1. General provisions
This Privacy Policy explains how personal data is processed on the website veronikab.seokursai.eu. We process data in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR), the Law on Legal Protection of Personal Data of the Republic of Lithuania and the Law on Electronic Communications.
2. Data controller
- Company name: XXX
- Company code: XXX
- VAT code: XXX
- Address: xxx
- Email: xxx@xxx.xx
- Phone: +370 xxx xxxxx
3. What data we collect
| Situation | Data | Purpose and legal basis | Retention period |
|---|---|---|---|
| Placing an order | First and last name, company name (if provided), delivery and billing address, email, phone number, order contents and amount, order notes | Performance of a contract, delivery, payment (GDPR Art. 6(1)(b)); storage of invoices and accounting documents (legal obligation, Art. 6(1)(c)) | Accounting documents: as required by law (up to 10 years); other order data: XX years |
| Payment | Card details are processed by our payment provider (WooPayments / Stripe). We do not receive or store your full card number. We only receive the payment status, transaction ID and the last digits of the card | Completing the payment, fraud prevention (Art. 6(1)(b) and (f)) | As above |
| User account | Username, email, password (stored encrypted), addresses, order history | Account administration (Art. 6(1)(b)) | For as long as the account exists |
| Abandoned checkout | Email, name and phone number entered at checkout, cart contents | Sending reminders about an unfinished order. Collected only with your consent (Art. 6(1)(a)) [check the plugin settings] | XX days |
| Contact and other forms | Name, email, phone (if requested), message content | Responding to your enquiry (Art. 6(1)(a) and (f)) | XX months after the last communication |
| Website analytics | Approximate location, device and browser type, pages visited, visit duration, referral source. We use Burst Statistics, a privacy-friendly tool [check whether IP addresses are anonymised] | Improving the website (Art. 6(1)(f), or consent where cookies are used) | XX months |
| Website security | IP address, login attempts, blocked requests (Wordfence) | Protecting the website against attacks (Art. 6(1)(f)) | XX days |
| Cookie consent | Your choice, timestamp, pseudonymised identifier (SureCookie consent log) | Proof of consent (Art. 6(1)(c) and (f)) | XX months |
| Newsletters / emails | Email, name | Consent (Art. 6(1)(a)); you can withdraw it at any time | Until you withdraw consent |
4. Cookies
Cookies are small text files stored on your device. We use strictly necessary cookies without consent. Analytics, marketing and other non-essential cookies are used only with your consent given through the cookie banner. You can change or withdraw your consent at any time via the “Cookie settings” link at the bottom of the website.
4.1. Strictly necessary cookies
| Cookie | Purpose | Duration |
|---|---|---|
| woocommerce_cart_hash, woocommerce_items_in_cart | Recognising the contents of your cart | Session |
| wp_woocommerce_session_* | Keeping cart and order data while you shop | ~2 days |
| woocommerce_recently_viewed | Showing recently viewed products | Session |
| wordpress_logged_in_*, wordpress_sec_*, wordpress_test_cookie | User login and authentication | Session or up to 14 days |
| wp-settings-*, wp-settings-time-* | Interface settings for logged-in users | 1 year |
| comment_author_* | Remembering commenter details (only if you tick the box) | 1 year |
| Consent cookie (SureCookie) | Remembering your cookie choices | XX months |
| Cookies set by Wordfence and LiteSpeed Cache | Security and caching (e.g. distinguishing logged-in users from visitors) | Session or short term |
4.2. Analytics cookies
| Cookie | Provider | Purpose | Duration |
|---|---|---|---|
| burst_uid | Burst Statistics | Recognising returning visitors for statistics [used only if cookies are enabled] | XX days |
4.3. Payment cookies
| Cookie | Provider | Purpose | Duration |
|---|---|---|---|
| __stripe_mid, __stripe_sid | Stripe (via WooPayments) | Fraud prevention and payment processing | 1 year / 30 min. |
4.4. Abandoned checkout cookies
A cookie may be set on the checkout page to recognise your cart so that we can send you a reminder about an unfinished order. Cookie name: [check the name used by the Cart Abandonment Recovery plugin]. Duration: XX days.
Note: we recommend verifying the exact cookie list and durations in the SureCookie scanner report and updating this table if anything differs.
4.5. How to manage cookies
You can delete or block cookies in your browser settings. If you block strictly necessary cookies, the shopping cart and checkout may stop working.
5. Data recipients
We share your data only with those who need it to provide the service:
- payment service providers (Stripe / WooPayments);
- delivery and courier service providers: XXX;
- website hosting and technical maintenance providers: XXX;
- accounting service providers: XXX;
- email delivery service providers: XXX;
- public authorities, where required by law.
Where data is transferred outside the European Economic Area (e.g. to providers based in the USA), we rely on the European Commission’s standard contractual clauses or other safeguards provided for by the GDPR.
6. Your rights
You have the right to: access your data; have inaccurate data rectified; have your data erased (“right to be forgotten”); restrict processing; object to processing based on legitimate interests; data portability; and withdraw consent at any time (this does not affect processing carried out before withdrawal).
To exercise your rights, write to xxx@xxx.xx. We will reply within 30 days.
If you believe your rights have been violated, you have the right to lodge a complaint with the State Data Protection Inspectorate of Lithuania (L. Sapiegos g. 17, Vilnius, vdai.lrv.lt).
7. Data security
We apply organisational and technical measures to protect data: encrypted connection (HTTPS), firewall and malware scanning, restricted access to data and regular backups.
8. Changes to this policy
We may update this policy. The current version is always published on this page.
Last updated: 1 October 2026