Mecmetrix Privacy Policy
Last updated: Saturday, August 22, 2026
1. Purpose and scope
This Privacy Policy explains how SIA “NewCognity” processes personal data in connection with the Mecmetrix website, account registration, subscriptions, customer support, and use of the cloud Service. It is a transparency notice and does not replace the agreement with a Customer, a Data Processing Agreement (“DPA”), or mandatory law.
Personal data means information relating to an identified or identifiable individual. “Processing”, “controller”, and “processor” have the meanings given in Regulation (EU) 2016/679 (the “GDPR”).
2. Who is responsible
The entity responsible for the processing described in this policy is SIA “NewCognity”, registration no. 40203771131, registered address: Pulksteņu iela 21, Pēterupe, Saulkrasti Parish, Saulkrasti Municipality, LV-2160, Latvia. Privacy questions may be sent to [email protected] or to our registered address. Telephone: +371 20324425.
3. Controller and processor roles
NewCognity is a controller when it processes data about account owners, Users, prospective customers, and billing contacts for its own purposes, including contracting, Service administration, security, payments, support, and compliance.
Where a Mecmetrix Customer enters data about its own customers, employees, vehicle owners, or other individuals into a Workspace, that Customer is generally the controller and NewCognity processes the data on the Customer’s behalf and documented instructions. The DPA describes this relationship in more detail. To exercise rights concerning data entered by a workshop or another Mecmetrix Customer, contact that Customer first; we will assist it with a valid request.
4. Categories of data
- Account and identity data: name, email address, telephone number, password in hashed form, language, employer, role, permissions, and account status.
- Business and contract data: business name, registration and tax numbers, address, contacts, selected plan, acceptance records, and contract-administration information.
- Billing data: subscription, transaction identifiers, invoices, payment status, and limited payment-method details. Stripe, not NewCognity, receives and processes complete card details.
- Workspace content: customer, vehicle, employee, booking, work, estimate, invoice, inventory, and related document data, notes, images, and attachments entered by a Customer or its Users.
- Communications: support requests, emails, feedback, and other communications with us.
- Technical and security data: IP address, browser and device information, login and activity logs, error and security-event data, cookie choices, and session identifiers.
- Analytics data: only with the required consent — website visits, pages used, and approximate technical information collected through Google Analytics.
5. Purposes and legal bases
- Entering into and performing a contract: account and Workspace creation, authentication, feature delivery, support, subscription administration, and payments (Article 6(1)(b) GDPR).
- Legal obligation: accounting, tax, lawful authority requests, and other statutory duties (Article 6(1)(c) GDPR).
- Legitimate interests: Service and network security, fraud prevention, troubleshooting, legal claims, administration, and improvement, where those interests are not overridden by individual rights and freedoms (Article 6(1)(f) GDPR).
- Consent: optional analytics, marketing cookies, or communications where consent is required (Article 6(1)(a) GDPR). Consent may be withdrawn at any time without affecting earlier lawful processing.
- Customer instructions: we process Workspace personal data as a processor to provide the Service under the DPA and Article 28 GDPR.
6. Recipients and service providers
Data is disclosed only as needed for the stated purpose. Recipient categories may include cloud hosting, database, file-storage, and backup providers; email and customer-support tools; security and error-monitoring providers; professional advisers; Stripe for payments and subscriptions; Google Analytics where analytics consent has been given; and document-recognition or commercial AI API providers only where the relevant feature is enabled and needed to perform a Customer-requested action.
Service providers may process data only under contracts, applicable confidentiality and security duties, and our or the Customer’s instructions. We may disclose data to a competent authority where legally required or to establish and defend legal rights. We do not sell personal data.
7. Transfers outside the EEA
Some providers or support teams may process data outside the European Economic Area. In that case, we use a transfer mechanism recognised by GDPR Chapter V, such as a European Commission adequacy decision or Standard Contractual Clauses, and supplementary safeguards where required. Information about the mechanism relevant to a particular service may be requested at [email protected].
8. Retention
We retain data only as long as necessary for its purpose. Account and Workspace data is generally kept during the agreement and then during the export and deletion period in the Terms and DPA. Contract, invoice, payment, tax, and accounting data is kept for statutory periods. Security logs and support communications are kept for a proportionate period to investigate incidents, protect the Service, and support claims. Backup copies are overwritten according to the backup cycle.
Where a dispute, legal obligation, or justified need to protect rights applies, relevant data may be retained longer with its use restricted to that purpose.
9. Security
We use technical and organisational measures appropriate to risk, including encrypted transmission, role-based access controls, secure password hashing, logical Workspace segregation, logging, backups, and security updates. Access is limited to people who need it for their duties. No system can guarantee absolute security; please report suspected incidents promptly to [email protected].
10. Your rights
Depending on the circumstances, you may have rights to information and access, rectification, erasure, restriction, objection to legitimate-interest processing, data portability, withdrawal of consent, and not to be subject to a solely automated decision producing legal or similarly significant effects. Some rights may be limited by law or the rights of others.
Send a request to [email protected] with enough information to identify you and the request. We may ask for additional information to verify identity. We will respond without undue delay, normally within one month; the GDPR permits an extension for complex requests if we notify you.
11. Complaints and supervisory authority
If you believe personal data has been processed improperly, please contact us first so we can investigate. You also have the right to complain to the Latvian Data State Inspectorate (Datu valsts inspekcija). Current contact information and submission procedures are available at www.dvi.gov.lv. This does not affect other administrative or judicial remedies.
12. Children, automation, and policy changes
The Service is intended for businesses and professional use, not children, and we do not knowingly invite children to create a Workspace independently. Mecmetrix automated and AI functions prepare drafts or suggestions that a User must review; NewCognity does not make solely automated decisions about an individual that produce legal or similarly significant effects.
We may update this policy as the Service, providers, or law changes. The current text and last-updated date are always published here. Where circumstances or law require, we will also notify Customers of material changes in the Service or by email.