Meistars AI

Privacy Policy

Version 2026-10-06 · The Latvian version is legally binding. The Russian and English versions are translations for convenience.

In short. We process your account data to provide the service. We store data in the EU (Frankfurt), do not sell it, do not use it for advertising and use no tracking cookies. The AI provider (OpenAI) receives only what a specific feature needs. You can download and delete your data in the app. You are responsible for your customers’ data — we process it on your behalf (Data Processing Agreement).

1. Controller and contact

Deniss Harlass, reg. No. fiziska persona, Rīga, Latvija. Privacy matters: denissharlass@gmail.com. No data protection officer has been appointed because one is not required (Article 37 GDPR); the service provider handles all questions.

2. Scope

3. What data, why and on what basis

DataPurposeLegal basis (Article 6 GDPR)
Name, e-mail, phone, password (hash only), interface language, last login timeAccount, login, communication about the serviceContract — Article 6(1)(b)
Business name, reg. No., VAT status and number, address, phone, e-mail, bank details, logo, default terms, invoice settings, accountant’s e-mailShown on offers and invoices, preparing documentsContract — (b)
Price list, jobs, estimates, offers, photos, voice transcripts, invoicesThe service’s featuresContract — (b)
Session token (hash only), request counters with a keyed hash of IP or e-mail, server logs at the hosting providerSecurity, preventing abuseLegitimate interests — (f)
E-mail verification status, notification settings, single-use password-reset and e-mail-verification tokens (hash only, plus the address they were sent to), e-mail log (type, status, keyed hash of the recipient address, time — no subject or content)Password reset, e-mail verification, notifications, retrying failed e-mailsContract — (b); legitimate interests — (f)
Usage events (e.g. “offer sent”, with the company ID, no content) and AI usage accounting (model, volume, cost, no content)Improving the service, cost control, limitsLegitimate interests — (f)
Accepted terms version and timeProving which terms the contract was concluded onLegitimate interests — (f); contract — (b)
Invoices for our paid plans (future)BookkeepingLegal obligation — (c)
Correspondence with us (e-mails)Answering questions and requestsContract — (b); legitimate interests — (f)

We obtain the data from you. Our legitimate interests are the security and improvement of the service and protecting our rights; you can object to processing on this basis (section 8).

4. Artificial intelligence

5. Recipients

6. Transfers outside the EEA

The database and server functions are in the EU (Frankfurt). Some sub-processors are US companies or process data in the US (e.g. OpenAI). Transfers rely on the European Commission’s adequacy decision for the EU–US Data Privacy Framework (where the provider is certified) or on standard contractual clauses (Decision (EU) 2021/914). You can request a copy by writing to us.

7. How long we keep data

DataPeriod
Account and business data, jobs, offers, approvals, photos, events, AI usageWhile the account exists. On account deletion — immediately from the live database; in backups up to 30 days.
BackupsA copy of the whole database every night, encrypted (AES-256), kept for 30 days at GitHub (US), then deleted automatically. The decryption key is kept outside GitHub.
E-mail log90 days.
Password-reset and e-mail-verification tokensValid for 30 minutes (password reset) or 7 days (e-mail verification); deleted one day after use or expiry.
Issued invoices and credit notes after account deletionIn a closed archive until the end of the 5th calendar year after the year of issue (Article 28 of the Accounting Act), then deleted.
Closed-account record (name, reg. No., e-mails, accepted terms versions)3 years after account deletion, or longer while the archive holds this account’s invoices.
SessionsUp to 30 days or until you log out.
Request countersBriefly (usually up to 24 hours).
Server logs at the hosting provider; the AI provider’s monitoring logs; the e-mail provider’s delivery logsAccording to the provider’s settings; OpenAI — up to 30 days.

8. Your rights

9. Cookies

NamePurposeDuration
ms_sessionLogin session (necessary; httpOnly)30 days or until you log out
ms_localeYour chosen language; set only when you press LV | RU | EN1 year

Both cookies are necessary to provide the service you asked for, so consent is not required (Article 7.1 of the Latvian Information Society Services Law). We use no analytics, advertising or third-party tracking cookies or similar technologies. The customer offer page sets no cookies.

10. Security

Main measures: database in the EU, encrypted connections, tenant separation in the database, passwords stored only as hashes, unguessable customer link tokens, unchangeable approval records, rate limiting. Full list: Annex B to the Data Processing Agreement.

11. E-mail

We send service e-mails only: e-mail address verification, password reset, notifications of a customer’s decision or question (each can be switched off in Settings), important changes to the terms and, on your behalf, an approval copy to your customer, an invoice to your customer and a monthly link for your accountant (if you set that up). Once e-mail sending is switched on, e-mails are sent by Resend from its EU region (Ireland); they contain no tracking pixels or link tracking, and we do not store subjects or contents. We send marketing e-mails only with your consent or, where the law allows, about similar services with an opt-out at any time (Article 9 of the Information Society Services Law).

12. Children

The service is for business use and is not intended for persons under 18.

13. Changes

We will announce material changes in the app or by e-mail. The version is shown at the top of the page.