Privacy policy

Data Innovations

Last updated:

Introduction

This Privacy Policy explains how Data Innovations (hereinafter “we”, “our”, “us”) collects, uses, stores and protects personal data in accordance with the European Union General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679) and applicable national data protection laws.

For the purposes of data protection law, Data Innovations acts as the Data Controller processing the personal data described in this Privacy Policy.

Data we collect

1. Information you provide directly

  • First name, last name
  • Email address, phone number
  • Company name, position
  • Billing and invoicing details
  • Correspondence data (emails, messages, support requests)
  • Data related to participation in training, onboarding or service delivery

2. Automatically collected data

  • IP address
  • Browser type and version
  • Device identifiers
  • Website usage data (pages visited, time spent, interactions)
  • Cookie identifiers (see the Cookie Policy)

3. Special categories of (sensitive) data

We do not knowingly collect or process special categories of personal data as defined in Article 9 of the GDPR. If such data were provided to us unintentionally, it will be deleted immediately.

Legal bases for processing personal data

We process personal data on the following legal bases:

  • Performance of a contract (Article 6(1)(b) GDPR) – to enter into and perform contracts and provide our services.
  • Legal obligation (Article 6(1)(c) GDPR) – to fulfil obligations set out in law, including accounting, tax and compliance requirements.
  • Legitimate interests (Article 6(1)(f) GDPR) – for improving service quality, ensuring system security, fraud prevention, abuse prevention and internal administration.
  • Consent (Article 6(1)(a) GDPR) – for marketing communications, newsletters and non-essential cookies, where required by law.

Where personal data is processed on the basis of consent, the data subject has the right to withdraw their consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

Purposes of processing personal data

We use personal data in order to:

  • Provide, maintain and improve the Services, ensuring their functionality, quality and continuity.
  • Administer client accounts and contractual relationships, including registration, contract conclusion and performance.
  • Process payments, invoicing and financial records in compliance with accounting and tax law requirements.
  • Communicate with clients, including customer service, technical support, service updates and important notices.
  • Ensure system security, monitoring and fraud prevention, to protect the services, users and data.
  • Fulfil legal and regulatory obligations set out in applicable law.

We do not use personal data for automated decision-making or profiling as defined in Article 22 of the GDPR.

Retention of personal data

We retain personal data only for as long as necessary to achieve the processing purposes set out above. Once the retention period expires, personal data is securely deleted or anonymised, in accordance with applicable law and technical security requirements.

Transfer of personal data and data processors

We may transfer personal data to trusted third parties acting as Data Processors, including:

  • Hosting and cloud infrastructure providers
  • Analytics and monitoring tool providers
  • Payment and invoicing systems
  • Legal, accounting and compliance partners
  • IT security and technical support providers

All data processors operate under GDPR-compliant Data Processing Agreements (DPAs) and process personal data only in accordance with our instructions.

We do not sell personal data and do not transfer it to third parties for marketing purposes.

Transfer of personal data outside the European Union / EEA

If personal data is transferred outside the European Economic Area (EEA), we ensure that appropriate safeguards are applied as required by the GDPR, including:

  • European Union Standard Contractual Clauses (SCCs);
  • European Commission adequacy decisions;
  • Additional technical and organisational security measures to ensure an appropriate level of personal data protection.

Data security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, disclosure, alteration or destruction, including:

  • Data encryption in transit and at rest;
  • Access control and authentication mechanisms ensuring that access to personal data is granted only to authorised persons;
  • Network and infrastructure security, including firewalls, monitoring and access restriction;
  • Regular data backups and recovery procedures;
  • Confidentiality commitments from employees and collaborators;
  • System monitoring, incident management and response procedures to detect and manage security breaches in a timely manner.

These measures are reviewed and updated regularly, taking into account technological progress, the level of risk and applicable legal requirements.

Your rights under the GDPR

You have the right to:

  • Access your personal data;
  • Request rectification of inaccurate or incomplete personal data;
  • Request erasure of personal data (“the right to be forgotten”), where the conditions set out in law apply;
  • Request restriction of the processing of personal data;
  • Object to the processing of personal data where it is processed on the basis of legitimate interests;
  • Exercise the right to data portability;
  • Withdraw your consent at any time, where personal data is processed on the basis of consent.

You can submit requests regarding your rights by email: info@datainnovations.lt. We respond to all reasonable requests within 30 calendar days, as provided for by the GDPR.

Cookie policy

1. What are cookies?

Cookies are small text files stored on your device when you visit a website. They are used to ensure the website works properly, to improve user experience and to collect analytical data.

2. What cookies do we use?

2.1 Essential cookies

These cookies are necessary for the website to function, including security, authentication and session management. Without them the website cannot work properly, so they cannot be disabled.

2.2 Analytics cookies

Used to analyse website usage in order to understand how visitors use the site and to improve its operation and content. These cookies are used only with your consent.

2.3 Preference (functional) cookies

These cookies allow us to save your settings, such as your chosen language or cookie preferences, to ensure a more convenient browsing experience.

A detailed cookie table (names, duration, providers) may be provided once the website is finalised.

3. Cookie consent

On your first visit you are shown a cookie consent notice (banner). Non-essential cookies are used only with your explicit consent, in accordance with the ePrivacy Directive and GDPR requirements. You have the right to withdraw your consent at any time.

4. Managing cookies

You can manage or disable cookies through your browser settings. Please note that disabling some cookies may affect the functionality of the website.

5. Third-party cookies

We may use trusted third-party services (e.g. analytics providers). All third-party cookies are deployed in accordance with GDPR requirements and with appropriate contractual and technical safeguards in place.

We turn complexity into clarity