Privacy Policy
Last updated: 19 July 2026
This Privacy Policy explains how IT Works MB, operating under the brand sprendimAI (“we”, “us”, “our”), collects, uses, stores, and protects personal data when you visit sprendimai.it and use the features on this website. We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and applicable Lithuanian law.
1. Data controller
The data controller is:
- IT Works MB
- Brand: sprendimAI
- Location: Klaipėda, Lithuania
- Email: info@sprendimai.it
- Website: https://sprendimai.it
For privacy requests, please email info@sprendimai.it. We do not currently appoint a separate Data Protection Officer; privacy requests are handled by the controller.
2. Whose data we process
We process personal data of website visitors, people who contact us, people who book a consultation, and people who use our discovery chatbot. This website does not offer public user accounts. Staff tools (including the internal advisor) are available only to authorised personnel and are covered by internal access controls.
3. What personal data we collect
3.1 Contact form
When you send a contact request, we collect: name, email address, company (optional), service interest, message content, your consent, and technical metadata such as IP address and submission time. We store this as a lead record and may send confirmation and internal notification emails.
3.2 Booking / free workflow review
When you book a slot, we collect: name, email address, company, description of the workflow or process to improve, current tools (optional), biggest issue (optional), selected date and time, your consent, and IP address. We use this to confirm the booking, notify our team, and manage the appointment.
3.3 Discovery chatbot
If you use the discovery chatbot, we may process the chat messages you send and structured information you provide, which can include name, company, email, phone, role, country, project and scope details, technical and commercial information, and your consent. Sessions are linked to a browser session. When you submit a discovery brief, we create a lead record, may send emails, and may generate review materials (for example HTML or PDF summaries). Review access via magic links may log email, hashed IP address, and user agent for security.
3.4 Website analytics (first-party)
We operate our own first-party analytics. Analytics runs only after you click Accept in the cookie banner. If you choose Necessary only, send a Do Not Track (DNT) signal, or have not made a choice yet, we do not record the visit. When enabled, we may record: page path, anonymised IP address (IPv4 last octet masked), browser user agent, language preference, and referrer URL. We do not use Google Analytics, Meta Pixel, or similar advertising trackers on this website.
3.5 Cookies and local storage
We use cookies and similar technologies that are needed for the site to work, and limited storage for preferences. You can manage optional analytics via the cookie banner:
- Necessary / functional (always on): session cookie (for chatbot and site session), CSRF security cookie, and language preference cookie.
- Consent preference: a first-party
cookie_consentcookie and matching localStorage value storingacceptedordeclinedfor about 12 months. - Chatbot UI storage: localStorage entries for chatbot open/closed state and width.
- No advertising cookies: we do not set third-party advertising or social tracking cookies.
3.6 Server and security logs
Our hosting and application infrastructure may process technical logs (such as IP address, request time, and user agent) needed to operate, secure, and troubleshoot the website.
4. Purposes and legal bases
We process personal data only for the purposes below, under the corresponding GDPR legal bases:
- Responding to inquiries and preparing proposals (contact form, chatbot submissions) — Art. 6(1)(b) GDPR (steps prior to a contract) and/or Art. 6(1)(a) (consent where a consent checkbox is required).
- Scheduling and delivering consultations (booking) — Art. 6(1)(b) and/or Art. 6(1)(a).
- Operating the discovery chatbot and generating discovery materials — Art. 6(1)(b) and/or Art. 6(1)(a).
- Sending transactional emails related to your request or booking (confirmations, notifications) — Art. 6(1)(b) and Art. 6(1)(f) (legitimate interest in reliable communication).
- First-party analytics — Art. 6(1)(a) (consent via the cookie banner Accept choice). You can withdraw by choosing Necessary only (clear site data or contact us to reset preference) or by enabling DNT.
- Security, fraud prevention, and abuse prevention (including IP logging on forms and review-link access logs) — Art. 6(1)(f).
- Legal obligations where applicable (for example accounting or responding to lawful requests) — Art. 6(1)(c).
Where processing is based on consent, you may withdraw consent at any time by contacting us. Withdrawal does not affect the lawfulness of processing before withdrawal.
5. Recipients and processors
We do not sell personal data. We share data only with service providers that process it on our instructions, or where needed to provide a feature you requested:
- Email delivery: SMTP email providers used to send confirmations and notifications related to leads and bookings.
- AI model providers for the discovery chatbot: depending on configuration, message content and related context may be sent to self-hosted models (for example via Ollama) and/or external AI APIs such as Google Gemini and/or OpenRouter, solely to generate chatbot responses and structure discovery information.
- Calendar sync: if calendar integration is enabled, booking details (such as name, company, email, and problem description) may be synced to our calendar system hosted at vf.sprendimai.it so we can manage appointments.
- Hosting and infrastructure: our website hosting, reverse proxy, TLS certificates, application servers, background task workers, and Redis cache/queue used to run the site.
- Optional object storage: if enabled, media files may be stored with an S3-compatible provider (for example MinIO).
- Frontend libraries via CDN: the site loads Alpine.js (jsDelivr) and AOS animation assets (unpkg). These requests may involve standard technical data processed by the CDN providers.
- Authorities: we may disclose data if required by applicable law or a binding legal request.
Internal staff tools (advisor) may use a separate AI gateway under our control. That tool is not available to the public and is limited to authorised staff.
6. International transfers
Our primary operations are in the European Union (Lithuania). Some processors, especially external AI APIs (such as Google Gemini or OpenRouter) and certain CDN or email providers, may process data outside the EEA. Where that happens, we rely on appropriate safeguards under GDPR Chapter V, such as an adequacy decision and/or Standard Contractual Clauses offered by the provider, together with the contractual and technical measures available to us. If you prefer not to have your content processed by external AI providers, please contact us by email instead of using the chatbot.
7. Retention
- Contact leads and booking records: kept for as long as needed to handle your request, maintain the business relationship, and meet legal or legitimate follow-up needs, then deleted or anonymised when no longer necessary.
- Chatbot draft sessions: inactive draft sessions are typically archived after about 30 days of inactivity.
- Submitted chatbot discovery materials: retained while needed for review, proposal work, and related communication, then deleted or anonymised on request or when no longer needed.
- Raw analytics page visits: deleted after 30 days; aggregated daily statistics may be kept longer without identifying individuals.
- Cookie consent preference: about 12 months, or until you clear site data / change the preference.
- Security and review-access logs: kept only as long as needed for security and abuse prevention.
8. Security
We apply appropriate technical and organisational measures, including HTTPS/TLS, access-restricted administration interfaces, CSRF protection, session controls, rate limiting where implemented, and role-based staff access. No method of transmission or storage is completely secure; if you suspect a data incident related to this website, contact us immediately at info@sprendimai.it.
9. Your rights
Under the GDPR, you have the following rights (subject to legal conditions and exceptions):
- Access — obtain confirmation and a copy of your personal data.
- Rectification — correct inaccurate or incomplete data.
- Erasure — request deletion (“right to be forgotten”) where applicable.
- Restriction — request restriction of processing in certain cases.
- Portability — receive data you provided in a structured, commonly used format, where processing is based on consent or contract and carried out by automated means.
- Objection — object to processing based on legitimate interests, including analytics, on grounds relating to your particular situation.
- Withdraw consent — at any time, where processing is based on consent.
- Lodge a complaint — with a supervisory authority.
To exercise your rights, email info@sprendimai.it and describe your request. We may need to verify your identity before acting. We will respond within the time limits required by GDPR (generally one month).
10. Supervisory authority
If you believe your data protection rights have been violated, you may lodge a complaint with the Lithuanian State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija, VDAI) or another competent EU supervisory authority in your place of residence or work:
- Website: https://vdai.lrv.lt
- Email: ada@ada.lt
11. Children
This website and our services are directed to businesses and professionals. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, contact us and we will take appropriate steps to delete it.
12. Automated decision-making
We do not make decisions that produce legal or similarly significant effects solely by automated means. The discovery chatbot uses AI to assist conversation and structure information; human review remains part of our sales and consulting process.
13. What we do not do
- We do not process online payments on this website.
- We do not run a public newsletter signup on this website.
- We do not use Google Analytics, Meta Pixel, or advertising trackers.
- We do not sell or rent personal data.
14. Changes to this policy
We may update this Privacy Policy when our processing practices or legal requirements change. The “Last updated” date at the top will be revised accordingly. Material changes will be reflected on this page.
15. Contact
For any privacy question or request, contact:
IT Works MB (sprendimAI)
Email: info@sprendimai.it
Klaipėda, Lithuania