Who is responsible
MB Verslas.in, company code 303070537, M. Valančiaus g. 7-45, LT-03158 Vilnius, Lithuania, operates Webs Protected and is responsible for the processing described here. Contact info@websprotected.com with privacy questions or requests.
Request notice: webs-privacy.2026-09-28.2, dated 28 September 2026. Optional analytics explanation updated 19 September 2026; optional consent version 2 requires a new choice. This policy covers website enquiries, resource requests, necessary preferences and optional analytics. Customer security-review evidence and engagement records have separate agreed handling rules.
Package and resource forms
The package form contains a selected package, name, email address and project name, with a website URL and short note that may be left blank. Resource forms contain an email field and a Privacy Policy acknowledgement.
When request collection is enabled, submitted details are validated by the website and server, then stored with the selected package or resource, a versioned privacy acknowledgement, server receipt time and a random request reference used to prevent duplicate retries. The website does not place form entries or security tokens in cookies, browser storage or page URLs. Opening this Privacy Policy preserves the form; closing the form clears its local entries, but does not erase a request already accepted by the server.
Do not enter passwords, API keys, payment-card details, raw customer records or other sensitive information. There are no file-upload fields.
Why we process information
We handle an individual’s package enquiry to take steps they request before a possible contract (GDPR Article 6(1)(b)). Where someone acts for a business, responding to that business enquiry relies on our legitimate interest in communicating with potential clients (Article 6(1)(f)). An enquiry does not form a contract or authorize security testing.
We use resource-request details to respond to the requested material and manage fulfilment, including transactional sample attachments, relying on our legitimate interest in answering that request. Protecting the website, preventing duplicate requests and unwanted repeat emails, managing suppression and internal notifications also rely on our legitimate interests in secure, reliable operation. The Privacy acknowledgement records that the notice was presented; it is not marketing consent.
Optional Analytics relies on your consent (Article 6(1)(a)). We use information needed to respond to statutory privacy requests and meet applicable record-keeping obligations under Article 6(1)(c). There is no automated decision-making with legal or similarly significant effects.
Resource delivery and marketing
The named nine-page English Vilniaus Saliutas sample from September 2026 is client-approved for delivery as an attachment in response to a website request. It remains a historical sample, not a current security assessment, testimonial, certification or guarantee.
Eligible new sample-report requests are handled by transactional email attachment. A saved request remains pending; a queue entry or an email provider’s acceptance does not by itself confirm delivery. Delivery may be delayed or unavailable when safety or capacity controls apply. Case-study requests remain content pending and are followed up manually when the document is ready.
Your email is used for the requested material and necessary delivery or error handling only. Requesting a resource does not subscribe you to marketing, authorize sales follow-up or require optional analytics consent. No public PDF download or indexed copy is provided by this form.
Cookie choices
Necessary storage remembers an explicit choice about optional analytics. Analytics is off by default. You can keep necessary storage only, allow analytics, or review and change your choice in Cookie Settings. Closing settings, scrolling or continuing to browse does not grant consent.
Necessary preference storage contains only a version number, the optional analytics choice and an update time. The host-only wp_consent cookie is used on HTTP(S); the webs-consent-v2 browser-storage key is used for a local file preview. No email, name, package selection or tracking identifier is stored there.
The preference lifetime is at most 24 hours. Invalid or expired choices return analytics to off, and unavailable preference storage leaves analytics off.
Analytics and external processing
Cloudflare provides website hosting, request handling and abuse protection. Supabase stores the request database in Frankfurt, Germany (eu-central-1). Resend sends internal notifications from its Ireland sending region; its message and log storage is in the United States. UAB Interneto vizija hosts our human correspondence mailboxes. These are separate services: choosing an EU database or sending region does not mean that all support, security or provider processing stays in the EU. For requester sample delivery, Resend also processes the requester’s email address, transactional message, approved PDF attachment and delivery diagnostics.
Cloudflare Turnstile processes technical information such as IP address, browser characteristics and interaction signals to prevent abuse. Cloudflare acts as our processor for site protection and separately as a controller when improving its bot-detection service, as described in its Turnstile Privacy Policy. Our server validates the token and does not store it in the enquiry. Rate limiting uses a short-lived keyed network-identity digest; raw IP addresses are not included in enquiry records. Application request-body logging is disabled.
Internal notification messages contain the request reference, request type and package/resource context. Contact details and notes remain in the restricted request worklist. A provider-accepted notification is not proof of inbox delivery. Uncertain notification outcomes are reconciled before any late resend.
Cloudflare, Supabase, Resend and Google may process information outside the European Economic Area, including in the United States. Their applicable data-processing terms provide safeguards for covered international transfers, including European Commission Standard Contractual Clauses where required. Regional hosting is not a guarantee of EU-only processing. Contact info@websprotected.com for the applicable provider and transfer information or a copy of relevant safeguards.
On the approved public website, Google Tag Manager loads our Google Analytics 4 tag only after you explicitly allow analytics under optional consent version 2. Tag Manager manages this single measurement route; it does not read form values. Before consent, necessary-only choices, expired or invalid preferences and unavailable preference storage cause no Google Tag Manager or Analytics request, cookie or measurement ping. There is no unconditional tracking iframe. Private previews and staging do not use the production tag IDs.
Optional measurement records page views, the opening of a package form, and a new durably accepted package or resource request. Only fixed package identifiers, offer family, currency and resource identifiers may accompany those events. Names, email addresses, notes, entered URLs, request references and security tokens are excluded. An enquiry is not recorded as a purchase and a pending resource request is not recorded as a download. Analytics consent is separate from the form Privacy acknowledgement and is not required to submit a request.
Google receives technical browser/device and connection information when consented measurement runs. The Webs-specific analytics cookies webs_ga and webs_ga_D1L2PF6KQT identify a browser and session, with a configured maximum lifetime of 24 hours and no automatic cookie extension. Google Analytics user and event retention is configured to two months, with reset on new activity disabled; this setting does not set a deletion deadline for aggregated reports or all Google service logs. Google signals, granular location/device collection, advertising personalization, user-provided data and enhanced measurement are disabled. No User-ID or cross-domain tracking is configured in the website code.
Withdrawing analytics consent disables further measurement for the current page and clears only this Webs tag’s identified cookies where the browser permits. It preserves your necessary choice and form entries; loaded third-party code cannot be unloaded, and data already sent or requests already in flight cannot be recalled. If you later allow analytics again, it resumes on the next page navigation. A blocked or unavailable analytics service does not prevent a package or resource request. No advertising, session replay, live chat, email-marketing, payment or scheduling script is used; website fonts and visual assets remain local.
Direct contact and accepted engagements
If you contact us separately, the information you choose to send may be used to respond and discuss your request. Depending on the circumstances, processing may be necessary for steps you request before a contract, an accepted contract, legitimate business interests or applicable legal obligations. Optional analytics or marketing would require the relevant consent.
Access to customer systems, review evidence, reports, remediation, retesting and cleanup are subject to separately agreed engagement documents. Retention periods and any providers for those records must be documented for the actual engagement. Website enquiry deadlines do not replace those separate requirements.
Retention and operational access
Access to enquiries, resource requests and the private worklist is restricted to authorized operators and the server operations needed to accept requests and recover notifications. Paulius maintains a retention worklist with individual expiry and review deadlines. Deletion and notification reconciliation are owner-operated, access-restricted processes; they are not public website actions. Automation does not silently extend a retention deadline.
Unconverted enquiries are kept for up to 180 days after the last substantive enquiry or proposal exchange. Automated reminders, notification attempts and retries do not restart this period. We record only the date and a minimal reference for a substantive exchange, rather than copying the correspondence into the request database.
Resource requests expire no later than 180 days after original submission, or 30 days after fulfilment or cancellation, whichever occurs first. A reminder, retry or change back to pending does not extend that deadline. The historical sample is supplied by requested email attachment; case-study content is still pending. A saved request does not promise immediate delivery.
We retain delivery status and attempt records to prevent duplicate or unwanted email and reconcile uncertain outcomes. Delivery diagnostics are removed 30 days after resolution, subject to a specific hold. A protected recipient fingerprint used to prevent repeat delivery expires no later than 180 days after the original request, after any linked unresolved or held request is safely resolved and removed. Suppression fingerprints have an explicit expiry of at most 180 days; any extension requires a reviewed purpose. Retries do not extend the original request deadline.
Resolved internal-notification diagnostics are removed after 30 days from definitive delivery or failure resolution. Only the minimum metadata needed to prevent duplicate notifications remains until the associated request expires. Provider acceptance alone is not treated as delivery.
Unresolved notifications are reconciled before deletion. A notification still unresolved at 90 days requires a documented justification and a dated further review; this does not authorize indefinite retention or automatic resending. A due request with an unresolved notification is flagged for prompt operator resolution.
Contract and accounting records follow their separately applicable requirements. A specific legal hold may suspend deletion where necessary; its reason and review date are recorded and it is not released automatically. Corresponding operational email copies are included in the manual review, subject to those separate obligations.
Deleting the active request does not recall delivered email or immediately erase rotating provider backups. The configured Supabase daily database backups retain seven days. Resend’s published standard-plan retention is 30 days for emails and logs, seven days for backups, and up to 90 days for remaining customer data after service termination. These periods are separate from our active request retention. We have not verified a fixed period for Cloudflare Turnstile technical records or Interneto vizija mail backups and service logs; those are governed by the applicable provider policies. Any database restoration must be checked against the retention worklist before normal processing resumes.
Your rights
Depending on applicable law and the circumstances, you may request access, correction, deletion, restriction or portability of your personal data, object to certain processing and withdraw consent. Some records may need to be retained to meet a legal obligation or handle a claim.
Send requests to info@websprotected.com. We may need to verify your identity before acting. You may complain to Lithuania’s State Data Protection Inspectorate at vdai.lrv.lt. Withdrawing consent does not affect processing lawfully carried out before withdrawal.
Updates
The policy version above identifies the notice associated with a submitted acknowledgement. We update the notice when processing purposes, providers or operating arrangements change. A form using a retired version must be refreshed before a new submission; an existing saved receipt retains its original acknowledgement.