal data in cases where necessary in accordance with applicable regulatory acts or binding requests.
Data transfer outside the European Economic Area may occur only in the context of analytics, if the user has consented to analytics cookies, as Google LLC may process data in the United States. Such transfer is based on the EU-U.S. Data Privacy Framework or another valid legal instrument compliant with Chapter V of the GDPR. Payment data is processed within the European Economic Area (Maksekeskus AS, Estonia).
6. Data Retention Period
The Controller stores order, invoice, transaction, and other information necessary for accounting records for as long as required by regulatory acts. In practice, this means that transaction and accounting data is stored for at least five years after the end of the year of the relevant transaction or longer if required by other applicable legal regulations, audit, tax control, or dispute resolution.
User account data is stored as long as the user account is active. If an account is unused for an extended period, the Controller may conduct an account review. If an account has not been used for three years and there are no other legal reasons for data storage, the Controller has the right to delete or anonymize account data, while, if possible, sending the user prior notification.
“Crystal Circle” loyalty program data is stored as long as a person is a program participant, as well as for one year after the end of participation to handle possible complaints, complete accounting records, and prevent fraud risks. Marketing consent data is stored until consent is withdrawn or until the Controller determines that the consent is no longer valid.
Guest wishlist information is stored according to the relevant cookie term, namely, typically until 30 days. Technical, session, and cookie data are stored according to the specific cookie’s validity term or server technical storage cycle. If data is necessary for dispute, claim, security incident, or supervisory process resolution, it may be stored longer until the relevant process is completed.
7. Data Subject Rights
7.1. Right of Access
A data subject has the right to obtain confirmation of whether the Controller is processing their personal data and, if processing occurs, to receive information about the purposes of processing, data categories, recipients, retention periods, and other information provided in Article 15 of the GDPR. The Controller has the right to request identity verification if necessary to prevent data disclosure to an unauthorized person.
7.2. Right to Rectification
A data subject has the right to request correction of inaccurate or incomplete personal data in accordance with Article 16 of the GDPR. If the user can correct part of the data themselves in their account, the Controller may point to such self-service option; however, this does not restrict the right to submit a separate request.
7.3. Right to Erasure
A data subject has the right to request deletion of their personal data in cases specified in Article 17 of the GDPR, for example, if the data is no longer necessary for the original purpose, consent has been withdrawn and there is no other legal basis for processing, or the data has been processed unlawfully. These rights are not absolute, as the Controller may have an obligation to retain certain data due to legal obligation, claim protection, or accounting requirements.
7.4. Right to Restrict Processing
A data subject has the right to request restriction of processing in cases specified in Article 18 of the GDPR, for example, if the accuracy of the data is contested or if a person objects to processing. During the restriction period, the Controller may store data but not use it for other purposes, except in cases permitted by regulatory acts.
7.5. Right to Data Portability
If processing is based on consent or a contract and is carried out by automated means, a data subject has the right to receive their provided personal data in a structured, widely used, and machine-readable format or, if technically possible, to have it transmitted to another Controller in accordance with Article 20 of the GDPR. These rights apply only to data that the person themselves has provided or data derived from the person’s activities and do not apply to derived assessments or legally mandatory stored data.
7.6. Right to Object to Processing
A data subject has the right at any time to object to processing of their data based on Article 6(1)(f) of the GDPR, including profiling insofar as it relates to such basis. If the Controller cannot prove compelling legitimate reasons that override the data subject’s interests, rights, and freedoms, the relevant processing must be stopped. An objection to direct marketing is enforceable without additional assessment.
7.7. Right to Withdraw Consent
If processing is based on consent, a data subject has the right to withdraw consent at any time in accordance with Article 7(3) of the GDPR. Withdrawal of consent does not affect the lawfulness of processing carried out until the withdrawal is received. Withdrawal does not affect processing operations that have another legal basis, such as contract fulfillment or legal obligation fulfillment.
7.8. Right to Lodge a Complaint with the Supervisory Authority
If a person believes that processing of their data violates data protection requirements, they have the right to lodge a complaint with the State Data Inspection, Elijas Street 17, Riga, LV-1050, email info@dvi.gov.lv, website www.dvi.gov.lv. However, the Controller encourages contacting the Controller first so that the issue can be resolved as quickly and appropriately as possible.
7.9. Procedure for Exercising Rights
To exercise their rights, a person may submit a request to info@frequencies.lv or by mail to the legal address. The Controller responds to the request without undue delay and normally no later than 30 days from the receipt of the request. If the request is complex or the number of received requests is large, the Controller has the right to extend the deadline by up to 60 days by informing the requester.
8. Cookie Policy
8.1. What are Cookies
Cookies are small text files that a website saves on a user’s device when the user visits the website. They allow the website to remember the user’s actions and choices for a certain period of time, for example, language preference, authorization status, products in the shopping cart, or wishlists. Some cookies are technically necessary for website operation, while others improve functionality or may be used for analytics and marketing in the future with user consent.
8.2. Essential Cookies
Essential cookies are necessary for frequencies.lv to function as an online store at all. Without them, it is impossible to maintain a session, save the cart, authorize a user, or ensure secure access to an account. These cookies cannot be disabled using the consent banner because without them the website cannot perform basic functions.
woocommerce_cart_hash – Shopping cart content integrity verification and storage; term: session.
woocommerce_items_in_cart – Indicates to WooCommerce system whether products have been added to the cart; term: session.
wp_woocommerce_session_[hash] – Unique WooCommerce user session identifier linking the buyer with order data; term: 2 days.
wordpress_logged_in_[hash] – Registered user authorization session; term: session or up to 14 days if “Remember me” function is enabled.
wordpress_sec_[hash] – Security authentication cookie for WordPress administration or authorization security; term: session.
wp-settings-[UID] – Stores user interface settings; term: 1 year.
PHPSESSID – PHP server session identifier; term: session.
pll_language – Stores selected language preference; term: 1 year.
8.3. Functionality Cookies
Functionality cookies are not absolutely necessary for order placement, but they significantly improve the user experience. They help save certain preferences and performance settings to make the website easier to use.