PRIVACY NOTICE
Updated: 2026 07 27
We respect your privacy and protect your personal information that you provide to us and that we collect for the purposes set out in this Privacy notice (the “Privacy Notice”). In the privacy statement, we explain what data we collect about you, how we use this personal data, and under what conditions the data may be disclosed to third parties. We also explain how we store and protect your personal data from misuse and what rights you have with respect to your personal data.
1. Who is your data controller?
Loadagent Technologies MB, legal entity code 307430993, address Vytėnų g. 73-1, LT-47484 Kaunas (hereinafter – “ Loadagent ” or “we”) is the controller of your personal data.
2. Whom should you contact if you have questions about personal data protection?
If you have any questions about the protection of personal data, please contact: [email protected]
3. How do we process your personal data and why?
In the course of our business activities, we collect personal data from our customers, potential customers, business partners (service providers, resellers, etc.), visitors to our website, and attendees of events organized by us, and we are therefore considered to be a data controller. As the data controller, in this Privacy Notice we inform you (the data subject) of the purposes for which we collect and process your personal data and indicate the legal basis for such data collection.
We may collect and process your personal data for the following purposes and on the following legal basis:
| Data processing purpose and description | Legal basis | Categories of personal data | Retention period |
|---|---|---|---|
| When you complete a contact form on our website – to communicate with you and assess how we can best assist you with your enquiry. The contact form service is provided by Formspree, Inc. (https://formspree.io/), which processes submitted form data on our behalf as a data processor under Art. 28 GDPR. | Art. 6(1)(f) GDPR – legitimate interests in responding to ordinary business enquiries; Art. 6(1)(b) GDPR – where the enquiry concerns steps prior to entering into a contract; Art. 6(1)(a) GDPR – consent, where the nature of the enquiry makes this appropriate. The applicable basis is assessed case by case. | Identification data (name); contact data (email address, telephone number); the subject matter of your enquiry; IP address (processed by Formspree as part of form submission handling). Please do not include special-category personal data (e.g. health information) in your message unless strictly necessary. | Until the specific request has been examined and answered, and for 12 months thereafter to handle any follow-up correspondence, disputes, or complaints arising from the same enquiry. |
| Cookies used on our website – to ensure the security and proper functioning of the website (strictly necessary cookies) and to analyse visitor traffic and website performance (analytics cookies). For full details of each cookie, its provider, and its storage period, please see section 6 (Cookies) of this Privacy Notice. | Strictly necessary cookies: Art. 6(1)(f) GDPR – legitimate interests in operating and securing the website. Analytics cookies: Art. 6(1)(a) GDPR – consent, in accordance with applicable ePrivacy rules. | Cookie data, including your IP address, URLs of pages visited and referring websites, browser and operating system type, and the time and date of your visit. | Cookie lifetimes vary by type and provider. Please see section 6 for details of individual cookies. |
| Data of potential customers and their representatives, collected at events, via professional social networks, and through other identified contact channels, processed for direct marketing purposes (commercial communications about our products and services). | Art. 6(1)(f) GDPR – legitimate interests in developing business relationships with potential corporate customers. For electronic marketing (email, SMS), prior consent under applicable ePrivacy legislation is required unless the existing-customer exception applies. Consent: Art. 6(1)(a) GDPR where required by ePrivacy rules. | Identification data, contact data | 12 months from collection or last meaningful interaction (defined as a reply, click, or direct meeting). May be extended to a maximum of 24 months where the contact remains objectively relevant based on their role and our service offering, subject to documented periodic review. Suppression lists are maintained after opt-out or objection. |
| Conclusion and performance of contracts with business partners | Art. 6(1)(f) GDPR – legitimate interests in administering business relationships with corporate partners and their representatives. Note: a partner's representative is typically not personally a party to the inter-company contract; Art. 6(1)(b) GDPR does not therefore apply to the representative's personal data. | Identification data, contact data, financial data, and communication data of the partner's authorised representatives | Up to 10 years following the end of the contract, to the extent required by applicable accounting, tax, and limitation-period obligations. Shorter periods apply to data categories (e.g. communication records) where the above obligation does not apply. |
| Administration of user accounts of authorised users designated by customers | Art. 6(1)(b) GDPR – performance of the service contract with the customer (account administration). Art. 6(1)(c) GDPR – compliance with legal obligations. Art. 6(1)(f) GDPR – legitimate interests (platform security, fraud prevention, service management). Where we act solely as a processor on documented customer instructions, a data processing agreement under Art. 28 GDPR governs. | Account credentials (username, email address), role and access permissions, usage logs, and billing contact data. | For the duration of the customer account. Processing subject to a customer data processing agreement is governed by that agreement. |
4. From where do we get personal data?
We receive your personal data directly from you when you provide it to us, for example by contacting us, visiting our website, submitting documents, or registering for and attending our events.
We also collect personal data from third parties and publicly available sources, such as newspapers and other news sources, public registers, professional social networks, government agencies, and corporate websites. Where we collect personal data from sources other than you directly, we will provide the information required by Art. 14 GDPR within the timeframe set out in Art. 14(3) GDPR (generally within one month of collection, at the time of first contact, or before first disclosure to a recipient, whichever is earliest).
5. To whom we disclose or transfer data. Do we transfer data outside the EU or the EEA?
Your personal data may be disclosed to the following categories of recipients: (a) cloud hosting and IT infrastructure providers; (b) CRM and email delivery service providers; (c) payment and accounting service providers; (d) website analytics providers; (e) legal and professional advisers; (f) event organisation providers; (g) advertising and social media platforms; and (h) other service providers engaged to support our operations. We identify actual recipients where possible; where we can only provide categories, those categories are as specific as possible. We do not sell your personal data.
Your personal data may be disclosed to public authorities, government bodies, or law enforcement agencies where we are required to do so by applicable law or a binding legal obligation, or where necessary for the establishment, exercise, or defence of legal claims under Art. 6(1)(c) or Art. 6(1)(f) GDPR. Each such disclosure is assessed individually.
We enter into data processing agreements under Art. 28 GDPR with all processors and are responsible for selecting processors that provide sufficient guarantees, issuing lawful instructions, and monitoring compliance. We are not automatically responsible for the independent processing activities of separate controllers described as business partners; their processing is governed by their own privacy notices. Where we act as a joint controller with another party, the respective responsibilities are set out in a joint-controller arrangement under Art. 26 GDPR.
We normally process personal data within the EU/EEA. Where personal data are transferred to third countries, we ensure appropriate safeguards are in place under Chapter V GDPR, such as adequacy decisions under Art. 45 or Standard Contractual Clauses under Art. 46 GDPR. Certain service providers (including Google Cloud and Microsoft) may process data subject to their own international transfer arrangements. You may request a copy of the applicable safeguards by contacting us using the details in section 2.
7. How do we protect data?
We take appropriate technical and organisational measures to protect the personal data we process, in accordance with Art. 32 GDPR, having regard to the nature, scope, context, and purposes of processing and the associated risks. These measures include encryption in transit and at rest, role-based access controls, single sign-on ( SSO) authentication, logging and monitoring, regular backups, and vulnerability management and incident response procedures. Specific controls are documented internally and reviewed periodically.
8. What are your rights as a data subject?
As a data subject, you have the following rights under GDPR, subject to the conditions and limitations set out therein:
- the right to access your personal data that we process about you;
- the right to have personal data rectified;
- the right to erasure (the 'right to be forgotten') – where one of the grounds in Art. 17(1) GDPR applies and no exception under Art. 17(3) GDPR is applicable;
- the right to restriction of processing – in the circumstances set out in Art. 18 GDPR;
- the right to data portability – to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller, where processing is based on consent or a contract and is carried out by automated means (Art. 20 GDPR);
- the right to object to processing based on Art. 6(1)(e) or Art. 6(1)(f) GDPR. You have an absolute right to object to direct marketing at any time, including related profiling; upon such objection, we will cease direct marketing processing immediately (Art. 21(2)-(3) GDPR);
- the right to withdraw consent at any time where processing is based on consent (Art. 7(3) GDPR), without affecting the lawfulness of processing carried out before withdrawal. You can withdraw consent by selecting “Cookie settings” in the footer of our website or web application and choosing “Reject”, or, for marketing communications, by clicking the unsubscribe link in the relevant email. Withdrawal is as straightforward as giving consent;
- the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects or similarly significantly affects you (Art. 22 GDPR). [We do not currently carry out solely automated decision-making with such effects / Where we do, we will provide information about the logic involved, its significance, and its envisaged consequences];
- the right to lodge a complaint with the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija), L. Sapiegos g. 17, LT-10312 Vilnius; email: [email protected]; website: www.vdai.lrv.lt. This right may be exercised at any time without first contacting us.
All requests and enquiries regarding the rights described above should be submitted in writing by email to [email protected] or by registered mail to Loadagent Technologies MB, Vytėnų g. 73-1, LT-47484 Kaunas, Lithuania. We will respond within one month of receipt of your request.
9. Is providing personal data mandatory?
Where we collect personal data directly from you, we will indicate at the point of collection whether providing the data is a statutory or contractual requirement, whether it is necessary to enter into a contract, and the consequences of not providing it (Art. 13(2)(e) GDPR). As a general guide: (a) for the contact form, providing data is voluntary but without it we cannot respond to your enquiry; (b) for partner contracting, providing identification and contact data is necessary to conclude and perform the agreement; (c) for user accounts, providing account credentials is necessary to access the platform.
10. Changes to the Privacy Notice
If we make changes to this Privacy Notice, we will record the date of the change in the updated version. Where changes are significant or introduce new processing purposes, we will provide additional notice by appropriate means (such as email or a prominent website notice) and, where required, seek fresh consent before commencing any new processing.
We encourage you to review this Privacy Notice periodically.