Effective as of: 2025 12 09
UAB "Aurilė" (hereinafter – the Company or we) values and protects your privacy. In this privacy policy (hereinafter – the Policy) we clearly and unambiguously explain how we process your personal data:
- when you use our websites:
- when you purchase goods in our e-shop,
- when you create an account,
- when you contact us by e-mail, phone or via social networks,
- when we use marketing and analytics tools (e.g. Google Analytics, Google Ads, Meta Ads, etc.).
This Policy also aims to inform you about your rights as a data subject and our obligations to ensure the protection of personal data.
The terms “you”, “your” and “visitor” refer to any natural person who uses the Website, purchases goods, contacts us or in any other way provides us with their personal data.
1. DATA CONTROLLER AND CONTACT DETAILS
Data controller:
UAB "Aurilė"
Address: Rotušės a. 5, LT-97110, Kretinga, Lithuania
E-mail for general data protection matters: info@goldinga.eu
E-mail for orders and customer service: info@goldinga.lt
Phone: +370 625 55585
This Policy forms an integral part of our terms and conditions of service, but it does not apply to third-party websites, applications or platforms (e.g. Facebook, Instagram, Google, payment service providers, etc.) that you may access via links on our Website. Before using any third-party services, you should always read their privacy policies.
If you have any questions related to this Policy, please contact us by e-mail at info@goldinga.eu.
By using the Website we assume that you have carefully read this Policy and agree to its content. If you do not agree with it or any part of it, please do not use our Website and/or services.
2. APPLICABLE LEGAL ACTS
When processing personal data we follow:
- Regulation (EU) 2016/679 of 27 April 2016 (General Data Protection Regulation, GDPR);
- the Law on Legal Protection of Personal Data of the Republic of Lithuania;
- other applicable national and European Union legal acts;
- recommendations of supervisory authorities (e.g. the State Data Protection Inspectorate of Lithuania).
3. WHAT PERSONAL DATA WE COLLECT AND PROCESS
The Company processes only those personal data that are necessary to achieve a specific, clearly defined purpose.
3.1. Account and contractual relationship data
When you create an account on the Website or purchase goods, we may process:
- first name, last name;
- e-mail address;
- phone number;
- username and (where applicable) the password hash;
- delivery address (street, city, postal code, country);
- order data (goods purchased, cart contents, order date, amount, discounts, delivery method, chosen shop version/country);
- customer service history (enquiries, complaints, returns, warranties, etc.).
3.2. Payment information
When processing payments we use third-party payment service providers, therefore we do not collect or store your bank card details ourselves.
Your data during payment may be processed, for example, by:
- Montonio,
- Inbank (formerly “Mokilizingas”),
- Stripe.
You can find their privacy policies and more detailed information on how they process data on their websites:
- Montonio – https://www.montonio.com/lt/legali-informacija/privacy-policy-v2/
- https://www.mokilizingas.lt/privatumo-politika
- https://stripe.com/en-lt/privacy
We receive and process only such payment-related information as is necessary to:
- confirm that the payment has been completed (payment method, status, date, amount);
- issue invoices and perform accounting;
- handle disputes, refunds, etc.
3.3. Communication data
When you communicate with us by e-mail, phone, via the contact form on the Website or social networks, we may process:
- your first name, last name (if provided);
- e-mail address, phone number;
- contents of messages/e-mails and attachments;
- other information that you voluntarily provide.
These data are processed in order to respond to your enquiry, solve issues, manage customer service and protect our legitimate interests (e.g. in case of a dispute).
3.4. Website usage and technical data
When using the Website, the following data may be collected automatically:
- IP address;
- device type, operating system, browser type and version;
- date and time of access, pages viewed, actions performed (e.g. adding items to cart, completing purchase);
- geo-location data (approximate location based on IP address, for statistics and personalisation only);
- language settings, chosen country version;
- data collected using cookies and similar technologies (for more details see the Cookie Policy).
These data help us to:
- ensure the security and stable functioning of the Website;
- adapt Website content to your device and language;
- analyse traffic and user behaviour (e.g. via Google Analytics);
- run remarketing and advertising campaigns (Google Ads, Meta Ads, etc.).
3.5. Marketing and analytics tools
We may use, including but not limited to:
- Google Analytics – a web analytics service that helps us understand how the Website is used;
- Google Ads (including remarketing) – to show ads to users who have visited our Website or similar audiences;
- Meta Ads (Facebook, Instagram advertising) – to display personalised ads on social networks and run look-alike audience campaigns;
- other SEO and performance monitoring tools (e.g. Google Search Console, etc.).
For these purposes cookies and similar technologies are typically used. In most cases the legal basis for processing personal data is your consent, which you give (or refuse) via our cookie banner.
3.6. Publicly available and survey data
We may process:
- data that you provide when participating in surveys, contests, games or when leaving reviews/ratings;
- publicly available data (e.g. public reviews on social networks), where this is necessary to improve service quality or for a legitimate interest.
4. LEGAL BASES FOR PROCESSING PERSONAL DATA
The Company may process your personal data on the following legal bases:
- Performance and conclusion of a contract
When you purchase goods, create an account, place an order or use our services. - Legitimate interest
For example:- to ensure the security of the Website and systems;
- to manage the customer database and prevent fraud;
- to establish, exercise or defend legal claims (e.g. collect and store evidence in case of a dispute);
- to carry out justified statistical and analytical activities (where data are used in an aggregated form).
- Legal obligation
For example:- to comply with accounting rules;
- to respond to lawful requests from authorities;
- to comply with other mandatory legal requirements.
- Your consent
For example:- to send newsletters and personalised offers;
- to use marketing and analytics cookies (Google/Meta/others);
- to publish your review together with your name (where agreed).
You can withdraw your consent at any time (see below for more information on your rights).
5. DATA COLLECTED ON THE WEBSITE AND COOKIES
5.1. Cookies and similar technologies
Cookies are small text files that are stored on your device (computer, phone, etc.) when you visit our Website. Cookies help us to:
- ensure the technical functioning of the Website (essential cookies);
- remember your preferences (language, country, cart contents, etc.);
- analyse Website usage (statistical cookies);
- display tailored ads and run remarketing campaigns (Google Ads, Meta Ads, etc. – advertising cookies).
More detailed information on the cookies we use, their types, retention periods and your choices is provided in a separate Cookie Policy on the Website.
If you do not agree to the use of cookies, you can:
- reject non-essential cookies in our cookie settings banner;
- change your browser settings to delete or block cookies (for more information you can visit http://www.allaboutcookies.org/).
Please note that disabling some cookies may cause certain Website functions to work incorrectly or not at all.
5.2. Third-party tools
In addition to cookies, the Website may use third-party tools (such as plug-ins, pixels, etc.) provided by Google, Meta and other service providers. These tools may collect anonymous or pseudonymous data about your behaviour.
Third-party service providers process data in accordance with their own privacy policies. We recommend reviewing those policies separately.
6. PURPOSES OF PROCESSING PERSONAL DATA
The Company processes personal data for the following purposes:
- Performance of contracts and provision of services:
- receiving and fulfilling orders;
- delivery of goods;
- issuing invoices;
- creating and managing accounts.
- Customer service and communication:
- responding to your enquiries, comments, complaints;
- managing returns, warranties, gift vouchers, etc.
- Operation and security of the Website:
- ensuring the technical functioning of the Website;
- detecting and preventing fraud, hacking and other misuse.
- Direct marketing and remarketing (with your consent or on the basis of legitimate interest, where permitted by law):
- sending newsletters and special offers;
- displaying personalised ads on Google/Meta/other platforms;
- running remarketing campaigns (showing ads to users who have visited the Website).
- Analytics and statistics:
- analysing Website traffic and behaviour (e.g. via Google Analytics);
- evaluating the effectiveness of SEO and advertising campaigns.
- Compliance with legal obligations and protection of legitimate interests:
- accounting;
- handling disputes and complaints;
- responding to official requests from authorities.
7. DIRECT MARKETING
We may use your e-mail address and/or phone number for direct marketing purposes, for example:
- to send newsletters;
- to send information about promotions, discounts and news;
- to send personalised offers based on your previous purchases or behaviour on the Website.
Direct marketing communication is usually based on your consent. In some cases (for example, if you are an existing customer) we may rely on legitimate interest, where permitted by law.
How to opt out of marketing?
You can opt out of direct marketing at any time by:
- clicking the unsubscribe link at the bottom of a newsletter;
- changing the settings in your account (if such functionality is available);
- sending us an e-mail to info@goldinga.lt or info@goldinga.eu, clearly stating that you no longer wish to receive marketing messages.
8. DISCLOSURE OF PERSONAL DATA AND COOPERATION WITH THIRD PARTIES
We may disclose your personal data to:
8.1. Data processors (service providers) acting on our behalf
For example:
- IT, server, hosting, e-mail and system maintenance service providers;
- payment service providers (Montonio, Inbank, Stripe, etc.);
- accounting and audit service providers;
- shipment and courier service providers (for delivery of goods);
- marketing and advertising partners (e.g. Google, Meta, newsletter platforms);
- other companies or individuals helping us to carry out our activities.
We conclude appropriate contracts with all data processors and ensure that they process your personal data only according to our instructions and in compliance with applicable legal requirements.
8.2. Third parties acting as independent data controllers
Your personal data may be disclosed to third parties when:
- required by law, court or authority decisions;
- necessary to protect our or third parties’ rights, property or safety;
- a business sale, reorganisation, merger or a similar transaction is carried out (data may be transferred to a potential buyer or its advisors).
We do not seek to sell your personal data to third parties for their own marketing purposes.
9. TRANSFER OF DATA TO THIRD COUNTRIES (OUTSIDE THE EU/EEA)
Some of our service providers (e.g. Google, Meta, etc.) may be established or may process data outside the European Union (EU) or the European Economic Area (EEA).
In such cases we ensure that:
- data transfer is carried out only on a valid legal basis, such as:
- an adequacy decision by the European Commission, or
- standard contractual clauses (SCCs), or
- other mechanisms allowed by the GDPR;
- appropriate technical and organisational measures are applied to protect your data.
For more information about specific international data transfers, you can contact us by e-mail at info@goldinga.eu.
10. SPECIAL CATEGORIES OF DATA
We do not knowingly collect special categories of personal data, such as:
- data about racial or ethnic origin;
- political opinions;
- religious or philosophical beliefs;
- trade union membership;
- genetic and biometric data;
- health data;
- data concerning sex life or sexual orientation.
Please do not provide us with such information. If you believe that we might be processing special category data, please contact us and we will take steps to delete such data as soon as permitted by law.
11. DATA SECURITY
The Company implements appropriate technical and organisational measures to protect personal data from:
- accidental or unlawful destruction, loss or alteration;
- unauthorised disclosure;
- unauthorised access.
Such measures include, among others:
- restricting access to data on a “need-to-know” basis;
- using secure servers, firewalls, antivirus and other security measures;
- regularly updating systems and reviewing access rights;
- carefully selecting data processors and ensuring they provide an adequate level of security.
12. RETENTION PERIODS FOR PERSONAL DATA
The Company keeps your personal data no longer than:
- is necessary for the purposes for which the data were collected; and
- required by applicable legal acts.
Indicative retention periods:
- Contract and purchase data – generally at least 10 years from the end of the transaction (in accordance with accounting and other legal requirements).
- Account data – as long as your account is active. If you delete your account or it remains inactive for a long time, the data may be anonymised or deleted, except for those we must retain by law.
- Marketing data – generally up to 2 years from your last interaction (e.g. opening an e-mail, clicking a link), unless you withdraw your consent earlier.
- Communication (enquiry) data – generally up to 2 years from the last contact, unless in a specific case a longer period is necessary (e.g. due to a dispute).
- Cookie data – according to the specific cookie’s lifetime (indicated in the Cookie Policy).
When the retention period expires, personal data are securely deleted or anonymised so that you can no longer be identified.
13. YOUR RIGHTS
As a data subject, you have the following rights:
- Right of access
To obtain confirmation whether we process your personal data and, if so, to access those data and receive a copy. - Right to rectification
To request that we correct inaccurate or incomplete personal data relating to you. - Right to erasure (“right to be forgotten”)
To request the erasure of your personal data where the conditions set out in the GDPR are met (e.g. data are no longer necessary for the purposes for which they were collected, you withdraw consent and there is no other legal basis for processing, etc.). - Right to restriction of processing
To request restriction of processing where you contest the accuracy of data, object to processing or when data are processed unlawfully but you do not want them to be erased, etc. - Right to data portability
To receive personal data that you have provided to us in a structured, commonly used and machine-readable format and, where technically feasible, request that we transmit those data to another data controller. - Right to object
To object at any time to the processing of your personal data when the legal basis is legitimate interest, including profiling. You also have the right at any time to object to the processing of your personal data for direct marketing purposes, including profiling related to such direct marketing. - Right to withdraw consent
Where processing is based on your consent, you may withdraw it at any time without affecting the lawfulness of processing based on consent before its withdrawal. - Right to lodge a complaint with a supervisory authority
If you believe that your rights have been infringed, you have the right to lodge a complaint with the competent supervisory authority (in Lithuania – the State Data Protection Inspectorate).
We always encourage you to first contact us by e-mail at info@goldinga.eu so that we can try to resolve the issue together.
Identity verification.
When exercising your rights, you may be asked to verify your identity in order to prevent disclosure of data to unauthorised persons. This may include:
- a request submitted from your account;
- a request submitted from the e-mail address that we have in our system and that is associated with you;
- additional questions to identify you;
- (where applicable) a request to provide an identification document or a certified copy.
We will normally respond to your request no later than within 30 calendar days from the date of receipt. In the case of complex or numerous requests, this period may be extended by up to two further months, and you will be informed separately of such an extension.
14. THIRD-PARTY LINKS
The Website may contain links to third-party websites, services or applications (e.g. social networks, payment service providers, courier systems, etc.).
We do not control these third parties and we are not responsible for the data they collect or for their privacy practices. We recommend that you read the privacy policy of each such website or service before using it.
15. CHANGES TO THIS PRIVACY POLICY
This Policy may be updated if:
- our activities, services or Website functionality change;
- applicable legal acts or supervisory authority recommendations change;
- we introduce new tools or technologies (e.g. new payment or marketing solutions).
The updated version of the Policy will always be published on the Website (https://www.goldinga.lt and the corresponding versions for other countries). In the event of material changes, we may additionally inform you, for example, by e-mail or notices on the Website.
16. CONTACT INFORMATION
If you have any questions, comments or wish to exercise your rights, please contact us:
By e-mail:
general data protection matters – info@goldinga.eu
orders and customer service – info@goldinga.lt
By post:
UAB "Aurilė"
Rotušės a. 5, LT-97110, Kretinga, Lithuania
By phone:
+370 625 55585
```