TFE · TRANSPORT FOR EVENTS

Privacy policy

How SIA "Transport For Events" handles personal data on this site — what we collect, why, how long we keep it and what your rights are.

1. Controller and contact details

The controller of personal data is SIA "Transport For Events" (below — TFE, "we"), registration number 40203088470, registered address Viskaļu iela 5, Rīga, LV-1026, Latvia.

For any question about the processing of personal data write to rekini@tfe.lv. We have not appointed a separate data protection officer — the scale of our activity does not require one.

This policy covers the website tfe.lv and the services offered on it: booking enquiries for picture cars, hot tubs and transport, invoices, and the client portal.

2. What data we process

Booking enquiry. When you submit the checkout form we receive your name, e-mail address, phone number, company name (if given), the requested rental dates, city, a free-text note and the list of items you selected. This goes into our enquiry and customer records.

Orders and invoices. From the enquiry we create an order and reservations, and for priced items also an invoice in PDF form. The invoice contains the customer's name or company name, contact details, the rental lines, the period and the amount. We send the invoice to the customer and to the company's billing address.

Client portal. If you create an account in the "For clients" section, we store your e-mail address, a cryptographic hash of your password (Argon2id — we never store the password in clear text and cannot recover it), the time your e-mail was verified, the time of your last sign-in, and single-use e-mail verification and password-reset tokens. Of those tokens we likewise store only the hash, and they are valid for a limited time.

Correspondence. Every order in the portal has a message thread — your messages and our replies are kept with that order. We likewise keep correspondence by e-mail or phone insofar as it concerns an enquiry or an order.

Technical data. The site's session record stores the session identifier, the IP address, the browser User-Agent string and the list of selected items. To throttle failed sign-in attempts we record the IP address and the time. Server logs capture requests, errors and similar technical information.

3. Purposes and legal bases

  • Preparing and performing a contract (GDPR Art. 6(1)(b)) — handling the enquiry, preparing a quote, reserving items, performing the rental, issuing invoices, running the client portal account and communicating about the order.
  • Compliance with a legal obligation (Art. 6(1)(c)) — accounting and tax law requirements for supporting documents.
  • Legitimate interests (Art. 6(1)(f)) — the security of the site and of accounts, prevention of fraud and abuse, preserving evidence and defending our rights in the event of claims.

We currently send no marketing messages and use neither profiling nor automated decision-making. If we offer a newsletter in the future, it will be sent only on the basis of separate, freely withdrawable consent (Art. 6(1)(a)).

4. Cookies

The site uses strictly necessary cookies only. There are no analytics, advertising, social-network or other tracking cookies here.

  • tfe_sess — the site session cookie. It holds a randomly generated identifier and links your browser to the session stored on the server: your list of selected items (the "cart"), the CSRF protection token, notices about the result of an action, and the sign-in state in the client portal or the admin area. Lifetime — 14 days. The cookie is HttpOnly and SameSite=Lax; over HTTPS it is also flagged Secure.

In addition we keep two technical flags in the browser's own storage (localStorage and sessionStorage — these are not cookies and are never sent to the server): an acknowledgement that you have read the cookie notice, and a note that the intro animation has already played in this browser session.

The "Accept" button in the notice bar confirms that you have read this information. Because we use necessary cookies only, no separate consent for them is required — without them the site would not work. You can delete or block cookies in your browser settings; the cart and signing in will then stop working.

External content. We host our fonts on our own server, so there are no Google Fonts requests. Some pages, however, currently load background images from Unsplash (images.unsplash.com), every page loads a shared style library from jsDelivr (cdn.jsdelivr.net), and the map on the contacts page loads map tiles from OpenStreetMap. Loading such an external resource means that the service in question sees your browser's IP address and the technical details of the request. We receive no visitor data back from those services.

5. Recipients and processors

Only those TFE staff who need it for their work have access to the data. In addition we use the following processors:

  • our server and website hosting provider;
  • the e-mail (SMTP) provider through which we send confirmations, invoices and portal links;
  • our accounting service provider — for processing supporting documents;
  • Google Drive — for archiving invoice PDFs to the company drive, when that option is enabled.

We may also disclose data to public authorities where the law requires it, and to legal advisers or a debt-collection provider where that is necessary to pursue claims. We do not sell personal data and do not pass it to third parties for marketing purposes.

6. Retention periods

  • Accounting documents — invoices and the data related to them — are kept for the period laid down by law, normally 5 years.
  • Enquiries, orders and correspondence are kept for as long as the client relationship lasts, and thereafter for the general limitation period for claims.
  • A client portal account is kept for as long as the account exists. On a deletion request we delete the account and the sign-in data, but invoices remain in storage because of the legal obligation mentioned above.
  • Security records are kept briefly: failed sign-in records are deleted automatically after roughly a day, a session record expires after 14 days, and server logs are kept only for error diagnostics and security purposes.

7. Transfers outside the EU/EEA

By default the data is processed in the European Union or the European Economic Area. The only transfer we anticipate is archiving invoice PDFs to Google Drive: it happens only when that option is enabled, and in that case the transfer relies on the provider's data processing agreement and on the standard contractual clauses approved by the European Commission. The external resources mentioned in section 4 (images, style library, maps) may likewise mean that your browser's IP address reaches servers outside the EU.

8. Your rights

In relation to your personal data you have the right to:

  • be informed about the processing and to access your data;
  • request the rectification of inaccurate data;
  • request erasure where there is no longer a basis for the processing;
  • request restriction of the processing;
  • receive the data you have given us in a structured, commonly used format and transmit it to another controller (data portability);
  • object to processing based on our legitimate interests;
  • withdraw consent where the processing is based on consent — withdrawal does not affect processing carried out beforehand.

Send your request to rekini@tfe.lv from the e-mail address given in the enquiry or on the account; if there is any doubt about identity we may ask for further information. We reply within one month at the latest — in complex cases that period may be extended, and we will tell you if it is.

9. Complaints

If you believe we have breached data protection requirements, please contact us first — most matters can be settled straight away. You also have the right to lodge a complaint with the supervisory authority:

Data State Inspectorate (Datu valsts inspekcija)
Elijas iela 17, Rīga, LV-1050, Latvia
pasts@dvi.gov.lv
www.dvi.gov.lv

10. Minors

Our services are intended for businesses and adults. We do not knowingly collect or process children's data. If we learn that an account or an enquiry has been created for a minor without the knowledge of their legal representative, we delete that data.

11. Changes to this policy

We update this policy whenever the functionality of the site or our processing practice changes. The current version is always available on this page, and we will announce significant changes on the site or by e-mail.

Last updated: July 2026.

From road to celebration.
BASED IN LATVIA · WORKING WORLDWIDE
© 2025–2026 SIA TFE · ALL RIGHTS RESERVED Privacy policy