Legal
Privacy notice
This notice explains how Talvara SIA handles personal data when you visit this website, make an enquiry, apply for a role, or engage us for services.
- Version
- 3.1
- Effective from
- 1 April 2026
- Last reviewed
- 1 April 2026
1. Who we are
Talvara SIA ("Talvara", "we", "us") is a company registered in Latvia under registration number 40203118447, with its registered office at Krāsotāju iela 14, 3rd floor, Riga, LV-1009, Latvia. For the processing described in this notice we act as the controller, unless stated otherwise.
Where we process personal data contained in a client's mail estate — mailbox content, archives, transport logs — we act as a processor on that client's documented instructions. That processing is governed by the data processing agreement between us and the client, not by this notice. If you are an employee or contact of one of our clients, please direct your request to that client, who is the controller of that data; we will support them in answering it.
We have appointed an internal privacy lead rather than a statutory data protection officer, having assessed that the criteria in Article 37 do not apply to us. You can reach that person at privacy@noor-mail.com or by post at the address above, marked "Privacy".
2. What we collect, why, and on what basis
We collect only what we need for a stated purpose. The table below sets out each category, the purpose and the lawful basis under Article 6.
| Who | What we hold | Purpose | Lawful basis |
|---|---|---|---|
| Website visitors | Server log entries: IP address, timestamp, requested resource, user agent, referrer | Serving the site, security monitoring, diagnosing faults | Legitimate interests (Art. 6(1)(f)) — operating a secure website |
| Enquirers | Name, organisation, work email, telephone, role, and what you tell us about your estate | Responding to your enquiry, arranging and holding a scoping call | Steps prior to entering a contract (Art. 6(1)(b)), or legitimate interests where you enquire on behalf of an organisation |
| Client contacts | Business contact details, role, correspondence, access records and authorisations | Delivering the engagement, support, change approval, billing | Performance of a contract (Art. 6(1)(b)); legal obligation for accounting records (Art. 6(1)(c)) |
| Job applicants | CV, covering note, correspondence, interview notes, references where offered | Assessing your application and communicating with you about it | Steps prior to entering a contract (Art. 6(1)(b)); consent for retention in our talent pool |
| Suppliers | Contact details of individuals at supplier organisations, contract records | Managing the supply relationship | Performance of a contract and legitimate interests |
We do not seek special category data as defined in Article 9. Please do not include health, political, religious or similar information in an enquiry or application; if you do, we will delete it unless it is genuinely necessary — for example an adjustment you have asked for during recruitment, which we process on the basis of your explicit consent.
3. Cookies and analytics
This website sets no cookies. We run no analytics product, no advertising pixels, no session recording and no fingerprinting, and we do not attempt to identify individual visitors.
Web fonts are served from a third-party font provider, which means your browser connects to that provider and it will see your IP address as part of that request. Aside from that connection, no third party receives information about your visit from this site.
The enquiry form on our contact page is a static demonstration: it has no submit control, no destination and no storage. Nothing entered into it leaves your browser.
4. Who we share personal data with
We do not sell personal data, and we do not share it for anyone else's marketing. We disclose it only to:
- Service providers who process on our behalf under Article 28 — hosting, email, accounting, applicant tracking and similar. Each is bound by a written processing agreement.
- Professional advisers such as auditors and lawyers, where necessary and under a duty of confidentiality.
- Public authorities, where we are required to disclose by law. Where we are legally permitted to tell you about such a request, we will.
A current list of the subprocessors used in delivering our services is maintained and available on request from privacy@noor-mail.com.
5. International transfers
Personal data we hold as a controller is stored and processed within the European Economic Area. Customer content processed under our service agreements is held within the European Union, as described in our compliance statement.
Where a transfer outside the EEA cannot be avoided, we rely on an adequacy decision where one applies, and otherwise on the European Commission's standard contractual clauses together with an assessment of the destination and any supplementary measures needed. We will tell an affected client before any such transfer is introduced into their service.
6. How long we keep it
Where a period expires but the data is subject to a legal hold or an ongoing dispute, we retain it until the matter concludes and then dispose of it.
7. Security
We apply technical and organisational measures appropriate to the risk, including encryption in transit and at rest, role-based access with least privilege, multi-factor authentication for all staff, time-bounded and logged administrative access, segregation of client environments, monitoring and alerting, background checks proportionate to role, and annual restore testing. Our information security management system is certified to ISO/IEC 27001:2022 for the scope stated on our about page.
No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to individuals, we will notify the competent supervisory authority within 72 hours where we are the controller, and will notify affected individuals where the risk is high. Where we act as a processor, we notify the client without undue delay so that they can meet their own obligations.
8. Your rights
Subject to the conditions in the GDPR, you have the right to: obtain confirmation of whether we process your data and a copy of it (Article 15); have inaccurate data corrected (Article 16); have data erased (Article 17); restrict processing (Article 18); receive data you provided in a portable format (Article 20); object to processing based on legitimate interests (Article 21); and withdraw consent at any time where processing relies on it, without affecting the lawfulness of processing before withdrawal.
We do not carry out automated decision-making producing legal or similarly significant effects, and we do not profile individuals.
To exercise a right, write to privacy@noor-mail.com. We will respond within one month, and will tell you if we need to extend that by up to two further months because the request is complex. We may ask for information to confirm your identity, and we will not use it for anything else. There is no charge unless a request is manifestly unfounded or excessive.
9. Complaints
If you are unhappy with how we have handled your personal data, please tell us first — we would rather fix it. You also have the right to complain to a supervisory authority, in the EU member state of your residence, your place of work, or where the alleged infringement occurred.
Our lead supervisory authority is the Data State Inspectorate of Latvia (Datu valsts inspekcija), Elijas iela 17, Riga, LV-1050, Latvia.
10. Changes to this notice
We review this notice at least annually. Where we make a material change we will update the version number and effective date above, and where the change materially affects an identified group — clients or active applicants — we will tell them directly rather than relying on this page.
Previous versions are available on request from privacy@noor-mail.com.