Privacy Policy
Your data, made clear
This policy briefly explains how we handle personal data when you visit bravik.lt or bravik.agency and contact us about services.
Version 1.4 · Effective 7 September 2026
Controller and scope
The controller is Linas Zairys, operating as a self-employed individual under individual activity certificate No. 914547 (Bravik / Bravik Agency). The activity is registered in Lithuania, and the same controller operates bravik.lt and bravik.agency.
This policy applies to website visitors and adult business representatives interested in our services. It does not cover processing once service delivery has begun.
Data we process
When you book a conversation through Cal.com, we process your name, email address, chosen time, time zone and other information you enter in the booking form. We use this information to arrange the meeting, provide the invitation and send booking-related messages.
When you contact us through the form, by email, or by telephone, we may receive your name, email address, telephone number, company name, website address, service interest, message, and correspondence history. Name, email, service, and message are required in the form; company, telephone, and website are optional.
We may also process an IP address and browser, device, and consent-choice information for website operation and security. We do not intentionally request special-category or other sensitive data, and we do not use automated decision-making to accept or reject clients.
Purposes and legal bases
We use enquiry data to respond, understand the request, assess possible work, prepare a proposal, and discuss working together. We do this at your request before entering an arrangement (Article 6(1)(b) GDPR).
We may send no more than three reminders about the same enquiry within 30 calendar days. We protect the website and form from abuse on the basis of our legitimate interests (Article 6(1)(f) GDPR). We do not send newsletters or use enquiries for unrelated advertising.
Cookies, analytics, and reCAPTCHA
We use technical measures and Google Invisible reCAPTCHA v2 for essential website functions and contact-form protection. reCAPTCHA may assess IP address, device, browser, and interaction information to distinguish people from automated requests.
Google Tag Manager is used to manage website tags, and Cookiebot presents and stores consent choices. Before you make a choice, a default state denies analytics and advertising storage. Google Analytics 4 and Hotjar may be activated only with your consent (Article 6(1)(a) GDPR). You can accept, reject non-essential technologies, choose settings, and later withdraw consent. GA4 user and event data is retained for 14 months; retention does not reset on new activity, and we do not use Google Signals, advertising personalisation, or advertising-account links.
We use Hotjar only for heatmaps and de-identified session recordings. Contact-form fields and their contents are not recorded, and we do not use Identify or Surveys. Recordings and heatmap data may be retained for up to 365 days.
We use the OpenAI Pixel to measure ChatGPT advertising results: successful enquiries, meeting bookings made on the website, and clicks on telephone or email links. OpenAI may associate these actions with an ad click using an identifier stored in a first-party cookie and technical browser information. We also send the booking event to Google Analytics 4 according to the tag consent settings. These events do not include your name, email address, message or meeting details. To avoid counting the same booking twice, we store only a hash of its identifier in the browser tab's session storage. These tools are not used in the intranet.
Recipients and international transfers
Cal.com handles meeting bookings. Meeting details are passed to the connected Google Calendar and used to create a Google Meet link. Cal.com also receives technical browser and connection information when the calendar loads.
Only Linas and Rita may access enquiries. Where needed, data is also processed for us by Hostinger (hosting and CDN), Google (Gmail, Tag Manager, Analytics, and reCAPTCHA), Cookiebot (consent management), Hotjar, and Resend (contact-form email delivery; service logs are retained for up to 30 days). OpenAI also receives events used to measure advertising results. We do not sell personal data or share it for unrelated marketing.
Where a provider processes data outside the European Economic Area, the safeguards in its terms apply, such as a European Commission adequacy decision or Standard Contractual Clauses.
Retention
If no working relationship begins, we retain the enquiry and correspondence for 12 months after the last contact. An IP record used to prevent excessive form submissions is held for about 10 minutes. GA4 and Hotjar periods are stated above; technical hosting logs are retained according to Hostinger's configured periods.
We retain data longer only where necessary to meet a legal obligation or to establish, exercise, or defend legal claims.
Your rights, security, and complaints
You may request access, correction, or deletion of your data; restriction of processing; data portability where applicable; or object to processing based on legitimate interests. You may withdraw consent at any time without affecting earlier lawful processing. Contact us by email; we may reasonably verify your identity before acting on a request.
We use HTTPS, limit access, protect Gmail with two-factor authentication, and protect work devices with passwords or biometrics. No system can provide absolute security. We may update this policy; a new version and date will be posted on this page.
If you believe your data is being handled improperly, please contact us first. You may also complain to the Lithuanian State Data Protection Inspectorate.