Privacy Policy

Last updated: August 26, 2026

This Privacy Policy explains how MB Kryptingi Projektai (company code 304844804), operating under the brand 1D.works, processes personal data when you use https://1d.works, contact us, subscribe to updates, book a meeting, or engage our services.

We process personal data under the General Data Protection Regulation (EU) 2016/679 (GDPR) and applicable Lithuanian law.

1. Data controller

MB Kryptingi Projektai
Taikos g. 150-30, Vilnius, Lithuania
Email: [email protected]

2. Personal data we process

ActivityData involvedPurpose
Visiting the websiteIP address, request and security data, browser/device informationDelivering and securing the website and diagnosing faults
Website analyticsPage URL, referrer and aggregated usage eventsUnderstanding which pages are useful and improving the website
Contact form or emailName, company, email address, subject, message and related correspondenceResponding to an inquiry and discussing a possible engagement
Newsletter signupEmail address and subscription preferencesSending updates you asked to receive
Booking a meetingDetails you provide to Calendly, such as name, email and scheduling informationArranging the requested meeting
Client workContact, proposal, contract, project and invoicing informationDelivering services and managing the client relationship
PaymentsBilling and transaction informationProcessing and recording payments

Please do not submit confidential information, special-category data, or personal data about another person through the contact form unless it is necessary and you are authorised to do so.

3. Legal bases

PurposeGDPR legal basis
Operating, securing and improving the websiteLegitimate interests (Art. 6(1)(f))
Responding to inquiries and arranging requested meetingsLegitimate interests and steps requested before entering a contract (Art. 6(1)(f) and Art. 6(1)(b))
Sending newsletter updatesConsent (Art. 6(1)(a))
Delivering services and managing engagementsContract performance (Art. 6(1)(b))
Accounting, tax and other mandatory recordsLegal obligation (Art. 6(1)(c))

You may withdraw newsletter consent at any time by using the unsubscribe link in an email. Withdrawal does not affect processing that took place before withdrawal.

4. Service providers and recipients

We use service providers only for the functions described below. They may receive the minimum data needed to provide that function:

  • Cloudflare — website delivery, security and request logs.
  • Google Cloud Platform (Cloud Run, United States region) — processing contact-form submissions.
  • Slack Technologies (Salesforce) — receiving contact-form messages for internal follow-up.
  • Mailchimp (Intuit) — newsletter subscriptions and delivery.
  • Calendly — meeting booking when you choose to use a Calendly link.
  • Simple Analytics BV — aggregated, cookie-free website analytics.
  • Wise — payment processing.
  • Google Fonts — delivering the website typeface; a request to Google can include technical connection data such as an IP address.
  • GitHub Gist — displaying code examples embedded in one of our Insights articles.
  • Webflow's content delivery network — delivering images used in legacy Insights articles.

We may also disclose data to professional advisers, public authorities, or courts where this is necessary to establish or defend legal claims or to meet a legal obligation. We do not sell personal data.

5. International transfers

Some providers listed above are based in, or may process data in, countries outside the European Economic Area. Their privacy notices describe their processing locations and transfer safeguards. Where GDPR requires a transfer mechanism, this may include an adequacy decision or the European Commission's Standard Contractual Clauses. Contact us if you want information about a transfer relevant to your data.

6. Retention

  • Contact-form submissions and inquiry correspondence are normally retained for up to 2 years after the last meaningful interaction.
  • Newsletter data is retained until you unsubscribe or we stop the mailing list, subject to a limited suppression record needed to honour an unsubscribe request.
  • Meeting-booking data is retained for as long as needed to arrange and follow up on the meeting.
  • Client and contractual records are retained for the engagement and applicable limitation periods.
  • Accounting and payment records are retained for the period required by Lithuanian law, generally 10 years.
  • Website security and technical logs are retained according to the relevant provider settings and only for as long as needed for security and fault diagnosis.
  • Simple Analytics provides aggregated analytics rather than visitor profiles.

We may retain data longer when required by law, needed for an active legal claim, or necessary to investigate security abuse.

7. Cookies and third-party content

1D.works does not use advertising or behavioural-tracking cookies. Simple Analytics is configured as cookie-free analytics.

The site loads resources from third parties, including Google Fonts, Webflow-hosted images, and embedded GitHub Gists. Those providers receive the technical information required to deliver the resource and may apply their own storage technologies. Following a link to Calendly, LinkedIn, Mailchimp, or another external website is also governed by that provider's privacy notice.

8. Your rights

Subject to the conditions in the GDPR, you may:

  • request access to your personal data;
  • ask us to correct inaccurate data;
  • ask us to erase data;
  • restrict or object to processing;
  • receive data you provided in a portable format where applicable;
  • withdraw consent at any time; and
  • lodge a complaint with the Lithuanian State Data Protection Inspectorate at vdai.lrv.lt.

Email [email protected] to exercise a right. We may need to verify your identity before completing a request.

9. Automated decision-making

We do not use personal data collected through this website to make decisions based solely on automated processing that produce legal or similarly significant effects.

10. Security

We use technical and organisational safeguards intended to protect personal data, including encrypted transport and access controls. No online service can guarantee absolute security, so please avoid sending secrets or sensitive personal data through the public contact form.

11. Changes and contact

We may revise this policy when our website, providers, or legal obligations change. The current version will be published on this page.

For privacy questions, contact [email protected].