Privacy Policy
How we collect, use, and protect personal data in accordance with the EU General Data Protection Regulation (GDPR).
Last updated: 10 July 2026
1. Data controller
The data controller responsible for your personal data under the General Data Protection Regulation (EU) 2016/679 ("GDPR") is:
UAB "TagRise Technologies"
Company code: 307657286
GiruliĊ³ g. 5, LT-12124 Vilnius, Lietuva
General enquiries: info@tagrise.lt
Legal / privacy: legal@tagrise.lt
Phone: +370 640 03264
For privacy-related requests, contact us at legal@tagrise.lt or use our contact form.
2. Scope
This Privacy Policy explains how UAB "TagRise Technologies"("we", "us") processes personal data when you use the TagRiseportal, APIs, and related services (the "Service"). It applies to customers, vendor and merchant users, administrators, and visitors to our public website.
3. Personal data we process
Depending on how you use the Service, we may process:
- Account data: name, email address, password hash, role and permission assignments, notification preferences.
- Operational data: carrier and number inventory, traffic sessions, SMS metadata, billing records, API keys (stored as hashes), SMPP binding configuration, audit logs.
- Technical data: IP address, browser type, device identifiers, session cookies, server and security logs.
- Communications: messages you send via our contact form, support correspondence, and transactional emails (e.g. password reset).
- Push notifications: Web Push subscription endpoints when you opt in.
We do not intentionally collect special categories of personal data (Art. 9 GDPR) unless you voluntarily include them in free-text fields.
4. Purposes and legal bases
We process personal data only where a legal basis applies:
- Contract (Art. 6(1)(b)): providing the Service, authenticating users, routing traffic, billing, and account administration.
- Legitimate interests (Art. 6(1)(f)): securing the platform, fraud prevention, service improvement, and limited analytics, balanced against your rights.
- Consent (Art. 6(1)(a)): optional Web Push notifications and contact form submissions where you tick the privacy consent box.
- Legal obligation (Art. 6(1)(c)): retaining records where required by applicable law, tax, or regulatory rules.
5. Recipients and processors
We may share personal data with:
- Hosting, database, and infrastructure providers acting as processors under GDPR Art. 28.
- Email delivery providers (SMTP) for transactional and notification messages.
- Authorised users within your organisation according to role-based permissions.
- Professional advisers or authorities when required by law.
We do not sell personal data. Any international transfer outside the EEA/UK uses appropriate safeguards such as Standard Contractual Clauses where required.
6. Retention
- Account data is kept while your account is active and for a limited period after closure.
- Traffic and billing records are retained according to operational and legal requirements.
- Security and audit logs are kept for a proportionate period to investigate incidents.
- Contact form enquiries are deleted when no longer needed to handle your request.
- Backup archives follow configured retention and encryption policies.
7. Your rights under GDPR
Where GDPR applies, you have the right to:
- Access your personal data (Art. 15)
- Rectification of inaccurate data (Art. 16)
- Erasure ("right to be forgotten") in certain cases (Art. 17)
- Restriction of processing (Art. 18)
- Data portability (Art. 20)
- Object to processing based on legitimate interests (Art. 21)
- Withdraw consent at any time, without affecting prior lawful processing (Art. 7(3))
To exercise these rights, contact legal@tagrise.lt. We respond within one month, extendable where permitted.
You may lodge a complaint with your local supervisory authority. A list of EU data protection authorities is published by the European Data Protection Board.
9. Security
We implement appropriate technical and organisational measures including encryption in transit (TLS), hashed credentials, role-based access control, audit logging, and encrypted backup artifacts. No method of transmission over the Internet is completely secure; please use strong passwords and protect API keys.
10. Children
The Service is intended for business users and is not directed at children under 16. We do not knowingly collect personal data from children.
11. Changes
We may update this Privacy Policy to reflect legal or operational changes. Material updates will be indicated by revising the "Last updated" date. Continued use after changes constitutes acknowledgement where permitted by law.