PRIVACY POLICY
Last updated: July 2026
1. General Information
This Privacy Policy explains how SIA “GR GLOBAL SERVICE”, operating under the METALLEGR trade mark, processes personal data when individuals visit the website www.grglobalservice.de or contact the company.
Personal data is processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council, the General Data Protection Regulation, and other applicable personal data protection laws and regulations.
2. Data Controller
The data controller is:
SIA “GR GLOBAL SERVICE”
Trade mark: METALLEGR
Registration No.: 40203286626
Address: Pārupes iela 2A, Baldone, Ķekavas novads, LV-2125, Latvia
Telephone: +371 27059979
Email: info@grglobalservice.de
Website: www.grglobalservice.de
Hereinafter referred to as the Controller.
Questions regarding the processing of personal data and requests to exercise data protection rights may be sent to info@grglobalservice.de.
3. Technical Data Processed When Visiting the Website
When the website is visited, its server and hosting service provider may automatically process the following technical data:
· IP address;
· date and time of access;
· section of the website visited;
· browser, device and operating system type;
· status of the server request;
· information about the website from which the visitor accessed the website, where such information is transmitted;
· other technical information automatically recorded in server log files.
This data is processed in order to ensure the operation, security and stability of the website, identify technical issues, investigate potential security incidents and protect the website against unauthorised or malicious use.
The legal basis for the processing is the Controller’s legitimate interest under Article 6(1)(f) of the General Data Protection Regulation in ensuring the secure, stable and technically correct operation of the website.
Videos displayed on the website are stored on and loaded directly from the website server. No external video platform is used for video playback.
4. Contact via the Contact Form, Email or Telephone
If a person contacts the Controller using the contact form, email or telephone, the Controller may process:
· first name and surname;
· company name;
· email address;
· telephone number;
· content of the message;
· information about the service of interest;
· other data voluntarily provided by the person in their message.
The data is processed in order to:
· respond to a question or request;
· prepare and send an offer;
· clarify the required service;
· take steps prior to entering into a contract;
· ensure further communication;
· protect the Controller’s legal interests in the event of a dispute.
Where the communication relates to a possible contract or the ordering of a service, the legal basis for the processing is Article 6(1)(b) of the General Data Protection Regulation.
In other cases, the legal basis for the processing is the Controller’s legitimate interest under Article 6(1)(f) of the General Data Protection Regulation in ensuring communication, responding to enquiries and protecting its legal interests.
Providing the data is voluntary. However, without the information required for communication, the Controller may be unable to respond to the request or prepare an offer.
5. Contact via WhatsApp
The website may contain a link or button enabling contact via WhatsApp.
The WhatsApp button is a simple external link. Until the visitor clicks it, the website does not establish a connection with WhatsApp and does not transfer the visitor’s personal data to WhatsApp.
When the WhatsApp button is clicked, the visitor is redirected to the WhatsApp application or website. From that point, personal data is also processed by WhatsApp Ireland Limited in accordance with its own privacy terms.
If a person sends the Controller a message via WhatsApp, the Controller may process:
· telephone number;
· WhatsApp profile name and profile picture, where visible;
· content of the message;
· documents, images or other files sent;
· time when the message was sent and received.
The data is processed in order to respond to the enquiry, prepare an offer, enable communication or take steps prior to entering into a contract.
The legal basis for the processing is Article 6(1)(b) of the General Data Protection Regulation where the communication relates to a possible contract, or Article 6(1)(f), based on the Controller’s legitimate interest in providing a convenient means of communication.
The use of WhatsApp is voluntary. The person may also choose to contact the Controller by email or telephone.
6. Cookies
Cookies are small text files that may be stored on a visitor’s computer, telephone or other device when the website is visited.
The website uses only technically necessary cookies or similar technologies required to:
· provide the website’s basic functions;
· maintain the security and technical stability of the website;
· ensure the proper operation of the website and its content.
Technically necessary cookies are not used for advertising, user profiling or analysing visitor behaviour.
The website does not use analytics, advertising or remarketing cookies.
Visitors may delete or block cookies through their browser settings. Blocking technically necessary cookies may affect the operation of certain website functions.
7. Hosting
The website’s hosting services are provided by Hostinger.
As part of the hosting service, the service provider may process:
· IP addresses;
· server log files;
· technical and security-related website data;
· data submitted through the contact form;
· information contained in website backups;
· email communication data where an email service provided by Hostinger is used.
The data is processed in order to ensure the operation, security and storage of the website, the creation of backups and the provision of technical support.
The legal basis for the processing is the Controller’s legitimate interest under Article 6(1)(f) of the General Data Protection Regulation in ensuring a secure and stable website infrastructure.
The hosting service provider processes personal data on behalf of the Controller in accordance with the applicable service agreement and data processing agreement.
8. Recipients of Personal Data
Personal data may be disclosed only to the extent necessary to achieve the relevant processing purpose.
Recipients or categories of recipients of personal data may include:
· hosting and server maintenance service providers;
· email service providers;
· website development and technical maintenance service providers;
· WhatsApp Ireland Limited, where a person chooses to use WhatsApp;
· accounting, legal or other professional service providers where necessary to protect the Controller’s legal interests;
· public authorities and law enforcement authorities in cases provided for by law.
The Controller does not sell personal data or disclose it to unrelated third parties for advertising purposes.
9. Retention of Personal Data
Personal data is retained only for as long as necessary for the purpose for which it was collected.
Data from contact forms, email, telephone and WhatsApp communications is retained until the relevant request or communication has been completed. The data may then be retained for a longer period where necessary for:
· entering into or performing a contract;
· complying with a legal obligation;
· establishing, exercising or defending legal claims;
· protecting the legal interests of the Controller or the data subject.
Server log files and other technical data are retained in accordance with the technical retention periods applied by the hosting service provider and only for as long as necessary to ensure security and technical operation.
After the applicable retention period has expired, personal data is deleted or anonymised.
10. Rights of the Data Subject
A person has the right to:
· receive information about the processing of their personal data;
· request access to their personal data;
· request the correction of inaccurate or incomplete data;
· request the deletion of data in the cases provided for by law;
· request restriction of processing;
· object to processing based on the Controller’s legitimate interests;
· receive their data in a structured and machine-readable format where the right to data portability applies;
· withdraw previously given consent where the processing is based on consent;
· lodge a complaint with a data protection supervisory authority.
To exercise these rights, a person may contact info@grglobalservice.de.
The Controller has the right to request additional information where necessary to verify the person’s identity.
11. Lodging a Complaint
If a person believes that the processing of their personal data infringes applicable personal data protection laws and regulations, they may contact the Controller at info@grglobalservice.de.
The person also has the right to lodge a complaint with a supervisory authority:
Datu valsts inspekcija – Data State Inspectorate of Latvia
Elijas iela 17, Riga, LV-1050, Latvia
Email: pasts@dvi.gov.lv
Telephone: +371 67223131
A person may also lodge a complaint with the competent data protection supervisory authority in the European Union or European Economic Area country in which they have their habitual residence or place of work, or in which the alleged infringement occurred.
12. Data Security
The Controller uses appropriate technical and organisational measures to protect personal data against unauthorised access, loss, disclosure, alteration or destruction.
Access to personal data is granted only to persons and service providers who require such access to perform their duties.
13. Changes to the Privacy Policy
The Controller has the right to amend this Privacy Policy where the functionality of the website, the services used, the types of personal data processing or the applicable laws and regulations change.
The current version of the Privacy Policy is always available on the website www.grglobalservice.de.
The date on which the Privacy Policy was last updated is stated at the beginning of the document.


