Privacy Policy

Effective date: 2026-08-26

UAB Inkodus (hereinafter – “Inkodus”) respects your privacy.
This Privacy Policy explains how we collect, use, and disclose personal data when providing IT consulting and programming services (Services).

By using the Services, you confirm that you have read and understood this Privacy Policy.

1. Data Controller and Contact Information

UAB Inkodus
Savanorių pr. 178A
Kaunas, Lithuania
Email: [email protected]
Tel.: +370 674 35 898

For privacy-related inquiries, please contact us at
[email protected]
(add “Privacy” in the subject line).

2. Scope of This Privacy Policy

This Policy applies to:

  • Clients ordering Services and their representatives;
  • Individuals communicating with us (emails, inquiries);
  • Visitors of our website https://inkodus.lt.

B2B context: When Services are used by a company (Client),
some processing may be carried out on behalf of the Client.
In such cases, the Client acts as data controller and Inkodus acts as processor.
A separate data processing agreement may be concluded where required.

3. What Personal Data We Collect

3.1. Data You Provide

  • Contact data: name, email, phone number;
  • Professional data: job title, company, department;
  • Correspondence: inquiries, support history, email content;
  • Billing data: invoicing details, VAT number, payment data (payment cards are processed by payment providers).

3.2. Data Collected Automatically

  • Technical data: IP address, browser type/version, device, OS, time zone, logs;
  • Usage data: page views, session duration;
  • Approximate location (city/country from IP).

3.3. Data from Other Sources

  • From Clients (e.g., business contact lists);
  • From service providers (e.g., payment confirmations).

4. Purposes and Legal Bases for Processing

4.1. Contract Performance

Purpose: contract conclusion and execution, service delivery, invoicing, support.
Legal basis: GDPR Art. 6(1)(b).

4.2. Legitimate Interests

Purpose: security, fraud prevention, diagnostics, service improvement, internal administration, legal claims.
Legal basis: GDPR Art. 6(1)(f).

4.3. Legal Obligation

Purpose: accounting retention, compliance with legal requests.
Legal basis: GDPR Art. 6(1)(c).

4.4. Consent

Purpose: marketing communications (if applicable), certain cookies.
Legal basis: GDPR Art. 6(1)(a). Consent may be withdrawn at any time.

5. Data Sharing

We disclose data only where necessary:

  1. To the Client (employer/organisation) if you act on their behalf;
  2. To service providers (processors), such as:
    • Hosting and infrastructure providers;
    • Email delivery services;
    • Analytics and diagnostics providers;
    • Payment processors.
  3. To authorities where required by law;
  4. In business transactions (merger, reorganisation, asset sale).

We do not make personal data publicly available without justification.

6. Data Retention

We retain personal data only as long as necessary or legally required.

  • Contractual data – during contract and reasonable post-termination period;
  • Accounting records – according to statutory retention periods;
  • Technical logs – limited retention for security/diagnostics.

7. International Transfers

If data is processed outside the EEA, appropriate safeguards are applied
(e.g., standard contractual clauses under GDPR).

8. Cookies

We may use:

  • Essential cookies (session/security);
  • Functional cookies (preferences);
  • Analytical cookies (with consent where required).

You can manage cookies via browser settings. Disabling essential cookies may limit functionality.

9. Security

We implement technical and organisational safeguards (access controls, encryption, logs, backups).
No system is fully secure, and absolute security cannot be guaranteed.

In case of a personal data breach, we act in accordance with GDPR requirements.

10. Your Rights

You may have the right to:

  • Access your data;
  • Rectify inaccurate data;
  • Request erasure;
  • Restrict processing;
  • Object to legitimate interest processing;
  • Data portability;
  • Withdraw consent;
  • Lodge a complaint with a supervisory authority.

Supervisory authority in Lithuania: State Data Protection Inspectorate (VDAI).

To exercise rights, contact:
[email protected] (add “Privacy” in subject).

11. Processing of Candidates’ Personal Data

11.1. Processed Data and Purposes

For the purpose of carrying out recruitment for open positions, we process the following personal data of candidates:

  • identity and contact details (first name, last name, email address, phone number);
  • professional experience and qualifications (CV, cover letter, education, work experience, certificates);
  • links to professional social networks provided by the candidate (e.g., LinkedIn, GitHub);
  • data shared during the recruitment process (email correspondence or communication environments, e.g., Microsoft Teams, data contained in a tripartite professional internship agreement or voluntary internship agreement, if the candidate is applying for an internship position);
  • references from former employers (only after informing the candidate in advance);
  • references from the current employer (only upon receiving separate consent from the candidate).

11.2. Legal Bases for Data Processing and Retention

  • Data is processed during the specific selection process for which the candidate filled out the application form, in order to assess the candidate’s suitability for the job as a potential employee and to take steps at the candidate’s request prior to entering into an employment or internship contract (Article 6(1)(b) of the GDPR);
  • Data is stored after the end of the selection for no longer than 3 months to ensure the company’s legitimate interest in protecting against potential legal disputes related to discrimination or unlawful refusal to hire experienced during the selection process (Article 6(1)(f) of the GDPR);
  • Data may be processed for no longer than 1 year in order to offer the candidate the opportunity to participate in another selection for open positions, if the candidate consents to this (Article 6(1)(a) of the GDPR).

11.3. Retention Periods

  • The candidate’s personal data is stored for no longer than 3 months after the position is filled, unless the candidate confirms their consent in the job application form to retain the data for 1 year from the date of submission of the application for the purpose of offering it for other vacancies.

11.4. Limitations on Data Collection

  • Our company does not process and does not request excessive personal data such as a photograph, date of birth, marital status, criminal record (non-conviction) data, unless required by legal acts for a specific position.

11.5. Candidate Rights and Withdrawal

  • The candidate has the right to withdraw their consent at any time or object to the storage of data for future selections by writing to [email protected]. In such a case, all candidate data is removed from our systems within 5 business days.

12. Children’s Data

Services are intended for individuals aged 18 and over.
We do not knowingly collect data from minors.

13. Third-Party Links

Our website may contain links to third-party services.
We are not responsible for their privacy practices.

14. Client (B2B) Obligations

If a Client provides personal data, the Client must:

  1. Have a lawful basis for processing;
  2. Inform data subjects;
  3. Apply data minimisation;
  4. Avoid unlawful or excessive content;
  5. Cooperate regarding data subject requests.

15. Changes to This Policy

We may update this Privacy Policy and will revise the effective date.
Significant changes may be communicated by email or website notice.

16. Contact

UAB Inkodus
Savanorių pr. 178A
Kaunas, Lithuania
Email: [email protected]
Tel.: +370 674 35 898
×

Loading...