DATA PROTECTION

Privacy Policy

We explain clearly what data we process when you visit the website or submit a business enquiry, why we use it and what rights you have.

Updated: 26 August 2026
This version applies to enquiries submitted through tradiala.lt and to essential website security and operational functions.

We collectTopic, email address and message

ControllerSelected according to the enquiry topic

RetentionNormally 12 months

AdvertisingForm content is not used for advertising

1. Scope and data controllers

This policy applies to tradiala.lt, its business enquiry form and first-party technical events associated with operation of the website. The controller is determined by the enquiry topic you select.

Logistics, transport, other / not sure

UAB Tradiala

Legal entity code 305608575

info@tradiala.lt

Operational improvement and Rita Grid

UAB Nėra-Bus

Legal entity code 308077293

info@nerabus.lt

If the enquiry topic was selected incorrectly, we transfer only the information necessary for the appropriate company to respond. If you are unsure which company to contact about privacy, email info@tradiala.lt.

2. Data we process

Data you provide

  • enquiry topic;
  • email address;
  • message content.

These fields are required so that we can route the enquiry to the appropriate team and respond. Without them, you cannot submit the form and we cannot provide a response. Please do not include special-category data, national identification numbers, financial credentials or other information that is not necessary for your enquiry.

Technical data processed automatically

  • HTTP information required to transmit and secure the request, such as IP address, browser type, time and technical response status;
  • Cloudflare Turnstile security signals, such as IP address, TLS characteristics, User-Agent, sitekey and origin domain;
  • first-party interaction events, such as a CTA or language selection, video view, form start and whether a submission succeeded or failed;
  • campaign parameters: UTM source, medium, campaign and content label.

First-party event data is minimised so that events are nearly anonymous. It does not contain form-field values, your email address or message content, and it is not used for advertising profiles or tracking across other websites.

3. Purposes and legal bases

Responding to an enquiry
Article 6(1)(b) GDPR where we take steps at your request before entering into a contract, and/or Article 6(1)(f) – our legitimate interest in handling and responding to business communications.
Protecting the form and website
Article 6(1)(f) GDPR – our legitimate interest in preventing spam, abuse and security incidents and in ensuring that the service is reliable.
Assessing website operation
Article 6(1)(f) GDPR – our legitimate interest in using minimised first-party events to understand whether content and the enquiry flow work correctly.
Meeting legal obligations
Article 6(1)(c) GDPR where data must be retained or disclosed under applicable law or a lawful request from a competent authority.

The enquiry form does not rely on consent and does not include marketing consent. If direct marketing is offered in the future, it will have a separate, optional choice and its own information.

4. How an enquiry travels

You complete the three form fields
Cloudflare Workers validates and routes the enquiry
Resend delivers the email
The controller selected by topic responds

Before submission, Cloudflare Turnstile assesses technical signals to distinguish a person from automated traffic. According to Cloudflare's documentation, Turnstile does not access, store or transmit form entries or other page-input content.

5. Data recipients and processors

Only authorised personnel or service providers of the relevant controller may access the data, and only to the extent needed for the purposes described in this policy.

Website hosting

Hostinger

Website Builder serves the website content and may process ordinary technical request and security logs. Enquiry form content is sent through Cloudflare Workers, not through a Hostinger form.

Infrastructure and security

Cloudflare, Inc.

Cloudflare Workers processes the form request, while Turnstile processes the security signals required to protect the form against automated abuse.

Email delivery

Resend, Inc.

Processes sender and recipient addressing data, the subject, message and delivery metadata so that the enquiry can be delivered by email.

Cloudflare acts as our processor when providing the Turnstile website-security function. Cloudflare also states in its notice that it acts as an independent controller when processing security signals to improve Turnstile's detection capabilities and relies on its own legitimate interests for that processing. Cloudflare's Turnstile Privacy Notice applies to that activity.

Data may also be disclosed to professional advisers or competent authorities where necessary to establish, exercise or defend legal claims, or where required by law. We do not sell personal data.

6. Transfers outside the EEA

Hostinger and Cloudflare use international infrastructure, while Resend's primary processing operations take place in the United States. Some data may therefore be processed outside the European Economic Area.

Such transfers are protected by the safeguards provided under applicable law: a European Commission adequacy decision where applicable (including the EU–US Data Privacy Framework), or European Commission Standard Contractual Clauses and supplementary measures where needed. You may request information or a copy of the applicable safeguards from the relevant controller.

7. How long we retain data

  • Business enquiries are retained for 12 months after the last substantive communication.
  • If an enquiry leads to a contract, or the data is needed for a legal obligation, accounting or the defence of legal claims, relevant information may be kept for the longer period applicable to that purpose.
  • Minimised first-party interaction events are retained for no longer than 90 days. They do not contain an email address, enquiry text, IP address or visitor identifier.
  • Security logs are kept by service providers only as long as necessary to identify abuse and incidents and protect the service, subject to their applicable retention periods.
  • Information may remain for a limited additional period in processor backups, in accordance with their documented deletion and backup procedures.

8. Your rights

Under the GDPR, subject to the circumstances and exceptions provided by law, you may:

  • obtain confirmation of whether we process your data and access that data;
  • ask us to correct inaccurate or complete incomplete data;
  • ask us to erase data or restrict its processing;
  • object to processing based on legitimate interests;
  • receive data you provided in a structured format and, where applicable, exercise data portability;
  • withdraw consent if a particular processing activity is based on consent, without affecting the lawfulness of processing before withdrawal.

Send your request, according to the enquiry topic, to info@tradiala.lt or info@nerabus.lt. We may request information to verify your identity. We normally respond to a valid request within one month.

You also have the right to lodge a complaint with the Lithuanian State Data Protection Inspectorate (VDAI). VDAI recommends first trying to resolve the matter by contacting the controller before lodging a complaint. Complaint guidance is available on the VDAI complaints page.

9. Security and automated decisions

We apply data minimisation, access controls, encryption in transit and other technical and organisational measures appropriate to the risk. Nevertheless, no method of transmission or storage can guarantee absolute security.

Turnstile may use cookies or equivalent local storage that are strictly necessary for its security function. They are not used for advertising. Minimised first-party events do not use third-party advertising cookies and contain no form content.

During a browsing session, we may store UTM parameters in first-party sessionStorage so that the campaign source is not lost when you move between pages on this website. We do not create a visitor identifier for this purpose, and the session entry is removed when the browser tab is closed.

We do not make decisions based solely on automated processing that produce legal or similarly significant effects for you, and we do not profile you. Turnstile automatically assesses only the likelihood of abuse in order to protect the form; that assessment is not used for business decisions about you.

10. Contacts, official sources and changes

For questions about this policy or personal data, contact the controller listed in section 1. We may update this policy when our services, processing practices or legal requirements change. The latest version will always be published on this page with its revision date.