1. Controller and scope
SIA Unda, registration number 59203002531, legal address Jūras iela 60, Engure, Tukuma Municipality, LV-3113, Latvia, is the controller of personal data described in this policy. You can contact us at info@unda.lv or +371 63181117.
This policy builds on the Company’s previous Privacy Policy and explains the processing connected with the current Diplomats corporate website.
2. Information we process
Depending on how you use the website, we may process:
- name, email address, telephone number and correspondence;
- company identity, registration, address, contact, commercial and financial information submitted through business forms;
- career interests, CV information and supporting documents;
- Customer Verification Form answers, declarations and uploaded PDF, JPEG or PNG documents;
- IP-derived security identifiers, request times, consent records, form status and technical error or delivery logs.
3. Purposes and legal bases
We process information to respond to enquiries, take steps towards or administer a business relationship, assess partnership and customer-verification submissions, recruit personnel, meet legal obligations, protect the website and Company, maintain evidence of communications, and establish or defend legal claims.
The legal basis depends on the context and may be steps at your request before a contract, performance of a contract, compliance with a legal obligation, the Company’s legitimate interests, or consent where the website specifically requests it. Withdrawing consent does not affect processing already carried out and does not stop processing supported by another legal basis.
4. Website forms and documents
Contact and business forms may send the submitted information to authorised SIA Unda personnel and store it in the website’s Payload CMS. The Customer Verification Form may generate a PDF summary, retain submitted documents in private storage and send internal and applicant email notifications when the configured mail service is available.
Career applications store the application, CV and optional supporting document in private Careers collections and may email the recruitment recipients. Career files are not placed in the public media library.
Uploaded files are checked for permitted type and size. They are not currently antivirus-scanned, and we do not claim that they are.
5. Website security and technology
The website uses signed, HttpOnly form-session cookies, CSRF protection, same-origin checks, rate limiting, honeypot checks and technical logs. Cloudflare Turnstile support exists for form security, but real Turnstile keys are not configured in the current local environment; where configured, the widget is loaded only on a protected form and Cloudflare processes the technical data needed for the security check.
Payload CMS stores website records and private submissions. Website administrators use a Payload authentication cookie. The website has an internal event data layer, but no analytics or marketing provider is currently installed. The Company film uses YouTube’s privacy-enhanced domain and is requested only after a visitor selects Play.
6. Recipients and processors
Access is limited to authorised SIA Unda personnel who need the information for recruitment, customer, commercial, finance, administration, legal or technical duties. Information may also be processed by website hosting and technical-maintenance providers, configured email providers, Cloudflare when Turnstile is enabled, and professional advisers or public authorities where required by law.
Data is not currently transferred to D-Bridge through an active integration. If such an integration is implemented later, this policy and the applicable notices must be updated before that transfer begins.
7. Retention
Customer Verification Form drafts saved in the browser expire after 12 hours. Its signed form session lasts up to 8 hours and the private success receipt up to 30 minutes. Cookie-consent records remain until they are replaced, withdrawn or cleared in the browser.
Submitted applications, generated summaries, uploads and related CMS records currently have no automatic deletion schedule. They are retained only while needed for the stated purpose, applicable legal obligations, response handling or legal claims and must be reviewed manually. Contractual and accounting records are kept for the periods required by law; supporting accounting records are generally retained for at least five years. This policy does not invent a shorter operational period that has not yet been approved and configured.
8. Your rights
Subject to the GDPR and applicable law, you may request access, correction, deletion, restriction, portability, or object to processing. You may withdraw consent where processing relies on consent. We may ask for information needed to verify your identity and locate the relevant records.
Send a request to info@unda.lv or to SIA Unda at the legal address above. If you believe your rights have been infringed, you may complain to the Latvian Data State Inspectorate at dvi.gov.lv.
9. Automated decisions and transfers
The website does not use personal data for automated decisions producing legal or similarly significant effects. We do not state that personal data never leaves the EEA: any configured service and its transfer safeguards must be assessed before production use.
10. Changes and contact
We may update this policy when website functions, processors or legal requirements change. The current version and update date are published on this page. Privacy questions may be sent to info@unda.lv.