Privacy and Cookie Policy
On this page
Effective from 26 September 2026 · Version dated 26 September 2026
1. Who is responsible for the data
The controller of personal data is Oleksandr Mozghovoi, a natural person carrying out economic activity as a self-employed person (saimnieciskās darbības veicējs), Aveņu iela 1, Krāslava, LV-5601, Latvia, [email protected], +371 28759510 (hereinafter “we”). Personal data is processed in accordance with the General Data Protection Regulation (GDPR) and the Personal Data Processing Law of Latvia (Fizisko personu datu apstrādes likums). No data protection officer has been appointed: under Article 37(1) GDPR, we are not required to have one.
2. What data we process and why
Your name, email, phone number and address or parcel locker are required to conclude and perform the contract: without them, we cannot accept the order. Any other data is provided at your discretion. We receive data from you; if you sign in with Google, Google provides us with your name, email address and Google account ID; we receive the payment status from Montonio and the delivery status from the carriers.
| Data | Purpose | Legal basis | Retention period |
|---|---|---|---|
| First name, surname, email, phone number, country, address or parcel locker, order contents, amount, payment method, delivery status | To accept and deliver the order, issue a receipt and respond to complaints | Performance of a contract; legal obligation (accounting) | 10 years: order data forms part of our accounting records under the Accounting Law of Latvia (Grāmatvedības likums) and Cabinet of Ministers Regulation No. 322. We keep it even after the account is deleted and erase it once this period ends |
| Account: email, password (hashed) or your Google account ID if you sign in with Google, name, order history, favourites, saved cart, language | Customer account, repeat orders | Contract (at your request) | As long as the account exists. You can delete it in your account or on request; we delete accounts that have not been logged in to for 3 years. Order data stays in our accounting records for 10 years (see the row above) |
| Promo code, number of the first order | To check that the −10% code has been used only once | Legitimate interest: prevention of abuse | 3 years |
| Referral link code in the order | To credit the order to the partner (for example, a blogger) whose link brought you to the website | Legitimate interest: tracking referral links; we do not share your data with the partner | Same as order data |
| Email from an unpaid order | One “Finish your order” reminder | Legitimate interest: reminding you of an order you started; it is a single email with no advertising, and you can object by replying to it | 7 days, then deleted |
| Email for the newsletter | New arrivals and sets, if you have subscribed | Consent: only by ticking a separate box; unsubscribe with a single link in any newsletter email | Until consent is withdrawn |
| Email for “notify me when available” and “suggest a fragrance” | To write to you when the fragrance becomes available | Consent | Until the email is sent, 12 months at most |
| Messages to the AI assistant on the website | To help choose a fragrance and answer questions | Legitimate interest: helping you choose a fragrance; do not enter unnecessary personal data in the chat | 90 days, then deleted; only the number of conversations remains in the statistics |
| Emails and complaints sent to [email protected] | To respond and resolve the matter | Contract; legitimate interest | 3 years |
| Gift recipient’s data (name, phone number, address) | Delivery only | Performance of a contract; inform the recipient of this policy | Same as order data |
| Technical server logs: IP address, time, requested page | Security, protection against attacks, troubleshooting | Legitimate interest | 30 days |
| Website error and performance reports (Sentry): error text, browser and operating system, browser language, page URL without parameters; no IP address, cookies or form content, and email addresses and phone numbers in error text are masked | To fix errors | Legitimate interest | Up to 90 days |
| Visit statistics (Umami on our server) and the website’s own events: product views, additions to the cart, checkouts, searches with no results, visits via referral links | To understand which pages and products perform well | Legitimate interest; Umami sets no cookies, the IP address is used at the time of the visit to determine the country and is not stored, visit records are pseudonymised; our own events are linked only to a random session ID of the browser tab, not to your account | 12 months, then aggregate figures only |
Deleted data remains in daily backups for up to 30 more days. We keep monthly database backups for 10 years together with the accounting records and use them only to restore data after a failure or where required by law. We do not request special categories of personal data and do not use automated decision-making that produces legal effects. The website is not intended for persons under the age of 18.
3. Who we share data with
Only with those without whom the order or a feature you have chosen cannot work, and only the minimum necessary:
- Montonio Finance UAB (Lithuania) — payment: order number and amount, name, email and phone number; card details are entered on Montonio’s side. Montonio processes payment data as an independent controller under its own privacy policy and provides us with the payment status and payment ID.
- Carriers Omniva, DPD, Smartposti, Latvijas Pasts, Unisend (via Montonio Shipping) — name, phone number, email, address or parcel locker; independent controllers.
- Hetzner Online GmbH (Germany) — hosting of the website, database and backups, servers in the EU.
- Google — the mailbox that receives emails sent to [email protected].
- Google Ireland Limited (Ireland) — sign-in with Google, only if you choose it: Google provides us with your name, email address and account ID; we never see your Google password. Google’s own privacy policy applies on its sign-in page.
- Resend (Resend, Inc., USA; emails are sent from the EU region in Ireland) — delivery of emails about orders, your account and back-in-stock fragrances, and of the newsletter: email address, name, email content.
- Anthropic (USA) — processing of messages to the AI assistant: conversation text without your registration details.
- Cloudflare (USA/EU) — DNS, website protection and email forwarding.
- Functional Software Inc. (Sentry, USA; data stored in the EU region) — error and performance reports without IP addresses or personal data (see section 2).
- Our accountant and the State Revenue Service (Valsts ieņēmumu dienests) — receipt data, as required by law.
We have concluded a data processing agreement with every processor that handles data on our behalf. We do not sell data or share it for third-party advertising.
4. Transfers outside the EU
The main data is stored in the EU. The US companies Resend, Anthropic, Cloudflare, Sentry and Google receive data on the basis of the European Commission’s adequacy decision (EU–U.S. Data Privacy Framework) where the company is certified under it, and otherwise on the basis of the European Commission’s standard contractual clauses (Articles 45 and 46 GDPR). A copy of the standard contractual clauses can be requested at [email protected].
5. Your rights as a data subject
You may request access to your data, rectification, erasure, restriction of processing and data portability, object to processing based on legitimate interest, and withdraw your consent at any time — this does not affect the lawfulness of processing before the withdrawal. We are required to keep the data of paid orders for 10 years as accounting records, so it cannot be erased before that period ends. Write to [email protected]: we will respond without delay and no later than one month; for complex requests, this period may be extended by up to two further months, and we will inform you of this. You may lodge a complaint with the Data State Inspectorate of Latvia (Datu valsts inspekcija, dvi.gov.lv) or with the supervisory authority of your country.
6. Security
The connection to the website is encrypted (HTTPS), passwords are stored as hashes, access to the admin panel is protected by a second authentication factor, and the database is backed up daily in the EU. We will notify you and the Data State Inspectorate of any personal data breach that poses a high risk to your rights within the time limits set by the GDPR.
7. Cookies and browser storage
We do not use advertising cookies or third-party tracking cookies. For the website and the features you choose to work, your browser stores:
| What | Purpose | How long |
|---|---|---|
Cookie wispera_locale | Remembers the language you selected | 1 year |
Cookie wispera_customer | Keeps you signed in to your account | Until you sign out, no longer than 30 days |
Cookie wispera_signed_in | A sign-in flag without any account data: lets the browser save your cart to your account | Same as wispera_customer |
Cookie wispera_google_oauth | Protects sign-in with Google (one-time check codes), only when you sign in with Google | Up to 10 minutes, deleted right after sign-in |
Cookie wispera_assistant | Chat session with the assistant and the message limit | 12 hours |
Cookie wispera_ref | The code of the referral link that brought you to the website, to credit the order to the partner | Until you close the browser |
Cookie __cf_bm (Cloudflare) | Technical protection of the website against bots | 30 minutes |
localStorage: wispera:cart, wispera:cart-intent | Keeps the products in your cart between visits | Until the cart is emptied |
localStorage: wispera:lang-bar-dismissed | Stops offering to switch the language once you have declined | Until you clear the website’s data in your browser |
sessionStorage: wispera:checkout-draft, wispera:order-cleared:* | Keeps the contact details and address you entered at checkout if the page reloads; removes the purchased items from the cart after payment | Until you close the tab; the draft is deleted right after payment |
sessionStorage: wispera:assistant:v1 | Keeps your chat with the assistant as you move between pages | Until you close the tab |
These cookies and records are necessary for the website or a feature you have chosen to work, so no consent banner is shown (Article 7.1 of the Law on Information Society Services of Latvia; Article 5(3) of Directive 2002/58/EC). Visit statistics are collected by Umami without cookies and without identifying the visitor, and by the website’s own events: for these, the browser tab keeps a random session ID and the campaign tags from the link in sessionStorage (wispera:sid, wispera:utm, wispera:once:*) — without your IP address, not linked to your account, until you close the tab. Staff signing in to the admin panel receive the cookie wispera_admin (valid for up to 12 hours after the last activity); it is never set for customers. We send the newsletter only if you tick a separate box, and you can unsubscribe with a single link in any newsletter email. The payment service provider may set its own technical cookies on its payment page, and Google on its sign-in page.
8. Changes
We publish each new version on this page with its date. In the event of material changes affecting accounts or the newsletter, we will notify you by email.