Privacy Policy
Last updated: June 26, 2026
1. Who We Are
EuroRAG is operated by Dominykas Viečas, operating as individuali veikla (individual business activity) under the laws of the Republic of Lithuania.
Contact: Terminalo g. 2-3, Šiauliai, LT-76371, Lithuania
Email: [email protected]
Supervisory authority: Valstybinė duomenų apsaugos inspekcija (State Data Protection Inspectorate), L. Sapiegos g. 17, 10312 Vilnius, Lithuania - vdai.lrv.lt
2. What Data We Collect
Data you provide directly
| Data | When collected | Purpose | Legal basis |
|---|---|---|---|
| Email address | Waitlist signup, purchase | Deliver product, send purchase confirmation and updates | Contract (Art. 6(1)(b)), consent for marketing (Art. 6(1)(a)) |
| GitHub username | Purchase (checkout form) | Grant access to private repository | Contract (Art. 6(1)(b)) |
| Billing information | Purchase | Process payment via Stripe | Contract (Art. 6(1)(b)) |
Data generated during purchase
| Data | Purpose | Legal basis |
|---|---|---|
| License key | Verify license validity | Contract (Art. 6(1)(b)) |
| Purchase record (email, tier, date, Stripe session ID) | Order fulfillment, support, accounting | Contract (Art. 6(1)(b)), legal obligation (Art. 6(1)(c)) |
Data collected automatically
| Data | Source | Purpose | Legal basis |
|---|---|---|---|
| IP address, browser type, pages visited | Cloudflare | Security, DDoS protection | Legitimate interest (Art. 6(1)(f)) |
| Advertising cookies and interaction data | Google Ads | Advertising measurement | Consent (Art. 6(1)(a)) - only after accepting cookies |
Data we do NOT collect
We do not access, store, or process any data from your EuroRAG deployment. The software runs on your server. We have no access to your users' data, documents, chat messages, or any other information processed by your EuroRAG instance.
3. Third-Party Processors
| Processor | Purpose | Data shared | Location |
|---|---|---|---|
| Stripe, Inc. | Payment processing | Billing info, email | US (EU SCCs) - DPA |
| Cloudflare, Inc. | Hosting, CDN, security, customer database (Workers + D1) | IP, request data, email, GitHub username, license key, purchase records | US (EU SCCs) - DPA |
| Sendinblue SAS (Brevo) | Transactional email, waitlist | Email address | France (EU) - DPA |
| GitHub (Microsoft) | Repository access delivery | GitHub username | US (EU SCCs) - Terms |
| Google LLC | Advertising measurement | Cookies, interaction data (after consent) | US (EU SCCs) - DPA |
4. Cookies
Strictly necessary (no consent required): Cloudflare security cookies (__cf_bm, cf_clearance) for bot protection.
Advertising (consent required): Google Ads cookies for advertising measurement and conversion tracking. Only set after you click "Accept" on the cookie banner.
You can withdraw cookie consent at any time by clicking "Cookie Settings" in the page footer.
5. Your Rights
Under GDPR Articles 15–22, you have the right to:
- Access your personal data (Art. 15)
- Rectify inaccurate data (Art. 16)
- Erase your data (Art. 17)
- Restrict processing (Art. 18)
- Data portability - receive your data in a structured format (Art. 20)
- Object to processing based on legitimate interest (Art. 21)
- Lodge a complaint with the Valstybinė duomenų apsaugos inspekcija
To exercise any of these rights, email [email protected]. We will respond within 30 days.
6. Data Retention
| Data | Retention period |
|---|---|
| Customer database (email, GitHub username, license key, purchase records) | Duration of license + 10 years (Lithuanian accounting requirements) |
| Payment records (Stripe) | As required by Lithuanian tax law (10 years) |
| Waitlist signups (Brevo) | Until you unsubscribe or the list is deleted |
| Cloudflare access logs | 72 hours (Cloudflare default) |
| Google Ads data | Per Google's retention settings |
7. International Transfers
Some processors (Stripe, Cloudflare, GitHub, Google) are US-based. Transfers are covered by Standard Contractual Clauses (SCCs) as approved by the European Commission. Links to each processor's Data Processing Agreement are listed in Section 3.
8. Changes to This Policy
We may update this policy to reflect changes in our practices or legal requirements. Material changes will be communicated via email to existing customers.