Privacy Policy

Effective date: March 1, 2026 · Last updated: March 6, 2026

1. Introduction

This Privacy Policy explains how XBURG (“we”, “us”, or “the Platform”), accessible at xburg.com, collects, uses, and protects information when you visit or interact with our Platform.

We are committed to protecting your privacy in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and the laws of the Republic of Latvia.

2. What Data We Process

2.1 Property Data (Public)

The core of XBURG is publicly available property data sourced from government registers. This includes:

  • Building locations, areas, and cadastral identifiers (VZD Cadastral Register)
  • Historical real estate transaction records (VZD Transaction Register / NĪTIS)
  • Cadastral valuations of properties, buildings, and apartments (VZD Valuation Register)
  • Flood risk zone classifications (LVĢMC)
  • Active sale and rent listings from publicly accessible sources

This data does not contain personal information about property owners. Transaction records from VZD are anonymized and contain only transaction amounts, dates, and property identifiers — not buyer or seller names.

2.2 Automatically Collected Data

When you visit the Platform, we may automatically collect:

  • Usage data — pages visited, features used, search queries (anonymized)
  • Technical data — IP address, browser type, device type, operating system
  • Performance data — page load times, errors encountered

This data is collected through Google Analytics and server logs and is used exclusively to improve the Platform.

2.3 Account Data

If you register for an account (currently limited to administrators), we collect your email address and an encrypted password. We do not require account registration for general Platform use.

3. Legal Basis for Processing

Under GDPR, we process data based on the following legal grounds:

  • Legitimate interest (Article 6(1)(f)) — for usage analytics and Platform improvement
  • Consent (Article 6(1)(a)) — for optional analytics cookies (where required)
  • Contract performance (Article 6(1)(b)) — for account-related functionality
  • Legal obligation (Article 6(1)(c)) — for compliance with applicable laws

4. Cookies and Tracking

The Platform uses the following categories of cookies:

CookiePurposeDurationType
next-auth.session-tokenAuthentication sessionSessionEssential
_ga, _gidGoogle Analytics (anonymous usage)Up to 2 yearsAnalytics

You can control cookies through your browser settings. Disabling analytics cookies will not affect Platform functionality.

5. Third-Party Services

We use the following third-party services that may process data:

  • Mapbox — map rendering and geocoding. Mapbox may collect anonymous telemetry data. See Mapbox Privacy Policy.
  • Google Analytics / Tag Manager — anonymous usage analytics. IP anonymization is enabled. See Google Privacy Policy.

We do not sell, rent, or share personal data with third parties for advertising or marketing purposes.

6. Data Storage and Security

All data is stored on servers located in the European Union (Frankfurt, Germany). We implement appropriate technical and organizational measures to protect data, including:

  • HTTPS encryption for all data in transit
  • Encrypted database connections
  • Rate limiting and bot protection
  • Regular automated backups
  • Role-based access controls

7. Data Retention

  • Property data — retained indefinitely as public-domain information
  • Server logs — retained for up to 30 days
  • Analytics data — retained according to Google Analytics default settings (up to 26 months)
  • Account data — retained until account deletion is requested

8. Your Rights Under GDPR

If you are located in the European Economic Area, you have the following rights regarding your personal data:

  • Right of access — request a copy of any personal data we hold about you
  • Right to rectification — request correction of inaccurate data
  • Right to erasure — request deletion of your personal data
  • Right to restrict processing — request limitation of how we process your data
  • Right to data portability — request your data in a machine-readable format
  • Right to object — object to processing based on legitimate interest
  • Right to withdraw consent — withdraw consent for optional data processing at any time

To exercise any of these rights, please contact us at info@xburg.com. We will respond within 30 days as required by GDPR.

You also have the right to lodge a complaint with the Data State Inspectorate of Latvia (Datu valsts inspekcija, dvi.gov.lv) or any other EU supervisory authority.

9. Children's Privacy

The Platform is not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected data from a child, we will promptly delete it.

10. International Data Transfers

All primary data processing occurs within the European Union. Some third-party analytics services (Google Analytics) may transfer anonymized data outside the EU. Such transfers are covered by Standard Contractual Clauses (SCCs) or adequacy decisions as required by GDPR.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated effective date. We encourage you to review this policy periodically.

12. Contact

For privacy-related questions, data requests, or to exercise your GDPR rights, contact us at:

info@xburg.com