Privacy Policy
Last updated: August 22, 2026
This Privacy Policy explains how Raivis Kalnins ("I", "me", "my") collects, uses, and protects your personal data when you visit raivis.tech ("the website"). I am committed to protecting your privacy and handling your data transparently and in compliance with the General Data Protection Regulation (GDPR).
1. Data Controller
Raivis Kalnins
Email: hello@raivis.tech
Website: https://raivis.tech
2. What Data I Collect
I collect only the minimum data necessary to operate the website and respond to your inquiries:
- Contact Form Data: When you submit the contact form, I collect your name, email address, and message. This data is stored in a database and sent to me via email so I can respond to your inquiry.
- Session Cookie (PHPSESSID): A single strictly necessary session cookie is set to enable CSRF (Cross-Site Request Forgery) protection and to remember your language preference (English or Latvian). This cookie contains a random session identifier — no personal data is stored in it. It expires when you close your browser.
- Server Access Logs: Like virtually all websites, my hosting provider (Hostinger) automatically logs standard technical data when you visit: your IP address, browser type (user-agent), referring page, and timestamp. These logs are used for security, troubleshooting, and aggregate statistics. They are retained for a limited period per Hostinger's standard practices.
3. How I Use Your Data
Your data is used exclusively for the following purposes:
- To respond to inquiries submitted via the contact form
- To protect the website against CSRF attacks and abuse (session cookie)
- To remember your language preference for a better browsing experience
- To maintain the security and proper functioning of the website (server logs)
4. Legal Basis for Processing (GDPR)
Under the GDPR, I rely on the following legal bases:
- Legitimate Interest (Article 6(1)(f)): CSRF protection, server security logs, and language preference — these are essential for the secure and functional operation of the website.
- Consent (Article 6(1)(a)): By submitting the contact form, you consent to the processing of your name, email, and message for the purpose of responding to your inquiry.
5. Data Retention
- Contact form messages: Stored in the website database indefinitely, unless you request deletion.
- Session cookie: Expires when you close your browser (session cookie).
- Server logs: Retained by Hostinger according to their standard retention policies (typically 30–90 days).
6. Third-Party Services
I use the following third-party services. None of them receive personal data directly from your browser:
- Google Gemini API (Chatbot): When you use the chatbot, your message is sent server-side to Google's Gemini API to generate a response. Per Google's API terms, data sent via the Gemini API is not used to train Google's models and is not retained. No personal identifiers are attached to the request.
- WeatherAPI: The weather widget in the footer fetches current weather data for Riga. This request is made server-side — no user data is sent to WeatherAPI.
- CDN Resources: The website loads CSS and JavaScript libraries from jsDelivr, cdnjs, and Google Fonts. These are standard CDN requests that may log your IP address as part of normal HTTP operation. No cookies are set by these services on my website.
7. Cookies
This website uses exactly one cookie: a PHP session cookie (PHPSESSID). This is a strictly necessary, first-party cookie required for CSRF security and language preference. It stores no personal data, does not track you across sites, and expires when you close your browser. No analytics, advertising, or tracking cookies are used. Because this cookie is strictly necessary for the website to function, no consent banner is required under the ePrivacy Directive and GDPR.
8. Your Rights (GDPR)
Under the GDPR, you have the following rights regarding your personal data:
- Right of Access: You can request a copy of the personal data I hold about you.
- Right to Rectification: You can ask me to correct any inaccurate or incomplete data.
- Right to Erasure ("Right to be Forgotten"): You can request that I delete your personal data.
- Right to Restriction of Processing: You can ask me to limit how your data is processed.
- Right to Data Portability: You can request your data in a structured, machine-readable format.
- Right to Object: You can object to processing based on legitimate interest.
- Right to Withdraw Consent: You can withdraw your consent at any time for contact form data.
To exercise any of these rights, contact me at hello@raivis.tech. I will respond within 30 days as required by GDPR.
9. Data Security
I take appropriate technical and organizational measures to protect your data: the website enforces HTTPS (encrypted connection), uses CSRF tokens to prevent request forgery, applies rate limiting on forms, sanitizes all user input, and stores contact messages in a password-protected database. The session cookie is hardened with HttpOnly, Secure, and SameSite=Strict flags.
10. Changes to This Policy
I may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last updated" date. I encourage you to review this page periodically.
11. Contact
If you have any questions about this Privacy Policy or wish to exercise your data rights, please contact me at:
Email: hello@raivis.tech
Website: https://raivis.tech