Privacy policy | Melinda
This is the website of the beauty studio Melinda - Lindas Skaistuma Studija. This page explains what data about you I receive, why I need it, who else sees it and how you can control it.
In effect from 02.09.2026.
1. Who processes your data
The controller responsible for your data is:
- Legal name
- SIA LH
- Registration no.
- 40203713237
- Website
- melinda.lv - Melinda - Lindas Skaistuma Studija
- Salon
- Rīga, Cēsu iela 9, LV-1012
- melinda@melinda.lv
- Phone
- +371 29916130
For any question about your data, write to melinda@melinda.lv - I answer those letters myself.
2. What I collect and why
2.1. Booking requests
The booking form asks for three things: your name, your e-mail address and the procedure you want. It asks for nothing else - no phone number, no address, no date of birth.
The request arrives in my mailbox, I get in touch and we agree on a time.
Legal basis: Article 6(1)(b) GDPR - steps taken at your request before providing a service.
2.2. What the server records alongside a booking
When you press send, the server also writes a row into the site's own database: the page the form was open on, the language, the chosen procedure, your IP address and the country derived from it, and a fingerprint of your browser - an irreversible hash, not the text itself. Your name and e-mail address never go into that database.
This is what lets me tell real bookings from ones sent by bots, and see which pages actually lead to a booking.
Legal basis: Article 6(1)(f) GDPR - my legitimate interest in keeping the site working and protecting it from abuse.
2.3. Cookies, statistics and advertising
The site loads three external tools: Google Analytics 4, the Meta (Facebook) Pixel and Microsoft Clarity. They see which pages you open, how long you stay, where you click and how you scroll, along with your IP address and browser details. Microsoft Clarity additionally records your mouse movements and clicks on the page.
If you press "Reject", none of them is loaded. Until you answer, none of them is loaded either.
Legal basis: Article 6(1)(f) GDPR - my legitimate interest in understanding how the site is used and in measuring the results of my advertising. You may object to this processing; the cookie policy says how to switch these cookies off.
2.4. Clicks on the social icons
The site also keeps a very small set of statistics of its own, which works without cookies. When somebody presses the Facebook, Instagram or WhatsApp icon, or opens the booking bar, the server records the kind of event, the page, the language, the IP address and the country. No name and no e-mail address goes there.
Legal basis: Article 6(1)(f) GDPR - my legitimate interest in knowing which channels actually bring clients.
2.5. Site security
The site has a private admin area. Attempts to log into it are recorded together with the IP address, the username entered and the country. If you are not trying to log into the site's admin area, none of this concerns you.
Legal basis: Article 6(1)(f) GDPR - my legitimate interest in protecting the site from unauthorised access.
2.6. Accounting
If you do come in for a procedure and pay for it, the transaction enters the company's accounting records.
Legal basis: Article 6(1)(c) GDPR - a legal obligation (the Latvian Accounting Law).
3. Who else sees your data
I do not sell or rent your data to anyone. It is seen only by those without whom the site would not work:
- The hosting provider - the company on whose server melinda.lv runs.
- The e-mail service (Google Workspace) - your booking arrives through it.
- Telegram - only when a booking e-mail fails to send. An alert then reaches me immediately containing your name, e-mail address and chosen procedure, so that the booking is not lost.
- Google, Meta and Microsoft - visit statistics and advertising measurement.
- Google Fonts and jsDelivr - the fonts and two open-source libraries load from those servers, so they see your IP address. They set no cookies.
Transfers outside the EU/EEA. Google, Meta, Microsoft and Telegram are companies outside the EU and process part of the data outside the EU/EEA. The terms of those transfers - the EU-U.S. Data Privacy Framework or standard contractual clauses approved by the European Commission - are set out in each company's own privacy policy; the links are in the cookie policy.
4. How long things are kept
- The booking e-mail in my mailbox - [period to be confirmed].
- The site's own statistics rows (event, page, language, IP address) - the site does not delete them automatically. I delete them once they are no longer needed for statistics: [period to be confirmed].
- Admin login attempts - 30 days, after which they are deleted automatically.
- Accounting documents - at least 5 years, as the Accounting Law requires.
- Cookies - each has its own lifetime; see the cookie policy.
5. Your rights
In respect of your own data you have the right to:
- find out what data of yours I process, and receive a copy of it;
- have inaccurate data corrected;
- ask for your data to be deleted;
- ask for the processing to be restricted;
- object to processing that rests on my legitimate interests;
- receive your data in a portable format;
- object to the analytics and advertising cookies at any time - the cookie policy says how to switch them off.
To use any of these rights, write to melinda@melinda.lv. I will answer within a month; if the question is complex that period may be extended by a further two months, and I will tell you if it is.
The cookie notice can be read again on the site itself - the button is on the cookie policy page. To stop the site setting cookies, forbid them in your browser settings.
6. Complaining to the supervisory authority
If you think I am handling your data wrongly, write to me first - most of the time that settles it straight away. You also have the right to lodge a complaint with the supervisory authority:
- Authority
- Datu valsts inspekcija (Data State Inspectorate of Latvia)
- Address
- Elijas iela 17, Rīga, LV-1050
- Phone
- +371 67223131
- pasts@dvi.gov.lv
- Website
- www.dvi.gov.lv
7. Children
The site is not aimed at children and I do not knowingly collect children's data. In Latvia a child may give consent to data processing in information society services from the age of 13; below that age a parent or guardian gives it.
If a procedure is for a minor, the booking is made and the consent given by a parent or guardian. If I learn that I have received a child's data without a parent's knowledge, I delete it.
8. How I protect your data
- The site runs only over an encrypted HTTPS connection.
- The booking form validates what is entered and limits its length.
- The admin area is password-protected, limits the number of failed login attempts and logs itself out after 30 minutes of inactivity.
- The statistics database sits outside the public folder, so it cannot be reached from the internet.
No measure is a guarantee, but these are the ones actually in place.
9. Changes to this policy
If I change this policy, the new version appears on this same page and the "in effect from" date changes with it. For a material change - a new tool that collects data, for instance - I will say so in the cookie notice.