Privacy policy
Last updated: 2026-09-16 • Version 1.0
This Privacy Policy explains how UAB Vextur processes personal data when you use our website, contact us, purchase or use our products and services, register for our webinars or events, or use our Moodle plugins.
1. Who we are
The data controller responsible for the processing of your personal data is:
UAB Vextur
Company code: 304824627
VAT number: LT100012152119
Registered office: Mokslininkų g. 2A, LT-08412 Vilnius, Lithuania
Email and privacy enquiries: info@vextur.com
If you have questions about this Privacy Policy or how we process personal data, please contact us at info@vextur.com
2. What personal data we process
Depending on how you interact with us, we may process:
- your name, email address, company and other contact details;
- account, license and product information;
- order, billing and payment information;
- information you provide when contacting our support or communicating with us;
- technical information relating to our website, products and Moodle plugins, such as device, browser, IP address, logs and license-related information;
- webinar or event registration and participation information; and
- your marketing and communication preferences.
We only process personal data that is adequate, relevant and necessary for the purposes described below.
3. Why we use your personal data
We use personal data to:
- provide, administer and support our products and services;
- process orders, payments, licenses and related administration;
- respond to enquiries and provide customer support;
- maintain the security, functionality and reliability of our website, products and services;
- organize and administer webinars and other events;
- comply with legal and accounting obligations and respond to lawful requests from authorities; and
- send marketing communications, where permitted by applicable law and, where required, with your consent.
Depending on the circumstances, our legal basis for processing is:
- performance of a contract or taking steps at your request before entering into a contract;
- compliance with a legal obligation;
- our legitimate interests, where these interests are not overridden by your rights and freedoms; or
- your consent, where consent is required.
Where we rely on legitimate interests, these may include operating and improving our business and services, maintaining security, preventing misuse, communicating with existing customers and managing our business relationships.
4. Moodle plugins
When you use a Vextur Moodle plugin, we may process personal data and technical information necessary to provide, maintain, secure and validate the plugin and its license.
Depending on the plugin and how it is configured, this may include information such as license information, installation or instance information, technical logs and information necessary to communicate with or support the plugin.
The specific data processed may vary between plugins. Where additional or specific privacy information is required for a particular plugin, it will be provided with that plugin.
Vextur’s role. For personal data relating to the plugin licence, customer account, invoicing and support, Vextur acts as controller. For any personal data of end-users processed on the Customer’s Moodle installation, the Customer acts as controller and Vextur, where applicable, acts as processor under a separate Data Processing Agreement (Article 28 GDPR). Vextur does not access end-user personal data hosted on the Customer’s Moodle installation without such a DPA.
5. Webinars and events
When you register for a Vextur webinar or event, we may process your name and email address and other information you provide in the registration process.
We use this information to register you, provide access to the webinar or event, send joining information and event-related communications, and administer the event.
Depending on the circumstances, the legal basis may be performance of a contract, our legitimate interests in organizing and administering the event, or consent where applicable.
If a third-party platform is used to organize or host the event, that provider may process personal data on our behalf or independently in accordance with its own privacy terms.
We normally retain webinar registration information for 12 months after the webinar, unless a longer period is required or justified for a particular purpose.
6. Who we share personal data with
We may share personal data with service providers that help us operate our business and provide our services, including providers of:
- hosting and cloud infrastructure;
- payment, accounting and invoicing services;
- customer support and communications;
- webinar and event platforms;
- security and technical services; and
- other services necessary to operate our website, products and business.
Vextur’s current sub-processors include: Skaylink (Moodle hosting), UAB Baltneta (hosting), Crayon Lithuania (AWS reselling) and Amazon Web Services (cloud infrastructure, including regions outside the EEA), Cookiebot (cookie consent management), Google LLC (Google Analytics) and Microsoft Corporation (Microsoft Clarity, Bing). A current sub-processor list is available on request from info@vextur.com.
We may also disclose personal data where required by law, to competent authorities, or where necessary to establish, exercise or defend legal claims.
We do not sell personal data.
Where a service provider processes personal data on our behalf, we require appropriate contractual and other safeguards as required by applicable law.
7. International transfers
Some of our service providers process personal data outside the European Economic Area (EEA). In particular: (i) the United States – Google (Google Analytics), Microsoft (Clarity, Bing), Meta Platforms Ireland (Facebook Pixel operations), certain Amazon Web Services regions; (ii) Indonesia – Amazon Web Services (Jakarta region), where used to serve customers in South-East Asia; (iii) the Kingdom of Saudi Arabia – Oracle Cloud infrastructure, where used to serve customers in the Middle East.
Where personal data is transferred outside the EEA, we use an appropriate transfer mechanism under Chapter V of the GDPR, in most cases the European Commission Standard Contractual Clauses (SCCs, Decision (EU) 2021/914), supplemented, where necessary, by additional safeguards following the CJEU judgment in Schrems II (C-311/18) and EDPB Recommendations 01/2020. Where a country benefits from an adequacy decision (such as the EU-US Data Privacy Framework for certified US recipients), the corresponding adequacy decision is relied upon.
You may contact us at info@vextur.com for further information about applicable safeguards.
8. How long we keep personal data
We retain personal data only for as long as necessary for the purposes for which it was collected, including to provide our services, meet legal and accounting obligations, resolve disputes and establish, exercise or defend legal claims.
Different types of information may therefore be retained for different periods.
The main categories of personal data processed by Vextur and the corresponding retention periods are set out in the following schedule:
# | Data category | Retention period | Trigger (start of the period) | Legal basis |
1 | Contractual data and contract performance records | 10 years after the end of the contract | From contract termination, expiry or full performance | Civil Code Art. 1.125(2) + General Document Retention Schedule (Chief Archivist Order |
2 | Accounting and financial records (invoices, payment documents, accounting registers) | 10 years | From approval of the annual financial statements | Law on Financial Accounting |
3 | Annual financial statements and related documents | 10 years | From approval of the statements | Law on Financial Accounting Art. 15 + General Document Retention Schedule |
4 | B2B customer contact-person data (active relationship) | Contractual relationship + 10 years | From the end of the relationship | GDPR Art. 6(1)(b); after end – Civil Code Art. 1.125(2) and legitimate interest |
5 | B2C (consumer) contact data | Purchase relationship + 10 years | From the last purchase | Civil Code Art. 1.125(2) + GDPR Art. 5(1)(e) |
6 | Support correspondence and helpdesk tickets | 3 years after ticket closure | From ticket closure (or last activity if open) | Civil Code Art. 1.125(1) + ISO 27001 documentation practice |
7 | Marketing consents and related contact data | Until consent is withdrawn + 3 years | From withdrawalor last active engagement (whichever earlier) | GDPR Art. 7(1) + Law on Electronic Communications |
8 | Marketing to existing customers (“soft opt-in”) | Until unsubscribe + 3 years | From the date of unsubscribe | Law on Electronic Communications Art. 81(2) + GDPR Art. 7 |
9 | Prospect / lead data (contact forms, enquiries) | 12 months from the last contact | From the last contact | GDPR Art. 6(1)(f) legitimate interest + |
10 | Cookie consents (Cookiebot / CMP records) | 12 months, then consent re-requested | From granting of consent | EDPB Guidelines 03/2022 + ePrivacy Directive 2002/58/EC Art. 5(3) |
11 | Webinar and event registration data | 12 months after the event | From end of the event | GDPR Art. 6(1)(f) legitimate interest + |
12 | Website technical logs (IP, User-Agent, HTTP, security events) | 6 months (up to 12 months for security investigations) | From creation of the log entry | GDPR Art. 6(1)(f) + Art. 32; minimisation under Art. 5(1)(c) |
13 | Moodle plugin licence-validation logs | 12 months after last validation | From last validation request | GDPR Art. 6(1)(b) + legitimate interest in preventing |
14 | Personal data breach register (GDPR Art. 33) | 5 years | From incident registration | GDPR Art. 33(5) + ISO/IEC 27001:2022 A.5.24 |
15 | Litigation and dispute records | 10 years after final decision enters into force | From court decision or settlement | Civil Code Art. 1.125(2) + General Document Retention Schedule |
16 | DSAR records – complaints and requests to exercise rights | 3 years from response provided | From response sent to data subject | GDPR Art. 5(2) accountability + Art. 12(3) |
17 | Backups (of any of the categories above) | Up to 90 days after primary record deleted | From deletion of the primary record | Technical necessity (GDPR Art. 32); ISMS rotation procedure |
For any category not listed above, Vextur applies the general storage-limitation principle under GDPR Art. 5(1)(e) – data is retained only as long as necessary for the specific purpose and is then securely erased or anonymised.
Children.
Our website and marketing services are not directed at children under the age of 16 (or a lower age applicable under local law but not below 14). We do not knowingly collect personal data from children through our website.
Where a Vextur Moodle plugin is installed in a Customer’s Moodle environment used by learners under 18, the Customer (typically the educational institution) acts as controller and is responsible for the lawful processing of that data.
9. Your rights
Subject to the conditions and limitations provided by the GDPR, you may have the right to:
- access your personal data;
- correct inaccurate or incomplete data;
- request erasure of your personal data;
- request restriction of processing;
- receive personal data you have provided to us in a portable format, where applicable;
- object to processing based on our legitimate interests;
- object to direct marketing; and
- withdraw consent where processing is based on consent.
You also have rights relating to certain solely automated decisions producing legal or similarly significant effects.
To exercise your rights, contact info@vextur.com. We may request information necessary to verify your identity. We will respond to your request within one month of receipt (this period may be extended by up to two further months where necessary, in accordance with GDPR Art. 12(3)). info@vextur.com
10. Marketing
We may send marketing communications where permitted by applicable law. For existing customers, marketing may be sent on the basis of legitimate interest (soft opt-in) under the Law on Electronic Communications of the Republic of Lithuania Art. 81(2), with a clear opt-out option in every message. For prospects and other recipients, we obtain prior consent before sending marketing communications.
You can unsubscribe from marketing communications at any time by using the unsubscribe mechanism included in the message.
11. Cookies
Our website uses cookies and similar technologies. Consent for non-essential cookies is managed through the Cookiebot consent management platform. Your consent is stored for 12 months, after which it is requested again (in line with EDPB Guidelines 03/2022 on deceptive design patterns).
Strictly necessary cookies may be used where permitted by law. Other cookies, including analytics, advertising or similar technologies where applicable, are used only where the required consent has been obtained.
You can change or withdraw your cookie consent at any time through the “Cookie settings” link in the website footer or via the Cookiebot icon in the bottom-left corner of every page.
11.1 First-Party Cookies
These cookies are set directly by your website’s domain to ensure the site functions properly, track visitor analytics, and manage advertising data.
# | Cookie Name | Description & Purpose |
1 | wp-wpml_current_language | Functional: Remembers the user’s selected language preference while browsing the website. |
2 | CookieConsent | Strictly Necessary: Stores the user’s cookie consent preferences (e.g., whether they accepted or rejected non-essential cookies) for this domain. |
3 | _ga | Analytics: Set by Google Analytics to calculate visitor, session, and campaign data, and keep track of site usage by assigning a randomly generated number to distinguish unique visitors. |
4 | _ga_ENMWRNN5S6 | Analytics: Set by Google Analytics to persist session state and maintain data regarding the user’s navigation across the website. |
5 | _clck | Analytics: Set by Microsoft Clarity to store a unique user ID, allowing the tool to connect the user’s interactions on the site over time. |
6 | _clsk | Analytics: Set by Microsoft Clarity to group multiple page views by a single user into a unified session recording to understand user behavior. |
7 | _fbp | Marketing: Set by Meta (Facebook) to track users across websites and deliver targeted advertisements or retargeting campaigns. |
11.2 Third-Party Cookies
These cookies are set by external domains that provide services on your website, such as embedded features, analytics, and advertising tracking.
# | Cookie Name | Description & Purpose |
8 | bcookie | Marketing/Analytics: A browser ID cookie set by LinkedIn to track users across websites for ad targeting and to monitor the performance of embedded LinkedIn services. |
9 | li_gc | Strictly Necessary: Set by LinkedIn to store the user’s consent regarding the use of cookies for non-essential purposes. |
10 | lidc | Functional: Set by LinkedIn to optimize data center selection and routing, ensuring their embedded services load quickly and efficiently. |
11 | __cf_bm | Strictly Necessary: Set by Cloudflare (used by LinkedIn) to distinguish between actual human users and malicious bots for security purposes. |
12 | MUID (Bing) | Marketing/Analytics: A unique Microsoft user identifier used by Bing to track users across multiple Microsoft domains for targeted advertising and analytics. |
13 | MR (Bing) | Analytics: Used by Bing to collect information for analytics purposes and to determine whether to refresh or update the user’s MUID cookie. |
14 | SRM_B | Analytics: Used by Microsoft Bing to identify unique web browsers visiting the site to monitor how users navigate and interact with Microsoft properties, for analytics and campaign measurement. |
12. Complaints
If you believe that we process your personal data in violation of applicable data protection law, you may contact us and we will make reasonable efforts to address your concerns.
You also have the right to lodge a complaint with the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija), the Lithuanian supervisory authority:
L. Sapiegos g. 17, LT-10312 Vilnius, Lithuania
Tel. +370 5 271 2804 / +370 5 279 1445
Email: ada@ada.lt • Website: https://vdai.lrv.lt/
13. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. The latest version will be published on this website together with its effective or update date.