Privacy Notice
Last updated: 15.09.2026
This notice explains how NALDERN processes personal data in connection with accounts, professional profiles, bookings, payments, security and legal compliance.
Controller
NALDERN is operated by NALDERN. Statutory operator details are available on the legal information page. Legal information.
Data collected
Account identity, contact details, language and optional marketing preferences, profile and skills, provider status, tax-registration country and tax/registration number, registration-verification records, booking records, payment and payout references, transaction counts, ratings, support messages, security logs, device/IP information and private work evidence.
Purposes and legal bases
Data is used to perform marketplace contracts, process payments, verify service completion, prevent fraud, secure accounts, resolve disputes, meet accounting/tax duties and improve the service. Depending on the processing activity, the legal basis may be performance of a contract, compliance with a legal obligation, legitimate interests or consent.
Payments
Full card details and connected-account identity checks are handled by the payment provider. NALDERN stores transaction identifiers, statuses and reconciliation information but is not designed to store full card numbers.
Private evidence
Evidence images are not published on professional profiles. Access is limited to the client and professional participating in that booking and authorised NALDERN administrators. Evidence is stored as private operational data and is not intended for public profile display.
Retention
Personal data is retained only for as long as needed for the purpose for which it was collected and for applicable legal, accounting, tax, fraud-prevention and dispute-resolution obligations. Retention periods or the criteria used to determine them depend on the record type and legal requirement.
Recipients
Data may be shared with payment, hosting, database, object storage, email, security, accounting and professional advisers where necessary and subject to suitable agreements. Provider identification, tax and transaction information may also be disclosed to the Latvian State Revenue Service or another competent authority where tax, accounting or DAC7 reporting law requires it.
International transfers
Where a service provider processes personal data outside the European Economic Area, NALDERN uses an appropriate transfer mechanism where required by applicable data-protection law.
Cookies
NALDERN uses essential session and security technologies needed for login, account protection and core marketplace functions. Non-essential analytics or marketing technologies should only be enabled with an appropriate legal basis and consent where required.
Marketing preferences
Optional product or marketing messages are sent only where consent is recorded. Users can withdraw that consent from the dashboard without affecting booking, payment, security or legal communications.
Your rights
Depending on applicable law, users may request access, correction, deletion, restriction, portability or objection and may complain to the Latvian Data State Inspectorate or another competent supervisory authority.
Security
The application includes password hashing, signed sessions, CSRF protection, rate-limited logins, optional email verification and admin TOTP, private evidence routes, upload validation, event idempotency and audit logs. Production also requires HTTPS, managed backups, monitoring, least-privilege access and incident response.