Privacy Policy · v1.0

Privacy Policy

LT · EN · Effective from 2026-05-01

TL;DR

We collect only the data necessary to deliver the service. We never sell your data. We never share it with advertising networks. We never use your data to train AI agents without your explicit consent. You have full rights to view, export, and delete everything we hold about you.

1. Who we are

Data Controller:

UAB Rūpestėlis Holding
Company code: 307514683
Registered office: J. Savickio g. 4, LT-01108 Vilnius, Lithuania
Email: tomas@rupestelis.com
Website: rupestelis.com

Supervisory Authority: State Data Protection Inspectorate of Lithuania (VDAI), L. Sapiegos g. 17, 10312 Vilnius, vdai.lrv.lt.

2. Our principles

  1. Minimalism. We collect only what's needed for the service.
  2. Transparency. You can always see what we hold (in-app and via data export request).
  3. Non-transferable ownership. Your data stays yours. We are custodians, not owners.
  4. No advertising tracking. We don't use Google Analytics, Facebook Pixel, or similar systems.
  5. No AI training. Your data does not enter model training without your explicit, separate consent.

3. What we collect

3.1. Sigillum Unicum (key order)

DataPurposeLegal basis
Name, surnameOrder personalization, shippingContract (GDPR 6.1.b)
EmailOrder confirmation, status, production updatesContract (GDPR 6.1.b)
Shipping address (28 EU/EEA countries)Physical DHL shippingContract (GDPR 6.1.b)
Payment informationProcessed via Stripe — we don't see card detailsContract (GDPR 6.1.b)
Sigillum hash (SHA-256)Key authenticity verification via QR codeContract (GDPR 6.1.b)

3.2. Founding 50 application (Akademija)

DataPurposeLegal basis
Name, organization, roleCohort fit assessmentConsent (GDPR 6.1.a)
EmailResponse on eligibility, cohort updatesConsent (GDPR 6.1.a)
Motivation paragraphHuman evaluation of applicant's perspectiveConsent (GDPR 6.1.a)

3.3. Waitlist

DataPurposeLegal basis
EmailNotification when product becomes availableConsent (GDPR 6.1.a)
Product categoryKnowing which product you signed up forConsent (GDPR 6.1.a)

3.4. Heart Members club (Rūpestėlis ID)

DataPurposeLegal basis
Email, nameClub membership administrationContract (GDPR 6.1.b)
Heart ID (cryptographic)Identity verification across Rūpestėlis servicesContract (GDPR 6.1.b)

3.5. Technical data

When you use our websites, our servers automatically log limited technical info: request time, IP address (kept for hours — security purposes), browser type, response code. Used solely for security monitoring and deleted after 30 days.

4. What we DO NOT do

5. Who we share data with (necessary processors)

PartyPurposeWhat data
Stripe (Ireland)Payment processingOrder info, payer email, card data (to Stripe, not us)
DHL ExpressSigillum shippingName, address, phone (if provided)
Jewelry partners LT/PLSigillum productionOrder SKU + Sigillum hash only — NO personal data
Hosting (DigitalOcean, EU region)Server infrastructureAll data stored on our server
Email delivery serviceNotificationsEmail + message content

All our subprocessors have signed GDPR-compliant Data Processing Agreements (DPA).

6. Retention periods

CategoryRetention
Order info (Sigillum, payments)10 years (Lithuanian tax law)
Founding 50 applications2 years after cohort end or upon deletion request
Waitlist emailsUntil product launch or your unsubscribe
Heart Members infoActive membership + 6 months after departure
Technical logs (IP, etc.)30 days

7. Your rights (GDPR Articles 15-22)

You have the right to:

To exercise — write to tomas@rupestelis.com. Response within 30 days (typically within 7).

8. International data transfers

Primary data is stored in the European Union (DigitalOcean Frankfurt region). Stripe (Ireland) and DHL (Germany) — also EU-based. We do not use US-only services where an EU alternative exists.

9. Security

10. Children

Our services are intended for individuals aged 18+. We don't knowingly collect children's data. If you learn that a minor (under 18) has submitted data — let us know, and we'll delete it immediately.

11. We don't use data for AI training

Per our ethical code (NOVA Charter), your data does not enter AI model training without your explicit, separate consent. Even when chatting with our agents (CaaS, Akademija, etc.), your conversations are used only to answer you, not to train the model for other users.

12. Cookies

We use only essential technical cookies for session maintenance (when logged in). We do not use advertising, analytics, or tracking cookies. Therefore no cookie banner is required under the ePrivacy Directive.

13. Changes

We may update this policy. Material changes will be announced on the website + by email (if you're a Heart Member or order holder). Earlier versions available on request.

14. Questions

All privacy-related questions — directly to me:

Tomas Margelis (CEO, de facto Data Protection Officer)
Email: tomas@rupestelis.com

I'll respond within 7 business days. Personally.

A note on honesty. This document is v1.0 — the first public version. It will be updated as services evolve. Our principle: if we're not sure something is OK to do with your data — we ask you first.