Privacy policy
Version 1.0 · effective from 18 August 2026 · Abian Marketplace SIA
This Policy describes the personal data that Abian Marketplace SIA processes in relation to representatives of our business customers and visitors to the website, the purposes for which and the legal bases on which such data are processed, the recipients to whom they are disclosed, the period for which they are retained, and your rights.
1. Controller and Scope of This Policy
1.1. The controller of personal data is Abian Marketplace SIA, registration number 40203763064, registered office at 7 Aldaru Street, Riga, LV-1050, e-mail [email protected], telephone +371 25443536 (hereinafter — Abian, we, us or our).
1.2. For data protection matters and to exercise data subject rights, please write to [email protected].
1.3. This Policy describes how we collect, use and process the data of natural persons who represent or are associated with our business customers (hereinafter — you or Users), as well as the data of website visitors.
1.4. A complete list of cookies and similar technologies, their purposes and retention periods is provided in a separate Cookie Policy, to which this Policy refers in Section 8.
1.5. We process personal data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (the General Data Protection Regulation, hereinafter — the GDPR) and other applicable laws and regulations.
2. Data We Process
2.1. We process the following categories of data:
General data: first name, surname, language of communication.
Professional data: position, the company represented and business contact details (e-mail address, telephone number).
Account data: username in the Abian Marketplace (Magento) system, login information, assigned permissions, user activity and other information provided voluntarily by the User.
Transaction data: orders, order confirmations, invoices, payment history, credit-limit information, complaints, returns and warranty claims.
Communication data: correspondence with us, including e-mails, contact-form submissions and notes of conversations.
Consent data: information concerning consents given and withdrawn for receiving commercial communications and using cookies, including the time and scope of the consent.
Compliance data: information obtained through sanctions and export-control checks, including information concerning members of management boards and beneficial owners.
Technical data: IP address, device and browser information, security logs and access logs.
2.2. Sources of data. We obtain data directly from you (when you register and use the system), indirectly from the legal entity that you represent, from public registers and sanctions lists, and from credit information bureaux.
2.3. Where we have obtained data indirectly rather than from you, we will inform you of the processing and the source of the data within a reasonable period, normally within one month of obtaining the data, unless you have already been informed or providing the information proves impossible or would involve disproportionate effort (Article 14 of the GDPR).
2.4. Provision of the data is a prerequisite for creating an account and processing orders. Without contact-person and account data, we cannot provide access to the Platform or fulfil orders. Consent to receive marketing communications and to the use of non-essential cookies is voluntary and does not affect the availability of the service.
3. Purposes and Legal Bases of Processing
3.1. We process data for the following purposes and on the following legal bases:
Performance of contractual obligations towards a business customer, processing orders and arranging delivery — our legitimate interests in ensuring performance of the contract with the legal entity represented (point (f) of Article 6(1) of the GDPR). If you are yourself a party to the contract as a person carrying on an economic activity — performance of a contract (point (b) of Article 6(1)).
Account administration, management of User authorisations and customer service — legitimate interests (point (f) of Article 6(1)).
Sending notifications concerning order status, transactions and changes to the account — legitimate interests (point (f) of Article 6(1)). These are transactional communications, and it is not possible to opt out of them while the contractual relationship remains in force.
Compliance with accounting and tax requirements and retention of invoices and supporting documents — compliance with a legal obligation (point (c) of Article 6(1)).
Sanctions, export-control and dual-use compliance checks, including screening customers, members of management boards and beneficial owners against sanctions lists — compliance with a legal obligation (point (c) of Article 6(1)) and legitimate interests (point (f)).
Creditworthiness assessment and credit-limit administration — legitimate interests (point (f) of Article 6(1)). In relation to legal entities, this assessment generally does not involve personal data; personal data are processed where the customer is a person carrying on an economic activity or where beneficial owners are screened.
Debt recovery and the bringing and defence of claims — legitimate interests (point (f) of Article 6(1)).
System security, fraud prevention, access logging and improvement of functionality — legitimate interests (point (f) of Article 6(1)).
Recommending suitable products and solutions on the Platform — legitimate interests (point (f) of Article 6(1)).
Sending informational materials and commercial communications — your consent (point (a) of Article 6(1)).
Use of analytics and marketing tools on the website — your consent (point (a) of Article 6(1)).
3.2. Where processing is based on legitimate interests, we have conducted a balancing assessment. A summary is available upon request by writing to [email protected].
3.3. Consent may be withdrawn at any time — in relation to marketing communications, by using the unsubscribe link in each communication or by writing to us; and in relation to cookies, by using the website’s consent-management tool. Withdrawal of consent does not affect the lawfulness of processing carried out while the consent was in force.
4. Profiling and Automated Decision-Making
4.1. Recommending products and solutions on the Platform constitutes profiling. It is based on previous order and browsing history and does not produce legal effects concerning you.
4.2. We do not take decisions based solely on automated processing that produce legal effects concerning you or otherwise significantly affect you. Decisions to grant, reduce or withdraw a credit limit are taken by an Abian employee after assessing the available information.
4.3. You have the right to object to profiling based on legitimate interests by writing to [email protected].
5. Recipients
5.1. We may disclose your data to the following categories of recipients:
Distributors and manufacturers — for order fulfilment and in cases involving warranties and product recalls;
Transport and logistics service providers — for delivery and tracking;
Providers of cloud services, hosting and IT infrastructure maintenance, including the maintainer of the Magento Platform;
The e-mail, office and document-management service provider at [email protected];
The provider maintaining the accounting and payment system;
Providers of marketing and analytics tools — Google Ireland Limited and Meta Platforms Ireland Limited;
Credit information bureaux — for creditworthiness assessments; they are provided with information concerning the company and, where applicable, the person carrying on an economic activity and payment discipline;
Banks and payment service providers — for processing payments;
Legal advisers, auditors and debt-recovery service providers — for the defence and recovery of claims;
State and municipal authorities — where required by laws and regulations, including the State Revenue Service and supervisory authorities.
5.2. Data-processing agreements that comply with the requirements of Article 28 of the GDPR have been concluded with all processors that process data on our behalf. We do not sell or rent your data.
6. Transfers of Data Outside the European Economic Area
6.1. When the analytics and marketing tools referred to in Section 8 are used, data may be transferred to recipients in the United States of America, namely Google LLC and Meta Platforms, Inc.
6.2. Transfers take place on the basis of the European Commission’s adequacy decision concerning the EU–US Data Privacy Framework, insofar as the relevant recipient is certified under it. Where the adequacy decision does not apply, transfers take place on the basis of the standard contractual clauses approved by the European Commission, together with supplementary safeguards.
6.3. You have the right to obtain information concerning the safeguards applied and a copy of the relevant documents by writing to [email protected].
7. Joint Controllership
7.1. In relation to the use of the Meta Pixel on the website, Abian and Meta Platforms Ireland Limited act as joint controllers within the meaning of Article 26 of the GDPR.
7.2. Allocation of roles: Abian is responsible for obtaining consent and providing information concerning the collection of data on the website; Meta is responsible for the subsequent processing of the data on its Platform and for facilitating the exercise of data subject rights in relation to that processing. This allocation follows from Meta’s Controller Addendum, which forms part of Meta’s Business Terms.
7.3. You may exercise your rights by contacting either joint controller. If you contact us, we will consider your request insofar as it relates to our part of the processing and, where necessary, explain how to contact Meta.
8. Cookies, Analytics and Tracking
8.1. The website uses strictly necessary cookies as well as analytics and marketing tools. Analytics and marketing tools that are not strictly necessary are activated only after the user has given consent through the consent-management tool; the relevant scripts are not loaded until consent has been obtained.
8.2. Subject to consent, the following tools are used:
Google Analytics 4 (GA4) — to analyse website visits and user flows;
Meta Pixel — to measure advertising effectiveness and for remarketing;
Google Ads — to track advertising conversions and for remarketing.
8.3. A complete list of cookies and similar technologies, their purposes, providers and retention periods is set out in the Cookie Policy. Consent given may be withdrawn or changed at any time using the same consent-management tool.
8.4. Consent to the use of cookies and tracking tools is given by the relevant natural person in their browser. A Customer that is a legal entity does not and cannot give such consent on behalf of its Users. The Customer’s obligation to inform its Users about data processing on the Platform is set out in Clauses 3.6 and 12.5 of the Terms of Use.
9. Retention Periods
9.1. We retain data no longer than is necessary for the relevant purpose:
Accounting and tax documents, including invoices — for the period prescribed by laws and regulations; supporting documents are generally retained for five years unless the law prescribes a longer period;
Account, order and transaction data — for the duration of the contractual relationship and for three years after the most recent transaction, in accordance with the limitation period for claims arising from commercial transactions;
Communication data — for three years from the end of the correspondence;
Creditworthiness-assessment data — for as long as the credit limit remains in force and for three years after its withdrawal;
Records of compliance and sanctions checks — for five years from the date of the check, in order to demonstrate that due diligence has been performed;
Marketing data — until consent is withdrawn; records of the consent and its withdrawal are retained for a further three years for evidential purposes;
Security and access logs — for up to 12 months;
Cookie data — in accordance with the periods specified in the Cookie Policy.
9.2. At the end of the relevant period, the data are deleted or irreversibly anonymised. Where a dispute or legal proceedings exist, we retain the relevant data until the matter has been finally resolved and the relevant decision enforced.
10. Data Security
10.1. We apply technical and organisational measures appropriate to the risks of the processing, including encryption of data in transit, need-to-know access controls, multi-factor authentication for administrative access, activity logging, backups and employee training.
10.2. Processors are contractually required to provide an equivalent level of security and to report incidents without delay.
10.3. In the event of a personal data breach, we act in accordance with Articles 33 and 34 of the GDPR: we notify the Data State Inspectorate within 72 hours where the breach is likely to result in a risk to the rights of natural persons, and we inform the affected persons where the risk is high. We also inform the Customer of security incidents affecting the Customer’s data or deliveries in accordance with Clause 10.7 of the Terms of Use.
11. Your Rights
11.1. You have the following rights:
Access to data — to obtain information concerning the data about you that we process and a copy of those data;
Rectification — to request the correction of inaccurate or incomplete data;
Erasure — to request the erasure of data (the right to be forgotten) in certain circumstances;
Restriction of processing — to request restriction of processing in certain circumstances;
Objection — to object to processing based on legitimate interests, including profiling, and to processing for direct-marketing purposes;
Data portability — to receive the data that you have provided to us in a structured, commonly used and machine-readable format, or to request that they be transmitted to another controller, insofar as the processing is based on consent or a contract and is carried out by automated means;
Withdrawal of consent — to withdraw consent given at any time;
The right not to be subject to a decision based solely on automated processing that produces legal effects;
Lodging a complaint — to apply to the supervisory authority or to a court.
11.2. How to exercise your rights. Please submit a request by writing to [email protected]. We will respond within one month of receiving the request; in complex cases, we may extend this period by a further two months, and will inform you accordingly. To protect your data, we may need to verify your identity. Exercising your rights is free of charge, except in the case of manifestly unfounded or excessive requests.
11.3. If you are dissatisfied with our response, you have the right to lodge a complaint with the Data State Inspectorate (www.dvi.gov.lv) and to apply to a court. We invite you to contact us first — most matters can be resolved more quickly.
12. Minors
12.1. Abian Marketplace is a B2B platform and is not intended for persons under 18 years of age. We do not knowingly collect data concerning minors.
13. Amendments and Versions of the Policy
13.1. We may amend this Policy. We will notify you of material amendments at the account e-mail address and publish the new version on the website no later than 14 days before it enters into force.
13.2. We maintain an archive of previous versions indicating the period during which each version was in force, so that it is possible to determine which version applied at a particular time.
13.3. This is Version 1.0, effective from 18 August 2026.
14. Related Documents
14.1. This Policy should be read together with the following documents:
Cookie Policy — a complete list of cookies, their purposes and retention periods (see Section 8 of this Policy);
Terms of Use — in particular Clause 3.6 (the parties’ roles as independent controllers in relation to contact-person data), Clause 6.2 (creditworthiness checks), Clause 10.7 (security incidents), and Section 12 (data protection and tracking);
Delivery Terms — disclosure of data to carriers for the performance of deliveries;
Warranty Terms — disclosure of data to manufacturers and service centres, as well as the warning concerning the deletion of data before equipment is submitted for repair;
Product Return Terms — processing of data in the consideration of complaints and return requests.
14.2. If this Policy and the Terms of Use conflict in relation to the rights and obligations of the parties, the Terms of Use shall prevail. The description of personal data processing is governed by this Policy.
15. Company Details
Service provider and Seller of the Goods:
Name and registration number: Abian Marketplace SIA, registration No. 40203763064
VAT registration number: LV40203763064
Registered office: 7 Aldaru Street, Riga, LV-1050
E-mail and telephone: [email protected], +371 25443536
Bank account: LV94HABA0551065606312 (AS Swedbank, SWIFT/BIC HABALV22)
For data protection matters: [email protected]
Supervisory authorities: Consumer Rights Protection Centre (market surveillance), Data State Inspectorate (personal data protection)