PRIVACY POLICY
The National Research and Innovation Institute (further – NIRI), a public entity, is committed to protecting the privacy
of your personal data and maintaining confidentiality. In this Privacy Policy, we have generally
described what data we may collect about you, how we will use it, as well as provided information
about your rights and how you can contact us. This Privacy Policy sets forth and defines our
personal data protection guidelines.
We assume that before using our website or becoming our customer or business partner, you have
read this Privacy Policy and accepted its terms.
As we are constantly developing, improving, and diversifying the services we provide, we may
occasionally need to make changes to our Privacy Policy. Any changes to our Privacy Policy will
also be published on our website.
Please also note that additional terms and information regarding the processing of personal data
may also be included in the cooperation, employment, or any other agreement concluded between
you and a public entity — the state scientific institute “National Research and Innovation Institute.”
DEFINITIONS:
GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April
2016 on the protection of natural persons with regard to the processing of personal data and
on the free movement of such data, and repealing Directive 95/46/EC (General Data
Protection Regulation);
Personal Data – any information relating to an identified or identifiable natural person whose
data is processed in accordance with this Privacy Policy, the GDPR, and applicable laws;
Processing – any operation or set of operations performed on personal data (e.g., collection,
recording, storage, consultation, use, disclosure, erasure, etc.);
Controller – The controller of your data is NIRI (including its structural units, subsidiaries, or
foundations, the Latvian Institute of Organic Synthesis Foundation), to whom you have
submitted your personal data or who has obtained your data, and who, alone or jointly with
other legal or natural persons, determines the purposes and means of processing your
personal data;
Processor – is a natural or legal person, public authority, agency, or other body that
processes your personal data on behalf of NIRI;
NIRI – a public entity – the state scientific institute “National Research and Innovation
Institute” (hereinafter also referred to as NIRI, we, our, us);
Third Party – means a natural or legal person, public authority, agency, or body other than
the data subject, controller, processor, and persons who, under the direct authority of NIRI or
the processor, are authorized to process personal data.
DESCRIPTION
| 1. Data Controller | NIRI is a state scientific institute that conducts fundamental and applied research in various scientific fields, promoting knowledge transfer, innovation, and sustainable development in Latvia. NIRI’s activities cover a broad spectrum of natural, engineering, biomedical, and environmental sciences, including chemistry, biology, materials science, biotechnology, basic medical sciences, and environmental and earth sciences. NIRI’s goal is to generate new knowledge and technologies that enhance the country’s scientific and innovation potential, as well as public welfare. NIRI combines high-level scientific expertise with practical research experience. The Institute’s researchers develop collaborations with Latvian and international universities, research institutes, and companies; participate in national and European Union projects; and implement knowledge and technology transfer initiatives. The Institute’s activities are characterized by a focus on innovation, quality, and scientific excellence, promoting the development of new technologies, products, and services, as well as the development of young scientists and the sustainability of scientific careers. |
| 2. In what circumstances does this Privacy Policy apply? | This Privacy Policy applies if you use, have used, or have expressed an intention or interest in using NIRI’s services, collaborating (including performing work duties) with us, visiting our institution, or attending events organized by us. It also applies to cases where you are indirectly associated with a service or cooperation agreement. It also applies to cases where our relationship was established prior to the effective date of this Privacy Policy, as well as if you have provided and/or NIRI obtains your Personal Data. |
| 3. What kind of personal data we process and why? | We process your Personal data, in accordance with the GDPR regulations, legal requirements, and this Privacy Policy, and solely in accordance with the previously defined purposes, including: – the Company’s , including security, property interests prevention of threats, prevention of criminal offenses, investigations, and detection: We monitor the common areas of our facility (entrance hall or entrances to buildings, common hallways with access to laboratories) and premises, and we process your Personal Data in the interest, including security, property interests to prevent threats and criminal offenses, investigation, and detection. Video surveillance is conducted in accordance with strict security and privacy regulations, using state-of-the-art technology and equipment. When visiting an institution, you may be asked to register in he visitor and prove your identity, stating the purpose of your visit. Personal data (example): Biometric data (facial image), location, and time First name,last name, signature, identity verification. Legal basis: Public interest, protection of vital interests, including health and life. – For the conclusion and performance of a contract: To conclude a contract and ensure its successful performance, or to communicate in the event of issues with contract performance, we may need information regarding the contact persons of our clients/business partners. If the contract is concluded with natural persons, we will need to identify you, obtain your contact and declared residential addresses, and the bank account number to which payment should be made, if such payment is provided for in the relevant contract. Personal data (example): First name, last name, contact information, personal identification number, declared and actual residential address, bank account number, business operator certificate number, etc. Legal basis: Contractual relationship (for the conclusion and performance of the contract). – To promote cooperation and improve operations: We are constantly improving our operations, and to inform our clients/business partners about changes, improvements, etc., we need effective communication with the client/business partner, so we may need information about the client’s or business partner’s contact person. Personal data (example): First name, last name, contact phone number, email address. Legal basis: Contractual relationship (for the conclusion and performance of the contract). – Verification of the absence of criminal offenses: In the cases specified in the Public Procurement Law, when conducting public procurement, we have an obligation to verify whether the relevant applicant, a member of its board of directors or supervisory board, an authorized representative, or a procurator, or a person authorized to represent the candidate or applicant in matters related to a branch, has not been found guilty by a prosecutor’s indictment or a court judgment that has entered into force and become final and non-appealable, or has not had a coercive measure imposed on them for any of the criminal offenses. Personal data (example): First name, last name, fact of detection of criminal offenses. Legal basis: Legal obligation (obligation established by law). – For the selection of bidders in public procurement: To evaluate bidders and award the contract to a bidder who engages qualified specialists necessary for the service, when conducting public procurement, information is collected about the contact person, and in certain procurements, information is requested about the specialist (natural person) to be engaged in the performance of the service or construction work. The Public Procurement Law and other legal acts also require public authorities to be as efficient as possible and to select the best and most suitable bid. A contact person is necessary for communication during the procurement procedure and for sending specific notifications. We also process your Personal Data as a potential cooperation partner’s employee/representative/authorized signatory to establish cooperation (e.g., when receiving bids in our tenders). Personal data (example): First name, last name, previous experience, education, professional qualifications etc. similar information. Legal basis: Legal obligations. – Incoming and outgoing correspondence: To organize the institution’s record-keeping, we register both your incoming and our outgoing letters. Legislation also requires us to provide you with responses if you have requested them. If the recipient is a natural person, personal data will be stored in our record-keeping system. Personal data (example): First name, last name, address. Legal basis: Legal obligation. – For publicity and preservation of historical heritage: For the purpose of publicity and preservation of historical heritage, we may process, including publishing, photos, videos, and similar materials from public and work-related events we organize. Personal data (example): Image of a person in photographs and in video recordings. Legal basis: Public interest. – Hiring or internship: To manage the recruitment process, to evaluate your application and background, previous work experience and education, their suitability for the position, as well as to contact you, we may process your Personal Data. When submitting an application, you can choose which Personal Data you wish to provide and to what extent. In some cases, we may request additional information or establish standards for the information you provide. You are responsible for the validity and accuracy of the personal information you provide. When evaluating your application, we will process the Personal Data included in your resume and cover letter. If you provide information that is not necessary for the selection process, we will not take that information into account. Please note: You will not be able to participate in the selection process if you choose not to provide the Personal Data we need to assess your suitability as a candidate. Personal data (example): First name, last name, contact information, address, etc. Legal basis: Consent, Legal obligation (e.g., Human Genome Research Act, Cabinet of Ministers Regulation No. 446). Public interest. For scientific purposes. – For donations to the Latvian Institute of Organic Synthesis Foundation. When making a donation, your personal data (e.g., first name, last name, bank account) becomes available to us as part of the donation process. Payment processing is provided by the payment platform makecommerce.lv, so we transfer the personal data necessary for payment execution to the platform’s owner—the licensed payment institution Maksekeskus AS. If the Latvian Institute of Organic Synthesis Foundation decides to publish a list of major donors on its website, you will have the right to choose whether your first name, last name, and donation amount are published. If you 6 do not provide such consent, the notation “Anonymous donor” will be used. Personal data (example): First name, last name, personal identification number, bank account number. Legal basis: Contractual relationship (sending and receiving donations), legal obligation, consent. We store your data related to donations made for as long as necessary for accounting purposes in accordance with applicable laws and regulations. We will process the personal data that you consent to publish on the Foundation’s website for an indefinite period. You have the right to withdraw your consent to the publication of your personal data at any time. – Cookies. We use cookies to gather information about how you use our website. Cookies allow us to ensure and improve the technical functionality of the website. The information collected does not contain data that would allow us to identify you as an individual. Participation in conferences and seminars organized by us. When you fill out the registration form, we will process personal data such as your first name, last name, contact phone number, and email address for communication purposes. If the event also involves a participation fee, we will additionally collect your bank account number. At certain conferences or seminars, the purpose of processing personal data may also be to ensure publicity for the NIRI event (coverage of the event on the NIRI website, social media, and other communication channels, using photo, audio, and video materials to cover the event). In such cases, informational signs will be placed at the event entrance stating that photos and videos are being taken or that video streaming is taking place during the event. Another purpose of personal data processing may also be to inform you about future conferences organized by NIRI in cases the registration form includes a section regarding consent to receive information about other seminars and conferences organized by NIRI, and you have given your consent to receive such information. Personal data (example): First name, last name, personal identification number, email address, phone number, bank account number. Legal basis: Contractual relationship, consent, public interest. – To comply with requirements set forth in other regulatory acts: In our operations, we must also comply with the requirements set forth in accounting regulations, the Archives Law, and other applicable laws and regulations. The legal basis for the processing of personal data in these cases will be the fulfillment of a legal obligation. |
| 4. From what sources can we obtain personal data? | – We primarily obtain personal data from the data subject themselves, i.e., during the process of entering into a contract or other forms of cooperation, as well as when you submit an application, email, etc., to us; – from video surveillance recordings if you visit our facility or premises. – if a contract is concluded with a third party and that party has designated you as a contact person or a person associated with the facility, or has submitted documents in which your personal data is reflected. In cases where information about you is provided to us in this manner, we require that you be made aware of NIRI’s Privacy Policy; – from our Data Processors, who collect your Personal Data with your consent or based on another legal basis, e.g., for research purposes. |
| 5. To whom do we transfer personal data? | We process data in accordance with applicable laws, Agreements, and the GDPR, and ensure that Personal Data is accessible only to individuals who have a legal basis for such access. Personal data may be transferred to: – our employees or directly authorized persons who need it to perform their job duties; – Personal Data Processors in accordance with the services they provide and only to the extent necessary (e.g., database, record-keeping, and IT system technical maintainers, financial management consultants, auditors, security service providers, video surveillance camera operators, technical partners for publicity events (photo/video), and other persons involved in providing services to us); – to state and local government authorities in cases specified by law (e.g., law enforcement agencies, sworn bailiffs, local governments, tax authorities, courts, supervisory authorities, and authorities overseeing structural funds); – third parties, after carefully assessing whether there is an appropriate legal basis for such transfer of personal data, for example, debt collection service providers, courts, alternative dispute resolution bodies, insolvency administrators, third parties that maintain registers (e.g., debtor registers, credit bureaus, etc.). |
| 6. Transfer of Personal Data Outside the European Union and the European Economic Area (EU/EEA) | We process personal data only within the EU/EEA. The transfer and processing of personal data outside the EU/EEA may occur if there is a legal basis for doing so, such as to fulfill a legal obligation, to enter into or perform a contract, for the public interest, or in accordance with your consent. The transfer and processing of personal data outside the EU/EEA may only take place if appropriate security measures have been implemented. |
| 7. Retention periods | Personal data is retained for as long as necessary to fulfill the relevant purposes of processing, as well as in accordance with the requirements of applicable law. When assessing the retention period for Personal Data, we take into account the requirements of applicable laws, aspects of fulfilling contractual obligations, your instructions, as well as the public interest. We store Personal Data for as short a period as possible. If your Personal Data is no longer necessary for the specified purposes, we will securely delete or destroy it. Some of the most common general retention periods for Personal Data: – Procurement. We retain your Personal Data—including the Personal Data of natural persons included in a bid submitted by a bidder or a legal entity—for 10 years after the expiration of the contract. – Hiring or Internship. Your Personal Data is stored in both paper and digital formats. The data retention period does not exceed 3 months after the relevant vacancy has been filled. – Publicity. We will store your first name, last name, phone number, or email address until the end of the event. We will store your image (photo or video) from events/activities for 5 years after the date of the event. – Invoices. Your Personal Data will be stored for 10 years after the invoice is issued/ received. – Performance of contractual obligations. Personal data is stored until the contract is fulfilled and there is no other legal basis for storing the data after the contractual obligations have ended. – Personal data that must be stored to comply with legal requirements will be retained in accordance with the provisions of the relevant legislation; for example, the Accounting Law stipulates that supporting documents must be retained until the date they are needed to establish the origin of each business transaction and track its progress, but for no less than 5 years; – to ensure data recovery, we will store Personal Data in backup copies until a minimum number of newer backup copies has been created, so that previous backup copies can be deleted; – to prove the fulfillment of our obligations, we will store Personal Data in accordance with the statute of limitations periods specified in regulatory enactments—10 years under the Civil Law, 3 years under the Commercial Law, and other periods, taking into account the time limits for filing claims set forth in the Civil Procedure Law. – We will retain data obtained through video surveillance for 1 calendar month to detect potential criminal offenses, if any have occurred. Video surveillance recordings may be retained for a longer period if they are required as evidence in legal proceedings. The retention periods for personal data may differ from the general retention periods, e.g., during legal proceedings or the potential filing of a claim. Personal data may be retained for longer than specified in these retention periods. |
| 8. How do we protect your personal data? | To protect your personal data from unauthorized access, unauthorized processing, accidental loss, disclosure, or destruction, we implement, regularly review, and improve personal data protection measures. To achieve this, we use modern technologies and technical and organizational measures, such as the selection and configuration of appropriate computer systems and the restriction of access to such systems, files, and facilities. However, we recommend that you follow general security guidelines for computer systems and internet use, as well as requirements for the protection and storage of your personal data (particularly identification documents). We will not be liable for unauthorized access to your Personal Data and/or loss of Personal Data if it occurred due to your fault or negligence. |
| 9. What are your rights your personal data? | We want to ensure that the processing of your Personal Data is fair and transparent and that the rights granted to you by law are exercised; therefore, you have the right to: – access your data – You have the right to obtain information from us regarding whether we are processing your Personal Data and, if so, to access your Personal Data; – to rectify your data – you have the right to request that we correct any inaccurate Personal Data. If there have been changes to the Personal Data you have provided to us, such as changes to your personal identification number, mailing address, phone number, or email, etc., please contact us and provide us with the updated data so that we can achieve the relevant purposes of Personal Data processing; – to delete your data – under certain circumstances, you may have the right to have your Personal Data deleted; this right does not apply if processing is necessary to exercise freedom of speech and information, to comply with legal requirements, or to establish, exercise, or defend legal claims; – in certain cases, to receive your personal data directly or to have it sent to another company (this right is known as the right to data portability). This right applies when the processing of your personal data is based on your consent or a contract, as well as when the processing is carried out by automated means; – withdraw consent – to the extent that we process your Personal Data based on your consent, you have the right to withdraw your consent to the processing of your Personal Data at any time by contacting us; – restrict the processing of your data – in certain cases, you have the right to restrict the processing of your Personal Data; – object to the processing of your data – you have the right to object to our processing of your Personal Data; To exercise these rights, please submit a written request to us or to the Data Protection Officer (contact information is provided at the end of the Privacy Policy). If you believe that we are not processing Personal Data in accordance with applicable law, you have the right to contact the State Data Inspectorate (http://www.dvi.gov.lv). |
| 10. Provisions for Data Processors and Business Partners | If you are one of our Processors or business partners who, pursuant to a mutually concluded agreement or work assignment, comes into possession of Personal Data, you must comply with the provisions regarding the processing of Personal Data. These provisions remain in effect even after the termination of the agreement or work assignment. In addition to the terms regarding the processing and confidentiality of Personal Data set forth in the contract and the GDPR, any of our Processors and business partners who receive or have received Personal Data from us must ensure that: – The processing of Personal Data may only take place in accordance with the subject matter of the contract/work assignment, without exceeding the authority and scope necessary for the performance of the relevant task; – Any Processing not expressly permitted in the contract/work assignment is prohibited; – The purpose of the Processing carried out by the Processor on behalf of the Controller is to fulfill the relevant contract under which the Processor operates; – The Processor/partner may process Personal Data only on behalf of the Controller and in accordance with the Controller’s instructions; – Personal data shall not be transferred to third parties or transferred outside the EU without a legal basis; – If the Controller requests information from the Processor regarding security measures, documentation, or other information regarding how the Processor processes Personal Data, a response must be provided no later than 5 (five) business days from the receipt of the request, provided that it is objectively possible to submit the information within this timeframe; – The Processor shall immediately, but no later than within 1 (one) business day, notify the Controller of any processing breaches, provided that it is objectively possible to provide the information within such a timeframe; – The Processor undertakes to ensure a high level of security for its products and services. he Processor ensures a security level, using organizational, technical and physical security measures in accordance with the requirements for information security measures set forth in Article 32 of the GDPR. |
| 11. Changes to our Privacy Policy | We regularly review our Privacy Policy. Amendments or clarifications will be made to the Privacy Policy in accordance with changes in legislation or our operations. |
| 12. Contact Information | If you have any questions regarding the processing of your personal data or this Privacy Policy, please contact us. Derivative public entity – State Scientific Institute “National Research and Innovation Institute” Aizkraukles 21, Riga, LV-1006, LATVIA Rātsupītes iela 1 k-1, Riga, LV-1067 Tel. +371 20245517 Data Protection Officer: Email: oskars@datudrosiba.com |





