Privacy and Cookie Policy
Last updated - May 26, 2026
In this Privacy and Cookie Policy we explain how we process personal data when you navigate through our Website.
This Privacy Policy describes policies and practices regarding our collection and use of Your personal data, as well as sets forth Your privacy rights. We recognise that personal data protection is an ongoing responsibility, and we may from time to time update this Privacy Policy, as we undertake new personal data processing practices.
We process Your personal data in compliance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter – “GDPR”).
Please take your time to carefully read this Privacy and Cookie Policy and, if you have any questions, please feel free to contact us.
1. DEFINITIONS
The following terms are defined as follows in this Privacy Policy:
- We / Controller - DECTA stands for DECTA SIA, company number 50103962441, registered office address: Roberta Hirsa Street 1, Riga, Latvija, LV-1045, e-mail: data.protection@decta.com;
- You - visitors of our Website.
- Website - the website accessible at https://hub.decta.com
- Policy - this Privacy and Cookie policy.
2. WHAT PERSONAL DATA DO WE COLLECT, FOR WHAT PURPOSES, AND ON WHAT LEGAL GROUNDS?
We obtain data directly from your device and browser when you visit and navigate our Website. We do not use user session recording tools or track individual user behavior (such as mouse movements or keystrokes).
We process your data on the following legal grounds, depending on the data category:
A. Server Logs (Nginx)
When you access our website, our Nginx reverse proxy automatically logs certain technical information. This is standard for almost all websites to ensure security and stability.
- What we collect: IP Address (Anonymized where possible), Browser type and version, the page you visited and the time of the visit, Referrer URL.
- Purpose: Security monitoring, fraud prevention, and ensuring the basic functioning of the Website.
- Legal Basis: Legitimate Interest (Article 6(1)(f) of the GDPR).
- Duration of data processing: 52 days
B. Website Analytics (Plausible)
Additionally, we use Plausible Community Edition to understand our website traffic. Plausible is a privacy-first analytics tool. It does not track individual users across sessions or across different websites.
- What we collect: Aggregated, anonymous traffic data.
- Purpose: To monitor the service we provide to you and to design improvements to our Website.
General Data Retention Rules
In those cases when the data storage period is not specifically indicated, your data will be stored no longer than necessary for the achievement of the purposes for which the data were collected, or for a period set by legal acts.
After the end of your data processing and storage period set in this Policy, we destroy your data or anonymise them irreversibly and reliably as soon as possible.
Your personal data can be stored for a period longer than indicated in this Policy only when:
- your data is necessary for the proper administration of damages, examination and settlement of a dispute, complaint, the protection of our legitimate interests or those of third parties;
- that is necessary in order that we could defend ourselves from existing or threatening demands, claims or legal actions and exercise our rights;
- there are reasonable suspicions of violations, illegal activities, which are or may be a subject to investigation;
- this is necessary for ensuring the functioning, resilience, integrity of backup copies, information systems, traceability of operations, statistical and other similar purposes;
- there are other grounds provided for in legal acts.
3. COOKIE POLICY
What are cookies?
A cookie is a small text file that is stored on a computer or other device (for example, a mobile phone) when you visit a website. A text file contains information that is used to improve the user experience for the visitors to a particular website. The cookie collects data about website visits, helps to improve the functionality of the website and provide relevant content.
What cookies are used by DECTA and for what purposes are they used?
We use only one category of cookies - necessary cookies, which are placed automatically, without obtaining your consent.
Necessary Cookies: These cookies are essential to the operation of our Website and our services and make it usable and secure by enabling basic functions, such as page navigation and access to the secure areas of our Website. The Website cannot function properly without these cookies.
List of cookies used on the Website:
| Name | Purpose | Expiry |
|---|---|---|
csrftoken |
Security: Protects against Cross-Site Request Forgery (CSRF) attacks. | 1 Year |
sessionid |
Functionality: Provided by Django to maintain your preferences during a visit. (Note: Since login is disabled, this contains no user-identifiable account data). | Session |
messages |
Functionality: Used to display temporary one-time notifications to you (e.g., "Form submitted successfully"). | Session |
When visiting hub.decta.com, the browser may automatically transmit certain cookies that were previously set by other DECTA websites within the decta.com domain. Hub.decta.com does not use these cookies for analytics, marketing, or profiling purposes and does not perform any further processing of them. The portal uses only strictly necessary cookies required for its operation and security.
Managing cookies
Considering that only strictly necessary cookies are used on this website, these cookies are placed automatically and you do not have an option to accept or reject these cookies via a cookie banner. You can set your browser to block or alert you about these cookies, but some parts of the site will not then work.
4. DO WE SHARE YOUR DATA WITH OTHERS?
We do not share your personal data with any external service providers for the operation of this Website, as it is hosted and maintained entirely on DECTA's internal servers.
Third parties: If necessary and legally justified, we also provide your data to separate data controllers, namely to the competent authorities, institutions, organisations, also other data controllers who are entitled to receive information in line with the applicable legislation and/or our legitimate interests, or based on your consent. For example, we have the right and the obligation to transfer information to the competent authorities (pre-trial investigation bodies, etc.) for the purposes of prevention of fraud, offence and crime prevention and investigation.
5. YOUR RIGHTS
You, as a data subject, have certain rights under the GDPR, including the right:
- to request access to your personal data and get a copy thereof;
- to request rectification or restriction of inaccurate or incomplete personal data;
- to request deletion or restriction of personal data which are excessive or unlawfully processed;
- to object to the processing of your personal data;
- to request transfer of your personal data provided in a structured, machine-readable format;
- to withdraw your consent at any time if data processing is based on the data subject’s consent;
- to file a complaint with the State Data Inspectorate (https://www.dvi.gov.lv/en). However, we would recommend contacting us first and we will try to resolve all your concerns together with you.
How can you contact us to exercise your rights? You can submit your request for the exercise of your rights to us by submitting a request by e-mail at data.protection@decta.com. Depending on your request, we may ask you to provide additional information to verify your identity.
5.1. The right to access data processed and the right to obtain a copy of personal data
Should you wish to obtain a copy of your personal data, contact us at data.protection@decta.com.
5.2. Right to rectification of personal data
In case you think that the information processed by us about you is inaccurate or incorrect, you have the right to demand to modify, amend or correct such information.
5.3. Right to withdraw the consent
Where applicable (e.g., if you have explicitly provided consent for specific services or features), when we process your data on the basis of your consent, you have the right to withdraw your consent at any time and data processing based on your consent will stop. You have the right to withdraw consent at any time by e-mail: data.protection@decta.com.
5.4. Right to object to data processing, when processing is based on legitimate interests
You have the right to object to personal data processing, when personal data is processed based on our legitimate interests by e-mail: data.protection@decta.com.
5.5. Right to erasure (right to be forgotten)
When there are certain circumstances indicated in the legislation on personal data protection (e.g. when the basis for data processing has disappeared, etc.), you have the right to request that we erase your personal data. In order to exercise this right, please contact us.
If you provide us with the request to erase all or some of your data and express your wish “to be forgotten”, we will no longer process those data of yours which will no longer be necessary for the purposes for which they were collected. After you have exercised the right “to be forgotten”, your personal data will be further processed for the following main purposes and on the following main grounds:
- If applicable (e.g., in cases involving paid services or transactions), for the purposes of meeting accounting, tax requirements, personal data will be further processed according to Article 6(1)(c) of the GDPR;
- in order to manage complaints and other requests and inquiries (e.g., for registered users or service fulfillment), personal data will be processed according to Article 6(1)(b) of the GDPR;
- in case of disputes, administration of damages, in order to pursue our other legal claims and protect our rights, data will be further processed according to Article 6(1)(f) of the GDPR.
5.6. Right to restriction of data processing
When there are certain circumstances indicated in personal data protection legislation (when personal data is processed unlawfully, when you challenge data accuracy, etc.), you also have the right to restrict your data processing. In order to exercise this right, please contact us. However, we must point out that, because of the restriction of data processing and during the period of such restriction, we may be unable to guarantee you all the Services (such as access to logged-in client areas).
5.7. Right to data portability
In order to exercise this right, please contact us at data.protection@decta.com.
5.8. Right to lodge a complaint
If you think that we process your data in breach of requirements of personal data protection legal acts, we always ask that you contact us directly at first. We believe that our good will efforts will be enough to disperse any doubts you may have. If you are not satisfied with a solution we suggest, you will have the right to lodge a complaint with the Data State Inspection (https://www.dvi.gov.lv/lv/iesniegumu-paraugi).
6. HOW DO WE ENSURE THE SECURITY OF YOUR PERSONAL DATA?
We use appropriate organisational and technical personal data security measures, including protection against unauthorized or unlawful processing of data and against accidental loss, destruction or damage. Such measures have been selected taking into account the risks that may arise for your rights and freedoms as those of a data subject.
We regularly monitor our systems for possible breaches or attacks, but it is not possible to guarantee full security of information transmitted online. With this in mind, you provide us with information by use of the internet connection at your sole discretion and assuming any associated risks.
7. YOU CAN CONTACT US AS FOLLOWS:
DECTA SIA, company number 50103962441, registered office address: Roberta Hirsa Street 1, Riga, Latvija, LV-1045, e-mail: data.protection@decta.com