Privacy Policy
How Touch & Care SIA collects, uses and protects your personal data under the GDPR
Last updated: 22 May 2026
This Privacy Policy explains how Touch & Care SIA ("LUKE", "we", "us" or "our") processes your personal data when you visit our website, book an appointment, or receive our aesthetic cosmetology services. We process your data in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR") and the Latvian Personal Data Processing Law (Fizisko personu datu apstrādes likums).
Data Controller
Touch & Care SIA
Cēsu iela 31, k-3, Entrance 4, Floor 3, Office 18, Riga, LV-1012, Latvia
Phone: +371 2550 0000 · Email: info@luke.lv
We have not appointed a Data Protection Officer; please direct all data protection queries to the contacts above.
1. What Personal Data We Collect
Depending on how you interact with us, we may process:
- Identity and contact data: name, email address, phone number, date of birth, and postal address
- Appointment and account data: services booked, appointment history, login credentials, and notes you provide
- Health and treatment data (special category): medical history, skin and hair condition, contraindications, allergies, medication, consultation and treatment records, and before/after documentation — see Section 3
- Payment data: transaction amount, date, and status. Card details are entered directly with our payment provider and are not stored on our servers
- Communication data: messages, emails, and enquiries you send us
- Technical and usage data: IP address, browser and device type, pages visited, and similar data collected via cookies (see Section 7)
2. Legal Bases for Processing
We only process your personal data where we have a lawful basis under Article 6 (and, for health data, Article 9) of the GDPR:
- Performance of a contract (Art. 6(1)(b)) — to manage your bookings, provide services, and handle payments
- Consent (Art. 6(1)(a)) — for marketing communications, non-essential cookies, and the processing of your health data (see Section 3); you may withdraw consent at any time
- Legal obligation (Art. 6(1)(c)) — to comply with accounting, tax, and service-documentation requirements
- Legitimate interests (Art. 6(1)(f)) — to secure our website, prevent fraud, and improve our services, where these interests are not overridden by your rights
3. Health Data (Special Category Data)
Sensitive data — handled with extra care
As an aesthetic cosmetology provider we process data concerning your health, which is a special category of personal data under Article 9 of the GDPR and is subject to stricter protection.
We collect health-related data (such as medical history, skin and hair condition, allergies, contraindications, and treatment records) only where it is necessary to assess your suitability for a procedure and to deliver treatment safely. We rely on:
- Your explicit consent (Art. 9(2)(a)), given before treatment; and/or
- The provision of health/medical care (Art. 9(2)(h)), where data is processed by, or under the responsibility of, qualified professionals bound by an obligation of professional secrecy
Your health data is accessible only to the specialists involved in your care, is kept confidential, and is never used for marketing.
4. How We Use Your Data
- To create and manage your account and bookings
- To assess suitability for, perform, and follow up on treatments
- To process payments and issue invoices and gift cards
- To send appointment confirmations, reminders, and service-related messages
- To send marketing communications where you have consented
- To meet legal, accounting, and tax obligations
- To maintain the security of our website and prevent fraud
- To analyse website use and improve our services (only with your cookie consent)
5. Who We Share Your Data With
We do not sell your personal data. We share it only with trusted service providers ("processors") who act on our instructions, and with authorities where legally required:
- Payment processing: Stripe, which securely handles card payments
- Website and email hosting: our hosting provider, which stores website and account data on its servers
- Booking notifications: a messaging service (Telegram) used to alert our staff to new bookings
- Website analytics: Google Analytics, only if you accept analytics cookies
- Public authorities: where required by law, or to establish, exercise, or defend legal claims
- Business transfers: in connection with a merger, sale, or reorganisation
6. International Data Transfers
Some of our providers (such as Stripe and Google) may process data outside the European Economic Area. Where this happens, the transfer is protected by appropriate safeguards under the GDPR, such as the European Commission's Standard Contractual Clauses or the EU–US Data Privacy Framework.
7. Cookies and Analytics
Necessary cookies (session, language, cart) are always active because the site cannot function without them. Analytics and marketing cookies are only set after you give consent through our cookie banner, which uses Google Consent Mode. Until you consent, no analytics or marketing scripts are loaded.
You can change or withdraw your choice at any time using the cookie settings button on the site, or by clearing cookies in your browser.
8. How Long We Keep Your Data
We keep your data only as long as necessary for the purposes above:
- Account and booking data: while your account is active and for a reasonable period afterwards
- Health and treatment records: for the period required by the laws governing documentation of the services provided
- Accounting and payment records: for at least 5 years, as required by Latvian accounting and tax law
- Marketing data: until you withdraw your consent
- Cookie data: for the lifetime of each cookie (the consent record is stored for up to 6 months)
9. How We Protect Your Data
- Encryption of data in transit (HTTPS)
- Access limited to authorised staff on a need-to-know basis
- Secure, access-controlled storage
- Staff bound by confidentiality
- Regular review of our security measures
10. Your Rights
Under the GDPR you have the right to:
- Access the personal data we hold about you
- Rectification of inaccurate or incomplete data
- Erasure ("right to be forgotten"), subject to our legal retention duties
- Restriction of processing
- Data portability — to receive your data in a structured, commonly used format
- Object to processing based on legitimate interests, or to direct marketing
- Withdraw consent at any time, without affecting processing carried out before withdrawal
To exercise any of these rights, contact us using the details below. We will respond within one month. We do not use automated decision-making or profiling that produces legal or similarly significant effects.
11. Right to Lodge a Complaint
If you believe we have not handled your data lawfully, please contact us first so we can resolve the matter. You also have the right to lodge a complaint with the Latvian supervisory authority:
Datu valsts inspekcija (Data State Inspectorate)
Elijas iela 17, Riga, LV-1050, Latvia
Phone: +371 67 223 131 · Email: pasts@dvi.gov.lv
Website: www.dvi.gov.lv
12. Children
Our services are not intended for persons under 18 years of age. A person under 18 may only attend accompanied by a parent or guardian who assumes full responsibility and provides consent.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will post the updated version on our website and revise the "Last updated" date. Significant changes will be communicated where appropriate. Your continued use of our services after changes constitutes acceptance of the updated policy.
Contact Us
If you have any questions about this privacy policy or wish to exercise your data protection rights, please contact us:
Floor 3, Office 18
Riga, Latvia, Postal Code: LV-1012