Privacy Policy

Privacy Policy

Privacy Policy

Effective date: July 10, 2026

1. Who we are

MB “Digitasodas”, a small partnership (mažoji bendrija), company code 305676811, VAT code LT100016563313, registered office at K. Čerbulėno g. 17-2, LT-47239 Kaunas, Lithuania (“we”, “us”), is the data controller for personal data processed in connection with the Unified-Suppliers service at unified-suppliers.com (the “Service”).

Privacy contact: [email protected]. We have not appointed a Data Protection Officer, as we are not required to under Article 37 GDPR; the contact above handles all privacy matters.

Our Service is intended for business users. If you use the Service on behalf of your employer, we process your data as a business contact of our Customer.

2. What data we collect

We collect only the following categories of personal data:

  • Account data: name, business email address, company name, and password (stored hashed).
  • Billing data: billing address, VAT number, and payment status. We do not store card numbers — payments are processed by Stripe, which receives your card details directly.
  • Usage data: IP address, browser type and version, pages visited, date/time and duration of visits, device identifiers, and diagnostic/log data.
  • Communications: messages you send to our support.
  • Cookie data: as described in Section 8.

We do not collect special categories of personal data and do not knowingly process data of anyone under 18. The Service is directed at businesses; if you believe a minor has provided us personal data, contact us and we will delete it.

3. Why we process your data, on what legal basis, and for how long

Purpose Data categories Legal basis (GDPR Art. 6) Retention
Providing and maintaining the Service, account management Account data, usage data Contract performance (6(1)(b)) Life of the account + 30 days (export grace period), then deleted; backup copies expire within a further 30 days
Billing and payment processing Billing data Contract performance (6(1)(b)) Duration of the contract
Accounting and tax records Billing data, invoices Legal obligation (6(1)(c)) — Lithuanian accounting law 10 years as required by Lithuanian law
Customer support Account data, communications Contract performance (6(1)(b)); legitimate interest (6(1)(f)) in defending legal claims after the contract ends Life of the account + 3 years after account closure; thereafter tickets are anonymized (identifying details removed) and may be kept for internal knowledge purposes
Service security, fraud and abuse prevention, debugging Usage data, logs Legitimate interest (6(1)(f)) — keeping the Service secure and functional Server logs: rotated continuously, retained for a maximum of 30 days (most logs are deleted within hours)
Analytics and Service improvement (Google Analytics, Microsoft Clarity) Usage data (via cookies), interaction data such as clicks and scrolling (Clarity) Consent (6(1)(a)) — collected via the cookie banner Up to 24 months (Google Analytics retention setting); Clarity per Microsoft's retention policy
Advertising and marketing measurement (Meta Pixel) Usage data (via cookies) Consent (6(1)(a)) — collected via the cookie banner 3 months (cookie lifetime); aggregated data per Meta's policy
Marketing emails (news, offers, product updates) Email address Consent (6(1)(a)); or legitimate interest (6(1)(f)) for similar-service offers to existing customers, with opt-out in every message Until you withdraw consent/opt out, or 2 years of inactivity
Service notifications (changes to terms, security, billing) Email address Contract performance / legal obligation Life of the account

Where we rely on legitimate interest, you have the right to object (Section 6). Where we rely on consent, you may withdraw it at any time without affecting prior processing.

4. Who receives your data

We share personal data only with the following categories of processors and recipients, under data processing agreements compliant with Article 28 GDPR:

Recipient Purpose Location Transfer safeguard
Stripe Payments Europe, Ltd. (privacy policy) Payment processing EU/US EU–US Data Privacy Framework / SCCs
Data-centre / infrastructure provider (we operate our own servers rented from an EU data-centre provider) Infrastructure and data hosting EU Not applicable (EEA processing)
Google Ireland Ltd. / Google LLC (Google Analytics) (privacy policy) Usage analytics (with consent) EU/US EU–US Data Privacy Framework
Meta Platforms Ireland Ltd. / Meta Platforms, Inc. (Facebook / Meta Pixel) (privacy policy) Advertising and marketing measurement (with consent) EU/US EU–US Data Privacy Framework
Microsoft Ireland Operations Ltd. / Microsoft Corp. (Microsoft Clarity) (privacy policy) Session analytics — heatmaps and usage replay (with consent) EU/US EU–US Data Privacy Framework
Email delivery provider Transactional and marketing email EU Not applicable (EEA processing)

Where we identify a recipient by category rather than by name, you may request the identity of the specific provider via our privacy contact. We may also disclose data where required by law or to protect our legal rights. We never sell personal data.

5. International transfers

Your data is primarily stored and processed in the European Economic Area — our hosting and email providers operate within the EU. Some providers (Stripe, Google, Meta, Microsoft) may process data in the United States. These transfers are protected by the European Commission's adequacy decision for the EU–US Data Privacy Framework, under which these providers are certified, and/or the Commission's Standard Contractual Clauses (2021), supplemented where needed by additional technical measures.

6. Your rights

Under the GDPR you have the right to: access your personal data; rectify inaccurate data; erase your data; restrict processing; data portability; object to processing based on legitimate interest (including direct marketing, at any time); and withdraw consent at any time.

You can exercise most rights directly in your account settings (update your data, export your data, delete your account) or by emailing our privacy contact. We may ask you to verify your identity. We respond within one month; for complex requests this may be extended by up to two further months, in which case we will inform you.

We do not carry out automated decision-making, including profiling, that produces legal or similarly significant effects for you.

Complaints: you have the right to lodge a complaint with a supervisory authority — in our case the Lithuanian State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija, vdai.lrv.lt) — or with the data protection authority of the EEA country where you live or work.

7. Security

We apply technical and organizational measures appropriate to the risk, including: encryption of data in transit (TLS), hashed password storage, role-based access controls and access on a need-to-know basis, regular backups, logging and monitoring. No system is absolutely secure; if a personal data breach occurs that risks your rights, we will notify the supervisory authority within 72 hours and affected users without undue delay, as required by Articles 33–34 GDPR.

8. Cookies

When you first visit our website, a cookie banner asks for your consent before any non-essential cookies are set. Analytics and marketing scripts (Google Analytics, Microsoft Clarity, Meta Pixel — managed via Google Tag Manager) are not loaded at all unless and until you give consent. Strictly necessary cookies do not require consent. You can change or withdraw your choices at any time by deleting the “unified_suppliers_cookie_consent” cookie in your browser settings — the consent banner will then appear again on your next visit — or by contacting us at [email protected].

Cookie Provider Purpose Type Duration
unified_suppliers_session Unified-Suppliers Keeps you logged in Strictly necessary Session
XSRF-TOKEN Unified-Suppliers Security — prevents cross-site request forgery Strictly necessary Session
unified_suppliers_cookie_consent Unified-Suppliers Stores your cookie choices Strictly necessary 12 months
_ga, _ga_* Google Analytics (via Google Tag Manager) Usage statistics Analytics (consent) Up to 24 months
_clck, _clsk Microsoft Clarity Session analytics — heatmaps and usage replay Analytics (consent) Up to 12 months
_fbp, _fbc (the latter only when you arrive via a Facebook ad) Meta (Facebook Pixel) Advertising measurement and retargeting Marketing (consent) 3 months

You can also control cookies through your browser settings, but blocking strictly necessary cookies may prevent parts of the Service from working.

9. Changes to this policy

We may update this policy from time to time. For material changes we will notify you by email at least 14 days before the changes take effect and update the effective date above. Earlier versions are available on request.

10. Contact

MB “Digitasodas” · K. Čerbulėno g. 17-2, LT-47239 Kaunas, Lithuania · Company code 305676811

[email protected]