Privacy Policy
Last updated: 5 August 2026
1. Controller
The personal data controller and service provider is:
- Name
- Maksims Miščenko
- Registration number
- 12083
- Address
- https://rekinu-kontrole.lv
- maksims@maxweb.lv
- VAT registered:
- No
2. Data we process
- Account data: name, email, workspace name and authentication information.
- Workspace data: client company details, uploaded XML/PDF invoices, validation results, statuses and drafts.
- Billing data: Stripe customer and subscription identifiers, plan and payment status. Rēķinu Kontrole never receives full card details.
- Technical data: security logs and the HMAC key used for public validator limits. The source IP is not stored in the rate-limit table.
- Support messages and information submitted by the user.
3. Purposes and legal bases
- Providing the service and processing invoices — performance of a contract (GDPR Art. 6(1)(b)).
- Payments, accounting and mandatory record retention — compliance with a legal obligation (c).
- Security, abuse prevention and service improvement — the controller's legitimate interests (f).
- Marketing messages will require separate consent if introduced.
4. Public validator
XML submitted without an account is processed during the request and is not saved in invoice storage. For abuse prevention, the IP address is converted to a one-way HMAC fingerprint before storage.
5. Recipients and transfers
The service uses Supabase (auth, database and files), Vercel (hosting), Stripe (billing) and the configured email provider. Data is not sold. Where processing occurs outside the EEA, an applicable transfer mechanism such as the European Commission's Standard Contractual Clauses is used.
6. Retention
- Public-validator XML is not stored; limit fingerprints are removed after the limit window and a short technical buffer.
- Account and workspace data is kept while the account is active and then deleted on request unless required by law or for a dispute.
- Billing records are retained for the period required by law.
7. Your rights
You may have rights of access, rectification, erasure, restriction, portability and objection. Send a request to the email below; a response is normally provided within one month. You may also complain to the Latvian Data State Inspectorate at dvi.gov.lv.
8. Security and changes
We use access controls, tenant-level RLS, private file storage and encrypted connections. No system is risk-free. Material policy changes will be announced in the service or by email.
Sources: Datu valsts inspekcija and Regulation (EU) 2016/679.