Privacy policy
How we process your personal data and your relative’s when you use our website, client account and services.
Effective from 6 October 2026
1. Who is responsible
The data controller is [COMPANY NAME], reg. No. [REG. NO.], registered address: [REGISTERED ADDRESS] (“we”). Your Native Care is our service brand.
For any question about personal data, write to info@yournativecare.com or call +371 20 000 000.
2. What data we process
- Customer data: name, surname, phone, email, preferred messenger, communication history.
- Care Recipient data: name, address, phone, language, habits and wishes needed for the visits.
- Notes on wellbeing that the companion notices during a visit and passes on to the family. These may be health data, so we process them only with consent and only as far as the service needs.
- Visit reports, and photos and video if the Care Recipient has agreed to them.
- Client account data: email, password hash (we never store the password itself), language, notification settings.
- Orders, packages, hours used, payments and contracts.
- Technical data: IP address and browser data in server logs, needed for security.
3. Why, and on what legal basis
- Replying to your enquiry and arranging the free meeting: steps prior to a contract (GDPR Art. 6(1)(b)).
- Providing the service, planning visits, running the client account and hours: performance of the contract (Art. 6(1)(b)).
- Accounting and tax: legal obligation (Art. 6(1)(c)).
- Wellbeing notes, photos and video: the Care Recipient’s explicit consent (Art. 6(1)(a) and Art. 9(2)(a)). Consent can be withdrawn at any time.
- Security of the website and account, handling complaints and cookie-free visit statistics: our legitimate interest (Art. 6(1)(f)).
- Reminders that a package is running out and report notifications: performance of the contract; you can turn them off in your account settings.
4. If you give us data about someone else
The service is usually ordered by a relative rather than by the Care Recipient. By giving us your relative’s details you confirm that they know and agree. At the first meeting we ask the Care Recipient ourselves for consent to reports, photos and video.
5. Who else sees the data
We do not sell data or use it for advertising. Only our staff and companions who need it for their work can see it, plus the processors that provide technical services to us:
- Cloudflare: website hosting and protection.
- [VPS HOSTING PROVIDER]: the client account and database server in the EU.
- Backblaze (EU data centre): photos, video and database backups.
- [EMAIL PROVIDER]: sending email.
- Stripe Payments Europe, Ltd. (Ireland): online payments. Only Stripe sees your card details; we never receive or store them.
- Plausible (on our own server): visit statistics without cookies and without identifying anyone.
- WhatsApp, Telegram, Viber: only if you choose to receive reports there.
6. Transfers outside the EU
Some processors (such as Cloudflare and Stripe) are international companies, and data may leave the European Economic Area. In those cases the safeguards provided by the GDPR apply: a European Commission adequacy decision or standard contractual clauses.
7. How long we keep data
- Enquiries that did not lead to a contract: 12 months.
- Account, order and report data: while the contract is active and for 12 months after it ends.
- Photos and video: while the contract is active; sooner if consent is withdrawn or you ask us to delete them.
- Contracts and accounting records: as long as Latvian accounting and tax law requires.
- Server logs: up to 90 days.
8. Your rights
You have the right to access your data, correct it, have it erased, restrict or object to processing, receive it in a portable format and withdraw consent at any time. Write to info@yournativecare.com and we will reply within one month.
If you believe your data is processed unlawfully, you can complain to the Latvian Data State Inspectorate (Datu valsts inspekcija, www.dvi.gov.lv).
9. Cookies
The website uses no cookies. The client account uses one strictly necessary cookie to keep you signed in. When you pay by card, Stripe’s payment page may use its own cookies for security and fraud prevention.
10. Security
The connection is always encrypted (HTTPS), passwords are stored only as hashes, and photos and video open only through short-lived links inside your family’s account. Only people who need data for their work can access it.
11. Changes
If this policy changes, we publish the new version on this page with a new effective date. We tell clients about significant changes by email.