Privacy policy updated 2023-01-01
Amendments or changes to the Policy shall enter into force upon publication on the website https://exoclass.io/privacy.

1. WHO IS COVERED BY THIS PRIVACY POLICY?
This Privacy Policy sets out the terms and conditions governing the collection and use of personal data by UAB “Exoclass” (hereinafter referred to as “we” or “Exoclass“), which applies to visitors to the website https://exoclass.com and our customers and/or other persons who use the Exoclass platform and our services (hereinafter referred to as “Services”). Please read this document carefully, as it is used to inform you about the processing of your personal data.

As this Policy is subject to change without notice, please check it each time you visit our website. You will find the most up-to-date version of the Privacy Policy there.

Our details:

UAB “Exoclass”
Legal entity code: 306125501
Address: Drobės str. 62, Kaunas, the Republic of Lithuania
Email address: [email protected]

2. WHY AND WHAT DATA DO WE COLLECT ABOUT YOU?

For what purpose do we collect personal data?
Exactly what data do we collect?Which GDPR clause do we rely on to process your personal data?
How long do we keep this data?
For the purpose of providing the Services, i.e. to enable you to use the Exoclass Platform and the services we provideThe following data are collected: User account details (name, surname, email address, phone number); payment details (payment card details, company address, legal entity code, VAT code). Required for payment of the Services ordered through our external payment transaction system. Information about the payment processor can be found in section 3 of the Privacy Policy; data uploaded or transmitted to the system by users of the Exoclass system (e.g. information about the services offered);Performance and conclusion of the contract (Article 6(1)(b) GDPR)The data is retained for as long as we provide the Services to you. Personal Data may be retained for a longer period of time if it is necessary for us to defend ourselves against claims, demands, lawsuits, or if longer retention is necessary for the performance of legal obligations and/or commitments, but not longer than 10 years from the end of the provision of the Services.
Financial records shall be kept for 10 years from the date of the purchase transaction, unless there is a need to keep the data for longer, for example to defend a legal claim.
To inform you about our news, and offers and to ask for your opinion via a newsletter (direct marketing)We collect your email address
Attention! We use double authentication to protect your data. This means that if you enter your email address, you will receive an email requesting authentication. Only by clicking on the link in the email will you be added to the subscriber list.
With your consent (Article 6(1)(a) GDPR)The data is retained for as long as we provide the Services to you and for 3 years after the end of the provision of the Services. Please note that you can opt-out of direct marketing communications by clicking on the unsubscribe link that you will find in each newsletter or similar direct marketing communication we send you
If you communicate with us and/or are interested in our ServicesWe collect your name, contact information, together with the messages and attachments you send to us, and your communication history with us (including the content of the messages and the timing of their receipt/delivery)
With your consent (Article 6(1)(a) GDPR)
Personal data is stored for 10 years from the end of the processing of the request for which you have applied. Personal data may be retained for a longer period if this is necessary to defend ourselves against claims, claims, actions or if longer retention is necessary to comply with legal obligations and/or commitments
To manage your social networks 
The following social media user data is collected and processed: name, contact information (if you provide it to us), comments left on our posts, shares of our posts, likes, follows and other reactions (including information about when you started following or liking Exoclass’ social media account), photo, messages you send us, history of your communication with us (content of the messages, time of receipt/delivery of the messages), feedback you leave, and Exoclass ratings.With your consent (Article 6(1)(a) GDPR)
10 years
To improve our website, ensure its performance, increase its security and tailor its content and format to the needs of usersWhen you visit the Exoclass website, we automatically collect the following data from you:
IP address, operating system, user ID and other information about your activities on our website and other websites. We collect and store this information as part of our log records or through the use of cookies. For more information about the use of cookies, please see section 7 “Cookies” of this Privacy Policy.
The processing of personal data obtained by means of cookies is based on our legitimate interest (Article 6(1)(f) GDPR)For more information on retention periods, please refer to section 7 “Cookies” of this Policy.

3. TO WHOM DO WE DISCLOSE YOUR PERSONAL DATA WITHIN AND OUTSIDE EEE?

Where necessary, Exoclass may transmit and/or otherwise disclose the personal data processed to public regulatory and law enforcement authorities, courts
and other state-authorized bodies.

Also, to the extent necessary to ensure the proper provision of the Services, Exoclass may transfer personal data to third parties – partners, service providers
(including providers of software, IT infrastructure maintenance, cloud services, server rental and maintenance, electronic communications, parcel delivery,
website administration, accounting, archiving, marketing services, etc.). We will only provide these service providers with as much data as necessary to
perform a particular service.

Within the EEA:

● OVHcloud, OVH SAS (server rental services). The servers’ geographical location is the European Union’s territory.

● Amazon Web Services (server rental services). The geographical location of the servers used is the territory of the European Union (dynamic servers can be used, the location of which is chosen individually according to the user).

● Cloudflare (server rental services). The geographical location of the servers used is the territory of the European Union (dynamic servers can be used, the location of which is chosen individually according to the user).

● To the payment processor UAB Paysera LT. Read their data protection policy here. Acts as an independent data controller.

● MB Šviesūs projektai (IT infrastructure maintenance services). The servers’ geographic location is the European Union’s territory.

Where you interact with us via social networks, you should check the data protection terms and conditions of the social network in question and its privacy policy. Any personal data you transmit to us via social networks is controlled by the specific social network operator (e.g. Facebook, Instagram, LinkedIn, Twitter).

Outside the EEA:

● Gmass (newsletter (marketing) service provider) (USA) Gmass’ privacy policy is available here.

● Meta Platforms, Inc. (Facebook) (USA). You can read Facebook’s privacy policy here. Facebook no longer relies on the Privacy Shield mechanism for data transfers to the US but continues participating in this programme. For transferring personal data outside the EEA, Facebook uses the Standard Contractual Clauses (SCC) approved by the European Commission.

● Meta Platforms, Inc. (Instagram) (USA). Instagram’s privacy policy can be found here. Instagram no longer relies on the Privacy Shield data transfer mechanism to the US, but continues to participate in this programme. Facebook uses the Standard Contractual Clauses (SCC) approved by the European Union Commission to transfer personal data outside the EEA.

● LinkedIn Corporation (LinkedIn). LinkedIn’s privacy policy can be found here. LinkedIn no longer uses the Privacy Shield mechanism for data transfers to the US but continues participating in this programme. For transfers of personal data outside the EEA, Facebook uses the Standard Contractual Clauses (SCC) approved by the European Commission.

● Google LLC (USA). Google’s privacy policy can be found here. We use Google cookies. Google no longer uses the Privacy Shield mechanism to transfer data to the US, but continues participating in this programme. For transfers of personal data outside the EEA, Google uses the Standard Contractual Clauses (SCC) approved by the European Commission.

4. HOW DO WE PROTECT YOUR PERSONAL DATA?

When processing and storing your personal data, we implement organisational and technical measures to protect personal data against accidental or unlawful destruction (e.g. regular data backup), alteration, and disclosure, as well as against any other unlawful processing. In addition, secure use of our website is ensured by one of the world’s most prominent Secure Socket Layer (SSL) certificates. The information sent between the user’s browser and our server is encrypted with an SSL certificate. Details of the certificate can be found at www.ssls.com.

While we take all reasonable steps to protect your information, no website, online transaction, computer system, or even wireless connection is completely secure. And while we are committed to making every effort to protect your personal data, we cannot guarantee the absolute security of your personal data transmitted on our platform. By transmitting any information, you assume the risks associated with its transmission. Once we receive your personal data, we will apply strict procedures and security measures concerning such data.

5. YOUR RIGHTS

Each data subject whose data is processed in our activities has the following rights:

● Know (be informed) about the processing of his personal data (GDPR Articles 12-14);

● To have access to his personal data processed (Article 15 GDPR);

● Request the rectification of inaccurate personal data relating to him (Article 16 GDPR);

● Request the erasure of personal data concerning him (“right to be forgotten”) (Article 17 GDPR). Please note that the Exoclass platform allows the user to delete (erase) personal data processed in the system themselves, except the statistical data collected by Exoclass, which are anonymised.

Attention! You only have the right to be forgotten if one of the following reasons applies:

● the personal data are no longer necessary for the purposes for which they were collected or otherwise processed;
● you withdraw your consent to the processing of personal data on which the processing is based, and there is no other basis for processing the data;
● you do not consent to the processing under Article 21(1) of the GDPR and there are no overriding legitimate grounds for processing.


● Restrict processing (Article 18 GDPR):

Attention! You only have the right to restrict the processing of your data when:

● the personal data is inaccurate;
● the processing of personal data is unlawful, but you do not consent to the erasure of the data;
● the controller no longer needs the personal data for its purpose but needs it to assert, exercise or defend legal claims against you;
● you object to processing in accordance with Article 21(1) of the GDPR unless the controller’s legitimate reasons override yours.

● Transfer your personal data where the processing is based on consent or contract, and the processing is carried out by automated means (this right is granted to “Provider” accounts, “User” type accounts do not have the functionality to transfer (move) data off the platform (Art.20 GDPR);

● To object to the processing of personal data on grounds relating to your particular case where the processing is carried out for the legitimate interests of the controller or of a third party, unless the controller demonstrates that the processing is carried out for compelling legitimate grounds which override your interests, rights and freedoms, or for the establishment, exercise or defence of legal claims (Article 21 of GDPR).

If you believe that UAB “Exoclass” is unlawfully processing your personal data or is not exercising your rights, you have the right to file a complaint with the State Data Protection Inspectorate (L. Sapiegos g. 17, 10312 Vilnius, tel. (8 5) 271 2804, 279 1445, e-mail: [email protected]).

You may exercise your rights by submitting a written request to our email address: [email protected].

6. THIRD-PARTY WEBSITES, SERVICES AND PRODUCTS ON OUR WEBSITES

The Exoclass website may contain third-party banners and links to their websites and services. Please note that we are not responsible for the content of these websites or the data security measures used by them. Therefore, if you follow a link from the Exoclass website to other websites, you should consult
their privacy policies separately.

7. SLAPS

The Exoclass website uses strictly mandatory marketing and statistical cookies (known as “cookies”) to help make our website attractive, functional and easyto navigate. For more information on how cookies work, please visit www.cookiecentral.com.

The information related to cookies is not used to identify you personally, and the data collected is under our control. We do not associate a visitor’s IP address and email address with personally identifiable data. Each visitor’s visit session will be logged, but the visitor to the Exoclass website will remain anonymous.

The Exoclass website uses WordPress, HotJar, Google Analytics, Google Tag Manager, Cookie Consent and other cookies.

Descriptions of the cookies used on the Exoclass website

Cookie nameThe category of cookiesDescription of the cookieCookie expiry date
wp-settings-time-1 wordpress_test_cookie PHPSESSID wp-settings-1 redux_current_tab cookie_notice_accepted redux_current_tab_getStrictly bindingStrictly binding cookies help to make a website usable by enabling basic functions such as navigation and access to secure areas of the website. The website cannot function properly without these cookies.Session cookie Session cookie Session cookie Session cookie 3 days 12 days 3 days
_hjSessionUser_{site_id} _hjid _hjFirstSeen _hjUserAttributesHash _hjCachedUserAttributes _hjViewportId _hjSession_{site_id} _hjSessionTooLarge _hjSessionRejected _hjSessionResumed _hjLocalStorageTest _hjIncludedInPageviewSample _hjIncludedInSessionSample _hjAbsoluteSessionInProgress _hjTLDTest _hjRecordingEnabled _hjRecordingLastActivity _hjClosedSurveyInvites _hjDonePolls _hjMinimizedPolls _hjShownFeedbackMessageFunctional/StatisticsThese cookies are applied after the Hotjar Tracking Code has been uploaded and ensure that the Hotjar Tracking Code functions properly. More information.Up to 1 year
wp-wpml_current_language
FunctionalThis cookie is used to track the user’s language preference1 day
ads/ga-audiencesMarketing“Google cookie that collects information about user behaviour on the websiteUntil the end of the session
trMarketingCollects information about user behaviour on the website and is used to optimise and present offers on FacebookUntil the end of the session
_gcl_auMarketingGoogle AdSense is used. Designed to experiment with the effectiveness of advertising on websites that use their services3 months
collectStatisticsOptimises ad placement based on user movements and the various bids from ad providers when displaying user adsUntil the end of the session
_gaStatistics“Google Analytics cookies are used solely to enable us to measure your usage patterns. These cookies are used to collect information and report website usage statistics to Google without personally identifying individual visitors. 
For more information about these cookies: http://www.google.com/policies/privacy/partners/
2 years
_gatStatistics
24 hours
_gidStatistics
24 hours

CONTACT US

If you have any questions regarding the protection of your personal data, please get in touch with us by email at: [email protected]