Privacy Policy
1. General provisions
1.1. The purpose of this personal data processing (privacy) policy (hereinafter — the Policy) is to provide the natural person (hereinafter — the data subject) with general information about the processing of personal data at the foundation “Artificial Intelligence Centre” (hereinafter — the Controller or MIC).
1.2. The Policy applies to the processing of personal data of the following persons:
- the Controller’s employees and recruitment candidates;
- participants of the special regulatory environment (sandbox) and their representatives;
- engaged experts, evaluators and cooperation partners;
- other persons whose personal data are processed as a result of the Controller’s activities.
1.3. Detailed information on specific personal data processing is provided in the Controller’s internal regulatory acts, contracts and service-related documents.
2. Controller and contact information
- foundation “Artificial Intelligence Centre”;
- registration No. 40008346331;
- legal address: Alberta iela 10, Riga, LV-1010;
- e-mail: info@ailatvia.lv
3. Data Protection Officer
3.1. On matters concerning personal data processing and the exercise of the data subject’s rights, the data subject may contact the Controller’s Data Protection Officer by writing to info@ailatvia.lv
4. Applicable regulatory acts
4.1. The Controller carries out personal data processing in accordance with:
- Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation; hereinafter — the Regulation);
- the Personal Data Processing Law;
- Articles 57–63 of Regulation (EU) 2024/1689 (Artificial Intelligence Act) on the regulatory sandbox;
- the Artificial Intelligence Centre Law and Cabinet Regulation No. 12 of 13 January 2026 “Procedure by which the Artificial Intelligence Centre organises the special regulatory environment and data processing”;
- other applicable regulatory acts.
5. Purposes and legal basis of processing
5.1. The Controller processes personal data for the following purposes and on the following legal basis set out in Article 6(1) of the Regulation:
- ensuring the operation of the special regulatory environment (sandbox) (receipt of applications, evaluation, admission of participants): subparagraph (c) (legal obligation in connection with Articles 57–63 of the AI Act, the Artificial Intelligence Centre Law and Cabinet Regulation No. 12) and subparagraph (e) (task carried out in the public interest);
- preparation, conclusion and performance of contracts: subparagraph (b) (contract) and subparagraph (c);
- engagement of experts and evaluators, administration of confidentiality and conflict-of-interest declarations: subparagraph (b) (contract) and subparagraph (f) (legitimate interest in ensuring independent evaluation);
- examination of submissions, complaints and correspondence: subparagraph (c) (Law on Submissions) and subparagraph (f);
- accounting and financial records: subparagraph (c) (Accounting Law and tax-related regulatory acts);
- organisation of public procurement and administration of contracts: subparagraph (c) (Public Procurement Law);
- recruitment, employment relations and informing the public: subparagraphs (b) and (c) (Labour Law, etc.); for informing the public — subparagraph (f).
5.2. Where processing is based on consent, the data subject may withdraw it at any time; withdrawal does not affect the lawfulness of processing carried out previously. The Controller does not carry out automated decision-making producing legal effects concerning the data subject.
6. Categories of personal data processed
6.1. Depending on the purpose of processing, the Controller processes:
- identification data (name, surname) and contact information (e-mail, telephone, address);
- representation-related data (position, the legal person represented);
- professional qualification and experience data (for experts, candidates);
- the content of communications and correspondence;
- contract, financial and settlement data.
6.2. Within its core activities, the Controller does not process special categories of personal data (Article 9 of the Regulation), except where required by regulatory acts (for example, within the framework of employment relations).
7. Recipients and processors of personal data
7.1. Personal data may be accessed by:
- the Controller’s authorised employees;
- engaged experts and evaluators, subject to confidentiality obligations;
- processors providing services to the Controller (IT and cloud services, accounting and legal services);
- public authorities in cases laid down by regulatory acts (including the Data State Inspectorate, courts, law enforcement authorities).
7.2. With processors, the Controller concludes contracts compliant with the requirements of Article 28 of the Regulation.
8. Transfer of personal data outside the EU and EEA
8.1. The Controller generally does not transfer personal data outside the European Union or the European Economic Area. Where the provision of certain services requires it, transfer takes place only by ensuring the safeguards provided for in Chapter V of the Data Regulation.
9. Personal data retention periods
9.1. The Controller retains personal data no longer than necessary to achieve the purpose of processing or as laid down by regulatory acts. Specific periods are set out in the Controller’s records nomenclature and register of processing activities.
9.2. After the expiry of the retention period, personal data are erased or destroyed.
10. Rights of the data subject
10.1. Under the Regulation, the data subject has the right to:
- access their personal data and receive information about its processing;
- request the rectification or completion of inaccurate data;
- request the erasure of data, insofar as not restricted by regulatory acts;
- request the restriction of processing;
- object to processing based on legitimate interests;
- data portability, insofar as processing is based on consent or a contract and is automated;
- withdraw previously given consent;
- lodge a complaint with the supervisory authority.
10.2. The rights are exercised by submitting a request to the Controller and confirming one’s identity. Certain rights may be restricted where processing is necessary for the fulfilment of obligations laid down in the Controller’s regulatory acts.
11. Security and personal data breaches
11.1. The Controller implements appropriate technical and organisational measures to protect personal data, including the restriction of access rights, confidentiality obligations of employees and experts, and the protection of information systems and end-devices.
11.2. In the event of a personal data breach, the Controller acts in accordance with Articles 33 and 34 of the Regulation.
12. Cookies
12.1. Cookies are not used on the Controller’s website.
13. Lodging complaints
13.1. The data subject has the right to lodge a complaint with the supervisory authority — the Data State Inspectorate (Elijas iela 17, Riga, LV-1050; e-mail pasts@dvi.gov.lv; www.dvi.gov.lv). Beforehand, the Controller invites the data subject to contact the Controller.
14. Entry into force and amendments of the Policy
14.1. The Policy enters into force upon its approval.
14.2. The Controller has the right to amend the Policy by publishing its current version on its website. If the purposes or scope of processing change, the Policy is supplemented before the relevant processing begins.