Privacy policy

Effective from 9 September 2026.

KIRSH Veselības Fabrika respects your privacy. This policy explains how we process personal data when you visit our website, submit an enquiry, contact us or receive healthcare services in Jelgava and Jēkabpils.

1. Who is responsible for your data?

The data controller is SIA “KIRSH LEGAL Solutions”, registration No. 45403035359, registered address: Rīgas iela 214, Jēkabpils, Jēkabpils Municipality, LV-5202. Healthcare institution code: 110000079.

Send questions about personal data and exercising your rights to birojs@kirshveselibasfabrika.lv, with “Personal data protection” in the subject line. You may also submit a request in person or by post to our registered address.

2. What data do we collect?

  • In enquiries and communications: your first name, surname, telephone number, email address, selected clinic, specialist or service, preferred appointment time and the information in your message, depending on the form completed.
  • During healthcare: data needed to identify the patient; information about health, symptoms, examinations, diagnosis and treatment; and representative details if you act on behalf of a patient.
  • For payments: invoice, payment and, where applicable, insurance information.
  • For website operation and security: IP address, request time, technical browser and device data, and information about errors. With your consent, Google Analytics also processes statistics about visits, devices, approximate location and interactions.

We usually receive data from you. Information needed for healthcare may also come from your legal or authorised representative, referring doctor, another healthcare provider, laboratory, booking platform or a lawfully accessible health information system. We use such information only for the relevant purpose and within the applicable legal basis.

Do not include your personal identity number, diagnoses, test results or other detailed health information in an ordinary contact form. If such data is needed, reception or a healthcare professional will explain a suitable way to submit it.

3. Why do we use data, and on what basis?

  • To respond and arrange an appointment: processing is necessary to take steps at your request before providing a service and to provide that service: Article 6(1)(b) of the General Data Protection Regulation (GDPR). For general enquiries, the basis is our legitimate interest in maintaining communication: Article 6(1)(f).
  • To provide healthcare: GDPR Article 6(1)(b) and (c); health data is also subject to Article 9(2)(h) and professional confidentiality requirements. We comply with the Medical Treatment Law, the Law on the Rights of Patients and medical record-keeping requirements.
  • To process payments and fulfil legal obligations: GDPR Article 6(1)(b) and (c). This includes accounting, document retention and providing information to competent authorities where required by law.
  • To protect the website and handle complaints or claims: our legitimate interests in ensuring system security, preventing misuse and defending our rights: GDPR Article 6(1)(f). Where a claim involves health data, Article 9(2)(f) also applies.
  • For visit analytics and separately selected marketing communications: your consent: GDPR Article 6(1)(a). Marketing consent is not required to receive services.

Submitting a form allows reception to contact you about that particular request; it does not in itself constitute consent to receive advertising. An appointment is confirmed after agreement with reception or confirmation in the booking system. Acknowledging that you have read the privacy policy does not replace the informed consent required for medical treatment.

4. Who may access your data?

Data is accessed by clinic personnel authorised to perform their duties, including reception, healthcare professionals and staff responsible for overseeing enquiries. Enquiries may be stored in the website form records and sent to the relevant clinic’s work email, including for internal enquiry oversight.

Where necessary, we use providers of IT, website maintenance, email, patient management and accounting services. When processing data on our behalf, they must follow our instructions, confidentiality requirements and data processing agreements. Data may also be received by your chosen booking platform, partners involved in treatment, your insurer if you use insurance, and authorities in cases prescribed by law. We do not disclose health information to unauthorised persons.

5. How long do we retain data?

  • Contact and enquiry data is retained while processing your request, arranging your appointment and resolving the matter. Further retention is justified only by the need to document the service provided, fulfil a legal obligation or handle a specific complaint or claim. The retention periods for medical records do not automatically apply in full to an enquiry.
  • For medical documents, the period depends on the document type. For example, a patient’s outpatient record is retained for 40 years after the last entry or 15 years after the patient’s death under Cabinet Regulation No. 265. Other documents may have different retention periods.
  • Payment documents are retained for the period specified for the relevant document type in the Accounting Law.
  • Security logs are retained for as long as necessary to detect and investigate incidents. Records related to an incident may be retained until the investigation is complete and for the period necessary to defend a claim.
  • Consent records are retained to respect your choice and, where necessary, demonstrate that consent was given or withdrawn. Cookie lifetimes are listed in the next section. Analytics user and event data retention is separate from the cookie lifetime and depends on the Analytics property’s retention settings. You may ask the controller about your specific data and the applicable retention period.

6. Cookies and analytics choices

Cookies are small pieces of data stored in your browser by a website. Technically necessary data supports sessions, form security and your privacy choices. We enable Google Analytics 4 only after consent to analytics. Rejecting analytics does not limit your ability to browse the website or book an appointment.

Cookie or data type Purpose and basis Retention period
kirsh_privacy_choice_v1 Our website cookie records your analytics choice; technically necessary. 180 days.
_ga and _ga_V4TD0HGP7J First-party Google Analytics cookies distinguish visitors and sessions for statistical purposes; only with consent. Up to 180 days in the website code.
Session and form security data Processing requests and protecting against unauthorised requests; technically necessary. For the relevant session.

You can change your choice at any time by clicking “Cookie settings” in the website footer. Withdrawing consent stops further analytics loading and deletes accessible Analytics cookies on this domain. Withdrawal does not affect the lawfulness of earlier processing. You can also manage cookies in your browser settings.

Google provides the analytics service; for EEA users, the relevant provider is Google Ireland Limited. More information: Google Privacy Policy. Consent to analytics does not include consent to advertising personalisation.

7. External websites and data transfers

The “Book at Piearsta.lv” button opens an external booking platform. Data entered there is also subject to that platform’s privacy terms. The same applies to links to social networks and other external websites. Website fonts are loaded from Google Fonts; the loading request sends technical connection data, including your IP address, to Google. When you open a page with an embedded external map, its provider may receive browser and connection information.

Some external services may process data outside the European Economic Area, including in the USA. Such transfers must have a basis compliant with Chapter V of the GDPR, such as a European Commission adequacy decision or standard contractual clauses with any necessary supplementary safeguards. Read about Google’s mechanisms in Google’s data transfer framework. You may request information about the safeguards applicable to your data, and a copy of them, from the controller.

8. Your rights

Depending on the processing, you have the right to access your data and receive a copy, request correction of inaccurate data, erasure or restriction of processing, and receive portable data where GDPR conditions are met. You may object to processing based on legitimate interests and withdraw consent at any time. You may object to use of your data for direct marketing at any time.

Erasure is not an absolute right: we cannot delete documents that must be retained by law or are needed to defend a legal claim. Not providing required data may prevent us from responding, making a booking or safely providing a service. You may choose not to provide optional data.

Send your request to birojs@kirshveselibasfabrika.lv. To avoid disclosing data to another person, we may request proportionate verification of identity or authority to represent you. We respond within one month; in complex cases, this may be extended by a further two months, with notice and reasons given within the first month.

You have the right to complain to the Data State Inspectorate: Elijas iela 17, Rīga, LV-1050; pasts@dvi.gov.lv; www.dvi.gov.lv. Contacting us first is not a prerequisite for submitting a complaint.

9. Data security and policy updates

Personal data is protected by technical and organisational measures appropriate to the risks, restricted access and confidentiality. Submitting a website enquiry does not itself result in an automated treatment decision. Reception arranges the appointment, and a healthcare professional assesses medical matters.

We review this policy when services, data processing or regulatory requirements change. The current version and its effective date are available on this page. If new processing requires consent, updating the policy does not itself replace that consent.