Privacy policy

Last updated on 8 July 2026.

1. General Provisions
1.1. MC Renaissance Ltd., registration No. 40103895609 (hereinafter referred to as the Company), provides accommodation services and real estate brokerage services within the scope of its business activities.
In the course of its business activities, the Company cooperates with clients, business partners, suppliers and other persons whose personal data may be processed in accordance with this Privacy Policy.

1.2. The purpose of this Privacy Policy is to provide information on how the Company processes personal data, including:
• the sources from which personal data are obtained;
• the purposes of processing;
• the legal basis for processing;
• data retention periods;
• recipients of personal data;
• the rights of data subjects and the procedures for exercising those rights.

1.3. When processing personal data, the Company complies with:
• Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation – GDPR);
• the Personal Data Processing Law of the Republic of Latvia;
• and all other applicable laws and regulations of the European Union and the Republic of Latvia relating to the protection of personal data.

1.4. This Privacy Policy applies to every natural person whose personal data are processed by the Company, regardless of the manner in which such data are provided, including:
• through the Company’s website;
• by e-mail;
• by telephone;
• in person;
• or through other communication channels.

1.5. The Company ensures the protection of personal data and processes such data with the utmost care.
The protection of personal data and privacy is of fundamental importance to the Company and constitutes an essential part of its corporate values.

1.6. This Privacy Policy applies to:

1.6.1. the Company’s clients, including prospective, current and former clients, persons making reservations, guests, prospective purchasers of real estate, prospective tenants, authorised representatives and other persons who use or intend to use the Company’s services;

1.6.2. the Company’s employees, prospective employees (job applicants), trainees and other persons whose personal data are processed within the framework of employment relationships or recruitment procedures;

1.6.3. persons visiting the Company’s premises, territory or other facilities where video surveillance is in operation;

1.6.4. visitors to the Company’s website: www.storiesapartments.com.

1.7. Information regarding the cookies used by the Company, including their types, purposes, retention periods and legal basis for processing, is available in the Company’s Cookie Policy, published on the Company’s website: https://storiesapartments.com/en/sikdatnu-politika.

 

2. Data Controller and Contact Information
2.1. The controller of personal data processing is MC Renaissance Ltd., registration No. 40103895609. Registered office: Turaidas iela 19, Jūrmala, LV-2015, Latvia.

2.2. If you have any questions regarding the processing of personal data or this Privacy Policy, you may contact the Company: e-mail: stories@storiesapartments.com, telephone: +371 27997740.

 

3. Purposes of Personal Data Processing, Legal Basis and Categories of Personal Data
3.1. The Company processes personal data for the following purposes:
3.1.1. To identify the client, communicate with the client or their authorised representative, make and administer reservations, provide accommodation services, administer payments, and handle applications related to the services provided.
Legal basis:
Article 6(1)(b) of the General Data Protection Regulation (GDPR) – processing is necessary for the performance of a contract or in order to take steps at the request of the data subject prior to entering into a contract.
Categories of personal data:
• first name;
• surname;
• personal identification number or date of birth (where required for identification or contract conclusion);
• contact information (telephone number and e-mail address);
• reservation details;
• information regarding accommodation services provided;
• bank account details;
• payment information;
• any other information necessary for the provision of services and the performance of the contract.
Retention period:
Personal data are retained throughout the contractual relationship or the provision of services and thereafter for the periods required by applicable law.
Data contained in accounting records are retained in accordance with the Accounting Law (generally for at least five (5) years).
Data required for the establishment, exercise or defence of legal claims may be retained until the expiry of the applicable limitation period (generally up to ten (10) years).

3.1.2. To identify the client, communicate with the client or their authorised representative, provide real estate brokerage services, prepare, conclude and perform contracts, administer payments, and handle applications related to the services provided.
Legal basis:
Article 6(1)(b) GDPR – processing is necessary for the performance of a contract or in order to take steps at the request of the data subject prior to entering into a contract.
Categories of personal data:
• first name;
• surname;
• personal identification number or date of birth (where required for identification or contract conclusion);
• contact information (telephone number, e-mail address and residential address);
• power of attorney details (where applicable);
• bank account details;
• payment information;
• any other information necessary for the provision of services and the performance of the contract.
Retention period:
Personal data are retained throughout the contractual relationship or the provision of services and thereafter for the periods required by applicable law.
Data contained in accounting records are retained in accordance with the Accounting Law (generally for at least five (5) years).
Data required for the establishment, exercise or defence of legal claims may be retained until the expiry of the applicable limitation period (generally up to ten (10) years).

3.1.3. To comply with the Company’s legal obligations in the fields of accounting, tax administration, financial reporting, payment documentation and preparation of financial statements.
Legal basis:
Article 6(1)(c) GDPR – processing is necessary for compliance with a legal obligation to which the Controller is subject.
Categories of personal data:
• identification data (first name, surname, personal identification number or date of birth where required by law);
• contact information;
• payment and settlement information;
• bank account details;
• information contained in invoices, accounting records, contracts and other accounting documents;
• information regarding services provided and transactions carried out;
• any other information required for compliance with applicable legal obligations.
Retention period:
Personal data are retained for the periods prescribed by applicable legislation governing accounting records and supporting documentation (generally not less than five (5) years in accordance with the Accounting Law), or for a longer period where required by law or necessary to protect the Company’s legal rights and legitimate interests.

3.1.4. To examine applications, complaints, claims and disputes submitted by clients, business partners and other persons, to protect the Company’s rights and legitimate interests, and to secure evidence for potential disputes, legal proceedings or other legal processes.
Legal basis:
Article 6(1)(f) GDPR – processing is necessary for the purposes of the legitimate interests pursued by the Controller.
Legitimate interest:
To ensure the proper handling of applications, complaints, claims and disputes, to protect the Company’s legal rights and legitimate interests, and to establish, exercise or defend legal claims.
Categories of personal data:
• identification data;
• contact information;
• communication and correspondence records;
• information contained in applications, complaints, claims and other documents;
• information regarding services provided;
• information relating to concluded agreements;
• information regarding real estate transactions or brokerage services;
• payment information;
• any other information necessary for assessing the particular case and protecting the Company’s legal rights or legitimate interests.
Retention period:
Personal data are retained until the relevant application, complaint, claim or dispute has been fully resolved and thereafter until the expiry of the applicable limitation period for legal claims (generally up to five (5) years for personal data protection disputes and up to ten (10) years for civil law claims).

3.1.5. To ensure the recruitment process, assess candidates’ suitability for vacant positions, and protect the Company’s legitimate interests in connection with the recruitment process.
Legal basis:
• Article 6(1)(b) GDPR – processing is necessary in order to take steps at the request of the data subject prior to entering into an employment relationship;
• Article 6(1)(f) GDPR – processing is necessary for the purposes of the Company’s legitimate interests;
• Article 6(1)(a) GDPR – the candidate’s consent, where the candidate has agreed to the retention of their personal data for future recruitment opportunities.
Legitimate interest:
To ensure an effective recruitment process and to protect the Company’s rights in the event of potential disputes.
Categories of personal data:
• first name;
• surname;
• contact details;
• employment history;
• education;
• professional qualifications;
• skills and competencies;
• any other information voluntarily provided by the candidate, to the extent necessary for the recruitment process.
Retention period:
Personal data are retained until the recruitment process has been completed and thereafter for no longer than six (6) months in order to protect the Company’s legitimate interests in the event of possible claims or disputes.
Where the candidate has consented to the retention of their personal data for future recruitment opportunities, such data shall be retained for the period specified in the consent or until the consent is withdrawn.

3.1.6. To ensure the security of the Company’s premises, territory, the persons present therein and the Company’s property, to prevent and detect criminal offences and other unlawful activities, and to protect the rights and legitimate interests of the Company and third parties.
Legal basis:
Article 6(1)(f) GDPR – processing is necessary for the purposes of the Company’s legitimate interests.
Legitimate interest:
To ensure the security of the Company’s premises, territory and the persons present therein, as well as to prevent security threats and other unlawful activities.
Categories of personal data:
• image of a person captured by the CCTV system;
• date of recording;
• time of recording;
• location of recording;
• any other information recorded by the video surveillance system.
Retention period:
CCTV recordings are retained for no longer than forty (40) days from the date of recording, unless a specific recording is required for the investigation of an incident, violation, dispute, legal claim or court proceedings.
In such cases, the recording may be retained until the relevant matter has been finally resolved.

3.1.7. To manage vehicle access to the Company’s premises, administer parking facilities, record vehicle entry and exit, and ensure the safety of the Company’s property and of third parties.
Legal basis:
Article 6(1)(f) GDPR – processing is necessary for the purposes of the Company’s legitimate interests.
Legitimate interest:
To ensure effective vehicle access control, prevent unauthorised access to the Company’s premises, and investigate security incidents and violations.
Categories of personal data:
• vehicle registration number;
• vehicle make or model;
• information regarding the date and time of entry and exit.
Retention period:
Personal data are retained for no longer than forty (40) days from the date of collection, unless the data are required for the investigation of an incident, violation, dispute, legal claim or court proceedings.
In such cases, the data may be retained until the relevant matter has been finally resolved.

3.1.8. To send clients newsletters, updates, special offers, information about the Company’s services, and other information that is not directly related to the performance of a concluded contract.
Legal basis:
Article 6(1)(a) GDPR – the data subject’s consent.
Categories of personal data:
• first name;
• surname;
• e-mail address;
• telephone number;
• information confirming the client’s consent to receive such communications.
Retention period:
Personal data are retained until the consent is withdrawn or until the Company ceases sending the relevant communications, unless applicable law requires a longer retention period.

3.2. Profiling and Automated Decision-Making
The Company does not carry out profiling of personal data and does not make decisions based solely on automated processing of personal data that would produce legal effects concerning the data subject or similarly significantly affect the data subject.

 

4. Sources of Personal Data
4.1. The Company primarily obtains personal data directly from the data subject, including when the data subject:
• makes a reservation;
• applies for the Company’s services;
• enters into or performs a contract;
• applies for real estate brokerage services;
• submits applications, requests, enquiries, complaints or claims;
• communicates with the Company by e-mail, telephone or in person;
• provides personal data through the Company’s website or other communication channels.

4.2. In certain cases, the Company may obtain personal data from:
• authorised representatives of the data subject;
• reservation platforms and real estate advertisements;
• business partners;
• prospective purchasers or tenants;
• state and municipal authorities;
• public registers;
• or other persons, to the extent necessary for achieving the specific purpose of processing and where such processing has a lawful basis.

4.3. Within the framework of video surveillance and vehicle access control, personal data are collected through the Company’s video surveillance and access control systems.

 

5. Retention of Personal Data
5.1. Personal data are processed and retained only for as long as necessary to achieve the relevant purpose of processing, comply with applicable legal requirements, or protect the Company’s legal rights and legitimate interests.
The applicable retention periods are determined according to the specific purpose of processing and are set out in Section 3 of this Privacy Policy.

 

6. Protection of Personal Data and Security Measures
6.1. The Company protects personal data by using modern technologies and taking into account the privacy risks associated with personal data processing, as well as the organisational, technical and financial resources reasonably available to the Company.
6.2. To ensure the security of personal data, the Company implements appropriate technical and organisational measures, including:
6.2.1. the use of firewalls;
6.2.2. encryption of data during transmission;
6.2.3. intrusion prevention and intrusion detection solutions;
6.2.4. other security measures appropriate to the current state of technology.

 

7. Transfer of Personal Data and Recipients
7.1. The Company transfers personal data to third parties only where there is a lawful basis for doing so, including:
• for the conclusion or performance of a contract;
• to comply with legal obligations imposed by applicable laws and regulations;
• based on the data subject’s consent; or
• for the protection of the Company’s legitimate interests.

7.2. Personal data may be transferred to companies within the Company’s group to the extent necessary for:
• group management;
• risk management;
• financial control;
• human resources management;
• accounting;
• legal support;
• and other administrative functions.
Such transfers are carried out only where an appropriate legal basis exists and in compliance with the applicable legal requirements.

7.3. Personal data may be transferred to the Company’s business partners and service providers that provide:
• payment processing services;
• accounting services;
• information technology support and maintenance;
• reservation management;
• legal services;
• debt recovery services;
• and other services related to the Company’s business activities.
These recipients process personal data only to the extent necessary for the performance of their services and in accordance with the applicable legal requirements.
7.4. Personal data may also be disclosed to state and municipal authorities, law enforcement authorities, courts, certified bailiffs and other competent authorities where required by applicable law.
7.5. Personal data may also be disclosed to third parties in other cases where the data subject has given consent or where such disclosure is permitted under applicable law.
7.6. Personal data are accessible only to those employees and authorised persons of the Company who require such access for the performance of their job duties or contractual obligations.

 

8. Transfer of Personal Data to Third Countries or International Organizations
8.1. As a general rule, the Company does not transfer personal data outside the European Union (EU) or the European Economic Area (EEA).
Where, in exceptional cases, such a transfer is necessary, the Company ensures that the transfer is carried out in compliance with the applicable legal requirements and that appropriate additional safeguards for the protection of personal data are implemented in accordance with the GDPR.

 

9. Rights of the Data Subject
9.1. The data subject has the right to receive information regarding the processing of their personal data by the Company.
9.2. The data subject has the right to:
• access their personal data;
• obtain information about the purposes of processing;
• the categories of personal data processed;
• the recipients of the personal data;
• the retention periods;
• the sources from which the personal data were obtained;
• and, where provided by law, receive a copy of their personal data.

9.3. The data subject has the right to request the rectification of inaccurate or incomplete personal data.

9.4. In the cases provided for by applicable law, the data subject has the right to request the restriction of the processing of their personal data.

9.5. The data subject has the right to object to the processing of their personal data where such processing is based on the Company’s legitimate interests.

9.6. The data subject has the right to data portability in the cases provided for by applicable law.

9.7. Where personal data are processed on the basis of consent, the data subject has the right to withdraw their consent at any time by sending an e-mail to: stories@storiesapartments.com
The withdrawal of consent shall not affect the lawfulness of processing carried out before the withdrawal.

9.8. To exercise your rights, please contact the Company:
E-mail: stories@storiesapartments.com
or send a written request to:
MC Renaissance Ltd.
Turaidas iela 19,
Jūrmala, LV-2015, Latvia.

For identification purposes, the Company accepts requests:
• submitted electronically and signed with a qualified electronic signature; or
• submitted in paper form bearing the handwritten signature of the data subject.

9.9. The Company shall respond to the data subject’s request within one (1) month of receipt.
Where necessary, taking into account the complexity or volume of the request, this period may be extended by up to two (2) additional months, and the data subject will be informed accordingly.
9.10. If the data subject believes that their personal data are being processed in violation of applicable data protection laws, they have the right to lodge a complaint with the Data State Inspectorate of Latvia (Datu valsts inspekcija).
Address:
Elijas iela 17,
Rīga, LV-1050, Latvia
E-mail: pasts@dvi.gov.lv
Telephone: +371 67223131
Website: www.dvi.gov.lv

 

10. Final Provisions
10.1. The Company may update this Privacy Policy from time to time.