Zer.lv Privacy and Personal Data Processing Terms

These Terms explain how personal data is processed when Zer.lv is visited or used. They apply only to Zer.lv operated by SIA FIXLAB and do not describe any unrelated service.

Version 2026-09-04 · Terms · Privacy Terms · DPA

  1. Controller and contact. For account registration, subscription billing, direct support, service security and Zer.lv administration, the controller is SIA FIXLAB, registration No. 40203523267, legal address Liepu aleja 38, Babīte, Babītes pag., Mārupes nov., LV-2101, Latvia. The only contact for privacy questions and data-subject requests is fixlablv@gmail.com.
  2. Scope and sources. Data subjects may include website visitors, company owners, employees and other authorised users, support contacts, and persons whose information a subscribing company enters into its workspace. Data is obtained directly from the person, from the owner or another authorised workspace user, automatically from the browser, device and server logs, or from Google when the person chooses Google sign-in.
  3. Account and company data. We may process first and last name, email, phone number, password hash, language, Google account link identifier, company or individual-business status, company name, registration and VAT/PVN numbers, legal address, bank account, subscription status, invoices, consent and terms acknowledgement records, support correspondence, and registration source information supplied in the page address, such as campaign tags, referring page and advertising click identifier.
  4. Technical and security data. We may process IP address, date and time of access, user-agent, browser, operating system, device name or model where available, session and mobile-device identifiers, push token, authentication results, security events, actions in the service and diagnostic error information.
  5. Workspace data. Depending on how the subscribing company uses Zer.lv, workspace data may include its clients and contacts, phone numbers and emails, devices and serial or IMEI numbers, orders, defects, services, products, inventory, sales, finance records, documents, comments, attachments, employees, roles, salaries and event logs.
  6. Controller and processor roles. The subscribing company is normally the controller of personal data that it or its users enter or import about clients, employees, suppliers and contacts. SIA FIXLAB processes that workspace data on the company's documented instructions as a processor under the Zer.lv DPA. SIA FIXLAB is an independent controller for account, subscription, billing, direct support, platform-security and legal-compliance data.
  7. Purposes and legal bases. Contract performance under Article 6(1)(b) GDPR covers registration review, account and subscription administration, authentication, requested support and Zer.lv functionality. Article 6(1)(c) covers invoices, accounting, tax and other legal duties. Legitimate interests under Article 6(1)(f) cover service and account security, fraud and abuse prevention, audit trails, service reliability, troubleshooting and the establishment or defence of legal claims. Consent under Article 6(1)(a) is used only for optional product news and may be withdrawn at any time. Use of Zer.lv is not treated as blanket consent to every processing operation.
  8. Required data. Fields marked as required are needed to review registration, identify the account owner and administer the contract. Company details are required only for the applicable company-account type. Optional fields may be left blank. Without the required data, the account or requested function cannot be provided.
  9. Cookies and browser storage. Zer.lv uses only storage necessary for secure sessions, language, table layout, filters and other user preferences. Authentication cookies are protected with HttpOnly, SameSite and, on HTTPS, Secure attributes. Zer.lv currently does not use advertising cookies, behavioural advertising, third-party analytics pixels or email-open tracking. If this changes, these Terms and, where required, the consent mechanism will be updated before such use.
  10. Google services. If Google sign-in is chosen, Google Identity Services verifies the sign-in and provides Zer.lv with the verified email address and a unique Google account identifier; the Google password is never provided to Zer.lv. Gmail is used to send transactional account, security and billing email and receives the recipient address and necessary message content. If Android push notifications or integrity checks are enabled, Firebase Cloud Messaging and Google Play Integrity may process a push token and necessary device, application and integrity signals. Google processes data under its applicable terms and privacy information.
  11. Hosting and files. Zer.lv uses data-centre hosting in Germany within the European Economic Area. Uploaded comment attachments are kept outside publicly accessible web storage and protected by access controls, encryption, file size and type validation and automated malware checks. Protected database backups are created for recovery and retained for a limited period.
  12. Recipients and disclosure. Personal data is not sold or rented. It is disclosed only to authorised SIA FIXLAB personnel where access is necessary and logged, to the service providers identified in these Terms, to professional advisers bound by confidentiality, or to public authorities where disclosure is legally required. Workspace records are not sent through Gmail as part of normal operation.
  13. International transfers. The main Zer.lv workspace hosting is located in the EEA. Some necessary service providers, including Google services selected or used for account functions, may process limited data outside the EEA. Such transfers take place only where permitted by Chapter V GDPR: for example, where the European Commission has recognised an adequate level of data protection or the recipient is bound by approved safeguards such as the European Commission Standard Contractual Clauses. Information about the applicable transfer mechanism may be requested at fixlablv@gmail.com.
  14. Data not requested. Zer.lv does not request or store payment-card details. The service is not intended for health, biometric or other special-category data, criminal-conviction data, passwords to customer devices, or personal content unrelated to the business purpose. A subscribing company must not enter such data unless it has established necessity, a valid legal basis and appropriate safeguards. Zer.lv does not access the content of repaired devices unless a user intentionally uploads that content.
  15. Retention. Account and active workspace data is kept while the service is provided and is normally deleted within 30 days after a verified account-deletion request or the end of processing, unless retention is legally required. Encrypted backup remnants expire within 30 days. Security, login, action and transactional-email logs are normally kept for 60 days. Verification records are kept for short anti-abuse and audit periods. Invoices and other accounting source documents are kept for at least the statutory period, normally at least five years. Relevant records may be kept longer where necessary for an active incident, fraud investigation, dispute or legal claim.
  16. Rights. Subject to the GDPR conditions, a person may request access, correction, erasure, restriction and portability, object to processing based on legitimate interests or direct marketing, and withdraw marketing consent without affecting earlier lawful processing. Requests may be sent only to fixlablv@gmail.com. SIA FIXLAB replies without undue delay, normally within one month; the period may be extended by up to two further months for a complex or numerous request, with notice of the reason. A complaint may be submitted to the Latvian Data State Inspectorate at www.dvi.gov.lv.
  17. Workspace requests. A person whose data was entered by a subscribing company should normally contact that company, because it determines the purposes and means of the workspace processing. If SIA FIXLAB receives such a request as processor, it will forward or otherwise assist the relevant company and will not independently decide the request except where law requires otherwise.
  18. Owner and employee access. The company owner manages employee roles and permissions. Employees may access only the functions and company data permitted to their account and cannot export company data. Different company workspaces are logically isolated. Platform-supervisor or support access is limited to support, recovery, maintenance, security, abuse investigation or legal duties and is logged.
  19. Minors and automated decisions. Zer.lv is a B2B service intended for adult owners and authorised business users. SIA FIXLAB does not knowingly register a child as an account owner. A subscribing company remains responsible for the lawful processing of any minor's data in its own customer records. Zer.lv does not make solely automated decisions that produce legal or similarly significant effects.
  20. Security and incidents. Passwords are not stored in plaintext and are protected using modern one-way password hashing. Controls include HTTPS, protected session cookies, multi-factor email verification where required, rate limiting, origin checks, role-based access, company isolation, encryption of attachments and backups, restricted administrative access, audit logging, backups and security maintenance. No online service can promise zero risk. Suspected security or privacy incidents may be reported to fixlablv@gmail.com. SIA FIXLAB assesses incidents and notifies the competent authority, affected persons or the relevant workspace controller where required by law.
  21. Changes. The current version date is shown on this page. Material changes are announced through Zer.lv or to the account email before they take effect where reasonably possible. Earlier versions and acknowledgement records may be retained where needed to demonstrate compliance. If translations conflict, the Latvian version prevails.