Privacy Policy

Last updated: 10 September 2026

1. Who we are

This website and the consulting practice behind it are operated by SIA “DanDubov Consulting”, registration number 45403058099, registered address Parka iela 4-1, Koknese, Aizkraukles novads, LV-5113, Latvia.

We are the controller (pārzinis) of the personal data described in this policy.

For any question about your data, or to exercise any of the rights in section 8, contact us:

We answer data protection requests within one month.

2. Visitors to this website

Cookies and analytics. We use Google Analytics 4 and Google Search Console, connected through the Google Site Kit plugin, to understand how the site is used. These set cookies in your browser. Analytics cookies are only set if you accept them; you can decline without losing access to any part of the site, and you can change your choice at any time by clearing your cookies and reloading the page.

Strictly necessary cookies - those that keep the site working and remember your cookie choice - are set without consent, as permitted by law.

Legal basis: consent for analytics cookies (Article 6(1)(a) GDPR); legitimate interest in operating a functioning website for strictly necessary cookies (Article 6(1)(f)).

Language detection. When you first open an English page, our server looks up the country of your IP address so that visitors from Latvia are shown the Latvian version of the site. The lookup goes through a geolocation service (ipapi.co, with country.is as a fallback); only the two-letter country code comes back, and it is cached for 24 hours against a hashed value of the address. Your IP address itself is not stored. A strictly necessary cookie (dd_lang, 180 days) remembers the language you chose so that we do not redirect you again.

Legal basis: legitimate interest in showing you the site in the right language (Article 6(1)(f)).

Contact form. If you write to us through the contact form we receive your name, email address and whatever you choose to put in the message. We use it to answer you and, if a working relationship follows, to carry on that conversation.

Legal basis: steps taken at your request before entering a contract (Article 6(1)(b)), or our legitimate interest in responding to enquiries (Article 6(1)(f)).

Booking a call. Meetings are booked through Calendly. When you book, Calendly collects your name, email address and the time you choose, and shares them with us. Calendly’s own privacy policy governs what it does with that data.

Newsletter. If you subscribe, we hold your email address in Mailchimp until you unsubscribe. Every email carries an unsubscribe link and unsubscribing is immediate and free.

Legal basis: consent (Article 6(1)(a)), which you may withdraw at any time.

3. Business contacts and prospective clients

This section matters if we have contacted you and you did not contact us first. We want to be plain about it.

What we hold. Your name, your role, your business contact details (work phone, work email, LinkedIn profile), the name of the company you work for, and notes about our conversations with you - including what was discussed and what we agreed to do next.

Where we got it. We do not buy contact lists. We compile information from sources that are public or that you have made public yourself:

  • the Latvian Register of Enterprises (Uzņēmumu reģistrs) and its published datasets;
  • public company information services such as firmas.lv, Lursoft and b2bhint;
  • your company’s own website and published materials;
  • public job advertisements;
  • LinkedIn and comparable professional networks;
  • referrals from people who know you, where we will always tell you who suggested we get in touch.

Why we hold it. To contact you about consulting services that we believe are relevant to your business, and to keep an accurate record of our own outreach so that we do not contact you more often than we should.

Legal basis: our legitimate interest in direct business-to-business marketing and in developing a professional client relationship (Article 6(1)(f) GDPR). We have weighed that interest against your rights, and we limit it in practice: we contact people only in a professional capacity about matters relevant to their work, we contact organisations rather than private individuals, we keep the frequency low, and we stop immediately on request.

Your right to object is absolute here. Under Article 21(2) GDPR, if you object to us processing your data for direct marketing, we must stop - with no balancing of interests and no reason required from you. Tell us by any means, including simply saying so on a call, and we will stop contacting you and add your details to a suppression list so that we do not contact you again by mistake. Keeping a minimal record of your objection is itself necessary in order to honour it.

4. Recording of telephone calls and meetings

We do not record cold calls. If we telephone you and you have not spoken to us before, that call is not recorded.

Scheduled calls and meetings may be recorded, and never without telling you first. Where a call or meeting is recorded, you will be told before the recording starts - either by a spoken statement from us or by an automatic announcement played by our telephone operator. Recording never begins before that notice.

If you would rather not be recorded, say so. We will stop the recording, delete anything already captured, and continue the conversation unrecorded. This has no effect on the meeting or on any work we may do together.

Why we record. For one purpose only: to keep an accurate record of what you told us about your business, so that our analysis and any proposal we write reflect your words rather than our memory of them. We do not use recordings for training material, for marketing, or for any public purpose, and we do not quote from them publicly.

Legal basis: our legitimate interest in an accurate record of a business discussion (Article 6(1)(f) GDPR). We have carried out and documented a balancing assessment before recording any call.

Who can hear them. Only Daniels Dubovskis. Recordings are held in encrypted storage and are not shared.

How long we keep them. Recordings are deleted [RETENTION PERIOD - INSERT] after the call, automatically and irreversibly. You may ask us to delete a recording sooner and we will do so.

5. Clients

When we work together we hold the contact details of the people we deal with, the correspondence between us, and the documents and information you give us for the engagement. We keep accounting records for as long as Latvian law requires - currently five years for accounting documents, and ten years for certain records under the Accounting Law.

Legal basis: performance of our contract with you (Article 6(1)(b)) and compliance with our legal obligations (Article 6(1)(c)).

6. How long we keep things

What How long
Analytics data As configured in Google Analytics 4, maximum 14 months
Contact form enquiries 12 months from our last exchange, unless a client relationship begins
Prospect contact records 24 months from the last contact, then reviewed and deleted if no relationship has developed
Suppression list (people who objected) Indefinitely - this is how we make sure we do not contact you again
Call and meeting recordings [RETENTION PERIOD - INSERT]
Newsletter subscriptions Until you unsubscribe
Client files and accounting records As required by Latvian law

7. Who else sees your data

We do not sell personal data and we do not share it for anyone else’s marketing.

We use service providers who process data on our behalf, under written agreements that require them to protect it:

  • Google (Analytics, Search Console, email) - website analytics and correspondence
  • Calendly - meeting bookings
  • Mailchimp - newsletter delivery
  • Microsoft - meeting hosting, transcription and file storage
  • Our telecommunications operator - call recording, where recording applies
  • Our web host and our accountant

Transfers outside the EEA. Some of these providers are established in the United States or process data there. Where that happens, the transfer is covered by the European Commission’s adequacy decision for the EU-US Data Privacy Framework or by Standard Contractual Clauses. You may ask us for details of the safeguards applying to any specific transfer.

We may also disclose data where we are legally required to do so.

8. Your rights

Under the GDPR you have the right to:

  • Access the personal data we hold about you, and receive a copy;
  • Rectify data that is wrong or incomplete;
  • Erase your data, where the law allows;
  • Restrict how we process it while a dispute is resolved;
  • Portability - receive data you gave us in a machine-readable form;
  • Object to processing based on our legitimate interests. Where the objection concerns direct marketing, we must stop, and we will.
  • Withdraw consent at any time, where we rely on it. This does not affect processing carried out before you withdrew.

To exercise any of these, write to info@dandubov.com. We do not charge for this and we will respond within one month.

You may also complain to the supervisory authority. In Latvia this is the Data State Inspectorate (Datu valsts inspekcija), Elijas iela 17, Rīga, LV-1050, telephone +371 67223131, email pasts@dvi.gov.lv, www.dvi.gov.lv. We would rather you came to us first, but that is your choice and not a condition.

9. Security

We keep personal data on access-controlled systems protected by strong authentication. Call recordings are encrypted. Access is limited to Daniels Dubovskis. We review this as the practice grows.

10. Changes to this policy

If we change how we handle personal data we will update this page and change the date at the top. Where a change materially affects you, we will tell you directly.