Privaatsuspoliitika
Last updated: January 16, 2026
1. Who We Are
CYBORA, UAB ("we", "our", "us") is a cybersecurity services company registered in the Republic of Lithuania. We are the data controller for personal data collected through this website and in connection with our services.
- Legal entity: CYBORA, UAB
- Registration number: 307553736
- VAT number: LT100019652119
- Registered address: Mikėno g. 15-1, LT-30245 Rokiškis, Lithuania
- Privacy contact: privacy@cybora.tech
This Privacy Policy explains what personal data we collect, why we collect it, how we use it, and what rights you have under the EU General Data Protection Regulation (GDPR) and applicable Lithuanian law.
2. Data We Collect
We collect the following categories of personal data:
- Contact information: name, work email address, phone number, company name, submitted via our contact form or direct communication.
- Usage data: IP address, browser type and version, pages visited, time spent on pages, and referral source, collected automatically via our own first-party analytics (see our Cookie Policy) — we do not use Google Analytics or any other third-party analytics service.
- Communications: the content of messages you send us through the contact form or by email.
- Technical data: cookies and similar tracking technologies (see our Cookie Policy for details).
We do not collect special categories of personal data (such as health, biometric, or political data) through this website.
3. How We Use Your Data
We use your personal data for the following purposes, each with its legal basis under GDPR Article 6:
- Responding to enquiries and providing services — legal basis: performance of a contract or pre-contractual steps (Art. 6(1)(b)).
- Sending service-related communications — legal basis: performance of a contract (Art. 6(1)(b)).
- Analysing website usage to improve our content and user experience — legal basis: legitimate interests (Art. 6(1)(f)); our interest is in maintaining and improving our website.
- Complying with legal obligations — legal basis: legal obligation (Art. 6(1)(c)).
- Direct marketing communications — legal basis: your explicit consent (Art. 6(1)(a)), which you may withdraw at any time.
We do not sell, rent, or trade your personal data to third parties.
4. Third-Party Processors and Data Transfers
We do not currently use any third-party analytics, advertising, or marketing processor — website usage analytics are handled entirely by our own first-party system, described in our Cookie Policy. Where we do use a processor (for example, e-mail delivery or hosting infrastructure), we ensure a data processing agreement is in place.
Where personal data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, including Standard Contractual Clauses approved by the European Commission.
We do not share your personal data with any other third parties except where required by law or with your prior consent.
5. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes described in this policy, or as required by applicable law:
- Contact form submissions: retained for up to 24 months from the date of submission.
- Service engagement data: retained for the duration of the engagement and up to 5 years thereafter, in line with Lithuanian accounting and contract law requirements.
- Website analytics data: retained for up to 12 months (see our Cookie Policy).
6. Your Rights
Under GDPR, you have the following rights regarding your personal data:
- Right of access: you may request a copy of the personal data we hold about you.
- Right to rectification: you may ask us to correct inaccurate or incomplete data.
- Right to erasure: you may request deletion of your data where there is no legitimate reason for us to continue holding it.
- Right to restriction: you may ask us to restrict processing of your data in certain circumstances.
- Right to data portability: you may request your data in a structured, commonly used, machine-readable format.
- Right to object: you may object to processing based on legitimate interests or for direct marketing purposes.
- Right to withdraw consent: where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, contact us at privacy@cybora.tech. We will respond within 30 days.
You also have the right to lodge a complaint with the Lithuanian supervisory authority:
- State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija – VDAI)
- L. Sapiegos g. 17, LT-10312 Vilnius
- vdai.lrv.lt
7. Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, accidental loss, alteration, or disclosure. As a cybersecurity company, information security is central to how we operate. Access to personal data is restricted to personnel who need it to perform their responsibilities — details of our approach are on our Security page.
8. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. The "Last updated" date at the top reflects the most recent revision. Material changes will be communicated where required by law.