Rules & privacy

“Naudokis” Privacy Policy

This Privacy Policy explains what personal data we process about you, why we do so, to whom we disclose it, how long we retain it, and what rights you have.

Effective June 1, 2026Updated July 14, 2026

Data controller: MB “Naudokis” Legal entity code: 307423504 Registered office address: Numėjos g. 6, LT-08402 Vilnius, Lithuania Privacy questions and requests: info@naudokis.lt

“Naudokis” is an item rental platform operating in Lithuania. This Policy applies to the “Naudokis” website, mobile application, administration tools, and related account, listing, reservation, payment, payout, identity verification, messaging, support, dispute, moderation, and notification functions.

The Terms of Use set out the rules for using the Platform and for rental transactions. This Policy explains how personal data are processed in connection with those activities. Terms defined in the Terms of Use have the same meaning in this Policy unless expressly stated otherwise.

In brief

  • We process core account, listing, reservation, and communication data in order to provide the Platform services.
  • Payments and payouts are processed by Stripe. “Naudokis” does not store the full payment card number, CVC, or PIN.
  • Didit may be used for identity and age verification, and Stripe may be used for payment or payout checks.
  • We display publicly only the information necessary for a listing and for trust. More precise contact and handover details are disclosed only when needed for a transaction.
  • Mixpanel product analytics and AppsFlyer app attribution are enabled only with consent. The public website uses cookieless Plausible audience and app-handoff measurement on the legitimate-interests basis described below.
  • Closing an account does not result in all data being deleted immediately. Financial, tax, dispute, security, or legal-defence data may be retained for longer.
  • You may request access to, rectification, erasure, or restriction of your data, data portability, object to certain processing, and withdraw consent.

1.Who this Policy applies to

This Policy applies to:

  • visitors to the website and the App;
  • registered Users;
  • Lessors and Renters;
  • Business Users, Traders, and their representatives;
  • persons whose data are provided in messages, support requests, reports, reviews, handover or return evidence, and disputes.

MB “Naudokis” is the data controller where it determines the purposes and means of the processing of personal data.

Some recipients, such as Stripe, social-login providers, banks, or public authorities, process part of the data as independent data controllers. Their own privacy notices and applicable law govern their independent processing.

Service providers that process data solely on our instructions are our data processors. The role of another Platform User or business customer depends on how and for what purpose that person uses the data received.

2.Where we obtain data from

We obtain data:

  • from you, when you register, complete your profile, list an item, make a reservation, pay, communicate, contact support, submit evidence, or leave a review;
  • from other Users, when they provide information concerning you in a reservation, message, review, report, or dispute;
  • automatically, when you use the Platform, for example from session, device, security, diagnostics, cookie, or SDK events;
  • from service providers, for example payment, identity-verification, social-login, address, analytics, or communications providers;
  • from registers, authorities, or public sources, where this is necessary to verify identity, business information, VAT status, taxes, security, or legal defence.

Where we obtain personal data other than directly from you and this Policy has not yet been provided to you, we provide the information within the period specified in Article 14 GDPR, unless an exemption provided by law applies.

3.What data we process

The scope of the data processed depends on the functions you use.

3.1. Account and profile

We may process:

  • your name, display name, email address, and telephone number;
  • your profile photograph and optional profile information;
  • login, authentication, and account-recovery data;
  • account status, settings, and verification badges;
  • records of acceptance of the Terms of Use, Privacy Policy, and other legal choices.

3.2. Identity and verification

Depending on the check, we may process:

  • your date of birth and confirmation that you are at least 18 years old;
  • the verification-session identifier, status, and result;
  • limited identity-document attributes and the document’s expiry date;
  • document, facial-match, liveness, or fraud-prevention signals;
  • a technical security marker intended to identify repeated use of the same document or personal data.

During identity verification, the provider may process an image of the document, an image of the person, video, or liveness-check data. Whether those data constitute biometric data depends on the technology and purpose used. If the data are processed as biometric data for the purpose of uniquely identifying a person, a separate condition under Article 9 of the GDPR and additional safeguards must apply.

3.3. Business, tax, and invoicing data

We may process:

  • the legal or trading name, registration number, and address;
  • the representative’s name, position, and representation information;
  • VAT status, VAT number, and the result of a VIES check;
  • tax-identification numbers and other data required for DAC7 checks;
  • invoice, receipt, credit-document, accounting, and tax-reporting data.

3.4. Listings and rental items

We may process:

  • the listing title, description, category, price, and Security Deposit;
  • photographs, videos, item characteristics, and availability;
  • the approximate location of the listing;
  • listing status, history, and moderation information.

3.5. Reservations, payments, and payouts

We may process:

  • the parties to the Reservation, dates, status, and handover or delivery method;
  • the rental price, Platform fee, Security Deposit, and other calculations;
  • Stripe customer, payment, refund, transfer, and payout identifiers;
  • authorisation, capture, refund, payout, and payment-dispute statuses;
  • invoice and payment-reconciliation records.

3.6. Handover, return, and disputes

We may process:

  • handover and return times, condition confirmations, and accessory lists;
  • photographs, videos, and other evidence relating to the item;
  • claims concerning damage, loss, delay, cancellation, or the Security Deposit;
  • the parties’ explanations, decisions, payout holds, and allocation of the Security Deposit.

3.7. Messages, support, and moderation

We may process:

  • messages sent through the Platform and their attachments;
  • support requests, complaints, and reports concerning Users or Listings;
  • DSA notices, moderation decisions, and appeals;
  • signals relating to rule violations, security, and attempts to circumvent the Platform.

3.8. Location and delivery data

We may process:

  • the approximate location of a Listing or search;
  • the collection, delivery, or handover address;
  • geocoding and address-normalisation results;
  • distance or delivery area.

We process precise device-location data only where a function uses those data and the required device permission has been granted.

3.9. Reviews and reputation

We may process:

  • a rating, review text, and its relationship to a Reservation;
  • the publicly displayed name and the User’s role in the transaction;
  • verification, activity, and other trust signals displayed on the Platform;
  • favourited Listings and other account preferences.

3.10. Device, security, and diagnostics

We may process:

  • IP address, user agent, and session information;
  • device type, operating system, App version, and language;
  • login, error, performance, security, and audit logs;
  • a push-notification token;
  • cookies, local-storage records, and identifiers of similar technologies.

3.11. Analytics and attribution

Only after obtaining the required consent may we process:

  • screen views, selected actions, and functions used;
  • a pseudonymous internal User identifier;
  • app-installation, opening, redirection, and campaign data;
  • attribution identifiers, campaign source, and selected conversion events;
  • a completed-rental revenue and currency event, where such measurement is enabled.

We do not seek to collect special-category data through the Platform’s general functions. If you voluntarily provide such data in a message, evidence, or support request, we process them only to the extent necessary to resolve that specific matter and to the extent permitted by law.

4.Whether you are required to provide data

We identify mandatory fields at the relevant stage of the Platform.

Account and login data are necessary to create and protect an account. Listing, Reservation, payment, handover, or return data are necessary only when you use the corresponding function. Telephone, identity, business, tax, invoicing, and payout data may be necessary because of the chosen function, payment-provider requirements, transaction risk, or law.

If you do not provide mandatory data, we may be unable to:

  • create or verify an account;
  • publish a Listing;
  • submit or accept a Reservation;
  • process a payment, refund, or payout;
  • issue an accounting document;
  • provide a function for which those data are necessary.

Optional profile fields, marketing, Mixpanel analytics, and AppsFlyer attribution are not necessary for the Platform’s core functions. If you do not consent, the relevant optional function or measurement will not operate, but this must not restrict the core rental functions.

5.Why and on what basis we process data

The principal purposes and legal bases under the GDPR are set out below.

Purpose of processingMain legal basis
Create and administer an account and authenticate the UserPerformance of a contract or steps taken before entering into a contract
List items and manage Reservations, messages, handover, return, and reviewsPerformance of a contract
Process payments, Security Deposits, refunds, and payoutsPerformance of a contract; legal obligation, where applicable
Verify age, identity, business representation, or entitlement to receive payoutsPerformance of a contract; legitimate interest in preventing fraud; legal obligation, where specifically applicable
Detect fake accounts, use of multiple accounts, stolen items, fraud, failure to return items, or attempts to circumvent the PlatformLegitimate interest in protecting Users, the Platform, and transactions
Moderate Listings, messages, and User conduct; apply account or function restrictionsPerformance of a contract; legitimate interest in maintaining a safe and fair Platform; legal obligation, where applicable
Resolve damage, loss, delay, cancellation, Security Deposit, or other disputesPerformance of a contract; legitimate interest in establishing, bringing, enforcing, or defending claims
Provide support and send essential notificationsPerformance of a contract; legitimate interest in administering the service; legal obligation, where applicable
Process invoices, accounting, VAT, VIES, tax, and DAC7 dataLegal obligation
Retain evidence of contracts, consents, and legal choicesLegal obligation; legitimate interest in demonstrating compliance and defending claims
Ensure the security of infrastructure, accounts, and payments; investigate incidentsLegitimate interest in ensuring information and Platform security; legal obligation, where applicable
Perform essential diagnostics and correct technical errorsLegitimate interest in maintaining a secure and functioning service; consent for access to terminal equipment where the technology is not strictly necessary
Measure aggregate website use and app-handoff outcomes with cookieless Plausible analyticsLegitimate interest in understanding and improving the public website and app-install bridge
Use Mixpanel product analyticsConsent
Use AppsFlyer installation, campaign, and conversion attributionConsent
Send electronic direct marketingConsent or the statutory existing-customer exception, where all its conditions are met
Comply with lawful authority requests and conduct legal defenceLegal obligation; legitimate interest in bringing, enforcing, or defending claims

Where we rely on legitimate interests, our specific interests are the security of the Platform and Users, prevention of fraud and abuse, payment reconciliation, dispute handling, service stability, defence of legal claims, and demonstration of compliance. Before relying on this basis, we assess the necessity of the processing, its effect on you, and possible safeguards.

You have the right, on grounds relating to your particular situation, to object to processing based on legitimate interests. Further information is provided in Section 14.

Where we rely on consent, you may withdraw it at any time as easily as you gave it. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

6.What is visible to others

6.1. Publicly

A public Listing may display:

  • Listing information, photographs, price, and Security Deposit;
  • approximate location;
  • limited Lessor profile information;
  • a verification badge, ratings, and reviews.

We do not display the exact address, full telephone number, email address, or identity documents publicly.

6.2. To registered Users or the parties to a Reservation

When a Reservation Request is submitted, limited profile, date, delivery, and request information may be shown to the other party.

Once a Reservation is confirmed, the parties may be provided with contact details, a more precise collection or delivery address, handover information, and messages necessary for the transaction.

During handover, return, or a dispute, the parties may be provided with condition evidence, photographs, timestamps, payment or Security Deposit information, and a summary of the decision to the extent required for the process.

6.3. Business and accounting information

Where a Business User or Trader participates in a transaction, the following may be displayed or disclosed:

  • legal or trading name;
  • registration number and country;
  • VAT status or VAT number;
  • billing address;
  • information necessary for invoicing and for informing consumers.

Users are prohibited from using other persons’ data obtained through the Platform for unrelated marketing, harassment, discrimination, creation of external databases, circumvention of the Platform, or any other unlawful purpose.

7.To whom we disclose data

We disclose data only to the extent necessary for the relevant function or obligation.

7.1. Data processors and technical service providers

Depending on the functions enabled, we may use:

  • AWS, including the eu-north-1 region, for infrastructure, databases, file storage, logs, and security;
  • Sentry and AWS CloudWatch for diagnostics, errors, performance, and security incidents;
  • Expo for technical mobile-App functions and push notifications;
  • Plausible Analytics for cookieless public-website audience measurement and app-handoff outcomes;
  • Mixpanel for consent-based product analytics;
  • AppsFlyer for consent-based app attribution and campaign measurement;
  • Postit for geocoding and normalising Lithuanian addresses;
  • Google Places API for address autocomplete where that function is used;
  • OpenAI or other AI service providers only for specific enabled assistive functions.

OpenStreetMap Nominatim is not used for new location requests. Its source attribution may remain in historical location records created previously.

7.2. Payment and identity providers

  • Stripe / Stripe Connect may act both as our processor and as an independent data controller, depending on the specific payment, payout, KYC, sanctions, or legal-compliance activity.
  • Didit may process identity, document, facial-match, liveness, and fraud-prevention data. Its role must be assessed according to the specific service and contract: when providing verification on our instructions, the provider acts as a processor; for any independently determined purposes of its own, if any, it acts as a separate controller.

7.3. Independent recipients

Data may also be received by:

  • banks, card networks, and other payment-infrastructure participants;
  • Apple, Google, or Facebook when you choose social login;
  • the other party to a Reservation, a business customer, or a Trader;
  • accounting, audit, legal, and other professional advisers;
  • the State Tax Inspectorate (VMI), VIES / European Commission systems, courts, law-enforcement bodies, supervisory authorities, and other public authorities where we are required or lawfully permitted to provide data.

We may publish an up-to-date list of principal providers on the Platform or provide it upon request.

8.Payments, payouts, and identity verification

8.1. Stripe

You enter payment-card details in a payment environment controlled by Stripe. “Naudokis” does not receive or store the full card number, CVC, or PIN.

“Naudokis” may receive and retain the following information necessary for the Platform:

  • Stripe customer, payment, refund, transfer, or payout identifiers;
  • amount, currency, and payment status;
  • authorisation, capture, refund, payout, or payment-dispute records;
  • limited information relating to the connected account and KYC status.

Stripe may independently process data for payment-law compliance, sanctions, anti-money-laundering, fraud prevention, and the security of its services.

8.2. Didit

Didit may process:

  • an image of the identity document and the data contained in it;
  • an image of the person, facial-match, or liveness-check data;
  • document-authenticity, validity, and fraud signals;
  • IP address, device, and verification-session data.

“Naudokis” generally stores the verification status, session identifier, expiry date, audit information, and limited verification results rather than maintaining a permanent archive of raw documents.

We retain raw document images in our systems only where, and only for as long as, this is genuinely necessary for a specific verification, dispute, payment, tax, security, or legal purpose.

We do not use identity or liveness data for emotion recognition, inference of sensitive characteristics, marketing, biometric categorisation, or the creation of a general reputation score.

8.3. Technical security marker

For fraud prevention, we may retain a cryptographically protected technical marker derived from a document number or personal identification number. It is used solely to detect the same document or data across multiple accounts.

This marker is not the raw document number or personal identification number. It is not used for marketing or unrelated profiling.

9.Taxes, VAT, invoices, and DAC7

We process business, VAT, VIES, invoicing, and tax data only to the extent necessary to:

  • administer Business User or Trader status;
  • prepare receipts, invoices, and credit documents;
  • comply with accounting and VAT obligations;
  • verify a VAT number in VIES;
  • determine and comply with tax or DAC7 obligations;
  • inform Users about submitted data where required by law.

DAC7 covers the rental of immovable property, personal services, the sale of goods, and the rental of any mode of transport. Ordinary rental of other movable items is not, in itself, a reportable activity under DAC7. Tax-profile or accounting data may nevertheless be required for other legal obligations.

Where an activity is reportable under DAC7, we may collect and provide to the State Tax Inspectorate (VMI) the seller’s identity, address, tax-identification, consideration, commission, tax, and account data.

10.Cookies, SDKs, analytics, and notifications

The Platform uses cookies, local storage, mobile SDKs, push-notification tokens, and similar technologies.

10.1. Essential technologies

Without separate consent, we may use only technologies that are strictly necessary for a service explicitly requested by you or for transmitting a communication, for example:

  • login and session management;
  • account and payment security;
  • saving privacy choices;
  • essential Platform functions.

If a technology is not strictly necessary under electronic-communications rules, we obtain consent before enabling it, even where subsequent processing of personal data under the GDPR would be based on another legal basis.

10.2. Essential diagnostics

We use Sentry and AWS CloudWatch to monitor technical errors, incidents, performance, and security. Configuration must limit direct identifiers, and data scrubbing is applied before error events are transmitted.

Essential diagnostics do not, by themselves, enable Mixpanel or AppsFlyer. If a particular diagnostic technology accesses terminal equipment for a purpose that is not solely strictly necessary, prior consent is required.

10.3. Plausible website analytics

The public website uses Plausible Analytics without analytics cookies or persistent browser-storage identifiers. It is not loaded on token-bearing account-action pages. The browser integration may process the page URL, referring page, interaction or conversion event, and technical request information such as IP address and user agent to produce aggregate audience statistics. Search and other ordinary non-token URL parameters may form part of the page URL reported by the browser integration.

Redirect and native-handoff endpoints may also send a server-side event. For those events we remove the URL query string and fragment before transmission. The event may include the redirect outcome, platform, target type, placement or campaign parameters, and a pseudonymous journey identifier used to connect an app-handoff outcome. We do not send Plausible your name, email address, payment details, Reservation identifier, full handoff token, or the precise address of a rental item.

This processing is based on our legitimate interest in measuring and improving the public website and the web-to-app bridge. The configured integration does not write analytics cookies or a persistent identifier to browser storage and currently runs independently of the Mixpanel or AppsFlyer consent choice. You may object to legitimate-interest processing as described in Section 14. If the configuration changes to use cookies, local storage, advertising identifiers, or another non-essential terminal-equipment technology—or if prior consent is otherwise required for the deployed technology—we will obtain consent before enabling that processing.

10.4. Mixpanel

Mixpanel is enabled only after consent to product analytics has been obtained.

Mixpanel may receive:

  • an internal pseudonymous User identifier;
  • App version, operating system, and language;
  • screen views and selected-action events;
  • limited properties relating to the use of functions.

Mixpanel’s European data-ingestion endpoint is used. When consent is withdrawn, we stop sending new events, disable tracking, and clear the local User association.

10.5. AppsFlyer

The AppsFlyer SDK, attribution identifiers, conversion and redirection data, App events, and the server-side completed-rental revenue event are enabled only after the relevant consent has been obtained.

Depending on the configuration, AppsFlyer may receive:

  • the AppsFlyer installation identifier;
  • platform, device, and connection technical information, including IP address;
  • installation, opening, redirection, and campaign data;
  • selected actions in the App;
  • for a completed rental, a pseudonymous User identifier, event time, revenue, and currency.

We do not send AppsFlyer your name, email address, full payment-card details, Reservation identifier, or the precise address of the rental item.

Transactional emails and their action links are not routed through AppsFlyer. An invitation link first opens a page controlled by “Naudokis”; AppsFlyer must not be loaded from that page before consent.

When consent is withdrawn:

  • the App must stop communication by the AppsFlyer SDK;
  • no new events are sent;
  • the attribution association stored in the account is removed;
  • server-side AppsFlyer events are no longer sent.

Withdrawal does not, by itself, erase data previously received by AppsFlyer. You may contact us regarding their erasure by exercising the rights set out in Section 14.

10.6. Push notifications

Push notifications may be used for Reservations, payments, messages, handover, security, support, or marketing.

You may disable the device permission for notifications at any time. If you opt out of marketing or disable notifications, you may still receive essential information through another channel, such as email or the Platform.

11.Automated checks, profiling, and AI

We may use automated tools to:

  • detect fake or duplicate accounts;
  • verify identity, age, documents, or liveness;
  • identify payment and fraud-risk signals;
  • detect prohibited content, sharing of contact details, or circumvention of the Platform;
  • classify support requests;
  • suggest Listing text or provide other clearly identified AI-assisted functions.

Signals used may include age, the verification result, use of the same document across multiple accounts, device or login signals, payment status, patterns of Platform use, and history of rule violations.

Possible consequences include:

  • identity verification is not completed or is rejected;
  • a Reservation, payment, Listing, or payout function is temporarily restricted;
  • Content is referred for additional review;
  • an account or transaction is referred for human assessment.

You may request human review, provide your explanation, and challenge a decision through Platform support or by email at info@naudokis.lt.

If a decision is made solely by automated means and produces legal or similarly significant effects, we apply a legal basis and safeguards in accordance with Article 22 GDPR.

We do not use automated or AI tools for emotion recognition, biometric categorisation, inference of special-category data, or unlawful discrimination.

12.Transfers of data outside the EEA

MB “Naudokis” is established in Lithuania. The Platform’s principal data and file storage operate in the AWS eu-north-1 region in Stockholm, Sweden, which is within the EEA.

Some providers, their affiliates, or subprocessors may process data outside the EEA. This may relate to payments, identity verification, social login, diagnostics, notifications, analytics, attribution, AI, or address functions.

For each transfer, we apply an appropriate mechanism under Chapter V GDPR, such as:

  • an adequacy decision of the European Commission;
  • the EU–US Data Privacy Framework where the US recipient is validly certified;
  • the European Commission’s Standard Contractual Clauses;
  • a transfer-impact assessment and supplementary technical or organisational measures where required.

You may obtain more information about the mechanism applicable to a particular recipient, or a copy of the Standard Contractual Clauses, by emailing info@naudokis.lt. We may reasonably redact commercially or security-sensitive information.

13.How long we retain data

We retain data no longer than necessary for the specific purpose, legal requirements, disputes, security, or legal defence. We calculate the period from the event specified in the table, unless a legal hold applies.

DataUsual period or criterion
Account and profile dataWhile the account is active. After account closure, only for as long as required for remaining legal, security, dispute, or compliance obligations
Records of acceptance of legal documentsUntil the end of the period during which it may be necessary to prove consent, acceptance of the Terms, or legal compliance
Listings and public ContentWhile active; after removal, on a limited basis where required for moderation, DSA evidence, a dispute, or legal defence
Reservations, payments, Security Deposits, refunds, and payoutsIn accordance with accounting, tax, payment, and dispute requirements; financial and accounting documents may be retained for up to 10 years or longer if required by law
Identity-verification status and audit recordsWhile the account is active; verification remains valid for up to 730 days from verification or until the document expires, whichever is earlier; deleted upon final account deletion if there is no other lawful basis for retention
Raw identity-document images in “Naudokis” systemsGenerally not retained; if received, retained only for the period necessary for a specific verification, dispute, payment, tax, security, or legal purpose
Verification data retained by DiditIn accordance with the retention period set in the “Naudokis” contract and Didit account; it must correspond to what is necessary for the specific verification purpose
Technical document-security markerFor as long as necessary to manage multiple-account or fraud risk; generally deleted with the identity record unless a dispute, investigation, or legal obligation is ongoing
Messages365 days from creation of the message
Chat photographs395 days from upload
Support and User reports, moderation decisions, and appeals3 years from resolution or the last update
Technical notification-delivery logs90 days from creation of the record
Audit data for an account-deletion request180 days from creation of the request
Marketing-consent recordWhile consent remains valid and for as long thereafter as necessary to demonstrate that it was obtained
Marketing opt-out recordFor as long as necessary to ensure that marketing is not sent and to prove the opt-out
Plausible website and handoff analyticsAccording to the period configured in our Plausible service; identifiable or pseudonymous event data are not retained longer than necessary for aggregate audience and handoff measurement
Mixpanel and AppsFlyer dataAccording to consent status and the periods configured in contracts and provider settings
DAC7 dataWhere the activity is reportable, 5 years from the end of the reporting period, unless the applicable rules require otherwise
Other tax and accounting dataIn accordance with the statutory period applicable to the specific document or obligation

If a dispute, authority investigation, security incident, or court proceeding is ongoing, we may retain the related data for longer while they are reasonably required for that process.

13.1. Erasure, anonymisation, and restriction

  • Erasure means that data are removed from active systems and disappear from backups in accordance with their secure-overwrite cycle.
  • Anonymisation means that the data can no longer reasonably be linked to you. Only properly anonymised data cease to be personal data.
  • Restriction of processing means that the data remain, but their use is limited, for example solely to the defence of legal claims.

13.2. What happens when an account is closed

When an account is closed:

  • the public profile and active Listings are removed or hidden;
  • any active payment, Reservation, Security Deposit, payout, or dispute must be completed;
  • financial, accounting, tax, and legal records remain for the specified period;
  • messages or evidence may remain where needed by the other party to the transaction, for a dispute, or for lawful defence;
  • message-author data may be anonymised in order to preserve the integrity of the other party’s conversation;
  • analytics data are anonymised or disassociated from the account where possible.

Closing an account is not the same as the immediate erasure of all data.

14.Your rights

Subject to applicable conditions and exemptions, you have the right to:

  • obtain confirmation as to whether we process your data and access those data;
  • rectify inaccurate data or complete incomplete data;
  • request erasure of data;
  • request restriction of processing;
  • receive the data you have provided in a structured, commonly used, and machine-readable format and, where technically feasible, have those data transmitted directly to another controller;
  • object, on grounds relating to your particular situation, to processing based on legitimate interests;
  • object to direct marketing at any time;
  • withdraw consent;
  • request human review, express your point of view, and contest an automated decision referred to in Article 22 GDPR;
  • lodge a complaint with a data-protection supervisory authority.

You may submit a request in the App where the relevant function is available, or by email at info@naudokis.lt.

Before fulfilling a request, we may ask you to verify your identity to a reasonable extent. We respond without undue delay and no later than within one month. In complex cases or where many requests have been received, the period may be extended by up to a further two months; we will inform you of the extension and its reason within the first month.

A request is generally handled free of charge. If it is manifestly unfounded or disproportionately repetitive, we may charge a reasonable fee or refuse to act on it, as permitted by the GDPR.

The right to erasure or to receive data is not absolute. We may limit a request to the extent that the data are necessary for accounting, tax, DAC7, payments, disputes, fraud prevention, security, the rights of other persons, or legal defence.

A data export may exclude internal fraud, risk, and security rules, legal assessments, tax-reporting files, or other persons’ data where disclosure would compromise security, breach the law, or infringe the rights of others.

We may send:

  • essential notifications concerning an account, Reservation, payment, Security Deposit, payout, message, handover, return, dispute, security, or legal changes;
  • informational notifications concerning the operation of a function you use or an important change to the service;
  • marketing, promotional, recommendation, or newsletter communications where we have consent or all conditions of the statutory existing-customer exception are met.

You may opt out of marketing by:

  • clicking the unsubscribe link in a communication;
  • changing settings in the App where this function is available;
  • emailing info@naudokis.lt.

After opting out of marketing, you will still receive essential service-, transaction-, security-, or law-related notifications.

16.Minors

The Platform’s transaction functions are intended only for persons aged 18 or over.

At the beginning of registration, an unverified record may technically be created, for example after an email address is submitted. It does not entitle a minor to use Listing, Reservation, payment, payout, Security Deposit, or handover functions.

Before enabling transaction functions, we may require identity and age verification. If we determine that a person is under 18, we reject the verification, restrict the functions, and may begin closing the account.

If you believe that a minor has provided us with their data, email info@naudokis.lt.

17.Security, authority requests, and changes to the Policy

We apply technical and organisational measures appropriate to the risk, including:

  • authentication and access controls;
  • encryption of data in transit;
  • separation of public and non-public data;
  • monitoring of logs, incidents, and access;
  • restricted access for staff and providers;
  • isolation of payment data through payment providers;
  • security and provider reviews.

No internet or mobile service is completely secure. Protect your login credentials and notify us immediately of suspected unauthorised access.

If a personal-data breach were to occur, we would notify the State Data Protection Inspectorate (VDAI) and, where required, the affected persons in accordance with the GDPR.

We provide data to public authorities only upon receipt of a legally valid request or where disclosure is required by law. We may retain audit records of the request, the assessment performed, and the response.

We may update this Policy when the Platform, data processing, providers, or law change. We will publish the new version on the Platform and specify its effective date. We will additionally notify you of material changes where required by their nature or by law. If consent is required for new processing, we will request it separately.

18.Contact details and complaints

For privacy questions, requests, or complaints, you may first contact:

MB “Naudokis” Numėjos g. 6, LT-08402 Vilnius, Lithuania info@naudokis.lt

You may also lodge a complaint with the State Data Protection Inspectorate or the competent data-protection authority of another EU Member State.

State Data Protection Inspectorate (VDAI) L. Sapiegos g. 17, LT-10312 Vilnius, Lithuania Email: ada@ada.lt Website: https://vdai.lrv.lt/