Privacy Policy
Effective from 17 July 2026.
Your data in brief
We use your data to accept your order, arrange payment and delivery, provide customer service and fulfil the duties laid down by law. We ask only for as much information as is needed to provide the specific service.
For newsletters and for statistics and marketing technologies, we ask for your consent separately. You can change your choices at any time. Have any questions? Write to us at info@nanogo.lt – we will help.
1. Who processes your personal data?
This Privacy Policy explains how UAB “NANO GO” (hereinafter – the Company) processes the data of visitors, buyers, account users, newsletter recipients and persons who contact the Company via the online store nanogo.lt.
Data controller:
UAB “NANO GO”
Legal entity code: 301790842
VAT payer code: LT100004173410
Registered office address: Tilžės g. 171-71, LT-76205 Šiauliai, Lithuania
Email: info@nanogo.lt
Phone: +370 618 46400
2. Key data processing principles
We process your data only for clear purposes and only to the extent needed to provide a specific service or fulfil a legal duty. We take care to ensure that the data is accurate, protected and not kept longer than necessary.
Separate consent is not required for the data processing that is necessary to accept an order, perform a contract, arrange delivery, keep accounting records or fulfil a legal obligation. We ask for consent where it is the appropriate legal basis, for example, for newsletters or non-essential cookie technologies.
3. What data do we process, for what purposes and for how long?
The “Legal references” column provides links to the official EUR-Lex and e-Seimas sources.
| Purpose | Data processed | Legal basis | Retention period | Legal references |
|---|---|---|---|---|
| Accepting and fulfilling orders | First name, last name, email address, phone number, billing and delivery addresses, the selected parcel locker or pick-up point, ordered goods, prices, discounts, order number and status, delivery and payment method and status, order notes, correspondence regarding the order, and company details when purchasing on behalf of a company. | Conclusion and performance of a contract – the data is necessary to accept and fulfil the order. |
In the active online store database: • orders awaiting payment – 30 days; • failed orders – 30 days; • cancelled orders – 6 months; • completed orders – 1 year; • returned orders – 1 year. Once the period expires, the order’s personal data stored in WooCommerce is deleted or anonymised, except for data that must be retained for accounting, legal claims or dispute resolution purposes. | GDPR Art. 6(1)(b) |
| Saving abandoned carts and sending reminders | Email address, first name, last name, the contact and order details entered, cart contents, product quantities and value, the time the cart was abandoned, a technical recovery identifier, data on the reminders sent, and information on opting out of reminders. | Legitimate interest in briefly saving the purchasing process that has been started and enabling a return to the cart. Email reminders are sent only where valid consent exists or, for an existing customer, where all the conditions of Article 81(2) of the Law on Electronic Communications are met. A person who has merely started but not completed their first purchase is not considered an existing customer. | Up to 30 days from cart abandonment, but no longer than until the order is completed, the reminders are opted out of, or consent is withdrawn. Once the period expires, the data is deleted or anonymised. | GDPR Art. 6(1)(f) GDPR Art. 6(1)(a) LEC Art. 81(2) |
| Payment administration and fraud prevention | Order number, amount payable, currency, payment method and status, payment transaction identifier, payer’s name and account details to the extent provided by the payment service provider, as well as technical and risk assessment data. The Company generally does not receive or store full payment card details. | Performance of a contract, fulfilment of legal obligations and the legitimate interest in ensuring the security of payments and of the Online Store. | Together with the data of the relevant order; payment service providers retain the data in accordance with their own legal obligations and privacy rules. | GDPR Art. 6(1)(b) GDPR Art. 6(1)(c) GDPR Art. 6(1)(f) |
| Arranging delivery | First name, last name, phone number, email address, delivery address or the selected parcel locker / pick-up point, shipment number, order and shipment information. | Performance of a contract – the data is necessary to deliver the ordered goods. | Together with the data of the relevant order; carriers retain the data in accordance with their own legal obligations and privacy rules. | GDPR Art. 6(1)(b) |
| Invoicing, accounting and tax obligations | First name, last name, address, order and payment data, invoice number, date, goods, amounts and taxes; when purchasing on behalf of a company – the company name, code, VAT payer code, address and representative’s details. | Fulfilment of legal obligations – the data is necessary to keep accounting records and fulfil tax duties. | VAT invoices and other mandatory accounting documents are retained for 10 years. If a longer mandatory period applies to a specific document, we retain it for longer. Electronic invoices and related accounting documents are stored in the Company’s Microsoft OneDrive archive and, where applicable, in accounting systems. VAT invoice register data is submitted to the State Tax Inspectorate (STI) i.SAF system. | GDPR Art. 6(1)(c) |
| Creating and administering a customer account | First name, last name, email address, username, the password hash (not the password itself), addresses, phone number, account settings, login and order history. | Performance of a contract and the user’s request to create and administer an account. | As long as the account is in use. An inactive account that has not been logged into and through which no orders have been placed for 3 years may be deleted. Separate periods apply to accounting documents and legal claims. | GDPR Art. 6(1)(b) |
| Enquiries, consultations and customer service | First name, contact details, the content of the enquiry or correspondence, attached documents, and order data where the question relates to an order. | Steps prior to entering into a contract, performance of a contract, or the legitimate interest in responding to enquiries and ensuring the quality of service. | Up to 2 years from the last correspondence, unless longer retention is required due to an order, a complaint or a legal claim. | GDPR Art. 6(1)(b) GDPR Art. 6(1)(f) |
| Withdrawal from the contract, returns, complaints, warranty and other disputes | First name, last name, email address, phone number, order or invoice number, information on the withdrawal from all or part of the order, the goods being returned and their quantities, order and product information, the dates of the order and of receipt of the goods, payment and delivery documents, the content of the electronic form, its submission date, time and processing status, data confirming receipt of the form, technical submission data where recorded, the content of the complaint, photographs, correspondence, the decisions taken and refund data. | Performance of a contract, fulfilment of legal obligations and the legitimate interest in establishing, exercising or defending legal claims. | 3 years from the final resolution of the matter, and in the event of a dispute – until the final resolution of the dispute and the expiry of the applicable limitation period for claims. | GDPR Art. 6(1)(b) GDPR Art. 6(1)(c) GDPR Art. 6(1)(f) |
| Direct marketing, newsletters and review requests | Email address, first name, selected language, data on the granting, renewal and withdrawal of consent, information on objections or opt-outs, and data on the delivery of and interaction with newsletters, offers and review requests, if collected by the communication system used. | Consent. Where all the conditions of Article 81(2) of the Law on Electronic Communications are met, the existing-customer exception and the Company’s legitimate interest may apply to an existing customer in respect of the Company’s similar goods or services. In such a case, the opportunity to object free of charge and easily is provided at the time the contact details are collected and in every message. | Data based on consent is retained until the consent is withdrawn, but no longer than 3 years from the consent or from its last documented renewal. In the case of the existing-customer exception – until an objection is made, but no longer than 3 years from the last purchase. Minimal data on consent, its withdrawal, an objection or an opt-out may be retained for up to 3 years so that we can demonstrate lawful conduct and refrain from sending unwanted messages. | GDPR Art. 6(1)(a) GDPR Art. 6(1)(f) LEC Art. 81(1) LEC Art. 81(2) |
| Reviews and product ratings | Name or chosen display name, email address, rating, review text, related order data, and technical data needed to prevent abuse. | The Company’s legitimate interest in administering, verifying and publishing authentic reviews submitted voluntarily and in preventing abuse. | As long as the review is published. After a review is removed, the data related to its administration may be retained for up to 1 year, and in the event of a dispute – until the dispute ends. | GDPR Art. 6(1)(f) |
| Website security and technical operation | IP address, date and time, browser and device data, request and error logs, login data, security event information, session and essential cookies. | Legitimate interest in ensuring the security of the website, accounts, payments and data. | Generally up to 90 days. In the event of a security incident, the relevant data may be retained longer – until the end of the investigation or dispute. | GDPR Art. 6(1)(f) |
| Statistics, advertising and conversion measurement | Identifiers of cookies and similar technologies, IP and device data, pages visited, interactions, purchase or conversion information, where permitted by the consent settings you have chosen. | Consent for non-essential cookies and for the statistics, advertising and conversion measurement related to them. Data necessary for the security of the website, an order or a payment is processed separately on the bases indicated in the relevant rows of this table. Without the relevant consent, it is not used or transferred to Google, Meta or other advertising and analytics service providers for advertising, audience building or conversion measurement purposes. | According to the term of the specific cookie or service indicated in the Cookie Policy, or until consent is withdrawn. | GDPR Art. 6(1)(a) |
4. Where do we obtain your data and is providing it mandatory?
We usually obtain the data directly from you when you visit the website, create an account, place an order, choose a payment or delivery method, submit the electronic withdrawal form, contact us, submit a review or agree to receive newsletters. We may also obtain order-fulfilment data from payment service providers, banks, carriers and other service providers involved in fulfilling the order.
Data marked with an asterisk or objectively necessary for the order must be provided so that we can conclude and perform the purchase–sale contract. If such data is not provided, we will be unable to place or deliver the order. Creating an account and subscribing to the newsletter are optional.
5. To whom do we transfer or grant access to the data?
We transfer the data only to the extent necessary to provide the relevant service, fulfil a legal obligation or protect a legitimate interest. The recipients of the data, or categories thereof, may be:
- payment service providers and banks: Maksekeskus AS / MakeCommerce, Montonio and the payment partners they engage, as well as Paysera LT, UAB and the bank chosen by the customer;
- delivery and parcel service providers: Venipak, Omniva, Unisend / LP Express and any other carrier clearly selected during the order or agreed with the customer;
- website hosting, maintenance and e-commerce system service providers: Hostinger, technical specialists authorised by the Company, and other website and e-commerce system service providers;
- accounting, document storage and administration service providers: accounting service providers, suppliers of the accounting systems used, and Microsoft OneDrive;
- email, customer service and newsletter service providers, where used to administer the Company’s communications;
- analytics, advertising and social media service providers, including Google and Meta, only after obtaining the relevant consent and to the extent described in the Cookie Policy;
- state and law enforcement authorities, courts, the STI, the SDPI, consumer rights protection authorities and other entities, where we are required to provide information under the law or where it is necessary to establish, exercise or defend legal claims.
Where a service provider acts as our data processor, it may process the data only in accordance with our instructions, the concluded contract and the applicable data protection requirements. Where a payment service provider, bank, carrier, state authority or other recipient independently determines the purposes and means of its data processing, it acts as a separate data controller. Depending on the specific service and the stage of data processing, a service provider may also act as a joint controller.
6. Transfers of data outside the European Economic Area
Some of the technology, cloud, analytics, advertising or communication service providers we use may process data outside the European Economic Area or grant access to it in other countries. In such cases, data is transferred only where there is a lawful basis for the transfer, for example, a European Commission adequacy decision, EU standard contractual clauses or other safeguards provided for under the GDPR.
You can obtain information about the data transfer safeguards applicable to a specific service provider and, where applicable, the possibility of receiving a copy of them by contacting us by email at info@nanogo.lt.
7. Cookies and similar technologies
Essential cookies are used to ensure that the website, cart, checkout, account, language selection and security functions work properly. Statistics, marketing and other non-essential technologies are used only with your consent.
You can change or withdraw your consent at any time by selecting “Manage consent” on the website. Detailed information about the cookies used, the services, their purpose and validity periods is provided in the Cookie Policy.
8. Direct marketing
We send newsletters and general promotional offers by email only after obtaining separate, freely given consent. The newsletter or marketing checkbox is not mandatory for placing an order and is not pre-ticked.
Where all the conditions of Article 81(2) of the Law on Electronic Communications are met, an existing customer may be sent messages regarding the Company’s similar goods or services, including a request to submit a review of a purchased product. In such a case, a clear, free-of-charge and easily exercisable opportunity to object is provided at the time the email address is collected and in every message sent.
You can withdraw your consent at any time, and object to direct marketing, by clicking the unsubscribe link in the message or by writing to us at info@nanogo.lt. The withdrawal of consent does not affect the lawfulness of the data processing carried out before its withdrawal. Order, payment, delivery, withdrawal-from-contract or security notifications are not direct marketing and may be sent without marketing consent where they are necessary to perform the contract, administer a request or fulfil a legal obligation.
An abandoned-cart reminder may contain a link allowing you to return to the purchasing process you started and a clear option to opt out of further such reminders. To a person who has started but not completed their first purchase and is not yet a customer of the Company, such a reminder is sent only after obtaining prior consent. The exception may be applied to an existing customer only where all the conditions established by law are met.
9. Reviews and ratings
A submitted review may be published publicly together with the display name you have chosen. The email address is not published publicly. We may check whether a review relates to a genuine order, moderate unlawful, misleading, offensive or product-unrelated content, and take measures against abuse.
More information is provided in the Feedback and Rating Management Rules.
10. Automated decision-making and profiling
UAB “NANO GO” does not take decisions that would produce legal or similarly significant effects on you based solely on the automated processing of personal data.
Where you have given your consent, analytics and advertising service providers may use cookies or other identifiers to build audiences, assess the effectiveness of advertising and display more tailored advertising. You can change or withdraw this consent at any time.
11. Your rights
Under the applicable data protection laws, and depending on the specific circumstances and the applicable exceptions, you have the right to:
- receive information about the processing of your data and access the data being processed;
- request the rectification of inaccurate data or the completion of incomplete data;
- request the erasure of data where there is no lawful basis for its further retention;
- request the restriction of data processing;
- receive the data you have provided in a structured, commonly used and machine-readable format and, where applicable, transmit it to another controller;
- object to data processing based on legitimate interest;
- object to direct marketing at any time;
- withdraw consent at any time where data is processed on the basis of consent;
- lodge a complaint with the State Data Protection Inspectorate.
The right to erasure is not absolute. We will be unable to erase data if we are required to retain it under the law or if it is necessary to establish, exercise or defend legal claims.
To exercise your rights, contact us by email at info@nanogo.lt. In your request, please provide enough information for us to determine which data or actions the request concerns. If we have reasonable doubts about the identity of the person submitting the request, we may ask for additional information necessary to confirm identity. We do not automatically require a copy of an identity document.
We respond to a request without undue delay and no later than within one month of receiving it. Depending on the complexity of the request and the number of requests, the period may be extended by a further two months, of which we will inform you within the first month. Requests are generally handled free of charge; a fee may be charged, or a request may be refused, only in the cases of manifestly unfounded or excessive requests provided for by law.
You may lodge a complaint with the State Data Protection Inspectorate: https://vdai.lrv.lt/en/. Before lodging a complaint, we encourage you to contact us first so that we can resolve the matter directly.
12. Data security and backups
We apply organisational and technical measures corresponding to the nature of the data processed and the potential risk, including restricting access rights, protecting accounts, maintaining software, security monitoring and the use of backups.
Data may temporarily remain in secure backups until it is overwritten in accordance with the applicable backup cycle. Backups are not used for ordinary operations. Where data is restored from a backup, the deletion and anonymisation periods established in this Policy apply to it anew.
13. Changes to the Privacy Policy
We may update this Privacy Policy following changes in laws, the technologies used, service providers or data processing procedures. We always publish the current version on the website. If the changes are material, we will inform you in an appropriate manner.
Update date: 2026-07-17