Skip to content

Privacy and Cookie Policy

On this page

Effective from 26 September 2026 · Version dated 26 September 2026

1. Who is responsible for the data

The controller of personal data is Oleksandr Mozghovoi, a natural person carrying out economic activity as a self-employed person (saimnieciskās darbības veicējs), Aveņu iela 1, Krāslava, LV-5601, Latvia, [email protected], +371 28759510 (hereinafter “we”). Personal data is processed in accordance with the General Data Protection Regulation (GDPR) and the Personal Data Processing Law of Latvia (Fizisko personu datu apstrādes likums). No data protection officer has been appointed: under Article 37(1) GDPR, we are not required to have one.

2. What data we process and why

Your name, email, phone number and address or parcel locker are required to conclude and perform the contract: without them, we cannot accept the order. Any other data is provided at your discretion. We receive data from you; if you sign in with Google, Google provides us with your name, email address and Google account ID; we receive the payment status from Montonio and the delivery status from the carriers.

DataPurposeLegal basisRetention period
First name, surname, email, phone number, country, address or parcel locker, order contents, amount, payment method, delivery statusTo accept and deliver the order, issue a receipt and respond to complaintsPerformance of a contract; legal obligation (accounting)10 years: order data forms part of our accounting records under the Accounting Law of Latvia (Grāmatvedības likums) and Cabinet of Ministers Regulation No. 322. We keep it even after the account is deleted and erase it once this period ends
Account: email, password (hashed) or your Google account ID if you sign in with Google, name, order history, favourites, saved cart, languageCustomer account, repeat ordersContract (at your request)As long as the account exists. You can delete it in your account or on request; we delete accounts that have not been logged in to for 3 years. Order data stays in our accounting records for 10 years (see the row above)
Promo code, number of the first orderTo check that the −10% code has been used only onceLegitimate interest: prevention of abuse3 years
Referral link code in the orderTo credit the order to the partner (for example, a blogger) whose link brought you to the websiteLegitimate interest: tracking referral links; we do not share your data with the partnerSame as order data
Email from an unpaid orderOne “Finish your order” reminderLegitimate interest: reminding you of an order you started; it is a single email with no advertising, and you can object by replying to it7 days, then deleted
Email for the newsletterNew arrivals and sets, if you have subscribedConsent: only by ticking a separate box; unsubscribe with a single link in any newsletter emailUntil consent is withdrawn
Email for “notify me when available” and “suggest a fragrance”To write to you when the fragrance becomes availableConsentUntil the email is sent, 12 months at most
Messages to the AI assistant on the websiteTo help choose a fragrance and answer questionsLegitimate interest: helping you choose a fragrance; do not enter unnecessary personal data in the chat90 days, then deleted; only the number of conversations remains in the statistics
Emails and complaints sent to [email protected]To respond and resolve the matterContract; legitimate interest3 years
Gift recipient’s data (name, phone number, address)Delivery onlyPerformance of a contract; inform the recipient of this policySame as order data
Technical server logs: IP address, time, requested pageSecurity, protection against attacks, troubleshootingLegitimate interest30 days
Website error and performance reports (Sentry): error text, browser and operating system, browser language, page URL without parameters; no IP address, cookies or form content, and email addresses and phone numbers in error text are maskedTo fix errorsLegitimate interestUp to 90 days
Visit statistics (Umami on our server) and the website’s own events: product views, additions to the cart, checkouts, searches with no results, visits via referral linksTo understand which pages and products perform wellLegitimate interest; Umami sets no cookies, the IP address is used at the time of the visit to determine the country and is not stored, visit records are pseudonymised; our own events are linked only to a random session ID of the browser tab, not to your account12 months, then aggregate figures only

Deleted data remains in daily backups for up to 30 more days. We keep monthly database backups for 10 years together with the accounting records and use them only to restore data after a failure or where required by law. We do not request special categories of personal data and do not use automated decision-making that produces legal effects. The website is not intended for persons under the age of 18.

3. Who we share data with

Only with those without whom the order or a feature you have chosen cannot work, and only the minimum necessary:

  • Montonio Finance UAB (Lithuania) — payment: order number and amount, name, email and phone number; card details are entered on Montonio’s side. Montonio processes payment data as an independent controller under its own privacy policy and provides us with the payment status and payment ID.
  • Carriers Omniva, DPD, Smartposti, Latvijas Pasts, Unisend (via Montonio Shipping) — name, phone number, email, address or parcel locker; independent controllers.
  • Hetzner Online GmbH (Germany) — hosting of the website, database and backups, servers in the EU.
  • Google — the mailbox that receives emails sent to [email protected].
  • Google Ireland Limited (Ireland) — sign-in with Google, only if you choose it: Google provides us with your name, email address and account ID; we never see your Google password. Google’s own privacy policy applies on its sign-in page.
  • Resend (Resend, Inc., USA; emails are sent from the EU region in Ireland) — delivery of emails about orders, your account and back-in-stock fragrances, and of the newsletter: email address, name, email content.
  • Anthropic (USA) — processing of messages to the AI assistant: conversation text without your registration details.
  • Cloudflare (USA/EU) — DNS, website protection and email forwarding.
  • Functional Software Inc. (Sentry, USA; data stored in the EU region) — error and performance reports without IP addresses or personal data (see section 2).
  • Our accountant and the State Revenue Service (Valsts ieņēmumu dienests) — receipt data, as required by law.

We have concluded a data processing agreement with every processor that handles data on our behalf. We do not sell data or share it for third-party advertising.

4. Transfers outside the EU

The main data is stored in the EU. The US companies Resend, Anthropic, Cloudflare, Sentry and Google receive data on the basis of the European Commission’s adequacy decision (EU–U.S. Data Privacy Framework) where the company is certified under it, and otherwise on the basis of the European Commission’s standard contractual clauses (Articles 45 and 46 GDPR). A copy of the standard contractual clauses can be requested at [email protected].

5. Your rights as a data subject

You may request access to your data, rectification, erasure, restriction of processing and data portability, object to processing based on legitimate interest, and withdraw your consent at any time — this does not affect the lawfulness of processing before the withdrawal. We are required to keep the data of paid orders for 10 years as accounting records, so it cannot be erased before that period ends. Write to [email protected]: we will respond without delay and no later than one month; for complex requests, this period may be extended by up to two further months, and we will inform you of this. You may lodge a complaint with the Data State Inspectorate of Latvia (Datu valsts inspekcija, dvi.gov.lv) or with the supervisory authority of your country.

6. Security

The connection to the website is encrypted (HTTPS), passwords are stored as hashes, access to the admin panel is protected by a second authentication factor, and the database is backed up daily in the EU. We will notify you and the Data State Inspectorate of any personal data breach that poses a high risk to your rights within the time limits set by the GDPR.

7. Cookies and browser storage

We do not use advertising cookies or third-party tracking cookies. For the website and the features you choose to work, your browser stores:

WhatPurposeHow long
Cookie wispera_localeRemembers the language you selected1 year
Cookie wispera_customerKeeps you signed in to your accountUntil you sign out, no longer than 30 days
Cookie wispera_signed_inA sign-in flag without any account data: lets the browser save your cart to your accountSame as wispera_customer
Cookie wispera_google_oauthProtects sign-in with Google (one-time check codes), only when you sign in with GoogleUp to 10 minutes, deleted right after sign-in
Cookie wispera_assistantChat session with the assistant and the message limit12 hours
Cookie wispera_refThe code of the referral link that brought you to the website, to credit the order to the partnerUntil you close the browser
Cookie __cf_bm (Cloudflare)Technical protection of the website against bots30 minutes
localStorage: wispera:cart, wispera:cart-intentKeeps the products in your cart between visitsUntil the cart is emptied
localStorage: wispera:lang-bar-dismissedStops offering to switch the language once you have declinedUntil you clear the website’s data in your browser
sessionStorage: wispera:checkout-draft, wispera:order-cleared:*Keeps the contact details and address you entered at checkout if the page reloads; removes the purchased items from the cart after paymentUntil you close the tab; the draft is deleted right after payment
sessionStorage: wispera:assistant:v1Keeps your chat with the assistant as you move between pagesUntil you close the tab

These cookies and records are necessary for the website or a feature you have chosen to work, so no consent banner is shown (Article 7.1 of the Law on Information Society Services of Latvia; Article 5(3) of Directive 2002/58/EC). Visit statistics are collected by Umami without cookies and without identifying the visitor, and by the website’s own events: for these, the browser tab keeps a random session ID and the campaign tags from the link in sessionStorage (wispera:sid, wispera:utm, wispera:once:*) — without your IP address, not linked to your account, until you close the tab. Staff signing in to the admin panel receive the cookie wispera_admin (valid for up to 12 hours after the last activity); it is never set for customers. We send the newsletter only if you tick a separate box, and you can unsubscribe with a single link in any newsletter email. The payment service provider may set its own technical cookies on its payment page, and Google on its sign-in page.

8. Changes

We publish each new version on this page with its date. In the event of material changes affecting accounts or the newsletter, we will notify you by email.