Darvilis logo
Home Services Why us Verify us Request a quote

Legal

Privacy Policy

Effective from 8 September 2026 · Version 1.0

Contents

  1. Who we are
  2. What this policy covers
  3. Website visitors and enquiries
  4. Customer and supplier contacts
  5. Bank account information
  6. Who we share data with
  7. How long we keep data
  8. Security
  9. Your rights
  10. Cookies
  11. Changes to this policy

1. Who we are

UAB Darvilis is the controller of the personal data described in this policy.

Legal name
UAB Darvilis
Company code
306219559
VAT number
LT100015627419
Registered address
Klevines str. 2-5, Klevines vil., Avizieniai eldership, Vilnius district municipality, LT-14180, Republic of Lithuania
Data protection contact
info@darvilis.lt
Telephone
+370 611 39680

We have not appointed a data protection officer, as we are not required to under Article 37 of the GDPR. All data protection matters are handled by the company’s management at the address above.

2. What this policy covers

This policy explains how we process personal data in three contexts:

  • the public website at darvilis.lt, including the contact form;
  • our business relationships with customers, suppliers and service providers;
  • our internal order-management and accounting system (“Darvilis Orders”, hosted at orders.darvilis.lt), which is used only by authorised company personnel and which retrieves information about the company’s own bank accounts through a licensed account information service provider.

Darvilis Orders is not a service offered to the public. It has no public sign-up, and access is granted only to named users authorised by the company’s management.

3. Website visitors and enquiries

Technical data

When you open darvilis.lt, our infrastructure provider processes technical data such as your IP address, browser type and the time of the request, in order to deliver the page and protect the site against attacks and abuse. The legal basis is our legitimate interest in operating a secure website (Article 6(1)(f) GDPR). We do not use analytics, advertising or tracking tools.

The website loads typefaces from Google Fonts. When it does, your IP address is disclosed to Google, which acts as an independent controller for that request.

Contact form

If you send us an enquiry, we process the name, e-mail address and message you provide, in order to answer you and, where relevant, to take steps at your request before entering into a contract (Article 6(1)(b) and (f) GDPR). Providing a name is optional; without an e-mail address we cannot reply. Messages are delivered to info@darvilis.lt through the form-relay service described in section 6.

4. Customer and supplier contacts

In the course of business we process contact details of individuals acting for our customers, suppliers and logistics partners: name, position, business e-mail address and telephone number, correspondence, and the order, invoice and shipment records connected with them. We do this to negotiate and perform contracts (Article 6(1)(b) GDPR), to comply with accounting, tax, customs and export-control obligations (Article 6(1)(c) GDPR), and for our legitimate interest in maintaining ordinary business relationships and defending legal claims (Article 6(1)(f) GDPR).

5. Bank account information

Darvilis Orders reconciles payments against orders and invoices. To do so, it retrieves information about bank accounts held by UAB Darvilis itself, using the account information service of Enable Banking Oy (Finland), an account information service provider authorised and supervised by the Finnish Financial Supervisory Authority (Finanssivalvonta) under PSD2. The connection is established only after an authorised representative of the company gives explicit consent in the bank’s own authentication channel.

What is retrieved

  • account identification: account number (IBAN), currency, account holder name;
  • balances;
  • transaction records: date, amount, currency, counterparty name and account number, payment reference and description.

These are corporate accounts. Personal data appears in them only where a counterparty is a natural person, or where an individual’s name is stated in the payment details.

Why and on what basis

We use this data solely to match incoming and outgoing payments to the correct customer or supplier order and invoice, and to keep our statutory accounting records. The legal bases are performance of a contract (Article 6(1)(b) GDPR), compliance with accounting and tax obligations (Article 6(1)(c) GDPR), and our legitimate interest in accurate financial reconciliation and fraud prevention (Article 6(1)(f) GDPR).

Limits of the access

  • Access is read-only. The system cannot initiate, change or cancel any payment.
  • Only accounts explicitly linked by the company are accessible.
  • The bank’s consent is time-limited (up to 180 days with the bank we use) and must be renewed by strong customer authentication.
  • Consent can be withdrawn at any time in the bank’s own channel or by writing to info@darvilis.lt. Retrieval then stops immediately; records already entered in our accounting are kept for the statutory periods in section 7.
  • The data is not used for credit scoring, profiling, marketing, or any automated decision-making producing legal effects.

6. Who we share data with

We do not sell personal data and we do not disclose it for advertising. We share it only with service providers acting on our instructions, and with authorities where the law requires it:

  • Enable Banking Oy (Finland) — account information service used for the bank connection described in section 5;
  • our accounting software provider — bookkeeping records, invoices and payment data;
  • Hostinger International Limited — hosting of our internal system on a server located in Vilnius, Lithuania;
  • Cloudflare, Inc. — delivery and protection of this website;
  • Google Ireland Limited — company e-mail and document storage;
  • FormSubmit — relay of website contact-form messages to our mailbox;
  • banks, auditors, tax and customs authorities — where required by law or to establish, exercise or defend legal claims.

Our data is stored within the European Union. Where a provider is established outside the European Economic Area or processes data there, the transfer is covered by the European Commission’s standard contractual clauses or by an adequacy decision, including the EU–U.S. Data Privacy Framework.

7. How long we keep data

  • Accounting documents and the bank transaction records supporting them — 10 years, as required by Lithuanian accounting and tax legislation.
  • Contracts and related correspondence — for the term of the relationship and 10 years afterwards.
  • Website enquiries that do not lead to a business relationship — up to 24 months.
  • Technical and security logs — normally no longer than 12 months.

When a retention period ends, the data is deleted or irreversibly anonymised.

8. Security

Access to Darvilis Orders is limited to named users authorised by management, protected by authentication at the server level and by role-based permissions inside the application, with read-only roles for users who do not need to make changes. All connections use TLS encryption. Credentials, API keys and cryptographic keys used for the bank connection are stored with restricted access and are never exposed to end users or embedded in client-side code. We keep regular backups of the system.

9. Your rights

Under the GDPR you have the right to request access to your personal data, its rectification or erasure, restriction of processing, and portability, and to object to processing based on our legitimate interests. Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.

To exercise any of these rights, write to info@darvilis.lt. We reply within one month; where a request is complex, we may extend that period and will tell you if we do. We may ask for information to confirm your identity.

If you believe we process your data unlawfully, you may lodge a complaint with the Lithuanian supervisory authority:

Authority
State Data Protection Inspectorate (Valstybine duomenu apsaugos inspekcija)
Address
L. Sapiegos str. 17, LT-10312 Vilnius, Lithuania
E-mail
ada@ada.lt
Website
vdai.lrv.lt

10. Cookies

This website does not use analytics, advertising or profiling cookies. Our infrastructure provider may set strictly necessary cookies for security and load balancing; these do not require consent and are not used to track you across websites.

11. Changes to this policy

We may update this policy as our services or legal obligations change. The current version is always published on this page with its effective date. Material changes affecting people whose data we already hold will be communicated directly where we have a means of contacting them.

Questions about this policy: info@darvilis.lt. See also our Terms of Service.

© 2026 UAB Darvilis. All rights reserved.

Privacy Policy · Terms of Service · info@darvilis.lt