1. Who is responsible
MB Instakademija (company code 304829880, registered office Tulpių g. 15, LT-44163 Kaunas, Lithuania; "we") runs the aeratus product family. We are the controller of the personal data this policy describes. Contact: hello@aeratus.app. We have not appointed a data protection officer because the law does not require one for us; privacy questions go to the same address.
2. Our two roles
- We decide how we process data about visitors to aeratus.app and to our products' own marketing pages; people who join a waitlist or write to us; users of accounts on our products; contacts at customer organisations, including billing contacts; and students' personal gslk accounts — the student's own profile, competencies and conversations with the AI coach (section 6). For this data we are the controller.
- Our customers decide about the data in their workspaces: attendees, registrants and speakers on vox; respondents on scito forms; people who use a q assistant; club and programme records on gslk — memberships, applications, club websites and club events; and authors, reviewers and readers of journals on mag. Text that you submit to an AI feature inside an organisation's workspace, and its result, are part of that organisation's data too. For all of this the organisation is the controller and we are its processor under our Data Processing Agreement. The organisation's own privacy notice applies, and requests should go to it. If you write to us about such data, we pass your request to the organisation and help it answer.
3. What we process, why, on what basis and for how long
| Who | Data | Purpose | Legal basis | Kept for |
|---|---|---|---|---|
| Website visitors | IP address, browser and device data, page requested, time — in hosting and security logs | Deliver the sites and protect them from abuse | Legitimate interest, Art. 6(1)(f) GDPR | Our database and server-function logs: 7 days. Our web host (Lovable) and network provider (Cloudflare) also keep request logs, as controllers in their own right, for their security and operation under their own privacy notices; we keep no copies |
| Waitlist | Email; optionally name, organisation, interests and a note; how you reached the form (referring site, campaign tags, page, browser language); a hashed network identifier to limit repeated sign-ups | Contact you when access opens for your organisation | Consent, Art. 6(1)(a) — given by submitting the form, which you can withdraw at any time | Until you withdraw; at the latest 12 months after we contact you about access, or 24 months after you joined if we never do |
| People who write to us | Name, email, message, attachments | Reply and keep a record of the exchange | Legitimate interest; steps before a contract, Art. 6(1)(b) | 24 months after the last message |
| Account users | Email, name, password (stored only as a hash by our authentication provider), language, photo if you add one, organisation memberships and roles, invitations, notification preferences, consent records, and a record of the terms you accepted (which version, when, and where — at sign-up, on joining or on creating an organisation); if you sign in with Google or Facebook where we offer it, the identifier, name, email and picture that provider shares | Provide the account and the Services | Contract with you, Art. 6(1)(b), or our and your organisation's legitimate interest in providing the Services to it, Art. 6(1)(f) | While the account exists; deleted when the account is deleted, except billing and security records kept for the periods below |
| Customer and billing contacts | Organisation name, billing contact, billing address and tax ID (collected by Stripe), plan, invoices, payment status | Sell and bill the Services; keep accounts | Contract, Art. 6(1)(b); legal obligation, Art. 6(1)(c) | Accounting documents 10 years, as Lithuanian accounting rules require |
| Service emails | Email address, message, delivery status | Account, security, billing and event notices; product updates only if you opt in | Contract and legitimate interest; consent for product updates | Delivery logs up to 12 months |
| Security and audit | IP address, browser identification string (user agent), changes to accounts and memberships, hashed keys used for rate limits | Keep the Services secure, investigate incidents, show what happened | Legitimate interest; the duty to secure data, Art. 32 GDPR | Audit records 24 months; rate-limit records no longer than 12 months |
| AI usage metering | User, organisation, feature, model, number of tokens, time | Enforce plan limits, bill AI credits, prevent abuse | Contract, Art. 6(1)(b), or legitimate interest, Art. 6(1)(f) | 24 months |
| Testing copies of an organisation's vox workspace | The organisation's published events only, never drafts or events awaiting its approval (event texts can mention people by name), with guests' names replaced by pseudonyms; contact details, attendees, question authors and photo uploaders removed; made-up attendees at addresses that cannot receive mail | Try a new version of vox on the organisation's own content before it reaches that organisation; only our platform administrators can open the copy, and it is never public and sends no email to anyone outside our staff | Done for the organisation, as its processor, and only on its written instruction (DPA Annex I); the organisation's own legal basis applies | Until we rebuild it or the organisation asks us to delete it; at the latest when its contract ends |
Content you create inside an organisation's workspace (for example an event you drafted) is that organisation's data and stays when you delete your account; the organisation controls it.
We do not sell personal data, do not use it for advertising, and do not make decisions about you with legal or similarly significant effects by automated means alone.
4. Where the data comes from
Most of it comes from you. Some comes from others: your organisation, when it invites you, adds you as a member, speaker or contact, or names you as its billing contact; Stripe, which tells us whether a payment succeeded; and Google or Facebook, if you choose to sign in with them where we offer it.
5. Do you have to give it to us?
You do not have to give us any data. But without an email address we cannot create an account, and without billing details we cannot sell a paid plan — the law requires invoices to name the buyer. The waitlist and product updates are entirely optional.
6. Who receives data
We use service providers that process data on our instructions under data-processing terms — with one disclosed exception, our web host Lovable, which has not yet signed a data processing agreement with us (see the sub-processor page): hosting and content delivery (Lovable, Cloudflare); database, authentication and file storage (Supabase, EU region in Stockholm); email delivery (Resend) and our mailbox (Hostinger); payments (Stripe, which also acts as an independent controller for some purposes, such as fraud prevention and its legal obligations); and AI models (Anthropic, and OpenAI for search in q). The current list, with locations and safeguards, is on our sub-processor page. We may also disclose data to professional advisers, auditors and authorities where the law requires it, or to a buyer of our business under the same protections.
7. Transfers outside the EEA
Some providers process data in the United States or elsewhere outside the European Economic Area. We transfer data only with a safeguard under Chapter V GDPR: the EU–US Data Privacy Framework where the provider is certified, or otherwise the European Commission's Standard Contractual Clauses, together with technical measures such as encryption in transit and sending a feature only the data it needs. The exception, until its data processing agreement is signed, is Lovable's global network, as the sub-processor page explains. You can ask us for a copy of a safeguard.
8. Personal gslk accounts
Students who create a personal gslk account hold it under the gslk terms of use and the gslk privacy notice, which describe the specific data (profile, competencies, conversations with the AI coach, the optional public person page and mentor listing, and optional research participation) and the consents involved. We are the controller of the account and of that data. What a student does inside a club — membership, applications, the club's events and website — is the club's or the programme's data, which they control (section 2); they see the student's own data only as far as the student's role and choices allow, as the gslk notice explains.
9. Cookies and similar technologies
If you have not agreed to more, we use only storage that is strictly necessary — for example to keep you signed in and to remember your language and your choices. Some customers switch on analytics tools on their own pages; those run only after you accept them on that site. Details for each product are in the Cookie Policy.
10. How we protect data
Encryption in transit (TLS); encryption at rest by our infrastructure providers; separation of each organisation's data enforced in the database (row-level security); access to live data limited to authorised administrators; rate limiting; audit logs; daily backups kept for 7 days. Annex II of the Data Processing Agreement has the detail.
11. Your rights
You can ask us for access to your data, correction, deletion, restriction of processing and a portable copy; you can object to processing based on legitimate interest and withdraw consent at any time (without affecting processing before withdrawal). Some rights are self-service: in vox and gslk you can delete your account in its settings, and vox emails contain a link to download or delete your registration data. For q, scito and mag accounts, and for everything else, write to hello@aeratus.app. We answer within one month; for complex requests we may extend this by two months and will tell you why. We may ask you to confirm your identity.
You may complain to the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija), L. Sapiegos g. 17, LT-10312 Vilnius, ada@ada.lt, vdai.lrv.lt, or to the authority where you live or work.
12. Children
Our Services are not directed at children. Accounts are for people aged 16 or over. If you believe a child has given us personal data, write to us and we will delete it.
13. Changes
We update this policy when our processing changes; the version date is shown at the top. We tell account holders about material changes by email or in the Services.
14. Contact
MB Instakademija · Tulpių g. 15, LT-44163 Kaunas, Lithuania · company code 304829880 · hello@aeratus.app