01 Data controller
The controller responsible for the personal data described in this policy is IT Julian Soft SIA, trading as JulianSoft — a limited liability company (sabiedrība ar ierobežotu atbildību) entered in the Commercial Register of the Republic of Latvia on 31 July 2026.
- Registration number: 40203766520
- Legal address: Dārzu iela 25, Rēzekne, LV-4601, Latvia
- SEPA identifier: LV65ZZZ40203766520
- Board member (valdes loceklis): Juliāns Molodcovs
- Data protection contact: hello@juliansoft.lv
We have not appointed a Data Protection Officer, as we do not meet the conditions in Article 37 of the General Data Protection Regulation (GDPR). Data protection enquiries are handled directly by the board member at the address above.
02 Scope of this policy
This policy covers two things: the juliansoft.lv website, and the client project work we carry out under contract — enquiries, quotes, development, deployment, invoicing and handover.
It does not cover third-party websites we link to, nor the way a client operates a system after we have handed it over. Once a project is delivered and the credentials are transferred, the client controls that system and is the controller for the personal data inside it. Our commercial terms are set out separately in the Terms of Service, and the storage technologies used by this website are described in the Cookies Policy.
03 What personal data we collect
Data you send us with an enquiry
The enquiry form on the Contact page is not connected to a backend yet. It checks what you have typed inside your own browser and transmits nothing: no submission reaches us, and nothing from it is stored anywhere. Until that endpoint is live, enquiries reach us by email.
Whichever route you use, the details we then process are: your name, email address, optionally your company name, the service you are interested in, an indicative budget band, and the message you write. Only the name, email and message are needed for us to reply; the rest simply lets us quote faster. Anything you volunteer inside the free-text message is processed too, so please do not send special-category data or credentials there.
Data we process while delivering a project
If an enquiry becomes a project, we additionally process the contact details of the people we work with on your side, billing details required for the invoice (company name, registered address, registration number, and the payment reference reaching our account at AS "SEB banka"), and correspondence about the work. In the course of building, migrating or debugging a system we may also come into contact with personal data held inside that system — customer records in an online store, leads captured by a landing page, tenant accounts in a SaaS platform. For that data we are a processor acting on the client's behalf, not a controller. See section 05.
Technical data
Like any website, juliansoft.lv is served by infrastructure that records standard request logs: your IP address, browser and device type, the pages you viewed, the referring page and a timestamp. No analytics provider is connected to the site at present, so no analytics data is collected today. If one is added later, it will run only where you have chosen “Accept all” in the consent banner, and only to produce aggregated page-view statistics.
Typefaces are loaded from Google Fonts. Every page requests a stylesheet and font files from fonts.googleapis.com and fonts.gstatic.com, so your IP address and browser user-agent are visible to Google as part of that request. See section 07 and the Cookies Policy.
This website does not set tracking cookies. Your consent choice is stored in your own browser using localStorage under the key js-cookie-consent, which is never transmitted to us and never leaves your device. Clearing your browser storage removes it, and the banner will simply ask again. Full detail is in the Cookies Policy.
04 Why we process it and on what legal basis
Every processing activity we carry out is tied to one of the legal bases in Article 6(1) GDPR. Nothing happens outside this table.
| Purpose | Data | Legal basis (Art. 6(1) GDPR) |
|---|---|---|
| Responding to the enquiry you email us and preparing a written scope and fixed quote | Name, email, company, service interest, budget band, message | Art. 6(1)(b) — steps taken at your request prior to entering into a contract |
| Performing the contract: building, deploying and handing over the project | Client contact details, project correspondence, access credentials you provide | Art. 6(1)(b) — performance of a contract to which you are a party |
| Issuing invoices and retaining accounting records | Billing name and address, registration number, invoice lines, payment reference | Art. 6(1)(c) — legal obligation under Latvian accounting and tax law |
| Optional website analytics to see which pages are actually read — reserved, not active at present | Pages viewed, referrer, approximate region, device and browser type | Art. 6(1)(a) — your consent, which you may withdraw at any time |
| Keeping the site available, secure and free of abuse | IP address, request logs, error logs, rate-limiting records | Art. 6(1)(f) — our legitimate interest in a secure, functioning website |
Where we rely on legitimate interests, we have weighed those interests against your rights and freedoms. The processing is limited to server-side logging needed to keep the site online — it is not used to build profiles or to target you. You can object to it at any time under section 10.
05 Processor role for client systems
When we work inside a system that belongs to a client — a store database, a lead table, a multi-tenant SaaS backend — the client decides why and how that personal data is processed. We act only as a processor under Article 28 GDPR:
- We process client data only on the client's documented instructions.
- We do not use it for our own purposes, and never for marketing, resale or model training.
- Access is limited to what the task requires, and credentials are returned or revoked at handover.
- We work with production data only where a staging copy or anonymized sample cannot do the job.
- We notify the client without undue delay if we become aware of a personal data breach affecting their system.
A written data processing agreement (Article 28 GDPR) is available on request and can be signed before project work begins. Ask for it in your first message and it will be attached to the quote.
06 How long we keep it
We keep personal data only for as long as it serves the purpose it was collected for, then delete it. In practice:
- Enquiries that do not become projects — up to 12 months from your last message, so we have context if you come back. Then deleted.
- Project and contract records — for the duration of the engagement plus the statutory limitation period for civil claims in Latvia, so that both sides can rely on what was agreed.
- Accounting records and invoices — 5 years, as required by Latvian accounting law. We cannot delete these earlier, even on request.
- Analytics data — none is collected at present; if analytics is enabled later, up to 14 months, in aggregated form.
- Server and security logs — short-lived, retained by our hosting provider under their standard log rotation.
- Client system data we touch as a processor — no longer than the project needs it; access is revoked at handover.
07 Who we share it with
We disclose personal data only to the parties that make the service work, and only to the extent each of them needs:
- Hosting and cloud providers that run the website and, where the project calls for it, the client's deployment (for example AWS, DigitalOcean or Google Cloud — usually in the client's own account).
- Payment providers such as Stripe and PayPal, where a client's project integrates them. Card data goes directly to the provider; see section 09.
- Google, whose Fonts service delivers the typefaces used on every page of this website. Google receives the IP address and user-agent of the browser making the request; according to Google's documentation the Fonts API sets no cookies.
- Our bank, AS "SEB banka", which processes the euro transfers used to settle invoices.
- Our accountants, who prepare the statutory books and filings.
- Public authorities, where disclosure is required by law — for example the State Revenue Service, or a court order.
We do not sell personal data, and we do not share it with advertising networks or data brokers. Every provider above acts under a contract that restricts them to processing on our instructions, except where they are independent controllers by law (such as the bank and the authorities).
08 International transfers
Personal data is processed primarily inside the European Union and the European Economic Area. Where a provider processes data outside the EU/EEA — some cloud and payment platforms operate globally — the transfer relies on one of the safeguards permitted by Chapter V GDPR: an adequacy decision of the European Commission for the destination country, or the European Commission's Standard Contractual Clauses combined with the provider's supplementary technical measures.
For client deployments the region is a decision the client makes with us before anything is provisioned. If you require EU-only processing, say so at the scoping stage and we will specify it in the written scope.
09 Security
Security is part of the build, not an afterthought bolted on at the end. The measures we apply to our own systems and to the projects we deliver include:
- Hashed credentials — passwords are stored as salted one-way hashes, never in plain text or reversible form.
- HTTPS/TLS everywhere, with certificates configured as part of deployment and traffic redirected off plain HTTP.
- Scoped access tokens — API keys and tokens are issued per integration with the narrowest permissions that work, and rotated when a project ends.
- Principle of least privilege — accounts and database roles get the minimum rights required for the task, and are revoked at handover.
- Payment card data never touches our servers. Checkout flows hand off to the payment provider, so card numbers are entered on the provider's infrastructure, not ours or the client's.
- Separated environments — staging work uses test or anonymized data wherever the task allows it.
No system is absolutely secure, and we will not claim otherwise. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the State Data Inspectorate within 72 hours of becoming aware of it, and notify you directly where the risk is high.
10 Your rights
Under the GDPR you can ask us to do all of the following, free of charge:
- Access — get confirmation of whether we process your data, and a copy of it (Art. 15).
- Rectification — have inaccurate or incomplete data corrected (Art. 16).
- Erasure — have your data deleted where we no longer have a valid reason to keep it (Art. 17).
- Restriction — have processing paused while a dispute about accuracy or legal basis is resolved (Art. 18).
- Portability — receive the data you gave us in a structured, machine-readable format, or have it sent to another provider (Art. 20).
- Objection — object to processing based on our legitimate interests (Art. 21).
- Withdraw consent — at any time, for anything based on consent. Withdrawal does not affect processing carried out before it (Art. 7(3)).
To exercise any of these, write to hello@juliansoft.lv and describe what you want. We respond within one month of receiving the request, as required by Article 12(3); if a request is unusually complex we may extend that by two further months and will tell you why within the first month. We may ask a question or two to confirm your identity before releasing data — that check protects you, not us.
Analytics consent can be changed at any moment without writing to anyone: use the cookie preferences control, also available in the footer of every page.
11 Complaints
If you believe we have handled your personal data unlawfully, please tell us first — most issues are a misunderstanding that can be fixed the same week. You are, however, always entitled to go straight to the supervisory authority.
The competent authority for IT Julian Soft SIA is the Latvian Datu valsts inspekcija (State Data Inspectorate), Elijas iela 17, Rīga, LV-1050, Latvia. If you live or work in another EU or EEA country, or the alleged infringement took place there, you may lodge your complaint with the supervisory authority of that country instead.
12 Automated decision-making
We do not carry out automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you, within the meaning of Article 22 GDPR. Quotes, scopes and project decisions are made by a person reading what you wrote.
Where a system we build for a client contains automated logic — fraud scoring in a checkout, for example — that logic belongs to the client's own controller responsibilities, and their privacy notice governs it.
13 Children
This website and our services are directed at businesses and at adults acting in a professional capacity. They are not intended for people under the age of 16, and we do not knowingly collect personal data from children. If you believe a child has sent us personal data, contact us and we will delete it.
14 Changes to this policy
We update this policy when the way we process data actually changes — a new provider, a new legal basis, a different retention period — and not merely to refresh a date. Each revision replaces the previous one in full, and the current version is always the one published at this address.
The last updated date is shown at the top of this page; today it reads 5 August 2026. If a change materially affects how we handle data you have already given us, we will tell you directly by email before it takes effect, so that you have a genuine opportunity to object or withdraw consent.
15 Contact us
Questions about this policy, a data request, or a data processing agreement for an upcoming project — all go to the same place, and a person reads them.
- Email: hello@juliansoft.lv
- Phone: +371 20 000 000
- Post: IT Julian Soft SIA, Dārzu iela 25, Rēzekne, LV-4601, Latvia
If your message is about a new project rather than about data protection, the contact form is the faster route.