Privacy Policy

Last updated: 3 August 2026

This policy explains what personal data Vindiko ("we", "us", "our") collects when you use vindiko.com, how we use it, and what rights you have under GDPR.

1. Data We Collect

We collect information you provide directly, such as your email address when you register and the damage descriptions, photos, and answers you submit during a dispute. We also collect standard server logs (IP address, browser type, pages visited) for security and performance monitoring.

2. How We Use Your Data

Your data is used solely to generate cost estimates and formal dispute letters on your behalf, and to maintain your account history. We do not use your data for advertising, and we do not sell it to third parties. To operate the service we rely on the following sub-processors: Anthropic (AI analysis, United States), Resend (transactional email, United States), Stripe (payment processing, Ireland and United States), Vercel (frontend hosting, United States), Railway (application hosting, United States) and Aiven (database hosting, European Union). Each sub-processor is bound by a Data Processing Agreement and processes data only as instructed by Vindiko.

3. Data Retention

Account data and dispute history are retained for as long as your account is active. When you delete your account it is deactivated immediately and permanently erased within 30 days, together with your disputes, any queued reports and your consent records. Contact-form enquiries are kept for 12 months from the date you send them. Security and administrative access logs, which include IP addresses, are kept for 12 months. Payment records are retained for the accounting period required by Lithuanian law; when you delete your account they are detached from your identity and kept only as anonymous transaction records. Data from an unfinished dispute is held in memory only and discarded within 30 minutes.

4. Cookies & Local Storage

We don't set any cookies. Signing in and remembering your selected language both use your browser's local storage instead, which is essential for the Service to work and can't be disabled. We do not look up your location: if you have not chosen a language, we suggest one from your browser's own language setting, and your IP address is never sent to a third party for this purpose. If we ever introduce analytics or other non-essential cookies, the consent banner shown on your first visit will ask for your permission before any are set — you can change or withdraw your choice at any time using the Cookie settings link in the footer.

5. Your Rights

Under GDPR you have the right to access, correct, or delete the personal data we hold about you. You may also request a copy of your data in a portable format via the "Export my data" option in your account settings. To exercise any other right, contact us at privacy@vindiko.com.

6. Security

All data is transmitted over TLS 1.3. Passwords are stored as salted hashes and are never stored in plain text. We conduct periodic security reviews and promptly address any vulnerabilities.

7. Changes to This Policy

We may update this policy from time to time. We will notify registered users by email at least 14 days before any material change takes effect. Continued use of the service after that date constitutes acceptance of the updated policy.

8. Contact

For privacy-related enquiries, email privacy@vindiko.com. For general questions, use the contact form at vindiko.com/contact. Our registered address is Vindiko, Gedimino pr. 1, Vilnius, Lithuania, Reg. No. 306145823.

9. Lawful Basis for Processing

We process your personal data on the following legal bases under Article 6 of the GDPR: account registration and dispute processing — performance of a contract (Article 6(1)(b)), because processing is necessary to provide the service you requested; contact form submissions and operational communications — legitimate interests (Article 6(1)(f)), to respond to your enquiries and maintain the security and performance of the service; transactional emails (verification, account notifications) — performance of a contract (Article 6(1)(b)).

10. International Data Transfers

Some sub-processors we rely on are based outside the European Economic Area (EEA). Anthropic (AI processing) and Resend (email delivery) are based in the United States. Where personal data is transferred outside the EEA, we ensure appropriate safeguards are in place under Chapter V of the GDPR, including Standard Contractual Clauses (SCCs) approved by the European Commission. You can request a copy of the applicable safeguards by emailing privacy@vindiko.com.