Privacy Policy
This policy explains what personal data we collect through adr.plus, why we collect it, who else sees it, and what you can ask us to do about it.
Chapters
Who we are
The website adr.plus is operated by SIA "STABBURAG". ADRplus is our brand name. There is no separate "ADRplus SIA". We decide why and how personal data collected through this website is used, which makes us the data controller under the GDPR.
- SIA "STABBURAG"
- Registration No. 45403048103
- VAT No. LV45403048103
- Ganību dambis 26A, Rīga, LV-1005, Latvia
- Email — [email protected]
- Phone — +371 22 32 88 77
Email is the fastest way to reach us about anything in this policy. Please use [email protected] — it is our only working address for privacy matters.
We have not appointed a data protection officer. Our activities do not meet the conditions in Article 37 of the GDPR that would make one mandatory. Questions go to [email protected].
What this policy covers
This policy describes what the website actually does. Where something is planned but not yet built, we say so.
It covers the website adr.plus, including the shop, the course pages, the contact form, the service enquiry forms and the free tools.
The learning platform at app.adr.plus is a separate system with its own accounts. This policy explains what we send there when you buy a course, and what the platform does with it.
When your company signs a service contract with us, we also process the data of your representatives and employees inside the platform. The terms of that processing are set out in the contract itself, in its section on personal data. This policy describes the processing that takes place through the adr.plus website.
Our cookies and browser storage are described separately in our Cookie Policy.
When you buy from the shop
At checkout you enter the recipient's name, phone number and email address, the delivery country, and either a parcel machine location or a street address, city and postcode. A company name is optional.
These details are sent to Stripe, our payment provider, as part of your checkout session. You then enter your card details on Stripe's own page. Card numbers never reach our servers.
Our own order records hold amounts, product names, the shipment tracking number and Stripe identifiers — not your name or address. However, we also store a complete copy of every payment event Stripe sends us, exactly as we receive it. Those copies do contain your name, email address, phone number, billing and delivery address, any company name or tax number you gave Stripe, and the last four digits and card brand. Your personal data therefore resides in these copies, not in our order table, which on its own appears anonymous.
Your basket is kept in a cookie on your device. See the Cookie Policy.
- Purpose — to take and fulfil your order, arrange delivery, issue the invoice and keep the accounting records.
- Legal basis — performance of our contract with you (Article 6(1)(b) GDPR). Keeping accounting records is a legal obligation (Article 6(1)(c) GDPR).
When you buy a course
The course page sends only the course name and your interface language to Stripe. You enter your email address and payment details on Stripe's page.
After payment, we send to our learning platform at app.adr.plus — your email address, your name if Stripe collected one, the course you bought, the payment reference, the amount and currency, your interface language and your Stripe customer identifier.
The platform then creates an account for you automatically. You do not register yourself. The platform sends you an email with your access link. That email comes from the platform, not from this website.
- Purpose — to give you access to the course you paid for.
- Legal basis — performance of our contract with you (Article 6(1)(b) GDPR).
When you use the contact form
We store your name, email address, your message and the language of the page you wrote from.
The message field is free text. Please keep it to your enquiry and do not include health information, identity document numbers or other sensitive details — we have no need for them.
- Purpose — to read and answer your enquiry.
- Legal basis — steps taken at your request before entering into a contract (Article 6(1)(b) GDPR). If your message is not about buying anything, our basis is our legitimate interest in replying to people who contact us (Article 6(1)(f) GDPR).
When you ask for a consultant contract or a platform subscription
We store your company name and registration number, your VAT number and legal address where you give them, the contact person's name, email address and phone number, the plan you selected and the number of employees.
- Purpose — to prepare your contract and the notice appointing your safety adviser.
- Legal basis — steps taken at your request before entering into a contract (Article 6(1)(b) GDPR).
We keep these enquiries for 2 years from your last contact unless a contract follows.
When you order a dangerous goods declaration
We store the company name, the contact name, the email address and phone number, the UN number and cargo description, your notes, and the documents you upload.
The documents are held on our server until payment is confirmed, then emailed to our consultant and deleted from the server. Unpaid requests are deleted after 72 hours. The emailed copy stays in our mailbox for the accounting retention period.
Please upload only the documents needed for the declaration.
- Purpose — to prepare the declaration you ordered.
- Legal basis — performance of our contract with you (Article 6(1)(b) GDPR).
Newsletter
We do not send a newsletter at the moment, and the sign-up form has been removed from the website. Nothing on adr.plus collects an address for marketing.
If we start sending one, it will be on your explicit consent only (Article 6(1)(a) GDPR), given by a separate action, and every email will carry a link that lets you unsubscribe. We will update this policy before the first email goes out.
If you gave us your address while the sign-up form was still on the site, write to [email protected] and we will delete it.
Cookies and site measurement
On every visit we place two items ourselves, a basket cookie and a cookie that records your cookie choice. Everything else depends on your choice in the banner. If you accept analytics, we set a random identifier for our own visit measurement, Cloudflare counts visits for us and Google Analytics 4 sets its cookies. If you accept advertising, Google Ads conversion measurement and the Meta pixel set theirs. Full details, including how long each one lasts, are in our Cookie Policy.
- Legal basis — for the basket and the consent record, these are strictly necessary for a service you asked for, so no consent is needed. For everything in the analytics and advertising categories, your consent (Article 6(1)(a) GDPR), which you can withdraw at any time in the cookie settings.
Technical logs and abuse protection
When you start a checkout or open an order confirmation page, we use your IP address to count requests and block flooding. The counter lives in our temporary store for up to one hour and then deletes itself. We do not write IP addresses to our database.
Our servers and application also produce technical logs — errors, system events and payment references. These can include the email address attached to an order.
The site search box puts your search term into the page address, so search terms can appear in server logs. Do not type personal details into the search box.
- Purpose — keeping the site available, preventing abuse and diagnosing faults.
- Legal basis — our legitimate interest in running a secure and working website (Article 6(1)(f) GDPR).
The free tools do not send us anything
Our calculators, the UN number search, the tunnel lookup, the test trainer and the DGSA self-check run entirely in your browser. What you type into them stays on your device — nothing is uploaded to us, and nothing is stored on our servers.
The tunnel map is the one exception — map images are fetched from an outside service, which therefore sees your IP address. See "Who we share data with".
If you order for someone else
If the delivery recipient is not you, we receive that person's name, phone number, email address and address from you, not from them.
We use those details only to deliver the order and to contact the recipient about the delivery. If you are that recipient and want to know more, or want your details removed, write to [email protected].
Who we share data with
We do not sell personal data. Google and Meta receive data from your browser only within the categories you accept in the cookie banner, and nothing before you choose. We use no social media buttons that track you.
These are the parties that actually receive data, by name.
Stripe — Stripe Payments Europe, Limited (Ireland) and Stripe, LLC (United States). Stripe processes the payment, hosts the payment page, creates the invoice and sends us the payment events. Stripe receives your name, email address, phone number, billing and delivery address, company name and tax number where you give them, your card details, your IP address and your browser information.
Our learning platform at app.adr.plus — operated by us. It receives the details listed under "When you buy a course", and only when you buy a course.
Our print partner and Omniva — shop orders are produced and dispatched by our printing partner ONprint SIA (Latvia), and carried by Omniva. To deliver your order they receive the recipient's name, phone number, email address and delivery address. We pass these details to ONprint by email. There is no automatic connection between our systems.
OpenFreeMap — supplies the map images on our tunnel map page from tiles.openfreemap.org. When you open that page your browser contacts them directly, so they receive your IP address, your browser information and which part of the map you are looking at. They set no cookies on our site. This happens as soon as the map page loads.
Our hosting provider — Hetzner Online GmbH (Germany) runs the servers that hold the website and its database. The servers are inside the EU.
Google — Google Ireland Limited (Ireland) and Google LLC (United States). Three things. When you type an address into our delivery, invoice or subscription forms, our server sends what you have typed to the Google Places interface so that it can suggest matching addresses. Your browser does not contact Google directly. Separately, our mailbox runs on Google Workspace, so all correspondence between you and us, including anything you attach, is stored there. Thirdly, the site loads the Google Tag Manager script on every page. Until you choose in the cookie banner it sets nothing on your device, but Google receives your IP address and the address of the page. If you accept analytics, Google Analytics 4 measures visits, and if you accept advertising, Google Ads measures which visits came from our advertisements. Both receive your IP address, the pages you open and actions such as sending a form or completing an order, and set the cookies listed in our Cookie Policy. Google LLC is certified under the EU-U.S. Data Privacy Framework.
Meta — Meta Platforms Ireland Limited (Ireland) and Meta Platforms, Inc. (United States). Only if you accept advertising cookies. The Meta pixel then tells Meta which of our pages you open and which actions you take, such as sending a form or completing an order, together with your IP address and browser information. We use this to measure our advertising on Facebook and Instagram and to show it to people who have visited our site. Meta also uses the data for its own purposes under its own policy. Meta Platforms, Inc. is certified under the EU-U.S. Data Privacy Framework.
Cloudflare, Inc. (United States) — protects our order and enquiry forms against automated abuse with Cloudflare Turnstile. The Turnstile script loads into your browser from Cloudflare, and we send Cloudflare your IP address so that it can verify the result. If you accept analytics cookies, Cloudflare also provides our visitor measurement, and its script receives your IP address and the page you have open. Cloudflare, Inc. is certified under the EU-U.S. Data Privacy Framework.
Our accountant — sees invoices only.
Public authorities — where the law requires us to hand data over.
Sending data outside the EU
Stripe. Our contracting party is Stripe Payments Europe, Limited in Ireland, inside the EU. Stripe, LLC in the United States is certified under the EU-U.S. Data Privacy Framework. The European Commission has decided that this framework provides an adequate level of protection, so transfers to Stripe in the United States rely on that adequacy decision. They do not rely on standard contractual clauses.
Google and Meta. Our contracting parties are Google Ireland Limited and Meta Platforms Ireland Limited, both in Ireland. Data from the analytics and advertising tools can also be processed by Google LLC and Meta Platforms, Inc. in the United States. Both are certified under the EU-U.S. Data Privacy Framework, so those transfers rely on the same adequacy decision. The tools run only within the categories you accept in the cookie banner.
OpenFreeMap. Map images are served from infrastructure we do not control, so we cannot tell you which country serves them. The only data involved is your IP address, your browser information and the map area you view. If you do not want this, do not open the tunnel map page.
If an adequacy decision we rely on is withdrawn, we will move that transfer onto another lawful mechanism and update this policy.
How long we keep data
| Data | How long we keep it |
|---|---|
| Orders and invoices | Invoices and supporting documents at least 5 years, accounting registers and inventory lists 10 years, annual reports until the company is reorganised or ceases activity (Grāmatvedības likums, Section 28) |
| Stored copies of the payment events Stripe sends us | 90 days, then deleted automatically |
| Contact form enquiries | 2 years from your last message |
| Enquiries from the service forms (leads) | 2 years from your last contact |
| Files attached to a dangerous goods declaration request | until payment is confirmed, unpaid requests are deleted after 72 hours |
| Correspondence in our mailbox | the accounting retention period |
| Newsletter sign-up | until you unsubscribe, a sign-up you never confirm is deleted after 7 days |
| Your cookie choice | 1 year, then we ask again |
| IP address used for rate limiting | up to 1 hour, deleted automatically |
| Server and application logs | 90 days |
One qualification — these periods are our policy, and most of them we apply by hand. Deletion runs automatically for unpaid declaration files after 72 hours, for the stored payment events and for unconfirmed newsletter sign-ups. For the other rows it is not built yet. Until it is, data is removed on request or during periodic review. If you ask us to delete your data, we do it — see "Your rights".
Do you have to give us your data?
No law requires you to give us anything. But some data is necessary for the thing you are trying to do.
- Without a name, phone number, email address and delivery address we cannot ship an order.
- Without an email address Stripe cannot complete a purchase and we cannot give you course access.
- Without an email address we cannot reply to your enquiry.
- Without a contact email address we cannot prepare a contract, a subscription or a dangerous goods declaration for you.
If you do not provide these, we simply cannot deliver, reply or give access.
Your rights
You can ask us to
- give you a copy of the personal data we hold about you.
- correct anything that is wrong or incomplete.
- delete your data, where we are not required to keep it — accounting records are the usual exception.
- restrict what we do with it while a dispute over accuracy or lawfulness is resolved.
- hand it over to you or to another provider in a machine-readable format, where we hold it on the basis of your consent or a contract.
- stop processing based on our legitimate interest, if your situation gives you grounds to object.
Where we rely on your consent, you can withdraw it at any time. That does not make what we did before the withdrawal unlawful.
Write to [email protected]. We answer within one month. If a request is complicated we may take up to two further months and will tell you why within the first month. This is free. If we cannot tell who you are from the request, we will ask you for something that confirms it.
Marketing email — your right to object
You can tell us at any time to stop sending you marketing email, for any reason or none. You do not have to justify it, and there is no cost.
Email [email protected] with "unsubscribe" and we will remove your address from the list. We will stop sending marketing email as soon as we act on your message.
If you want to complain
If you think we are handling your data wrongly, please tell us first at [email protected]. Most issues are quicker to fix directly.
You can also complain to the Latvian supervisory authority.
- Datu valsts inspekcija
- Elijas iela 17, Rīga, LV-1050, Latvia
- +371 67223131
- [email protected]
- www.dvi.gov.lv
Complaining is free. The authority normally responds within three months. It asks that you contact the controller first and attach our reply to your complaint. You can also go to court instead of, or in addition to, complaining.
Children
This website is built for professionals working with dangerous goods. It is not intended for children.
In Latvia, a child can consent to online services from the age of 13. Below that, a parent or guardian must consent. We do not knowingly collect data from children under 13, and we do not verify anyone's age — there is no age check on this site.
If you believe a child under 13 has given us personal data, email [email protected] and we will delete it.
Automated decisions and profiling
We do not make automated decisions that produce legal effects for you or similarly significantly affect you.
We do not profile you. Prices are the same for everyone. Nothing on this site is personalised to your behaviour.
Special categories of data
We do not ask for and do not want health data, biometric data, or any other special category of personal data under Article 9 of the GDPR. No form on this site collects it. Please do not send it to us in a contact message.
How we protect data
Card numbers are entered on Stripe's payment page and never reach our servers. Our database and cache are not reachable from the internet. Only the website itself can talk to them. Payment events from Stripe are checked with a cryptographic signature before we accept them, and the data we send to our learning platform is signed the same way.
Access to the live database and servers is limited to the owner.
No system is perfectly secure. If a breach occurs that is likely to put your rights at risk, we will notify you and the supervisory authority as the GDPR requires.
Changes to this policy
We update this policy when what we do changes. The current version date is shown at the top of this page. If a change affects something you consented to, we will ask for your consent again before acting on it.


