Privacy policy

Updated 4 September 2026

This sets out what data Nexara processes, where it comes from, how long it is kept and what you can ask for. Without legal language wherever it can be avoided.

Who processes your data

Dovydas Norvila, trading as Nexara

Email: [email protected]
Phone: +370 678 06966

No data protection officer has been appointed: the scale of the activity does not require one. For any question, write directly to the address above.

When you simply open this website

The site has no cookies, no visitor tracking and no advertising panels. We use neither Google Analytics nor the Facebook pixel nor any other analytics tool.

Two things nevertheless happen on their own, and we have to say so:

When you write or call us

We process what you provide yourself: name, email address, phone, company and the content of your message. We use it only to reply and continue the conversation. Basis: steps taken at your request before entering into a contract.

Correspondence is kept in the [email protected] mailbox (Google Workspace) for as long as the conversation may still be relevant, and no longer than three years from the last message.

When you fill in the intake form

The form at nexara.lt/anketa is for work already agreed: it collects what is needed to build the workspace. That is the company name, contact person, email address, your price list, frequently asked questions and your preferred tone of communication, plus the country code Cloudflare attaches to the request.

The form is written into Cloudflare KV storage. While you are filling it in, the answers are also kept in your own browser (localStorage) so you can leave and come back; you can delete them from the browser at any time by clearing site data.

Basis: performance of a contract. Form data is kept while we provide the service and deleted within 30 days of the end of the engagement, unless you ask for it to be deleted sooner.

When you receive an email from us that you did not ask for

Nexara writes to businesses directly. This is the most important part, so it is set out openly.

Where we got your address

Only from public sources: the contact page of your own website and the public Lithuanian register of legal entities. We do not buy addresses, do not trade them, and do not collect them from private social media accounts.

What data we hold

Company name, public email address, phone, website address, field of activity and, where it is published publicly, the name of the manager. We collect no special category data.

What we rely on

Legitimate interest in offering a business our service (GDPR Article 6(1)(f); recital 47 of the GDPR refers to this possibility directly). We write to company addresses, not to those of private individuals. Every email states who is writing and how to make it stop.

How to make it stop

Reply to any of our emails with any form of no, or write to [email protected]. The address goes onto the suppression list the same day, and you will receive nothing further from us.

The suppression list is the one case where we keep your address longer than you might wish: without it we could not guarantee we will not write again. It is used for no other purpose.

Contacts that did not reply and showed no interest are removed from our lists within 12 months of the last email.

Who the data goes to

To service providers without whom the work is not possible. Each processes data on our instructions and only for the stated purpose:

WhoFor whatWhere
CloudflareWebsite hosting, form storage, protectionEU and US, standard contractual clauses
Google (Workspace, Fonts)Email, calendar, fontsEU and US, standard contractual clauses
AnthropicDrafting and classifying textUS, standard contractual clauses

We do not sell data and do not pass it to advertising networks. We disclose it to public authorities only where the law requires it.

If you are our client

When we build a workspace for you, your mailbox, your spreadsheets and your client data stay yours. The workspace connects to them rather than moving them to us. In respect of your clients' data you are the controller and we are the processor, acting on your instructions. When the engagement ends we remove our access, and everything that was in your systems stays there.

How long we keep it

DataHow long
Email correspondenceUp to 3 years from the last message
Intake form dataUp to 30 days after the end of the engagement
List of contacts who did not replyUp to 12 months from the last email
Suppression listIndefinitely, so that we do not write again
Accounting records10 years, as required by law

What you can ask for

Under the GDPR you have the right to:

Write to [email protected]. We reply within 30 days, usually much sooner. There is no charge.

If our answer does not satisfy you, you can complain to the State Data Protection Inspectorate of Lithuania (L. Sapiegos g. 17, Vilnius, vdai.lrv.lt).

Automated decisions

Artificial intelligence models are used when drafting emails and replies. They write text, but they take no legal decisions affecting you. Where a reply is written by software, that is stated in the message itself.

When this policy changes

When we change it we will put a new date at the top of the page. If a change is material and you are our client, we will tell you by email.