01
Who controls your data
Parffolio is operated by Raitis Senkovs, a private individual and the controller responsible for personal data processed through parffolio.com.
Raitis SenkovsAptiekas iela 13-26
LV-1005, Riga, Latvia
privacy@parffolio.com
info@parffolio.com
This Policy applies to parffolio.com and its fragrance, search, rating, moderated-comment, consent and contact functions.
02
Personal data we process
Depending on how you use Parffolio, we may process:
- Technical and security data: IP address, request time, requested URL, user agent, response status and security signals contained in server or infrastructure logs.
- Consent information: the consent-policy version, selected categories, timestamp and a random local receipt stored in the
pf_consentcookie. - Community data: ratings, preferences, impressions and moderated comments; the public name and optional scent-of-the-day selection attached to a comment; and a pseudonymous signed browser identifier created only after your first submission.
- Contact data: name, email address, selected topic, subject, optional page URL, message and the technical information needed to deliver and protect the form.
- Analytics data, with consent: page views, approximate location derived from IP, device/browser information, traffic source and interaction data processed through Google Analytics 4.
- Advertising data, with consent: conversion, campaign and remarketing signals processed through configured Google Ads features.
Parffolio does not ask for special-category personal data. Please do not include unnecessary sensitive information in a contact message.
03
How we collect it
We receive data directly when you vote, submit a moderated comment, submit the contact form or write to us; automatically when your browser requests the site; and from our infrastructure providers when they protect, deliver or log those requests.
We do not currently offer user accounts or a newsletter. Comments are reviewed before publication. The name, comment text, optional selected fragrance, date and comment reference become public only after approval.
04
Why we process data and our legal bases
| Purpose | Data | Legal basis |
|---|---|---|
| Deliver pages, secure the service and prevent abuse | Technical logs, request and security data | Legitimate interests in operating and protecting the service; legal obligations where applicable |
| Remember the visitor’s cookie choices | Consent version, categories, timestamp and local receipt | Compliance with consent obligations and legitimate interests in demonstrating the choice |
| Provide community ratings and permit updates | Pseudonymous identifier and submitted choices | Performance of the function requested by the participant and legitimate interests in vote integrity |
| Receive, review and publish community comments | Name, comment, optional scent of the day, pseudonymous identifier, moderation status and abuse-prevention signals | Performance of the requested community function and legitimate interests in moderation, safety and service integrity |
| Respond to enquiries and rights requests | Contact-form and correspondence data | Steps requested by you, legitimate interests in communication, and legal obligations for data-subject requests |
| Measure audience and improve the site | Google Analytics data | Your consent |
| Measure advertising, build audiences or personalise ads | Google Ads and campaign data | Your consent |
You may withdraw optional consent at any time through Cookie settings. Necessary processing does not depend on optional consent.
05
How community identifiers and comments work
Browsing a fragrance page does not create a voting identifier. When you make your first community submission, the server creates a random identifier and stores a signed value in the first-party pf_vid cookie. It is HttpOnly, SameSite=Lax and Secure on production HTTPS. It lets the database maintain one current submission per visitor, fragrance and supported metric; a later submission updates the current value. The same identifier can associate a submitted comment with abuse controls and a later privacy request, but it is never displayed publicly.
The identifier is pseudonymous, not anonymous, and is not used for advertising. Short-lived rate-limit records use privacy-reduced hashes derived from the identifier and limited request signals. Clearing the cookie creates a new identifier and may prevent us from linking a later request to the earlier record.
The “Cookie settings” panel can display a privacy reference derived from your current identifier without exposing the signed cookie. Include that reference when asking us to locate community records. A reference cannot be displayed before the first submission or after the identifier cookie has been deleted.
06
Service providers and recipients
We use selected providers only where needed to operate or measure the service:
- Hostinger provides VPS and hosting infrastructure; the selected server is located in Lithuania.
- Cloudflare provides domain, DNS, content-delivery and security services.
- Google Ireland Limited / Google LLC provide Google Analytics 4 and Google Ads only for categories that the visitor has allowed and only after the relevant production tag is configured.
- Email delivery providers process contact-form messages and direct email correspondence.
Providers process data under their own terms or our instructions as applicable. We may also disclose data where required by law, to protect rights or safety, or in connection with a lawful reorganisation. We do not sell personal data.
07
International transfers
Parffolio is established in Latvia and its selected hosting server is in Lithuania. Cloudflare, Google, email providers or their subprocessors may process data outside the European Economic Area.
Where EU data-protection law requires it, transfers rely on an adequacy decision, the EU Standard Contractual Clauses or another valid safeguard. You may contact us for information about the safeguard relevant to your data.
Optional Google processing does not begin unless the corresponding consent category has been granted.
08
How long we keep data
- Routine server and security logs are generally kept for up to 90 days, unless an incident, legal claim or investigation requires longer.
- Community ratings, preferences and impressions are retained for up to 24 months from their most recent update. A scheduled maintenance command deletes older identifiable community rows.
- Pending or hidden comments are generally reviewed or deleted within 12 months. Published comments may remain while relevant to the discussion, unless removed under the Community Guidelines, a valid rights request or another legal reason.
- The optional
pf_comment_namepreference cookie remembers only the submitted display name for up to 180 days and is created only when Preferences storage is allowed. A selected scent of the day is not stored in that cookie. - Short-lived rate-limit records expire after their applicable abuse-prevention window and are deleted by scheduled maintenance.
- The
pf_consentcookie expires after up to 180 days unless replaced, reset or deleted sooner. - The
pf_vidcookie expires after one year unless deleted sooner. - Google Analytics first-party cookies normally expire after up to two years unless a shorter setting is configured or the visitor withdraws consent and deletes them sooner. User-level data retention inside the GA4 property must be configured separately by the operator.
- Google Ads cookie lifetimes depend on the activated feature; common conversion cookies may remain for up to 90 days.
- Ordinary contact messages are generally kept for up to 24 months after the matter closes. Records needed to demonstrate how a rights request was handled may be kept for up to three years.
We may retain information longer where law requires it or for a specific dispute, security incident or legal claim. We delete or de-identify information when it is no longer needed.
09
Your data-protection rights
Depending on the circumstances, you may request access, rectification, erasure, restriction, data portability, or object to processing based on legitimate interests. You may withdraw consent at any time without affecting earlier lawful processing.
Send a request to privacy@parffolio.com. We may ask for proportionate information to verify the request and locate the relevant record, including the community privacy reference available in the Cookie settings panel. We normally respond within one month; complex or multiple requests may lawfully take longer.
You may complain to the Data State Inspectorate of Latvia, Elijas iela 17, Riga, LV-1050, Latvia; pasts@dvi.gov.lv; +371 67223131, or to another competent supervisory authority.
10
Cookies and your choices
Parffolio presents equal first-layer options to accept all optional categories, reject non-essential technologies or manage granular preferences. Optional switches are off by default.
Google Consent Mode v2 establishes denied defaults before any Google tag may load. In the current basic implementation, Analytics and Google Ads scripts are not requested until the visitor grants the corresponding category.
Use Cookie settings in the footer to review the categories, save a different choice, reject all optional categories or reset the local consent record. Withdrawing Analytics or Marketing consent updates the Google consent state and removes known accessible first-party Google cookies.
Read the Cookie Policy for the exact inventory, provider descriptions and typical durations.
11
Security
We use proportionate technical and organisational measures, including encrypted HTTPS transport, restricted configuration files, signed HttpOnly voting identifiers, signed contact-form and comment-challenge tokens, mathematical verification, honeypot and same-origin checks, pre-publication moderation, request-rate controls, database constraints and service-provider security measures. No online system can guarantee absolute security.
If a personal-data breach creates a risk requiring notification, we will notify the competent authority and affected people as required by law.
12
Age, automation and changes
Parffolio community features are intended for people aged 16 or over. We do not knowingly seek personal data from younger children.
We do not make solely automated decisions that produce legal or similarly significant effects. Aggregate scores and abuse checks do not make such decisions.
We may update this Policy when services, providers or law change. Material changes will be shown by a new date and version.
Questions about this document may be sent to info@parffolio.com. Privacy requests should be sent to privacy@parffolio.com.