Privacy policy
Updated 4 September 2026
This sets out what data Nexara processes, where it comes from, how long it is kept and what you can ask for. Without legal language wherever it can be avoided.
Who processes your data
Dovydas Norvila, trading as Nexara
Email: [email protected]
Phone: +370 678 06966
No data protection officer has been appointed: the scale of the activity does not require one. For any question, write directly to the address above.
When you simply open this website
The site has no cookies, no visitor tracking and no advertising panels. We use neither Google Analytics nor the Facebook pixel nor any other analytics tool.
Two things nevertheless happen on their own, and we have to say so:
- Server logs. The site is hosted on Cloudflare Pages. Cloudflare sees your IP address, browser type and the time of the request. That is needed for the page to be served at all and for attacks to be blocked. Basis: legitimate interest in keeping the service running and secure.
- Fonts. The Inter typeface is served from our own server, so opening the page sends your IP address nowhere. We deliberately do not use the Google Fonts network.
When you write or call us
We process what you provide yourself: name, email address, phone, company and the content of your message. We use it only to reply and continue the conversation. Basis: steps taken at your request before entering into a contract.
Correspondence is kept in the [email protected] mailbox (Google Workspace) for as long as the conversation may still be relevant, and no longer than three years from the last message.
When you fill in the intake form
The form at nexara.lt/anketa is for work already agreed: it collects what is needed to build the workspace. That is the company name, contact person, email address, your price list, frequently asked questions and your preferred tone of communication, plus the country code Cloudflare attaches to the request.
The form is written into Cloudflare KV storage. While you are filling it in, the answers are also kept in your own browser (localStorage) so you can leave and come back; you can delete them from the browser at any time by clearing site data.
Basis: performance of a contract. Form data is kept while we provide the service and deleted within 30 days of the end of the engagement, unless you ask for it to be deleted sooner.
When you receive an email from us that you did not ask for
Nexara writes to businesses directly. This is the most important part, so it is set out openly.
Where we got your address
Only from public sources: the contact page of your own website and the public Lithuanian register of legal entities. We do not buy addresses, do not trade them, and do not collect them from private social media accounts.
What data we hold
Company name, public email address, phone, website address, field of activity and, where it is published publicly, the name of the manager. We collect no special category data.
What we rely on
Legitimate interest in offering a business our service (GDPR Article 6(1)(f); recital 47 of the GDPR refers to this possibility directly). We write to company addresses, not to those of private individuals. Every email states who is writing and how to make it stop.
How to make it stop
Reply to any of our emails with any form of no, or write to [email protected]. The address goes onto the suppression list the same day, and you will receive nothing further from us.
The suppression list is the one case where we keep your address longer than you might wish: without it we could not guarantee we will not write again. It is used for no other purpose.
Contacts that did not reply and showed no interest are removed from our lists within 12 months of the last email.
Who the data goes to
To service providers without whom the work is not possible. Each processes data on our instructions and only for the stated purpose:
| Who | For what | Where |
|---|---|---|
| Cloudflare | Website hosting, form storage, protection | EU and US, standard contractual clauses |
| Google (Workspace, Fonts) | Email, calendar, fonts | EU and US, standard contractual clauses |
| Anthropic | Drafting and classifying text | US, standard contractual clauses |
We do not sell data and do not pass it to advertising networks. We disclose it to public authorities only where the law requires it.
If you are our client
When we build a workspace for you, your mailbox, your spreadsheets and your client data stay yours. The workspace connects to them rather than moving them to us. In respect of your clients' data you are the controller and we are the processor, acting on your instructions. When the engagement ends we remove our access, and everything that was in your systems stays there.
How long we keep it
| Data | How long |
|---|---|
| Email correspondence | Up to 3 years from the last message |
| Intake form data | Up to 30 days after the end of the engagement |
| List of contacts who did not reply | Up to 12 months from the last email |
| Suppression list | Indefinitely, so that we do not write again |
| Accounting records | 10 years, as required by law |
What you can ask for
Under the GDPR you have the right to:
- find out what data of yours we hold, and receive a copy;
- have inaccurate data corrected;
- have data erased;
- object to processing based on legitimate interest, including the sending of emails;
- request restriction of processing;
- receive your data in a common machine-readable format.
Write to [email protected]. We reply within 30 days, usually much sooner. There is no charge.
If our answer does not satisfy you, you can complain to the State Data Protection Inspectorate of Lithuania (L. Sapiegos g. 17, Vilnius, vdai.lrv.lt).
Automated decisions
Artificial intelligence models are used when drafting emails and replies. They write text, but they take no legal decisions affecting you. Where a reply is written by software, that is stated in the message itself.
When this policy changes
When we change it we will put a new date at the top of the page. If a change is material and you are our client, we will tell you by email.