1. Data Controller
The controller of your personal data is the individual operating under
Individuali veikla (Individual Activity) Registration No. 1498242,
EVRK: 621090, registered in the Republic of Lithuania (hereinafter — "we", "us",
"Provider").
Contact: [email protected]
2. What Data We Collect
We collect and process the minimum amount of personal data necessary to provide our Service:
2.1. Data You Provide
- Email address — provided during purchase, used to deliver your license
key.
2.2. Data Collected Automatically
- Payment transaction data — payment method details (via Paddle) or cryptocurrency wallet addresses and transaction
identifiers, processed through our payment processors for order verification.
- Device information and telemetry — when you launch the GreenGo application or make a purchase, we collect your IP address and basic device hardware information for the purposes of license validation, security, and abuse prevention.
- Basic server logs — IP address, browser type, and request timestamps when
you visit our website. These are retained for security purposes and automatically deleted
after 30 days.
2.3. Data We Do NOT Collect
- We do not collect names, physical addresses, phone numbers, or government
IDs.
- The GreenGo desktop application does not access or read your personal files outside of the audio files you explicitly provide to it.
3. Legal Basis for Processing
We process your personal data under the following legal bases as defined by the
General Data Protection Regulation (GDPR, Regulation (EU) 2016/679):
- Contract performance (Art. 6(1)(b) GDPR) — processing your email and
payment data is necessary to deliver the license key you purchased.
- Legitimate interest (Art. 6(1)(f) GDPR) — processing server logs for
security and fraud prevention.
4. How We Use Your Data
- To deliver your license key via email after purchase.
- To verify payment transactions.
- To respond to support inquiries you initiate.
- To maintain website security and prevent abuse.
5. Data Sharing
We do not sell, rent, or share your personal data with third parties for
marketing purposes.
Your data may be processed by the following third-party service providers, solely for the
purposes described above:
- Payment processors — Paddle (Merchant of Record) for fiat/credit card payments, and SHKeeper (self-hosted) for cryptocurrency processing. Transaction data is processed securely by these partners.
- Hosting provider — our web server provider, for serving the website.
6. Data Retention
- Email and license data — retained for as long as your license is active,
plus 3 years for legal compliance and support purposes.
- Payment transaction records — retained for 10 years as required by
Lithuanian tax and accounting legislation.
- Server logs — automatically deleted after 30 days.
7. Your Rights Under GDPR
As a data subject, you have the following rights under the GDPR:
- Right of access (Art. 15) — request a copy of the personal data we hold
about you.
- Right to rectification (Art. 16) — request correction of inaccurate
data.
- Right to erasure (Art. 17) — request deletion of your data ("right to be
forgotten"), subject to legal retention obligations.
- Right to restriction of processing (Art. 18) — request that we limit
processing of your data.
- Right to data portability (Art. 20) — receive your data in a structured,
machine-readable format.
- Right to object (Art. 21) — object to processing based on legitimate
interest.
To exercise any of these rights, contact us at
[email protected]. We will respond within
30 days.
8. Cookies
Our website uses only strictly necessary cookies required for the website to
function (e.g., session management). We do not use:
- Analytics cookies
- Advertising or tracking cookies
- Third-party cookies
9. International Data Transfers
All data is processed within the European Economic Area (EEA). If any processing were to occur
outside the EEA, we would ensure appropriate safeguards are in place in accordance with
Chapter V of the GDPR.
10. Data Security
We implement appropriate technical and organizational measures to protect your personal data
against unauthorized access, alteration, disclosure, or destruction, including:
- HTTPS encryption for all website traffic.
- Access controls and authentication for administrative systems.
- Regular security reviews.
11. Children's Privacy
Our Service is not directed at children under 16 years of age. We do not knowingly collect
personal data from children. If you believe a child has provided us with personal data, please
contact us immediately.
12. Supervisory Authority
If you believe your data protection rights have been violated, you have the right to lodge a
complaint with the Lithuanian supervisory authority:
Valstybinė duomenų apsaugos inspekcija (VDAI)
State Data Protection Inspectorate
L. Sapiegos g. 17, 10312 Vilnius
Website: vdai.lrv.lt
Email: [email protected]
13. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be posted on this
page with an updated revision date. We encourage you to review this page periodically.
14. Contact
Activity registration: Individuali veikla Nr. 1498242, EVRK: 621090