Legal
Privacy Policy
Last updated: July 23, 2026
Privacy Policy
1. Who We Are
Aymarif LLC (“Aymarif”, “we”, “us”) is the data controller responsible for your personal data under the EU GDPR and Lithuanian Law on Legal Protection of Personal Data.
- Legal entity: Aymarif LLC (Uždaroji akcinė bendrovė)
- Registered address: Girulių g. 5, LT-12124, Vilnius, Lithuania, EU
- Data Protection enquiries: privacy@aymarif.com
2. What Personal Data We Collect
We collect personal data only when you provide it directly. We do not engage in mass data collection, tracking, or profiling.
2.1 Contact Form Data
When you submit our contact form, we collect your name, email address, company (optional), and the subject/content of your message. You consent to this processing by ticking the consent checkbox.
2.2 Cookie Data
See our Cookie Policy. Non-essential cookies are only set after consent.
2.3 Data We Do NOT Collect
- We do not collect special categories of data (health, ethnicity, biometric, etc.).
- We do not sell your personal data.
- We do not use automated decision-making or profiling.
3. Legal Basis for Processing (GDPR Art. 6)
- Consent (Art. 6(1)(a)) — contact form submissions and non-essential cookies.
- Legitimate interests (Art. 6(1)(f)) — responding to enquiries, business communication, site security.
- Legal obligation (Art. 6(1)(c)) — where law requires record retention.
4. How We Use Your Data
- To respond to your enquiry and provide requested information/services.
- To maintain records of communications for business purposes.
- To operate, maintain, and secure our website.
- To comply with legal obligations.
5. Data Retention
- Contact enquiries not leading to engagement: deleted within 12 months.
- Active client records: retained for the business relationship + period required by Lithuanian accounting law (typically 10 years).
- Consent records: kept until you withdraw consent or request deletion.
6. Data Sharing & Sub-Processors
We do not sell or trade your data. We may share it with: hosting providers (EU/EEA-based), email/form service providers, and professional advisors (lawyers, accountants) where legally required.
International transfers: Primarily within the EU/EEA. If any sub-processor is outside the EU/EEA, Standard Contractual Clauses (SCCs) will be in place.
7. Your GDPR Rights
| Right | Article | What it means |
|---|---|---|
| Access | Art. 15 | Ask what data we hold about you. |
| Rectification | Art. 16 | Correct inaccurate data. |
| Erasure | Art. 17 | Delete your data (“right to be forgotten”). |
| Restriction | Art. 18 | Limit processing temporarily. |
| Data portability | Art. 20 | Receive data in machine-readable format. |
| Objection | Art. 21 | Object to legitimate-interest processing. |
| Withdraw consent | Art. 7(3) | Withdraw consent anytime. |
Contact privacy@aymarif.com to exercise these rights. We respond within one month.
8. Right to Lodge a Complaint
Contact the Lithuanian supervisory authority: State Data Protection Inspectorate (VDAATI) — www.ada.lt, or your local EU supervisory authority.
9. Security Measures
- Encryption in transit (HTTPS/TLS).
- Access controls — only authorised personnel.
- Data minimisation — we collect only what is necessary.
- Periodic review of our data practices.
10. Children’s Privacy
This website is not directed at children under 16. We do not knowingly collect data from children. Contact us if you believe this has occurred.
11. Changes to This Policy
We may update this policy. The “last updated” date reflects the most recent revision.