Privacy Policy regarding the processing and protection of personal data of users of the website https://spsassemanagement.lv
Last updated: 05.02.2026
This is a translation of the Privacy Policy. In the event of any discrepancy between the Latvian, English, and Russian versions, the Latvian version shall prevail.
1. General Provisions
1.1. This document “Privacy Policy regarding the processing and protection of personal data of users of the website https://spsassemanagement.lv” (hereinafter referred to as the “Policy”) has been developed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation, GDPR) and the Law of the Republic of Latvia “Personal Data Processing Law” (Fizisko personu datu apstrādes likums).
1.2. The Policy is the primary internal document of the Controller regulating activities in the field of processing and protection of personal data, aimed at ensuring the protection of human rights and freedoms when processing personal data, including the protection of rights to privacy, personal, and family secrets.
1.3. The Policy determines the composition of personal data obtained, the purposes of their processing, the procedure for storage and transfer, as well as the measures implemented by the Controller aimed at protecting personal data.
1.4. This Policy applies to all information that the Controller may obtain about the User during their use of the website https://spsassemanagement.lv (hereinafter referred to as the “Site”).
1.5. Use of the Site signifies the User’s unconditional agreement to the terms of this Policy and the conditions of processing their personal data specified herein. In case of disagreement with these terms, the User must refrain from using the services of the Site.
2. Basic Concepts Used in the Policy
2.1. Site — a collection of graphic and information materials, as well as computer programs and databases, ensuring their availability on the Internet at the network address https://spsassemanagement.lv.
2.2. User — any visitor to the website https://spsassemanagement.lv.
2.3. Personal Data — any information relating to a directly or indirectly identified or identifiable natural person (User).
2.4. Processing of Personal Data — any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
2.5. Controller (previously referred to as “Operator”) — legal entity SPS Agency SIA, which, alone or jointly with others, organizes and/or carries out the processing of personal data, and determines the purposes of processing personal data, the composition of personal data to be processed, and the actions (operations) performed with personal data.
3. Principles of Personal Data Processing
3.1. The processing of personal data is carried out on a lawful and fair basis.
3.2. The processing of personal data is limited to the achievement of specific, predetermined, and legitimate purposes. Processing of personal data incompatible with the purposes of data collection is not permitted.
3.3. The content and volume of processed personal data correspond to the stated purposes of processing. The processed personal data are not excessive in relation to the stated purposes of their processing.
3.4. When processing personal data, the accuracy of personal data, their sufficiency, and, where necessary, relevance to the purposes of personal data processing are ensured.
3.5. Storage of personal data is carried out in a form that allows identification of the data subject, for no longer than required by the purposes of personal data processing, unless the storage period for personal data is established by law or contract.
4. Composition of Processed Personal Data
4.1. The Controller may process the following personal data of the User, provided by the User when filling out feedback forms (“Request Strategic Briefing”, “Request Track Record Access”, and others) on the Site:
– First Name, Last Name;
– Contact Phone Number;
– Email Address;
– Name of the Company, Organization, or Family Office represented by the User;
– Position or Role of the representative;
– Data contained in the “Inquiry Focus” and “Context/Additional Requirements” fields, which may include information about the User’s interests in the field of asset management.
4.2. The Site also collects and processes anonymized data about visitors (including “cookies”) using internet statistics services (Google Analytics and others).
5. Purposes of Personal Data Processing
5.1. Purpose of processing: Establishing feedback with the User, including sending notifications, requests regarding the use of the Site, provision of services, processing requests and applications from the User, as well as verifying the User’s credentials to grant access to confidential information (Track Record).
5.2. Purpose of processing: Providing the User with access to personalized resources of the Site (including restricted portfolio sections).
5.3. Purpose of processing: Conclusion, execution, and termination of civil law contracts.
5.4. Anonymized User data collected using internet statistics services serve to collect information about the actions of Users on the Site, improve the quality of the Site and its content.
6. Legal Grounds for Personal Data Processing
6.1. The Controller processes the User’s personal data only if they are filled in and/or sent by the User independently via special forms located on the Site. By filling out the relevant forms and/or sending their personal data to the Controller, the User expresses their consent to this Policy.
6.2. The Controller processes anonymized data about the User if this is permitted in the User’s browser settings (saving of “cookies” and use of JavaScript technology are enabled).
6.3. The legal basis for processing is also the legitimate interest of the Controller in carrying out its commercial activities and the necessity to take steps prior to entering into a contract at the request of the data subject (Art. 6(1)(b) GDPR).
7. Procedure for Collection, Storage, Transfer, and Other Types of Processing
7.1. The security of personal data processed by the Controller is ensured by implementing legal, organizational, and technical measures necessary to fully comply with the requirements of current legislation in the field of personal data protection.
7.2. The Controller ensures the safety of personal data and takes all possible measures to exclude access to personal data by unauthorized persons. Within the framework of the Controller’s activities, a strict confidentiality regime is observed regarding information received from institutional investors and Family Office representatives.
7.3. The User’s personal data will never, under any circumstances, be transferred to third parties, except in cases related to the implementation of current legislation.
7.4. The term of personal data processing is unlimited (until the withdrawal of consent). The User may withdraw their consent to the processing of personal data at any time by sending a notification to the Controller via email to the Controller’s email address a.marcinskis@sps-agency.com marked “Withdrawal of consent to the processing of personal data”.
8. Personal Data Protection Measures
8.1. The Controller takes necessary and sufficient organizational and technical measures to protect personal data from unauthorized or accidental access, destruction, modification, blocking, copying, as well as from other illegal actions of third parties.
8.2. The Site uses a secure connection via SSL/TLS protocol, which ensures data encryption during transmission from the User to the Controller.
8.3. Access to personal data is restricted to authorized employees (specifically the Managing Partner) who have signed a Non-Disclosure Agreement (NDA).
9. Liability and Dispute Resolution
9.1. The Controller is liable for improper processing of personal data in accordance with the legislation of the Republic of Latvia and GDPR.
9.2. The Controller is not liable for the actions of third parties who gained access to data as a result of unauthorized access to the Site or through the fault of the User themselves.
9.3. All disputes between the Controller and the User shall be resolved in accordance with the legislation of the Republic of Latvia.
10. Final Provisions
10.1. The Controller has the right to make changes to this Policy without the User’s consent. The new version of the Policy comes into force from the moment it is posted on the Site, unless otherwise provided by the new version of the Policy.
10.2. In all other matters not regulated by this Policy, the Controller is guided by the current legislation of the Republic of Latvia and the provisions of GDPR.
10.3. The User can receive any clarifications on issues of interest regarding the processing of their personal data by contacting the Controller via email.
11. Controller Contact Information
Name: SPS Agency SIA
Registration Number: 40203593207
Legal Address: Muitas street 1, Riga, LV-1010, Latvia
Contact Phone: +371 286 02222
Email: a.marcinskis@sps-agency.com
