Privacy Policy
Version 2026-10-06 · The Latvian version is legally binding. The Russian and English versions are translations for convenience.
1. Controller and contact
Deniss Harlass, reg. No. fiziska persona, Rīga, Latvija. Privacy matters: denissharlass@gmail.com. No data protection officer has been appointed because one is not required (Article 37 GDPR); the service provider handles all questions.
2. Scope
- Users of Meistars AI (tradespeople and businesses and their staff using the account) and visitors to the website.
- For data you enter about your customers you are the controller and we are the processor. Your customers have a separate privacy notice.
3. What data, why and on what basis
| Data | Purpose | Legal basis (Article 6 GDPR) |
|---|---|---|
| Name, e-mail, phone, password (hash only), interface language, last login time | Account, login, communication about the service | Contract — Article 6(1)(b) |
| Business name, reg. No., VAT status and number, address, phone, e-mail, bank details, logo, default terms, invoice settings, accountant’s e-mail | Shown on offers and invoices, preparing documents | Contract — (b) |
| Price list, jobs, estimates, offers, photos, voice transcripts, invoices | The service’s features | Contract — (b) |
| Session token (hash only), request counters with a keyed hash of IP or e-mail, server logs at the hosting provider | Security, preventing abuse | Legitimate interests — (f) |
| E-mail verification status, notification settings, single-use password-reset and e-mail-verification tokens (hash only, plus the address they were sent to), e-mail log (type, status, keyed hash of the recipient address, time — no subject or content) | Password reset, e-mail verification, notifications, retrying failed e-mails | Contract — (b); legitimate interests — (f) |
| Usage events (e.g. “offer sent”, with the company ID, no content) and AI usage accounting (model, volume, cost, no content) | Improving the service, cost control, limits | Legitimate interests — (f) |
| Accepted terms version and time | Proving which terms the contract was concluded on | Legitimate interests — (f); contract — (b) |
| Invoices for our paid plans (future) | Bookkeeping | Legal obligation — (c) |
| Correspondence with us (e-mails) | Answering questions and requests | Contract — (b); legitimate interests — (f) |
We obtain the data from you. Our legitimate interests are the security and improvement of the service and protecting our rights; you can object to processing on this basis (section 8).
4. Artificial intelligence
- Voice input: the audio recording is sent to OpenAI for transcription together with your price-list names (as a vocabulary). We do not store the audio.
- Estimate: the job description and your price-list names, aliases and units are sent to OpenAI — no prices and no customer contact details. Do not put unnecessary personal data in the description.
- Price-list import: the uploaded document or photo is sent to OpenAI to be read; we do not store the file, only the rows you confirm are saved.
- Under its API terms OpenAI does not use this data to train models and may keep it for up to 30 days for abuse monitoring. If AI is switched off, an offline algorithm without OpenAI is used.
- AI output is a suggestion that you check. We do not make automated decisions that have legal effects for you (Article 22 GDPR).
5. Recipients
- Sub-processors — hosting, database, AI, code and backup storage, e-mail delivery: list.
- Your customers see your business details on an offer and receive the e-mails we send on your behalf (approval copy, invoice); your accountant — if you send them files or switch on the monthly sending.
- Authorities and courts where required by law; professional advisers (lawyers, accountants) under confidentiality; a successor if the service is transferred.
6. Transfers outside the EEA
The database and server functions are in the EU (Frankfurt). Some sub-processors are US companies or process data in the US (e.g. OpenAI). Transfers rely on the European Commission’s adequacy decision for the EU–US Data Privacy Framework (where the provider is certified) or on standard contractual clauses (Decision (EU) 2021/914). You can request a copy by writing to us.
7. How long we keep data
| Data | Period |
|---|---|
| Account and business data, jobs, offers, approvals, photos, events, AI usage | While the account exists. On account deletion — immediately from the live database; in backups up to 30 days. |
| Backups | A copy of the whole database every night, encrypted (AES-256), kept for 30 days at GitHub (US), then deleted automatically. The decryption key is kept outside GitHub. |
| E-mail log | 90 days. |
| Password-reset and e-mail-verification tokens | Valid for 30 minutes (password reset) or 7 days (e-mail verification); deleted one day after use or expiry. |
| Issued invoices and credit notes after account deletion | In a closed archive until the end of the 5th calendar year after the year of issue (Article 28 of the Accounting Act), then deleted. |
| Closed-account record (name, reg. No., e-mails, accepted terms versions) | 3 years after account deletion, or longer while the archive holds this account’s invoices. |
| Sessions | Up to 30 days or until you log out. |
| Request counters | Briefly (usually up to 24 hours). |
| Server logs at the hosting provider; the AI provider’s monitoring logs; the e-mail provider’s delivery logs | According to the provider’s settings; OpenAI — up to 30 days. |
8. Your rights
- Access to your data and a copy; rectification; erasure; restriction; objection to processing based on legitimate interests; data portability (Articles 15–21 GDPR).
- You can do most of this yourself: Settings → Download my data (JSON), edit profile and business, Delete account.
- Otherwise write to denissharlass@gmail.com. We reply within one month (Article 12 GDPR).
- You have the right to lodge a complaint with the Latvian Data State Inspectorate (www.dvi.gov.lv).
9. Cookies
| Name | Purpose | Duration |
|---|---|---|
ms_session | Login session (necessary; httpOnly) | 30 days or until you log out |
ms_locale | Your chosen language; set only when you press LV | RU | EN | 1 year |
Both cookies are necessary to provide the service you asked for, so consent is not required (Article 7.1 of the Latvian Information Society Services Law). We use no analytics, advertising or third-party tracking cookies or similar technologies. The customer offer page sets no cookies.
10. Security
Main measures: database in the EU, encrypted connections, tenant separation in the database, passwords stored only as hashes, unguessable customer link tokens, unchangeable approval records, rate limiting. Full list: Annex B to the Data Processing Agreement.
11. E-mail
We send service e-mails only: e-mail address verification, password reset, notifications of a customer’s decision or question (each can be switched off in Settings), important changes to the terms and, on your behalf, an approval copy to your customer, an invoice to your customer and a monthly link for your accountant (if you set that up). Once e-mail sending is switched on, e-mails are sent by Resend from its EU region (Ireland); they contain no tracking pixels or link tracking, and we do not store subjects or contents. We send marketing e-mails only with your consent or, where the law allows, about similar services with an opt-out at any time (Article 9 of the Information Society Services Law).
12. Children
The service is for business use and is not intended for persons under 18.
13. Changes
We will announce material changes in the app or by e-mail. The version is shown at the top of the page.