Privacy Policy
This Policy explains how TASK.LV, SIA, registration number 40103484175, processes personal data when you use WEBMasters.lv.
Version 1.0 · Effective from 2026-08-17
The Latvian version has legal priority; this is its approved translation.
Platform operator
- Legal name
- TASK.LV, SIA
- Registration number
- 40103484175
- Registered address
- Krišjāņa Valdemāra iela 145 k-1 – 1, Rīga, LV-1013, Latvia
- Contact
- task@task.lv · +371 20386420
1. Controller and scope
TASK.LV, SIA, registered at Krišjāņa Valdemāra iela 145 k-1 – 1, Rīga, LV-1013, Latvia, is the controller for Platform accounts, marketplace operation, security, support, marketing choices and legal compliance. Contact us at task@task.lv.
Customers and contractors may independently control personal data contained in their briefs, deliverables or business systems. They must give their own notices and establish a lawful basis where applicable.
2. Personal data we process
We collect data you provide, data generated through Platform use and limited data received from configured service providers.
- Account and identity data: name, email, role, company, registration details and verification status.
- Profile data: biography, skills, languages, work history, portfolio, location, contact details and uploaded files.
- Project data: orders, proposals, contracts, milestones, deliverables, messages, reviews, complaints and dispute evidence.
- Financial data: billing details, provider references, transaction status, balances, refunds and payout records; full card details are handled by the payment provider.
- Technical data: IP address, device and browser information, session identifiers, timestamps, security events and audit logs.
- Preference data: language, notification settings and consent choices.
- Integration data returned by login, identity, email, SMS, payment or translation providers when you choose the relevant feature.
- Support data: correspondence, diagnostic details and information needed to investigate a request.
3. Purposes and legal bases
We process only data reasonably necessary for the following purposes and rely on the legal basis appropriate to each activity.
- Perform the contract: create accounts, publish profiles and orders, support proposals, contracts, communications, payments and requested exports.
- Legitimate interests: secure the Platform, prevent fraud, moderate content, improve reliability, provide support and defend legal claims, balanced against user rights.
- Legal obligation: accounting, tax, sanctions, lawful authority requests, consumer protection and regulatory records.
- Consent: optional analytics or marketing cookies and optional communications where consent is required.
- Take requested pre-contract steps, such as displaying a proposal or verifying details before contracting.
- Protect vital interests in exceptional situations involving an immediate threat to a person.
- We do not repurpose data incompatibly without a new legal basis and, where required, a new notice or consent.
4. Cookies and similar technologies
Necessary cookies support sessions, security, language, CSRF protection and saved consent and operate without optional consent where permitted. Analytics and marketing categories remain disabled unless selected in the consent panel.
You may change browser controls and withdraw optional consent. Withdrawal does not affect earlier lawful processing; blocking necessary cookies may prevent sign-in or protected actions.
- Session cookie: authentication and continuity of the current visit.
- Consent cookie: records the policy version and selected categories for up to one year.
- Language session value: remembers the selected locale.
- Optional providers must not be activated before the relevant consent unless another lawful exemption applies.
5. Recipients and service providers
We disclose personal data only when necessary to operate a chosen feature, complete a transaction, comply with law, protect rights or follow your instruction. Providers act under contracts and access controls appropriate to their role.
Other marketplace users see information needed for public profiles, orders or a contract. Public pages do not intentionally display private contact, payment or authentication data.
- Hosting, database, security, backup and technical-support providers.
- Email, SMS, identity and social-login providers selected or configured for the feature.
- Payment providers, banks, accountants and fraud-prevention services for transactions.
- Translation or AI providers only when a user requests the corresponding function.
- Courts, regulators, law enforcement or professional advisers where disclosure is legally justified.
6. International transfers
Some configured providers may process data outside Latvia or the European Economic Area. We assess the destination and provider before enabling production processing.
Where required, transfers rely on an adequacy decision, approved standard contractual clauses or another lawful safeguard. You may request information about the applicable safeguard at task@task.lv.
- Only data necessary for the selected service is transferred.
- Provider access is limited by contract, credentials and technical controls.
- A feature remains disabled when required credentials, contracts or safeguards are not in place.
7. Retention
We retain personal data only for the purpose for which it was collected and for legal, accounting, security and dispute periods. The exact period depends on record type and an unresolved contract, complaint or legal hold.
After the applicable period, data is deleted or irreversibly anonymised. Backup copies rotate on a controlled schedule and are not restored for ordinary use after deletion.
- Active account and profile data: while the account is active and for a limited closure period.
- Contracts, invoices and transaction evidence: for the statutory accounting and claims periods, commonly up to ten years where Latvian law requires it.
- Authentication codes: until expiry and a short security-verification period.
- Security, webhook and immutable audit records: for a proportionate security, fraud and compliance period.
- Consent history: for the period needed to demonstrate the recorded choice and policy version.
8. Security
We use access controls, prepared database queries, CSRF protection, secure session cookies, password or code controls, restricted administration, audit records, local frontend dependencies and transport encryption where available.
No system is risk-free. Users must protect their email and devices, verify counterparties and promptly report suspected compromise to task@task.lv.
- Access is limited according to role and operational need.
- Sensitive configuration values are kept in server configuration and are not intentionally exposed to public pages.
- Incidents are assessed, contained, documented and notified where applicable law requires it.
9. Your rights
Subject to the GDPR and applicable law, you may exercise the following rights by contacting task@task.lv. We may request proportionate identity verification and normally respond within one month, subject to lawful extensions.
Rights may be limited where retention or refusal is required by law, protects another person's rights or is necessary for legal claims. We will explain an applicable limitation.
- Access your personal data and obtain information about its processing.
- Correct inaccurate data and complete incomplete data.
- Request erasure where no lawful reason requires continued processing.
- Restrict processing in the circumstances provided by law.
- Receive portable data you provided where processing is automated and based on consent or contract.
- Object to processing based on legitimate interests and object at any time to direct marketing.
- Withdraw consent at any time without affecting processing before withdrawal.
- Lodge a complaint with the competent supervisory authority and seek a judicial remedy.
10. Automated decisions and AI
The Platform does not currently make decisions producing legal or similarly significant effects solely by automated processing. Risk signals may support a human review but do not replace it where a significant decision is made.
AI translation is initiated by the user. Submitted text may be sent to the configured provider for that request and should not contain unnecessary secrets or special-category data.
11. Children
WEBMasters.lv is a professional marketplace and is not directed to children. Accounts may be created only by persons aged 18 or older.
If we learn that a child's data was submitted without a lawful basis, we will restrict and delete it as appropriate. Concerns may be sent to task@task.lv.
12. Policy changes and contact
We update this Policy when processing, providers or legal requirements change. Material changes are communicated through the Platform or registered contact details before they take effect where required.
Privacy requests and questions may be sent to task@task.lv or by post to TASK.LV, SIA, Krišjāņa Valdemāra iela 145 k-1 – 1, Rīga, LV-1013, Latvia. Please describe the account and request without sending unnecessary identity documents.
Supervisory and consumer authorities
You may complain about personal-data processing to the Data State Inspectorate of Latvia.