Skip to content

Legal

Privacy notice

This notice explains how Talvara SIA handles personal data when you visit this website, make an enquiry, apply for a role, or engage us for services.

Version
3.1
Effective from
1 April 2026
Last reviewed
1 April 2026

1. Who we are

Talvara SIA ("Talvara", "we", "us") is a company registered in Latvia under registration number 40203118447, with its registered office at Krāsotāju iela 14, 3rd floor, Riga, LV-1009, Latvia. For the processing described in this notice we act as the controller, unless stated otherwise.

Where we process personal data contained in a client's mail estate — mailbox content, archives, transport logs — we act as a processor on that client's documented instructions. That processing is governed by the data processing agreement between us and the client, not by this notice. If you are an employee or contact of one of our clients, please direct your request to that client, who is the controller of that data; we will support them in answering it.

We have appointed an internal privacy lead rather than a statutory data protection officer, having assessed that the criteria in Article 37 do not apply to us. You can reach that person at privacy@noor-mail.com or by post at the address above, marked "Privacy".

2. What we collect, why, and on what basis

We collect only what we need for a stated purpose. The table below sets out each category, the purpose and the lawful basis under Article 6.

Who What we hold Purpose Lawful basis
Website visitors Server log entries: IP address, timestamp, requested resource, user agent, referrer Serving the site, security monitoring, diagnosing faults Legitimate interests (Art. 6(1)(f)) — operating a secure website
Enquirers Name, organisation, work email, telephone, role, and what you tell us about your estate Responding to your enquiry, arranging and holding a scoping call Steps prior to entering a contract (Art. 6(1)(b)), or legitimate interests where you enquire on behalf of an organisation
Client contacts Business contact details, role, correspondence, access records and authorisations Delivering the engagement, support, change approval, billing Performance of a contract (Art. 6(1)(b)); legal obligation for accounting records (Art. 6(1)(c))
Job applicants CV, covering note, correspondence, interview notes, references where offered Assessing your application and communicating with you about it Steps prior to entering a contract (Art. 6(1)(b)); consent for retention in our talent pool
Suppliers Contact details of individuals at supplier organisations, contract records Managing the supply relationship Performance of a contract and legitimate interests

We do not seek special category data as defined in Article 9. Please do not include health, political, religious or similar information in an enquiry or application; if you do, we will delete it unless it is genuinely necessary — for example an adjustment you have asked for during recruitment, which we process on the basis of your explicit consent.

3. Cookies and analytics

This website sets no cookies. We run no analytics product, no advertising pixels, no session recording and no fingerprinting, and we do not attempt to identify individual visitors.

Web fonts are served from a third-party font provider, which means your browser connects to that provider and it will see your IP address as part of that request. Aside from that connection, no third party receives information about your visit from this site.

The enquiry form on our contact page is a static demonstration: it has no submit control, no destination and no storage. Nothing entered into it leaves your browser.

4. Who we share personal data with

We do not sell personal data, and we do not share it for anyone else's marketing. We disclose it only to:

  • Service providers who process on our behalf under Article 28 — hosting, email, accounting, applicant tracking and similar. Each is bound by a written processing agreement.
  • Professional advisers such as auditors and lawyers, where necessary and under a duty of confidentiality.
  • Public authorities, where we are required to disclose by law. Where we are legally permitted to tell you about such a request, we will.

A current list of the subprocessors used in delivering our services is maintained and available on request from privacy@noor-mail.com.

5. International transfers

Personal data we hold as a controller is stored and processed within the European Economic Area. Customer content processed under our service agreements is held within the European Union, as described in our compliance statement.

Where a transfer outside the EEA cannot be avoided, we rely on an adequacy decision where one applies, and otherwise on the European Commission's standard contractual clauses together with an assessment of the destination and any supplementary measures needed. We will tell an affected client before any such transfer is introduced into their service.

6. How long we keep it

Website server logs
90 days, then deleted
Enquiries that do not become engagements
24 months from last contact
Client contract and correspondence records
Duration of the engagement plus 6 years
Accounting records
As required by Latvian accounting and tax law
Unsuccessful applications
12 months, or 24 months in our talent pool with your consent
Customer content under a service agreement
Per the client's own retention schedule; deleted or returned at the end of the engagement at the client's election

Where a period expires but the data is subject to a legal hold or an ongoing dispute, we retain it until the matter concludes and then dispose of it.

7. Security

We apply technical and organisational measures appropriate to the risk, including encryption in transit and at rest, role-based access with least privilege, multi-factor authentication for all staff, time-bounded and logged administrative access, segregation of client environments, monitoring and alerting, background checks proportionate to role, and annual restore testing. Our information security management system is certified to ISO/IEC 27001:2022 for the scope stated on our about page.

No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to individuals, we will notify the competent supervisory authority within 72 hours where we are the controller, and will notify affected individuals where the risk is high. Where we act as a processor, we notify the client without undue delay so that they can meet their own obligations.

8. Your rights

Subject to the conditions in the GDPR, you have the right to: obtain confirmation of whether we process your data and a copy of it (Article 15); have inaccurate data corrected (Article 16); have data erased (Article 17); restrict processing (Article 18); receive data you provided in a portable format (Article 20); object to processing based on legitimate interests (Article 21); and withdraw consent at any time where processing relies on it, without affecting the lawfulness of processing before withdrawal.

We do not carry out automated decision-making producing legal or similarly significant effects, and we do not profile individuals.

To exercise a right, write to privacy@noor-mail.com. We will respond within one month, and will tell you if we need to extend that by up to two further months because the request is complex. We may ask for information to confirm your identity, and we will not use it for anything else. There is no charge unless a request is manifestly unfounded or excessive.

9. Complaints

If you are unhappy with how we have handled your personal data, please tell us first — we would rather fix it. You also have the right to complain to a supervisory authority, in the EU member state of your residence, your place of work, or where the alleged infringement occurred.

Our lead supervisory authority is the Data State Inspectorate of Latvia (Datu valsts inspekcija), Elijas iela 17, Riga, LV-1050, Latvia.

10. Changes to this notice

We review this notice at least annually. Where we make a material change we will update the version number and effective date above, and where the change materially affects an identified group — clients or active applicants — we will tell them directly rather than relying on this page.

Previous versions are available on request from privacy@noor-mail.com.