Skip to content
Book

Legal

Privacy Policy

What personal data this site collects, why, on what legal basis, who it reaches, how long it is kept, and what you can require us to do about it.

Last updated 9 September 2026

Who is responsible for your data

The controller of the personal data described in this policy is:

Controller
Remigijus Laučius
Trading as
Noventi Labs
Legal form
Individual activity (individuali veikla)
Activity certificate
1374246
VAT
Not registered for VAT
Address
Versmės g. 12, Jonučių II k., Kauno r.
Country
Lithuania
Website
noventilabs.com
Contact
info@noventilabs.com

For anything in this policy, including any request about your own data, write to info@noventilabs.com. We have not appointed a Data Protection Officer, because we are not required to under Article 37 of the GDPR: we do not monitor people systematically on a large scale and we do not process special categories of data on a large scale. That address reaches the people who make the decisions described here.

What this policy covers

This policy covers the public website and the things you can do on it: read pages, take the business assessment, subscribe by email, book a consultation, and sign in to the client area. It applies to the General Data Protection Regulation (EU) 2016/679 and, in Lithuania, to the Law on Legal Protection of Personal Data.

It does not cover a separate written agreement for paid work, which will say what data is processed for that engagement, nor any other website we link to.

What we collect, why, and on what legal basis

We collect only what a given purpose actually needs. Every row below is a real field in this system rather than a category we might one day fill, and the legal basis is the specific one we rely on under Article 6(1) of the GDPR.

WhatWhyLegal basisKept for
Consultation booking: your name, email address, company, industry, business stage, the challenge you describe, your message, and the date, time and time zone you choseTo arrange, confirm and hold the consultation you asked for, and to have a record of what was discussed and whenArticle 6(1)(b) — steps taken at your request before entering into a contract, and performance of that contract24 months after our last contact about it, unless a contract requires us to keep it longer
Business assessment: your answers about business stage, industry, goal, current marketing and main challenge, together with the name and email address you give at the endTo produce and send you the assessment result, and to follow up about it if you asked us toArticle 6(1)(a) — your consent, given by completing and submitting the assessment24 months, or until you withdraw consent or ask us to delete it, whichever is sooner
Email subscription: your email address, your name if you give it, and which page or article you subscribed fromTo send you the material you subscribed toArticle 6(1)(a) — your consentUntil you unsubscribe, which every email lets you do in one click
Client area account: your email address, a password stored only as a cryptographic hash, and your sign-in sessionsTo give you an account and keep it secureArticle 6(1)(b) — performance of a contract with youWhile the account exists, and 12 months afterwards for security records
Site usage: a randomly generated identifier, the pages you view, approximate location derived from your IP address, and device and browser typeTo understand which pages are read and where people leave, so the site can be improvedArticle 6(1)(a) — your consent, given through the cookie banner and withdrawable at any timeUp to 14 months in Google Analytics, then deleted automatically
Session recording: how your visit moves through the pages — scrolling, clicks, where you pause — together with device, browser and approximate location from your IP addressTo find layouts that confuse people, which a page-view count cannot showArticle 6(1)(a) — your consent, given separately from the other purposes and withdrawable at any timeUp to 12 months in Hotjar, then deleted automatically
Advertising: the fact that you visited, which pages, and whether you booked a consultation, finished the assessment or subscribed — reported to Meta with an identifier for this browser, and never with your name or addressTo measure whether our advertising works and to reach people like our visitorsArticle 6(1)(a) — your consent, given separately from the other purposes and withdrawable at any timeMeta decides how long it keeps this; we hold no copy of it
Server and email logs: IP address, request time, page requested, browser identification, and delivery records for email we send youTo keep the site available, to investigate faults and abuse, and to show that a message was sentArticle 6(1)(f) — our legitimate interest in the security and availability of our own serviceUp to 12 months
Correspondence: anything you write to us by email or through a formTo answer you and keep a record of what was agreedArticle 6(1)(f) — our legitimate interest in handling enquiries, or Article 6(1)(b) where it concerns a contract24 months after the exchange ends

Where we rely on legitimate interests we have weighed them against your rights and concluded that the processing is limited, expected, and not something that overrides your interests. You can object to it at any time — see your rights below — and we will stop unless we can show compelling grounds that override yours.

Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect anything done before you withdrew.

Giving us any of this is voluntary. There is no statutory or contractual obligation to provide it. The only consequence of not providing it is that the particular thing cannot happen: without an email address we cannot confirm a booking or send an assessment result.

Cookies and similar technologies

The site stores a small number of things on your device. Almost all of them are strictly necessary — your language, your light or dark preference, your signed-in session — and under Article 5(3) of the ePrivacy Directive, implemented in Lithuania by Article 99 of the Law on Electronic Communications, those need no consent.

Three things are not necessary, and they are three separate questions rather than one: counting how the site is used, recording how a visit moves through it, and reporting your visit for advertising. None of them is loaded, and no request is made to any of the companies involved, until you have agreed to that particular one. You may agree to any, all or none of them, and refusing changes nothing else on the site. The Cookie Policy lists every item by name, purpose and lifetime, and explains how to change your mind.

Who else sees your data

We do not sell personal data. Most of it reaches only service providers who run parts of this service on our behalf, under contracts requiring them to process it only on our instructions. One thing is different and is called out plainly here rather than buried: if you agree to the marketing purpose, the fact of your visit is reported to Meta, which uses it for its own advertising. That is the one item on this page that leaves our control, and it happens only if you have agreed to it.

WhoWhat they doWhere
Hostinger International LtdHosts the website and the mailbox that receives and sends our emailEuropean Union
Supabase, Inc.Runs the database that stores bookings, subscriptions and accounts, and handles sign-inHosted in Ireland, in the European Union; the company is established in the United States
Google Ireland LimitedProvides Google Analytics — but only if you have consented, and never otherwiseEuropean Union, with onward transfer to Google LLC in the United States
Hotjar LtdRecords how visits move through the pages, so confusing layouts can be found — only if you have consentedMalta, in the European Union; data is stored in the European Economic Area
Meta Platforms Ireland LimitedReceives the fact of your visit through the Meta pixel and uses it for advertising — only if you have consented. Meta is not our processor; see belowIreland, with onward transfer to Meta Platforms, Inc. in the United States

We may also disclose data to professional advisers, or to a public authority where the law requires it. If our business is transferred, data may pass to the acquirer, and we will tell you before that happens.

The Meta pixel, and what is different about it

Two of the three optional tools are ordinary processors: Google Analytics and Hotjar hold data on our instructions and do nothing else with it. Meta is not in that position, and pretending otherwise would misdescribe what happens to you.

When the pixel loads, it reports your visit to Meta Platforms Ireland Limited, which uses it for its own advertising purposes. Under the Court of Justice judgment in Fashion ID (Case C-40/17, 29 July 2019) that makes us and Meta joint controllers for the collection and transmission of that data — jointly responsible for the part that happens on this site. What Meta does with it afterwards is Meta’s own processing, decided by Meta, and we have no access to it and no control over it.

What that means for you in practice: obtaining your consent for the transmission is entirely our responsibility, not Meta’s, which is why the pixel is not loaded and no request is made to Meta until you have agreed to the marketing purpose. It also means you may exercise your rights against either of us. For anything concerning Meta’s own use of the data, Meta’s privacy policy and its own contact points apply; for the part that happens here, write to us.

If you would rather this did not happen, decline the marketing purpose — on the banner, or afterwards through Cookie settings at the bottom of any page. Nothing else changes if you do.

Transfers outside the European Economic Area

Data stays in the European Union wherever we can arrange it, and the database that holds bookings and accounts is hosted in Ireland.

Some recipients are established in the United States, or send data on to a company that is, so some access from there is possible. Those transfers rely on the European Commission adequacy decision of 10 July 2023 for the EU-US Data Privacy Framework where the recipient is certified under it, and otherwise on the Commission Standard Contractual Clauses adopted on 4 June 2021, together with the additional technical measures those clauses require. You may ask us for a copy of the safeguards that apply, and we will send it.

How long we keep it

The retention period for each purpose is in the table above. Two things override it: where accounting or tax law requires a longer period, we keep what that law requires and nothing more; and where you ask us to erase data and no such obligation applies, we erase it rather than waiting for the period to run out.

When a period ends we delete the data or irreversibly anonymise it, so that what remains can no longer identify you.

How we protect it

The site is served only over an encrypted connection. Passwords are never stored in a form that can be read, only as a hash. The database enforces row level security, so an anonymous visitor can submit a booking but cannot read anybody else back — the list of bookings and subscribers is readable only by an authenticated administrator. Access is limited to the people who need it.

No system is perfect. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the supervisory authority within 72 hours as Article 33 requires, and we will tell you directly where Article 34 requires it.

Your rights

Under the GDPR you have the following rights over your own personal data. They are yours to use, and using them costs nothing.

  • Access (Article 15) — to be told whether we hold data about you, and to receive a copy of it together with the information in this policy.
  • Rectification (Article 16) — to have inaccurate data corrected and incomplete data completed.
  • Erasure (Article 17) — to have data deleted where it is no longer needed, where you withdraw the consent it rested on, or where you successfully object.
  • Restriction (Article 18) — to have us hold data without using it while a dispute about its accuracy or our grounds is resolved.
  • Portability (Article 20) — to receive the data you gave us in a structured, commonly used, machine-readable format, and to have it sent directly to another controller where that is technically feasible.
  • Objection (Article 21) — to object at any time to processing based on our legitimate interests, and to object absolutely to direct marketing, which we will then stop immediately.
  • Withdrawal of consent (Article 7(3)) — to withdraw consent at any time, as easily as you gave it. For analytics that is the Cookie settings link in the footer; for email it is the unsubscribe link in every message.
  • Not to be subject to automated decision-making (Article 22) — we take no decisions about you by automated means that produce legal effects or similarly significantly affect you. The business assessment returns general suggestions based on the answers you chose; it decides nothing about you and has no effect on anything. If you agree to the marketing purpose, Meta may use your visit as one signal among many in deciding which advertisements to show you; that is Meta’s own processing rather than a decision of ours, and it is avoided entirely by declining that purpose.

To exercise any of them, write to info@noventilabs.com. We will respond within one month, as Article 12(3) requires. If a request is unusually complex we may extend that by two further months, and we will tell you within the first month if we do. We may ask you to confirm your identity where we cannot otherwise be sure who is asking, because handing your data to somebody else would be the worse failure.

Complaining

If you think we have handled your data wrongly, please tell us first — most of it is fixable quickly and we would rather know.

You also have the right under Article 77 to complain to a supervisory authority, whether or not you come to us first. In Lithuania that authority is Valstybinė duomenų apsaugos inspekcija (the State Data Protection Inspectorate), L. Sapiegos g. 17, 10312 Vilnius, Lithuania. Telephone +370 5 271 2804, email ada@ada.lt, website vdai.lrv.lt.

You may complain instead to the supervisory authority in the EU country where you live or work, or where you believe the problem occurred. You may also seek a judicial remedy under Article 79.

Children

This site is for businesses and is not directed at children. We do not knowingly collect personal data from anyone under 14, which is the age set in Lithuania under Article 8(1) of the GDPR for consent to information society services. If you believe a child has given us data, write to info@noventilabs.com and we will delete it.

Changes to this policy

If we change how we handle personal data, we will change this page and move the date at the top. Where a change materially affects you — a new purpose, a new recipient, a longer retention period — we will tell you directly rather than relying on you to notice, and where the change requires your consent we will ask for it before doing anything.

This version is dated 9 September 2026.