1. Parties, scope and precedence
This Data Processing Agreement ("DPA") forms part of the Terms of Service between MB Instakademija ("we", the processor) and the Customer ("you", the controller). It applies whenever we process personal data on your behalf to provide the Services ("Customer Personal Data"). If you are yourself a processor for another controller, we act as your sub-processor and this DPA applies accordingly. On personal data, this DPA prevails over the Terms. Terms such as "personal data", "processing" and "personal data breach" have the meaning given in the GDPR (Regulation (EU) 2016/679).
2. Details of the processing
Annex I sets out the subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects for each product.
3. Your instructions
We process Customer Personal Data only on your documented instructions. Your instructions are the Terms, this DPA (including the retention periods in Annex I), the way you configure and use the Services, and written instructions you send to hello@aeratus.app. You also instruct us to derive aggregated, anonymous statistics about the use of the Services — for example the number of events, questions or form submissions — to operate, bill, secure and improve them; those statistics identify no one. We process the data otherwise only where EU or Lithuanian law requires it, and then we tell you first unless that law forbids it. We tell you immediately if we believe an instruction infringes data-protection law.
4. Your responsibilities
You are responsible for the lawfulness of the processing you instruct: having a legal basis, informing data subjects, obtaining consents, and handling special categories of data and identity documents with the safeguards the law requires (section 6.3 of the Terms).
5. Confidentiality
Every person we authorise to process Customer Personal Data is bound by an obligation of confidentiality.
6. Security
We implement the technical and organisational measures in Annex II, taking into account the state of the art, the cost of implementation and the risks for data subjects (Article 32 GDPR). We may update the measures as long as the overall level of protection does not fall.
7. Sub-processors
7.1 You give us general written authorisation to engage sub-processors. The current list is on our sub-processor page and forms Annex III.
7.2 We tell you about any intended addition or replacement of a sub-processor at least 30 days in advance, by email to your administrators and by updating the list. Within that period you may object on reasonable data-protection grounds. If we cannot resolve the objection, you may terminate the affected Service and we refund prepaid fees for the rest of the period.
7.3 We impose on each sub-processor, by contract, data-protection obligations that give at least the protection of this DPA, and we remain liable to you for their performance. One exception is open and disclosed on the sub-processor page: our web host, Lovable, has not yet signed a data processing agreement with us.
8. Transfers outside the EEA
We transfer Customer Personal Data outside the European Economic Area only under Chapter V GDPR: an adequacy decision (including the EU–US Data Privacy Framework for certified recipients) or the European Commission's Standard Contractual Clauses concluded by us or by our sub-processor with the recipient outside the EEA, with supplementary measures where needed. The one exception until its data processing agreement is signed is Lovable, as the sub-processor page explains.
9. Data subjects' rights
Taking into account the nature of the processing, we help you respond to requests from data subjects, mainly through tools in the Services (exports, editing and deletion; in vox, the download-and-delete link in every attendee email). If a data subject contacts us directly about Customer Personal Data, we forward the request to you without undue delay and reply to them only to say we have done so.
10. Help with your obligations
Taking into account the information available to us, we help you with security of processing (Article 32), notification of personal data breaches (Articles 33–34), data-protection impact assessments and prior consultation (Articles 35–36).
11. Personal data breaches
We notify you without undue delay, and where feasible within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notice contains the information Article 33(3) GDPR requires, as far as it is available; we provide the rest as it becomes available. We take reasonable steps to contain the breach and limit its consequences. Notifying the supervisory authority and the data subjects is your decision, and we help you do it.
12. Return and deletion
At the end of the Services you can export Customer Personal Data as the Terms and the Data export and switching terms describe. After the export period we delete it within 30 days; it leaves our backups when they expire (within 7 days), unless EU or Lithuanian law requires us to keep it. On request we confirm deletion in writing.
13. Records, information and audits
We keep a record of the processing we carry out on your behalf (Article 30(2) GDPR). We make available all information necessary to demonstrate compliance with Article 28 GDPR: this DPA, Annex II, the sub-processor list and our sub-processors' certifications or audit reports where they exist. If that is not enough, you or an independent auditor bound by confidentiality may audit us once a year, on 30 days' written notice, during business hours and at your cost, without access to other customers' data. Further audits are possible when a supervisory authority requires them or after a personal data breach.
14. Liability
Each party's liability under this DPA is subject to the limitations in the Terms. Nothing in this DPA limits either party's liability to data subjects under Article 82 GDPR or the powers of supervisory authorities.
15. Term and law
This DPA applies for as long as we process Customer Personal Data. Lithuanian law applies, and the courts named in the Terms decide disputes.
This version. For a Customer who accepted an earlier version, this version applies from 16 November 2026, except for changes that the law requires or that do not disadvantage the Customer, which apply at once (section 21 of the Terms).
Annex I — Details of the processing
Nature and purpose: hosting, storing, organising, displaying, transmitting and deleting Customer Personal Data to provide the Services the Customer uses, including the emails it sends, the public pages it publishes and the AI features it invokes; and, only where the Customer instructs it in writing, testing new versions of vox on a pseudonymised copy of its workspace (the testing copy, below).
Duration: the term of the Terms plus the deletion period in section 12.
Retention while the contract runs. Unless a signed order form sets other periods, you instruct us to apply these:
- vox registrations, waitlist entries, event feedback, call-for-papers submissions and speaker-intake answers are anonymised 24 months after the event — export them before then if you need them for longer;
- records of the emails the Services send for you, and page-view records, are deleted after 12 months;
- q conversation logs, ratings, unanswered-question lists and contact-form sending records are deleted after 24 months;
- records used only for rate limiting are kept for no longer than 12 months;
- a testing copy of your vox workspace, if you instructed one (below), is kept until we rebuild it or you ask us to delete it, and at the latest until the contract ends;
- everything else is kept until you or your Users delete it, or until the contract ends (section 12).
| Product | Data subjects | Personal data |
|---|---|---|
| vox (events) | Event attendees and registrants; speakers and guests; people in the organisation's address book; people who post questions, feedback, messages or gallery photos; certificate holders | Name, email, answers to registration questions the Customer defines (which may include special categories, such as dietary or accessibility needs), uploaded files (papers, CVs, slides), attendance and check-in, tickets, reminder and email preferences, public speaker profiles (name, role, company, biography, photo, links), photos, certificates |
| q (assistant) | People who use the assistant or its contact form; senders of emails the Customer forwards into its knowledge pipeline | Questions and answers, session and rating data, a hashed network identifier for rate limiting, country and browser type, contact-form name, email and message, forwarded email text and attachments |
| scito (forms) | Form respondents and invitees | Name, email, answers to Customer-defined fields, uploaded files (which may include identity documents and diplomas), waitlist and invitation status, email consent |
| gslk (club and programme workspaces) | Members, applicants, alumni, guests and mentors of clubs and programmes; people shown on club websites | Names and contact details entered by administrators, member cards (role, biography, photo), applications, form submissions, website content |
| mag (journals) | Authors and co-authors, reviewers, editors, readers who contact the editors | Account details, manuscripts and metadata, reviews and editorial notes, messages |
Testing copy (vox; only on your written instruction). So that a new version of vox can be tried on your own content before it reaches your organisation, you may instruct us in writing to keep a separate, non-public copy of your vox workspace. It holds only your published events — never drafts or events still awaiting your approval — with their titles, descriptions, programmes, sessions, categories, registration-form questions, approved photos (with the photographer's credit) and approved questions, sponsors' and organisations' logos, and your site's settings: its appearance, page texts, FAQ, templates and writing-style settings. Descriptions, translations, content blocks and poster texts are copied as written, so they can still mention people by name. Guests are included only when a published event shows them; their names are replaced by pseudonyms ("Svečias 01") and only the organisation they represent is kept; their photos, biographies, roles and links, the authors of questions, the uploaders of photos, the person shown as inviting, private meeting and recording links, and every email address and phone number in free text are removed or replaced. Registrations, contacts, invitations, speaker-intake and call-for-papers answers, feedback, live messages and logs are never copied; the copy holds made-up attendees whose addresses cannot receive mail (@example.invalid). Images are shown from your workspace rather than copied, so a file you delete disappears from the copy at once; an event you unpublish and other content you delete stay in the copy until it is rebuilt. Only our platform administrators can open it: it has no members and no web address of its own, it is not indexed, and it sends no email to anyone outside our own staff. We rebuild or delete it whenever you ask, and delete it when the contract ends (section 12).
Special categories: the Services are not designed for special categories of data. Where the Customer chooses to collect them (for example health-related needs in a registration form), the Customer makes sure an Article 9 GDPR condition applies and limits who can see them.
Annex II — Technical and organisational measures
- Hosting: database, authentication and file storage on Supabase in the EU (AWS eu-north-1, Stockholm); web applications served by Lovable over Cloudflare's network.
- Encryption: TLS on all connections; encryption at rest by the infrastructure providers.
- Separation of customers: customer records carry their organisation's identifier and are protected by PostgreSQL row-level security; public pages run under a restricted role that can read only published content.
- Access control: password sign-in with email confirmation (PKCE flow); role-based permissions inside each organisation; access to production data limited to authorised platform administrators.
- Application security: content-security policy and security headers (vox, gslk); input validation; rate limits on public forms, emails and AI features; private storage with short-lived signed links for sensitive uploads.
- Logging: audit records of changes to accounts and memberships; email delivery logs; error reports.
- Resilience: daily backups kept for 7 days.
- Data minimisation: AI features receive only the content the feature needs; in vox, attendees' registration data is not sent to AI providers.
- Deletion and export: self-service account deletion in vox and gslk (in q, scito and mag, on request by email); attendee download-and-delete links (vox); exports for customers; deletion on termination; the retention periods in Annex I.
- People and process: confidentiality obligations; a breach-response procedure with notification as in section 11; a review of each sub-processor and its terms — the open exception, our web host Lovable, is disclosed on the sub-processor page.
Annex III — Sub-processors
The current list, with each provider's role, location and transfer safeguard, is on our sub-processor page.