Privacy Policy

Last updated: June 26, 2026

1. Who We Are

EuroRAG is operated by Dominykas Viečas, operating as individuali veikla (individual business activity) under the laws of the Republic of Lithuania.

Contact: Terminalo g. 2-3, Šiauliai, LT-76371, Lithuania
Email: [email protected]

Supervisory authority: Valstybinė duomenų apsaugos inspekcija (State Data Protection Inspectorate), L. Sapiegos g. 17, 10312 Vilnius, Lithuania - vdai.lrv.lt

2. What Data We Collect

Data you provide directly

DataWhen collectedPurposeLegal basis
Email addressWaitlist signup, purchaseDeliver product, send purchase confirmation and updatesContract (Art. 6(1)(b)), consent for marketing (Art. 6(1)(a))
GitHub usernamePurchase (checkout form)Grant access to private repositoryContract (Art. 6(1)(b))
Billing informationPurchaseProcess payment via StripeContract (Art. 6(1)(b))

Data generated during purchase

DataPurposeLegal basis
License keyVerify license validityContract (Art. 6(1)(b))
Purchase record (email, tier, date, Stripe session ID)Order fulfillment, support, accountingContract (Art. 6(1)(b)), legal obligation (Art. 6(1)(c))

Data collected automatically

DataSourcePurposeLegal basis
IP address, browser type, pages visitedCloudflareSecurity, DDoS protectionLegitimate interest (Art. 6(1)(f))
Advertising cookies and interaction dataGoogle AdsAdvertising measurementConsent (Art. 6(1)(a)) - only after accepting cookies

Data we do NOT collect

We do not access, store, or process any data from your EuroRAG deployment. The software runs on your server. We have no access to your users' data, documents, chat messages, or any other information processed by your EuroRAG instance.

3. Third-Party Processors

ProcessorPurposeData sharedLocation
Stripe, Inc.Payment processingBilling info, emailUS (EU SCCs) - DPA
Cloudflare, Inc.Hosting, CDN, security, customer database (Workers + D1)IP, request data, email, GitHub username, license key, purchase recordsUS (EU SCCs) - DPA
Sendinblue SAS (Brevo)Transactional email, waitlistEmail addressFrance (EU) - DPA
GitHub (Microsoft)Repository access deliveryGitHub usernameUS (EU SCCs) - Terms
Google LLCAdvertising measurementCookies, interaction data (after consent)US (EU SCCs) - DPA

4. Cookies

Strictly necessary (no consent required): Cloudflare security cookies (__cf_bm, cf_clearance) for bot protection.

Advertising (consent required): Google Ads cookies for advertising measurement and conversion tracking. Only set after you click "Accept" on the cookie banner.

You can withdraw cookie consent at any time by clicking "Cookie Settings" in the page footer.

5. Your Rights

Under GDPR Articles 15–22, you have the right to:

To exercise any of these rights, email [email protected]. We will respond within 30 days.

6. Data Retention

DataRetention period
Customer database (email, GitHub username, license key, purchase records)Duration of license + 10 years (Lithuanian accounting requirements)
Payment records (Stripe)As required by Lithuanian tax law (10 years)
Waitlist signups (Brevo)Until you unsubscribe or the list is deleted
Cloudflare access logs72 hours (Cloudflare default)
Google Ads dataPer Google's retention settings

7. International Transfers

Some processors (Stripe, Cloudflare, GitHub, Google) are US-based. Transfers are covered by Standard Contractual Clauses (SCCs) as approved by the European Commission. Links to each processor's Data Processing Agreement are listed in Section 3.

8. Changes to This Policy

We may update this policy to reflect changes in our practices or legal requirements. Material changes will be communicated via email to existing customers.