English version
1. Who we are and when this policy applies
This Privacy Policy explains how UAB Medidomus collects, uses, stores and discloses personal data when you visit the medidomus.lt or woodfab.lt websites, contact us, submit an enquiry, complete a Meta instant form, subscribe to marketing, interact with our social media accounts, or work with us as a customer, prospective customer, supplier or business partner.
WOOD FAB is a trading brand used by UAB Medidomus and is not a separate legal entity. UAB Medidomus is therefore the sole data controller for the processing described in this policy. In this policy, “we”, “us”, “Medidomus” and “WOOD FAB” all refer to UAB Medidomus.
| Data controller | UAB Medidomus, also trading under the WOOD FAB brand |
|---|---|
| Company code | 302635325 |
| Registered office | Medžiotojų g. 6, Užpaliai, Utena district, LT-28385, Lithuania |
| Privacy contact | info@medidomus.lt |
| Websites | https://www.medidomus.lt and https://www.woodfab.lt |
2. Personal data we may process
- Identity and contact data, such as your name, work email address, telephone number, job title, company name and website.
- Enquiry and project data, such as required products, quantities, drawings, sketches, measurements, materials, finishes, budget, timescales and preferred cooperation model.
- Contract and transaction data, including quotations, orders, delivery information, invoices, payment status and correspondence connected with contract performance.
- Marketing preferences, including the fact, date and source of consent, selected interests and opt-out information.
- Communications data, including emails, social media messages, comments, call notes and meeting information.
- Technical and usage data, such as IP address, device and browser information, cookie identifiers, pages viewed, visit time and referral source, where permitted by law and your cookie choices.
- Publicly available professional information when we reasonably identify potential business contacts, such as a name, role and company contact information published on a company website or professional network.
Please do not include special category data, such as health, biometric, political or religious information, personal identification numbers or copies of identity documents in an enquiry unless we specifically request it and have a lawful basis.
3. Where we obtain personal data
- Directly from you when you complete a form, email or call us, meet us or enter into a contract.
- From Meta platforms when you voluntarily submit an instant form addressed to WOOD FAB or Medidomus, or message our Facebook or Instagram account.
- From LinkedIn and other professional or public sources where necessary for reasonable B2B contact.
- From your employer, colleague, project partner, architect, contractor or customer when they reasonably identify you as a contact person.
- Automatically from our websites and IT systems, subject to cookie and privacy settings.
4. Purposes, legal bases and retention
| Purpose | Data | Legal basis | Retention |
|---|---|---|---|
| Responding to enquiries and preparing quotations | Contact, company, project requirements and correspondence | Steps before a contract; legitimate interest in responding to B2B contacts | Up to 24 months after the last meaningful contact if no contract follows |
| Performing contracts, orders and projects | Contact, contract, technical, delivery and payment data | Contract performance; legal obligation; legitimate interest in administering business relations | For the contract and afterwards as required by law or to protect legal claims |
| Managing Meta lead forms | Form answers, contact, company, product and cooperation interests | Steps at your request before a contract; legitimate interest in assessing a business enquiry | Up to 24 months after the last meaningful contact unless a longer legal period applies |
| Sending newsletters and offers | Email, name, company, interests, consent and engagement data | Consent; only a legally permitted existing-customer exception where applicable | Until consent is withdrawn or 24 months after the last engagement, whichever is earlier; suppression evidence is retained longer |
| Operating and securing websites | IP, logs, device, essential cookies and security events | Legitimate interest in secure and functioning systems | According to technical and security need, normally no longer than 12 months unless linked to an incident |
| Analysing website use | Cookie identifiers, page and campaign interactions | Consent where non-essential analytics or advertising cookies are used | According to cookie duration and consent settings |
| Managing social media accounts | Public profile, comments, messages, reactions and campaign interaction | Legitimate interest in communication and presenting our business; consent where required | According to platform settings and up to 24 months in our systems if transferred to CRM |
| Accounting, compliance and legal claims | Contracts, invoices, payments, correspondence and evidence | Legal obligation; legitimate interest in bringing, exercising or defending claims | For mandatory accounting periods and applicable limitation periods |
“Last meaningful contact” means the most recent two-way communication about a specific project, quotation, order or genuine cooperation opportunity. Sending an automated newsletter alone does not restart this period.
5. Meta lead forms and social media
When you submit a form on Facebook or Instagram, Meta initially collects your data under its own privacy policy and sends the data identified in the form to UAB Medidomus. After receipt, UAB Medidomus processes the data as controller for the purposes stated in this policy. The data may be stored in Meta Leads Center and our internal CRM.
Meta Platforms Ireland Limited may act as a separate controller for operating and securing its platform, delivering advertisements and measuring performance. For certain functions, such as Page Insights, Meta and the page administrator may have joint-controller responsibilities prescribed by law. You can review Meta's practices and exercise platform-related rights through its Privacy Centre.
Meta Privacy Policy: https://www.facebook.com/privacy/policy/
6. Newsletters and direct marketing
We send newsletters or promotional messages unrelated to your original enquiry only after obtaining separate, freely given consent, or where a specific existing-customer exception is permitted by law. Marketing consent is not a condition of submitting an enquiry, receiving a quotation or entering into a contract.
You can withdraw consent at any time by using the unsubscribe link in an email or contacting info@medidomus.lt. Withdrawal does not affect processing carried out before withdrawal. We may retain minimal suppression information so that we do not send further unwanted marketing.
7. Cookies and similar technologies
The websites may use essential cookies required for operation, security and remembering your choices. We use analytics, functional or advertising cookies only with your consent where consent is required. You can change or withdraw consent through the cookie settings available on the relevant website.
The cookie panel on each website must identify the provider, purpose and duration of the cookies actually in use at that time. If website technologies or suppliers change, the cookie list must be updated.
8. Recipients of personal data
Access within UAB Medidomus is limited to personnel who need the data for their work. We may also disclose data to trusted service providers only to the extent necessary to provide their services:
- cloud, email, document, CRM and IT support providers, including Microsoft 365 services;
- website hosting, development, security, analytics and consent-management providers;
- Meta and other social media or advertising platforms under their applicable service terms;
- payment, accounting, audit, legal, insurance, logistics and delivery providers;
- competent public authorities, courts or law-enforcement bodies where disclosure is legally required.
Service providers that process data on our behalf act as processors under contract and may use data only on our documented instructions, unless the law makes them a separate controller for a particular activity. We do not sell personal data and do not provide independent sales partners with general access to lead data.
9. International data transfers
Some technology and social media providers may process personal data outside the European Economic Area. Where this occurs, we rely on a European Commission adequacy decision, Standard Contractual Clauses or another safeguard permitted by the GDPR. You may contact us for information about the safeguard relevant to a particular transfer.
Microsoft has established EU Data Boundary commitments for many core Microsoft 365 services. Limited categories of data may nevertheless be transferred outside the EEA for security, support or other documented operational needs. Contractual and legal safeguards apply to such transfers.
10. Data security
We use organisational and technical measures designed to protect personal data against unauthorised access, alteration, disclosure, loss or destruction. These measures may include access controls, multifactor authentication, backups, security updates, confidentiality duties and incident-management procedures. No system can be guaranteed to be completely secure.
11. Your rights
Subject to applicable conditions and exceptions, you have the right to:
- receive information and access your personal data;
- correct inaccurate data and complete incomplete data;
- request erasure of personal data;
- request restriction of processing;
- object to processing based on legitimate interests and object to direct marketing at any time;
- receive data you provided in a structured, commonly used and machine-readable format where data portability applies;
- withdraw consent at any time;
- not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, where that right applies.
To exercise a right, contact info@medidomus.lt. We may request reasonable information to verify your identity. We normally respond within one month. For complex requests, the period may be extended as permitted by the GDPR.
12. Complaints
If you believe we have handled your data improperly, please first contact us at info@medidomus.lt. You also have the right to complain to the Lithuanian State Data Protection Inspectorate or to the supervisory authority in another EEA country where you live or work.
Lithuanian State Data Protection Inspectorate: https://vdai.lrv.lt/en/
13. Automated decisions and children's data
We do not use data obtained from Meta forms, website enquiries or newsletters to make solely automated decisions that produce legal or similarly significant effects. Our services and B2B forms are not intended for children, and we do not knowingly collect children's data for marketing.
14. Changes to this policy
We may update this policy when our business, systems, service providers or legal obligations change. We will publish the current version and effective date on the websites. Where required, we will provide additional notice of material changes.
15. Contact us
Send privacy questions, requests or complaints to:
- Email: info@medidomus.lt
- Postal address: UAB Medidomus, Medžiotojų g. 6, Užpaliai, Utena district, LT-28385, Lithuania