EN — Privacy Notice

Controller: Variosity, MB, company code 306006123, Žalumos 18-oji g. 6, Brinkiškės, Vilniaus r., Lithuania. Contact: info@mandoberdani.it.

We may process identity/contact/enquiry data; account/authentication data; company, billing, payment-status, order and contract data; portal, agent and usage events; prompts, files, messages, context and outputs; IP/time/browser/device/security/access logs; language preference; and suppression records. Hosted checkout should prevent us from receiving full card details. Do not submit special-category or highly sensitive data without written assessment.

Purposes and legal bases are: responding to enquiries and taking requested pre-contract steps — GDPR Article 6(1)(b); entering into and performing the contract and managing the account, service, support, payment status and access — contract; issuing and retaining accounting records and meeting tax and legal duties — legal obligation; security, abuse detection, claims management, service improvement and business correspondence — legitimate interests after balancing the individual’s rights; direct marketing only where a separate lawful basis exists and with a clear opt-out; and consent where specifically requested, until withdrawal, without affecting the lawfulness of earlier processing. Enquiry data does not automatically become marketing data.

To provide AI functions, prompts, files, messages, context, metadata and outputs may be sent to OpenAI or another selected LLM/API provider, under that provider’s privacy, security, retention, abuse-monitoring, region, international-transfer and subprocessor rules. A Customer-connected LLM/API/tool is used on the Customer’s instruction and the Customer is responsible for its suitability and notices. Mandoberdani does not intend to make solely automated legally significant decisions about individuals without human oversight. The Customer must not enable such legally or similarly significant solely automated use without a separate legal and technical assessment.

The public site, its technical logs and business email currently use Hostinger infrastructure; on 23 August 2026 the live public-server IP was attributed to Vilnius, Lithuania, although Hostinger subprocessors may operate elsewhere. OpenAI/API, Revolut Merchant and Fiskl receive data only when the relevant function is expressly agreed and activated; publication does not activate payment or Fiskl transfers. The self-hosted CRM is not a separate external recipient. Advisers, auditors and authorities may receive data where lawfully necessary.

The current direct-provider status, DPA and official subprocessor evidence are published at /subprocessors. We do not claim all data always remains in the EU. Outside-EEA transfers rely, where applicable, on adequacy, EU Standard Contractual Clauses or another GDPR Chapter V mechanism. A provider’s available/configurable region is treated as actually used only after account-specific verification. The Customer controls the regions and transfers of a Customer-selected provider under that provider’s contract.

Retention: unsuccessful enquiries 12 months after last meaningful contact; incomplete signup/unpaid orders 24 months from the last action; account identity, accepted contract/order and essential performance evidence for the relationship and, where necessary for claims, up to 10 years after termination; ordinary support/business correspondence for the relationship plus 3 years, while separately identified contract/claim evidence may be kept up to 10 years; operational configuration and non-essential technical settings during the relationship and up to 90 days after termination, with earlier deletion at the Customer’s request unless a technical or legal ground requires retention; accounting/payment evidence 10 years; Customer content, chats, prompts, files and outputs during the relationship and up to 90 days after termination, with earlier deletion at the Customer’s request unless a legal hold or security investigation requires longer; ordinary public-site access and technical logs 90 days, except that a security-incident extract may be retained for up to 24 months; evidence of security incidents, audits and administrative actions for 24 months, or longer during an investigation, dispute or mandatory hold; rights-request evidence 3 years; minimal suppression records while marketing continues plus 5 years; active backups up to 30 days after primary deletion. Documented legal claims/holds, fraud or security investigations, unpaid debts, authority orders and mandatory duties suspend ordinary deletion only while necessary. When the exception ends, the data is deleted, anonymised or reliably restricted according to its category; deleted backup data is not restored to active use except for incident recovery, after which the deletion instruction is re-applied.

Individuals may request access, correction, erasure, restriction, objection, portability and withdrawal of consent. We may verify identity and clarify scope. We respond without undue delay and normally within one month; in complex cases the period may be extended as permitted by the GDPR, and the individual will be informed of the extension. Contact info@mandoberdani.it. A person may complain to the Lithuanian State Data Protection Inspectorate (VDAI) or another competent EEA authority without first contacting us.

We use risk-proportionate access control, encrypted transport, backups and monitoring, without guaranteeing absolute security. The public website currently evidences only functional language preference in localStorage, not active advertising/analytics tracking. Before enabling new tracking, an integration or a data flow, this notice and, where necessary, the consent mechanism must be updated. Material changes are published in an updated version, and active customers are notified of significant changes through an appropriate channel.

Privacy Notice — Mandoberdani