Privacy Policy
Last updated: 1 July 2026
1. General Information
This Privacy Policy explains how SIA IMNOTEKSI, operating the Sphera Kauguri sushi café ("we", "our", "us"), collects, uses, stores and protects your personal data when you use our website, place orders, or contact us.
We process personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and applicable Latvian law.
Data Controller
SIA IMNOTEKSI Registration No.: 40103368451 VAT No.: LV40103368451 Registered address: Kaivas iela 31/3-78, Rīga, LV-1021, Latvia E-mail: info@spherakauguri.lv Phone: +371 25 006 008
2. What Personal Data We Collect
- Name
- Telephone number (stored in normalised international format, +371…)
- E-mail address
- Delivery address, postal code, and the coordinates / delivery zone derived from your address (see §5)
- Order details and order history
- Customer profile data we build from your orders: number of orders, total amount spent, first and last order dates (see §7)
- Account data if you register: password (stored hashed, never in plain text)
- Payment status (full card details are handled by our payment provider — we never receive or store them)
- IP address, browser and device information
- Cookies and website-usage information (see §8)
3. Why We Process Your Data
- Processing, preparing and delivering your orders
- Managing customer accounts (if you register)
- Determining the delivery zone and fee for your address
- Customer support and order/delivery notifications (e-mail and SMS)
- Payment processing
- Maintaining a customer database (see §7)
- Protecting our business and customers from abuse, fraud and non-payment (see §7)
- Website security and troubleshooting
- Meeting legal and accounting obligations
- Improving our website and services
- Sending marketing offers where you have consented
4. Legal Basis for Processing
- Performance of a contract — processing, preparing and delivering your order; operating your account.
- Legal obligation — accounting and tax record-keeping.
- Legitimate interests — maintaining our customer database, preventing abuse/fraud (including the blacklist, §7), security logging, and improving our services.
- Consent — marketing communications and non-essential (analytics) cookies. You may withdraw consent at any time.
5. Recipients and Sub-processors
We do not sell your personal data. We share it only as necessary with:
- Payment provider — Klix (operated by AS Citadele banka): you are redirected to Klix to pay; card/bank-link data is handled by Klix, not by us.
- E-mail provider: to send order confirmations, invoices and status updates.
- SMS provider: to send order updates and the blacklist notification (§7).
- Address geocoding & maps — OpenStreetMap / Nominatim: when you enter a delivery address at checkout, it is sent to OpenStreetMap's Nominatim service to determine coordinates and your delivery zone; map tiles are also loaded from OpenStreetMap.
- Hosting provider: our website and data are hosted on servers located in the EU.
- Web analytics (only with your consent): Google Analytics 4 / Google Tag Manager, if enabled.
- Accounting provider and public authorities where required by law.
All processors are bound to process your data securely and only on our instructions.
5a. International Data Transfers
Our processors are located in the EU/EEA wherever possible. Where a processor (for example, web analytics or an SMS provider) transfers data outside the EEA, we rely on a European Commission adequacy decision or on Standard Contractual Clauses and appropriate safeguards.
6. Data Retention
We keep personal data only as long as necessary:
- Order & accounting records — 5 years, as required by Latvian accounting law.
- Customer database profile — up to 2 years from your last order, after which it is anonymised.
- Account data — until you delete your account (self-service deletion is available).
- Blacklist records — kept while the legitimate interest (business protection) applies; reviewed periodically.
- Blacklist attempt logs (including IP) — kept for a limited period for security, then deleted.
- Marketing consent — until you withdraw it.
- Cookies — see the Cookie Policy.
7. Customer Database and Fraud Prevention (Blacklist)
Customer database. On each completed order (including guest orders) we create or update a customer record — name, phone (normalised), e-mail, delivery-address history, number of orders, total spent, and first/last order dates — identified by your phone number or e-mail. This lets us fulfil orders, provide support, and manage our customer relationship (legitimate interest, and contract performance).
Fraud prevention / blacklist. To protect our business and other customers from abuse, repeated non-collection, fraud or misuse, we maintain a blacklist of phone numbers and/or e-mail addresses on the basis of our legitimate interest (GDPR Art. 6(1)(f)). At checkout, the phone and e-mail you enter are automatically compared (after normalisation) against this list; if there is a match, online ordering is declined and we may notify the affected number by SMS. We log such attempts (date, phone/e-mail, IP) for security purposes. This comparison is automated, but blacklist entries are added and reviewed by our staff — not by automated profiling. You have the right to object and to request a review — please contact us (§14).
8. Cookies
Our website uses:
- Necessary cookies (always active) — required for the site, cart and checkout to work.
- Analytics cookies (only with your consent) — help us understand and improve website usage.
When you first visit, our cookie banner lets you accept or decline non-essential cookies. You can change your choice at any time via "Cookie settings" in the website footer. For details, see our separate Cookie Policy.
9. Data Security
We apply appropriate technical and organisational measures to protect your data against unauthorised access, loss, alteration, disclosure or destruction — including HTTPS across the site, hashed passwords, access controls, and EU-based hosting. No online service can guarantee absolute security, but we work continuously to safeguard your information.
10. Your Rights
Under GDPR you have the right to: access your data; correct it; request deletion; restrict or object to processing; data portability; and withdraw consent at any time (where processing is based on consent). You may also lodge a complaint with the Latvian supervisory authority:
Datu valsts inspekcija — Elijas iela 17, Rīga, LV-1050 · pasts@dvi.gov.lv · www.dvi.gov.lv
11. Marketing Communications
If you have subscribed to marketing, you can unsubscribe at any time via the link in our e-mails or by contacting us.
12. Children's Privacy
Our services are not directed at children. Under Latvian law, the digital-consent age for information-society services is 13; we do not knowingly collect personal data from children under 13 without parental consent.
13. Third-Party Links
Our website may link to third-party services or payment providers. We are not responsible for their privacy practices — please review their policies separately.
14. Changes and Contact
We may update this Privacy Policy; the latest version and its effective date are always published on our website.
For any privacy question or to exercise your rights, contact:
SIA IMNOTEKSI · Kaivas iela 31/3-78, Rīga, LV-1021, Latvia E-mail: info@spherakauguri.lv · Phone: +371 25 006 008