In effect from 3 September 2026 (v1)
Privacy notice
Kontūras is a small studio building websites, AI agents and automations. This notice explains what personal data we collect on konturas.lt, why and on what legal basis we process it, who we share it with, how long we keep it, and what your rights are.
1. Data controller
The controller is Inovacijų dialogas, MB, a Lithuanian small partnership, legal-entity code 306672068, VAT LT100016637613, Vilnius, Lithuania.
For any data-protection question, use the inquiry form on this site — say that your question concerns personal data and we will reply via the contact you leave in the form. We have no data protection officer — we are not required to appoint one, because we do not process personal data on a large scale.
The same company — Inovacijų dialogas, MB — also runs the bookkeeping service vedu.lt. That is a separate line of business with its own privacy notice; this notice covers only the konturas.lt site.
2. What we collect
Through the inquiry form we collect your name, e-mail address, an optional company name and website, the service area you select, a budget range, a preferred timeline and an optional message. There are no just-in-case fields.
Alongside the inquiry we store only two technical values in the database: the country code and the address of the page you arrived from. We do not store your IP address or browser identifier (user agent) — the IP is used briefly to protect the form from automated submissions (Cloudflare Turnstile) and to rate-limit inquiries, and the user agent leaves the server only on its way to Meta (see section 5).
While you browse the site we collect nothing further until you have given consent in the cookie banner. Once you do, the analytics and advertising tools collect page views, IP address and browser identifier — see section 6.
We do not collect special categories of data (health, beliefs and the like), and we ask you not to enter such data in the message field.
3. Purposes and legal basis
Handling your inquiry and preparing a quote — steps taken at your request prior to entering into a contract (GDPR Art. 6(1)(b)). You submit the data yourself when asking for a quote.
Site and form security, bot protection and rate limiting — legitimate interest (GDPR Art. 6(1)(f)). Application error logging rests on the same basis.
Visit analytics and ad conversion measurement — only with your consent (GDPR Art. 6(1)(a)), given in the cookie banner. You can withdraw consent at any time; withdrawal does not affect processing carried out beforehand.
We carry out no automated decision-making or profiling within the meaning of GDPR Art. 22 — every inquiry is reviewed by a person. We do not sell data.
4. How long we keep it
If no project follows, we keep inquiry data for up to 24 months from the last exchange and then delete it.
If a contract is concluded, further processing rests on that contract, and accounting documents are kept for the period the law requires.
Error-log entries are kept for up to 90 days. Retention of data sent to the advertising and analytics recipients is set by those recipients and stated in their own privacy policies.
5. Who receives the data
The following providers help us process the data. Most of them are processors acting on our instructions. The ad networks (Meta, Google, OpenAI) are the exception: they process what they receive as independent controllers, for their own purposes.
Data reaches the ad networks only after marketing consent. The e-mail address is hashed (SHA-256) before sending — we never send it unhashed; IP address and browser identifier are sent in the clear, because these interfaces do not accept hashed values for those fields. The site's form collects no phone number, so none is sent.
On OpenAI: the contract is with OpenAI Ireland Limited, registered in Ireland — under the OpenAI Ad Tools Data Processing Addendum (19 August 2026 edition) it is the entity that processes EEA data. Any onward transfer outside the EEA is made by OpenAI itself, which undertakes to use a valid transfer mechanism but does not name which one — Standard Contractual Clauses (SCCs) or the EU-U.S. DPF — in that addendum. Until OpenAI publishes it, we name no specific mechanism here. In the same addendum OpenAI reserves the right to use what it receives to develop, provide and improve its own and its affiliates' products and services, not only to measure our advertising.
We may also disclose data to law-enforcement or supervisory authorities where the law requires it.
| Recipient | Role | Region |
|---|---|---|
| Hostinger International Ltd. | server hosting and outbound e-mail (SMTP) | EU |
| Cloudflare, Inc. | Turnstile verification, security and caching | EU data localisation |
| Functional Software, Inc. (Sentry) | application error logging | EU (de.sentry.io) |
| Google Ireland Ltd. | Google Analytics 4 visit statistics (with analytics consent); once Google Ads is switched on, also ad-conversion measurement and attribution (with marketing consent): receives an internal inquiry number, the IP address and the browser identifier | EU/US under the EU-U.S. DPF |
| Meta Platforms Ireland Ltd. | Meta Pixel and Conversions API — receives a hashed e-mail address, a hashed country code, the IP address, the browser identifier, the page you arrived from, and the service areas, budget range and preferred timeline you selected in the form (only with consent) | EU/US under SCCs + the EU-U.S. DPF |
| OpenAI Ireland Limited | ChatGPT Ads pixel and Conversions API — receives a hashed e-mail address, the IP address, the browser identifier and the oppref click reference (only with consent); processes the data as an independent controller | EU; OpenAI does not name its onward-transfer mechanism |
6. Cookies
Essential cookies are always set — the site would not work without them. Analytics and marketing cookies are switched on only after you agree in the cookie banner; until then they are not set.
You can change your choice at any time via "Cookie settings" at the bottom of the site. After withdrawal no new cookies are written, but existing ones remain until the expiry shown in the table — to remove them immediately, use your browser settings.
Third-party cookies are controlled by the respective companies. Their privacy policies:
- policies.google.com/privacy
- facebook.com/privacy/policy
- openai.com/policies/eu-privacy-policy
- cloudflare.com/privacypolicy
| Cookie | Purpose | Lifetime | Cookie provider |
|---|---|---|---|
| konturas_consent | your cookie-consent choice (essential) | 180 days | Inovacijų dialogas, MB |
| __cf_bm, cf_clearance | Cloudflare bot management and the Turnstile challenge result (essential) | ~30 min / up to 30 days | Cloudflare, Inc. |
| _ga, _ga_* | Google Analytics 4 visit statistics (analytics) | up to 2 years | Google Ireland Ltd. |
| _gcl_au | Google Ads conversion linking — ties an ad click to an inquiry submitted later (marketing); set only once Google Ads is switched on | 90 days | Google Ireland Ltd. |
| _fbp, _fbc | Meta Pixel conversion tracking and ad attribution (marketing) | up to 90 days | Meta Platforms Ireland Ltd. |
| konturas_cids | ad-click references (Google gclid, gbraid, wbraid and ChatGPT Ads oppref); only oppref is stored with the inquiry, so that it can be attributed to the ad that brought you here — the Google references stay in the cookie and are not used (marketing) | 90 days | Inovacijų dialogas, MB |
| __oppref | the ChatGPT Ads click reference, reused by later page views (marketing) | lifetime not published by OpenAI | OpenAI Ireland Limited |
7. Your rights
You have the right to access the data we hold, to have it corrected or erased, to restrict processing, to data portability, to object to processing based on legitimate interest, and to withdraw consent at any time. Exercising these rights is free of charge; we reply within the deadlines the GDPR sets.
One limit we will not hide: once you give marketing consent, some of the data — a hashed e-mail address, the IP address, the browser identifier and the answers you selected in the form — has already been sent to Meta (and, once ChatGPT Ads is switched on, to OpenAI). We cannot recall that transmission: the data sits in those companies' systems and we have no means of deleting it from there. On receiving an erasure request we stop sending further events immediately and pass the request to that company's own deletion tooling, but the deletion itself is carried out by them. Google is a different case. Today the site uses Google Analytics 4 for visit statistics only, and its events are sent solely on analytics consent. Once Google Ads is switched on (it is not yet) and marketing consent has been given, a submitted inquiry is also recorded as an ad conversion: Google receives an internal inquiry number, the IP address and the browser identifier — we send neither an e-mail address nor a phone number. From then on Google Ads receives data about every page you open, not only about a submitted form. One further limit: the browser downloads the Google tag file itself on either consent — analytics or marketing — so already at that point Google receives your IP address, your browser identifier and the address of the page you are on.
Providing the data is voluntary. Without a name and an e-mail address we cannot accept an inquiry or prepare a quote — there is no other consequence.
If you believe we are mishandling your data, you have the right to lodge a complaint with the State Data Protection Inspectorate (VDAI), Lithuania's data-protection authority — vdai.lrv.lt.
8. Version
This is the first version of this notice (v1), in effect from 3 September 2026. Changes are recorded in the site's git history, so every revision can be traced. Whenever the notice changes, the updated version is published on this page.