Privacy Policy
How AmberBirch, SIA processes and protects personal data.

Privacy Policy
AmberBirch, SIA
8 September 2026
I. General provisions
This Privacy Policy (hereinafter – the Policy) describes how AmberBirch, SIA, registration No. 40203021261, registered office: “Finieris”, Krustpils parish, Jēkabpils municipality, LV-5204 (hereinafter – the Company), processes the personal data of natural persons.
The Company is a personal data controller that processes personal data on its own behalf and in its own interests, ensuring responsible data processing in compliance with the applicable laws and regulations.
The Policy applies to any natural person (hereinafter – the Customer or the Data Subject) who uses, has used or has expressed a wish to use the services provided by the Company, purchases or supplies products (including raw materials), or otherwise cooperates with the Company.
Data subjects within the meaning of this Policy are:
• buyers, suppliers, business partners and their authorised representatives or contact persons;
• job applicants;
• visitors to the Company’s website www.amberbirch.lv (hereinafter – the Website);
• visitors to the Company’s office, mill and premises.
The Policy applies regardless of the form or environment (in person, on paper, electronically or on the Website) in which the Customer provides personal data, and also to relationships established before this Policy entered into force.
In accordance with the General Data Protection Regulation (GDPR) and the applicable laws and regulations of the Republic of Latvia, the Company ensures the confidentiality of personal data and has implemented appropriate technical and organisational measures to protect data against unauthorised access, unlawful processing, disclosure, accidental loss, alteration or destruction.
Personal data is any information that directly or indirectly allows the Customer (an identified or identifiable natural person) to be identified.
Processing of personal data is any operation performed on personal data (including collection, recording, structuring, storage, modification, granting access, retrieval, transfer, erasure, etc.).
Information about the Customer is processed and protected in accordance with this Policy, the Company’s internal rules and the requirements of laws and regulations. Additional and more detailed information about data processing in specific cases (for example, in cooperation agreements, job applications or access control rules) may be provided in the relevant agreements, other documents or on the Company’s website www.amberbirch.lv.
II. Processing of personal data
2.1. Sale of veneer and purchase/supply of roundwood
When you contact the Company about purchasing veneer or supplying roundwood (raw materials) – including via the contact form on the Website, by e-mail or by the phone number provided – the Company processes the personal data of the Customer and its representatives for the following purposes:
• to review the request, application or offer and respond regarding cooperation opportunities;
• to prepare a commercial offer and agree on the terms of cooperation;
• to conclude and perform a contract and monitor the performance of the transaction;
• to administer further cooperation, including planning timber deliveries, logistics, payments, accounting and document circulation.
Categories of data processed:
• identification data (first name, surname);
• contact details (e-mail address, phone number, correspondence address, position, profession and the company/legal entity represented);
• the content of correspondence, requests and communication;
• transaction and contract performance data (delivery and loading/unloading address, bank details, timber accompanying documents and measurement data, powers of attorney, etc.).
Data subjects:
• the Customer (a natural person);
• a representative, employee or authorised person of a Customer, supplier or business partner (legal entity).
Legal basis for processing:
• taking steps prior to entering into a contract and performance of a contract, where the contract is concluded with the Customer as a natural person;
• the Company’s legitimate interests – ensuring cooperation, B2B communication with representatives of business partners, retaining evidence of transactions and conducting business;
• compliance with a legal obligation – meeting the requirements of accounting, tax and industry-specific laws and regulations (including those on timber circulation and the relevant accompanying documents).
Data recipients:
• the Company’s authorised employees and departments;
• outsourced service providers and processors (IT maintenance, accounting, logistics and transport, timber measurement and certification service providers);
• public administration and law enforcement authorities (for example, the State Revenue Service, the State Forest Service) upon a justified request, in the manner and to the extent prescribed by laws and regulations.
2.2. Recruitment and employment opportunities
If a job applicant applies for a vacancy or otherwise expresses interest in employment opportunities at the Company (including by sending an application by e-mail, using the application form on the Website or handing in a CV in person), the Company processes personal data for the following purposes:
• to assess the applicant’s qualifications, skills and suitability for the relevant vacancy;
• to communicate with the applicant, clarify the status of the application and arrange job interviews;
• to prepare and conclude an employment contract if the application is successful;
• to protect the Company’s legal interests (securing evidence in the event of possible claims or disputes relating to the selection process);
• to build a pool of applicants for future vacancies (only with the applicant’s separate consent).
Categories of data processed:
• identification data (first name, surname);
• contact details (e-mail address, phone number, residential or correspondence address);
• information contained in the curriculum vitae (CV), cover letter and documents attached to the application (education, work experience, language skills, certificates, course certificates, etc.);
• references from previous employers (only if the applicant has consented or has provided the details of the relevant contact persons);
• information obtained during the job interview and the results of practical tasks;
• other information that the applicant provides in the application on their own initiative.
Data subjects:
• the job applicant.
Legal basis for processing:
Data is processed in order to:
• take steps prior to entering into a contract at the request of the data subject;
• fulfil the Company’s obligations under laws and regulations in the field of employment relationships;
• pursue legitimate interests, such as selecting the most suitable candidates.
Data recipients:
• the Company’s departments involved in recruitment;
• IT service providers;
• persons specified in external laws and regulations, upon their justified request, in the manner and to the extent prescribed by external laws and regulations.
If a job applicant’s application is unsuccessful, the personal data submitted is deleted after the period specified in Section 4 of this Policy, unless the data subject has consented to the retention of their data for consideration for future vacancies.
2.3. General enquiries and communication with the Company
When you contact the Company via the contact form on the Website, by e-mail, by phone or through other communication channels about matters not directly related to the sale of veneer, the supply of roundwood or recruitment (clauses 2.1 and 2.2), the Company processes personal data in order to review the request received, provide a response and ensure further communication.
Categories of data processed:
• identification data (first name, surname);
• contact details (e-mail address, phone number, residential or correspondence address);
• the content of the correspondence and request that the data subject includes in the message on their own initiative.
Data subjects:
• any natural person who contacts the Company (website visitor, business partner, media representative, member of the public, etc.).
Legal basis for processing:
Data is processed to pursue legitimate interests, such as reviewing requests received and providing responses.
Data recipients:
• the Company’s authorised employees and departments;
• IT service providers.
2.4. Video surveillance
The Company carries out video surveillance in its office, mill, timber reception yards and adjoining premises (“Finieris”, Krustpils parish, Jēkabpils municipality) to ensure the safety of the Company, its employees, visitors and third parties, as well as the protection of property and material assets.
Categories of data processed:
• video recordings and the image, appearance and behaviour of the persons captured in them;
• the place, date and time when a person was within the video surveillance zone;
• vehicle type, make and registration number (if a person moves around the premises in a vehicle).
Data subjects:
• visitors to the Company’s office, mill and premises;
• representatives of customers, suppliers and business partners (including lorry drivers);
• the Company’s employees and contractors.
Legal basis for processing:
Data is processed to pursue legitimate interests – protecting the Company’s buildings, mill, timber stocks and transport areas against theft, damage or unauthorised access, preventing or detecting criminal offences and other violations of the law, ensuring the safety of the working environment and of persons, and recording evidence to protect legal interests in the event of incidents.
Data recipients:
• the Company’s authorised employees (for example, security, IT or management representatives);
• IT and video surveillance system maintenance service providers (processors);
• licensed security service providers that provide physical and technical security;
• law enforcement authorities, courts and state/municipal institutions (for example, the State Police) upon a justified request in the manner prescribed by laws and regulations.
Video surveillance zones are marked with appropriate signs at the entrances to the office and premises.
2.5. Website functionality, security and analytics
To ensure the secure and smooth operation of the Website, improve the user experience and evaluate Website traffic, the Company and its authorised IT service providers process the technical and behavioural data of Website visitors, including in order to:
• ensure the security of the Website, protection against cyberattacks and protection of the contact form against automated requests (spam);
• display the interactive map and ensure its functionality in the “Contacts” section;
• evaluate the number of visits to the Website, analytics and traffic sources in order to improve the structure and performance of the Website.
Categories of data processed:
• IP address and the approximate geographic location derived from it;
• device, operating system and browser type and technical parameters;
• identifiers of cookies and similar technologies;
• visit and browsing history on the Website (including pages visited, viewing time and clicks).
Data subjects:
• Website visitors.
Legal basis for processing:
• the Company’s legitimate interests with regard to technically necessary and security cookies that ensure the basic functionality of the Website, protection against spam and secure operation;
• the data subject’s consent (for analytics and preference cookies);
Data recipients:
• the Company’s authorised employees and departments;
• IT, website maintenance, security and analytics service providers (processors), such as Google Ireland Ltd. and Cloudflare Inc., ensuring data protection in accordance with the applicable international data transfer mechanisms.
Detailed information about the cookies used on the Website, their types, validity periods and service providers is available in the Company’s Cookie Policy.
III. Automated processing and profiling
The Company does not carry out automated decision-making or profiling that would produce legal effects for the Customer or similarly significantly affect the Customer. Should this change, the Company will supplement this Policy accordingly, specifying the purposes of profiling, the logic used, as well as its significance and the envisaged consequences for the data subject.
IV. Data retention period
The Company stores and processes the Data Subject’s personal data only for as long as necessary to achieve the specific processing purposes, or as long as at least one of the following conditions applies:
• a contract concluded between the Company and the Data Subject (or the legal entity represented by the Data Subject) is in force, or steps are being taken prior to entering into a contract;
• the Company has a legal obligation to retain the relevant documents and data in the manner prescribed by external laws and regulations (for example, the Accounting Law, the Archives Law, etc.);
• the Company or the Data Subject may exercise and defend their legitimate interests in the manner prescribed by laws and regulations (for example, bring an action in court, lodge objections or secure evidence within the limitation period);
• the Data Subject’s consent to the relevant processing of personal data is in force, where no other legal basis for processing exists.
When the retention period ends or none of the above conditions applies any longer, the Data Subject’s personal data is securely deleted, destroyed or irreversibly anonymised so that it can no longer be linked to a specific natural person.
The retention period for cookies and related data corresponds to the validity period of each specific cookie as specified in the Company’s Cookie Policy. The Data Subject may change or withdraw their consent at any time in the cookie management tool integrated into the Website.
V. Rights of the data subject and how to exercise them
In accordance with data protection legislation, including the General Data Protection Regulation, the data subject – a natural person whose personal data is processed by the Company – has the following rights with regard to the processing carried out by the Company:
• to receive additional information about the processing of personal data carried out by the Company, to request a copy of the data subject’s personal data held by the Company and to receive information about how to obtain that copy;
• to request rectification of the data subject’s personal data (if the information about the data subject held by the Company is found to be inaccurate or incomplete, the data subject has the right to request that the Company correct it);
• to withdraw consent to the processing of personal data given to the Company;
• to request erasure of the data subject’s personal data;
• to request restriction of the processing of personal data (marking the personal data held by the Company to restrict its processing in the future);
• to request data portability (the possibility to receive information about the data subject’s personal data in a machine-readable format);
• to object to the processing of personal data based on the Company’s legitimate interests;
• to receive confirmation as to whether the Company processes the data subject’s personal data, where such data is not being processed.
The above rights of the data subject are not absolute, and their exercise may be limited. For example, the Company has the right to refuse to stop processing personal data if the Company demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or for the establishment, exercise or defence of the Company’s legal claims.
To exercise the data subject’s rights or to obtain additional information about the processing carried out by the Company, the data subject or other persons may contact the Company using the contact details provided in this Policy.
The Company’s compliance with data protection rights is supervised by the Data State Inspectorate. To resolve any disputes or uncertainties, the Company asks data subjects to contact the Company first. If the data subject is not satisfied with the response received, or in other cases, they have the right to lodge a complaint with the Data State Inspectorate (address: Elijas iela 17, Riga, LV-1050; e-mail: info@dvi.gov.lv; phone: 67223131).
VI. Obligations and responsibility of the data subject
• The Data Subject is responsible for the accuracy, validity and completeness of the personal data provided when submitting requests, initiating and maintaining cooperation with the Company or concluding contracts.
• To ensure accurate performance of the contract, compliance with laws and regulations and uninterrupted communication, the Data Subject (or the Customer/business partner they represent) must inform the Company in good time of any material changes to the personal data provided (for example, a change of contact details or authorised representative).
• If the Data Subject provides the Company with the personal data of third parties (for example, their employees, representatives or contact persons), the Data Subject (or the legal entity they represent) is responsible for informing those persons about the processing of their data in accordance with this Policy.
• Notifications of changes to data must be sent in writing to the Company’s e-mail address or registered office specified in Section 9 of this Policy.
VII. Transfer of personal data to third countries
The Company processes data using service providers located in the European Union/European Economic Area or elsewhere.
The transfer of personal data to third parties, regardless of the recipient’s location, is governed by the applicable laws and regulations or by a contract between the Company and the relevant third party that includes data confidentiality and processing security conditions.
If personal data is transferred to a country outside the European Union/European Economic Area (a third country), this is done on one of the following legal bases:
• a European Commission decision on the adequate level of data protection in the relevant third country;
• appropriate safeguards, such as standard contractual clauses (SCC) approved by the European Commission or binding corporate rules (BCR);
• the derogations set out in Article 49 of the General Data Protection Regulation.
The Customer may request up-to-date information about specific cases in which personal data is transferred to third countries and the safeguards applied by contacting the Company using the contact details specified in Section 9 of this Policy.
VIII. Amendments to the Policy
The Company has the right to unilaterally amend this Privacy Policy at any time in accordance with the applicable legislation, ensuring that the current Privacy Policy is published on the Company’s Website.
IX. Contact information
The Customer may contact the Company regarding personal data protection, including withdrawal of consent, requests, exercise of data subject rights and complaints about the processing of personal data.
The Company’s contact details for personal data protection matters: e-mail: info@amberbirch.lv; address: “Finieris”, Krustpils parish, Jēkabpils municipality, LV-5204.
