Updated: 20.08.2025
In short: we collect business contact data and portal usage data to perform contracts, support customers, issue invoices, deliver goods, and comply with the law. You may request access, rectification, or deletion of your data, as well as object to processing for direct marketing.
Why do we request payment details? We use this information solely for accurate and accelerated processing of payments and invoicing. We do not have access to your bank account, do not use the data for other purposes, and do not share it with third parties unless required by law.
We do not collect sensitive personal data. Most information relates to business contacts and company details.
| Purpose | Example operations | Legal basis (GDPR) |
|---|---|---|
| Account registration and administration | Profile creation, access rights | Contract (Art. 6(1)(b)); Legitimate interest (Art. 6(1)(f)) |
| Order and delivery processing | Quotations, invoices, delivery, returns | Contract; Legal obligation (VAT/accounting – Art. 6(1)(c)) |
| Support and communication | Customer support, shipment status, notifications | Contract; Legitimate interest |
| Security and abuse prevention | Event logs, login monitoring | Legitimate interest; Legal obligation |
| B2B marketing | Product updates, newsletters | Consent (Art. 6(1)(a)); Legitimate interest; right to object |
| Product analytics | Anonymized usage statistics | Legitimate interest; for cookies – consent |
You may withdraw consent to marketing at any time via account settings or the “Unsubscribe” link in emails.
Our website bankoflamps.com uses cookies for proper functionality and (with your consent) for analytics and marketing. Upon your first visit, you will see a “Cookie Settings” banner where you can choose which categories of cookies to allow. You may change your choice later by clearing cookies in your browser settings and re-entering the site.
Analytical and marketing cookies are used only with your consent. Cookies do not contain personal data and cannot directly identify or contact you.
We share data only when necessary:
Data processing agreements (Art. 28 GDPR) are in place with all processors. We do not sell data.
If data is transferred outside the EEA, we apply safeguards in accordance with GDPR Chapter V: Standard Contractual Clauses (SCCs), third-country law assessments, and additional security measures.
| Data category | Retention period | Basis |
|---|---|---|
| Portal accounts | As long as the contract is valid; archived up to 3 years after deactivation | Contract / Legitimate interest |
| Financial documents | 10 years | Legal obligation (tax/accounting) |
| Support correspondence | up to 2 years | Legitimate interest |
| Marketing consents | as long as consent is active, plus 2 years for audit | Consent / Legal obligation to retain proof |
| Analytical log data | 6–24 months (aggregation/anonimization) | Legitimate interest |
We apply technical and organizational measures: encryption (TLS/SSL), access control, audit logs, backups, data minimization and need-to-know principles, staff training, confidentiality agreements with contractors.
Payment data is transmitted securely via encryption and secure communication channels. Bank of Lamps | SIA ATTA-1 does not have access to your bank accounts and does not store payment card data; the data is used solely for invoicing and payment processing.
You have the right to request access, rectification, erasure, restriction of processing, portability, objection to processing (including marketing). To exercise your rights, write to [email protected]. You may also lodge a complaint with a supervisory authority: the Data State Inspectorate (Latvia) or your local EU authority.
The services are intended for B2B and are not directed at children. We do not knowingly process data of persons under 16 years old.
We may update this Policy. The version published on the website replaces all previous editions; we notify of significant changes in the account and/or by email.
For questions or rights requests, write to: [email protected]. Postal address: Daugavgrivas street 77, LV-1007, Riga, Latvia.
Version: 20.08.2025 • Applicable law: GDPR and Latvian law • Language: EN