Controller and publisher
Legiscope UAB is the controller for the processing described here and the professional publisher of this website. The details below identify the responsible legal entity, publication director and website host.
This notice covers the public website, the contact form and correspondence, privacy-rights handling, and the public demonstration-booking flow. Legiscope is the controller for these website processing operations only.
The Legiscope application follows a different logic: for the personal data customers manage there, Legiscope acts as a processor, under the Terms of Service and the Data Processing Agreement.
Legiscope UAB
- Legal registration
- Register of Legal Entities of the Republic of Lithuania · company code 304581221
- Registered office
- Laisvės pr. 60-1107, LT-05120 Vilnius, Lithuania
- VAT identification
- LT100011142510
- Publication director
- Thiébaut Devergranne
- Website hosting
- Amazon Web Services EMEA SARL · 38 Avenue John F. Kennedy, L-1855 Luxembourg · +352 2789 0057
- Privacy contact
- To reduce automated address harvesting and spam, contact us directly through the privacy form.
Processing activities
Each card describes one processing activity. The common request procedure is stated once in “How to exercise your rights”; the final row of each card identifies the rights and choices specific to that activity.
If a colleague gives us your details in an enquiry, or a person booking a demonstration identifies another attendee, we provide or link to this notice at our first communication with you unless you already have the information or an Article 14 GDPR exception applies.
No processing activity described here produces a decision with legal or similarly significant effects solely by automated means. The reCAPTCHA risk assessment used to protect public forms is explained in P-04.
Website delivery and security
- Why and who
- Deliver requested pages, maintain availability, prevent abuse and diagnose faults. This concerns website visitors and the devices requesting public resources.
- Data and source
- Your device and network services supply the IP address, request time and address, referrer where present, browser, device and protocol details, and response, error or security-event data.
- Basis and necessity
- Article 6(1)(f) GDPR — legitimate interests in operating and securing a reliable website. Connection data is generated automatically and is necessary to return the requested content.
- Recipients and transfers
- Amazon Web Services provides delivery and infrastructure. Global edge delivery or support access is covered, where required, by the AWS DPA and 2021 EU Standard Contractual Clauses.
- Retention
- Request data is kept only through the configured operational period needed for delivery, security monitoring and fault investigation. A record attached to a documented incident or claim is separated from routine logs and deleted when that incident and any applicable claim period close.
- Rights for this activity
- Access, rectification, erasure, restriction and objection may apply. Portability does not apply because this processing is not based on consent or contract.
Business and general enquiries
- Why and who
- Answer and follow up sales, procurement, security or general enquiries. This concerns the sender and any business contacts identified in the correspondence.
- Data and source
- You, a colleague or your organisation supplies names, professional contact and role details, the message, subject, attachments and ordinary correspondence metadata.
- Basis and necessity
- Article 6(1)(f) GDPR — legitimate interests in answering professional enquiries and managing prospective relationships. Article 6(1)(b) applies only where the individual is personally the prospective contracting party and requests pre-contract steps. A return contact and enough context are necessary; everything else is optional.
- Recipients and transfers
- Google Workspace provides correspondence services and may use global processing or support locations. Restricted transfers follow its data-processing terms and applicable EU Standard Contractual Clauses.
- Retention
- Prospective-business correspondence is kept for up to three years after the last meaningful contact. Contractual records or correspondence needed for a legal obligation or claim follow the applicable contract, accounting or limitation period.
- Rights for this activity
- Access, rectification, erasure, restriction and objection may apply. Portability applies only to data you provided that is processed automatically under Article 6(1)(b).
Demonstration booking and follow-up
- Why and who
- Show live availability, then create, administer and follow up a requested product demonstration. This concerns visitors who open the booking page, people who book and any attendees they include.
- Data and source
- Loading availability sends the requested date window and ordinary connection metadata, including the IP address, to the booking endpoint. If you book, you provide the required name, work email and selected time, plus an optional organisation and note; calendar and meeting data are then created.
- Basis and necessity
- Article 6(1)(f) GDPR — legitimate interests in showing availability and administering a requested professional meeting. Connection data is necessary to return available times; name, work email and time are necessary to book. Organisation and message are optional, and booking creates no account, purchase or commitment.
- Recipients and transfers
- AWS handles availability and booking through an endpoint in us-east-1. Google Workspace and Calendar handle correspondence and meeting details. Restricted transfers use the applicable provider DPA and 2021 EU Standard Contractual Clauses; safeguard information may be requested through the privacy form.
- Retention
- Booking and prospect follow-up records are kept for up to three years after the meeting or last meaningful contact. A record needed for an established contract, legal obligation or claim follows the applicable contract, accounting or limitation period.
- Rights for this activity
- Access, rectification, erasure, restriction and objection may apply. Portability does not apply because this activity is based on legitimate interests.
reCAPTCHA protection for public forms
- Why and who
- Protect the contact and demonstration-booking forms from automated abuse. This concerns people and devices that proceed to either protected form.
- Data and source
- Your device, browser, network and interaction supply the IP address and risk signals. Google creates the reCAPTCHA token, assessment and _GRECAPTCHA cookie.
- Basis and necessity
- The GDPR basis is Article 6(1)(f): legitimate interests in protecting public forms and service availability. Separately, Legiscope relies on the strictly-necessary terminal-access exemption because reCAPTCHA is limited to securing a form the visitor has chosen to use. Any broader terminal use would require prior consent.
- Recipients and transfers
- Google acts as processor for reCAPTCHA Customer Data under the Google Cloud terms. Global processing and restricted transfers follow the Cloud DPA and applicable EU Standard Contractual Clauses.
- Retention
- The form uses the token for the protected submission and does not reuse it for marketing. Google deletes Customer Data under the reCAPTCHA service and Cloud DPA lifecycle; after a complete deletion instruction, the Cloud DPA allows up to 180 days for deletion. The _GRECAPTCHA cookie follows the service lifetime and may be cleared through browser controls.
- Rights for this activity
- Access, rectification, erasure, restriction and objection may apply; portability does not. The risk assessment may stop an abusive-looking submission, but it does not produce a legal or similarly significant decision about you.
Privacy-rights requests and complaints
- Why and who
- Authenticate where necessary, investigate and answer a privacy request or complaint, and retain proportionate handling evidence for the requester or authorised representative.
- Data and source
- You, your representative and relevant systems provide contact details, the request and correspondence, lookup information, proportionate verification or authority evidence, investigation notes and the response.
- Basis and necessity
- Article 6(1)(c) GDPR for rights and accountability obligations; Article 6(1)(f) for legal-claim evidence. Enough information to locate the data and authenticate the requester is necessary; less intrusive verification is preferred.
- Recipients and transfers
- Relevant providers, advisers and the competent authority or court may assist where necessary. Google Workspace correspondence uses its data-processing terms and applicable Standard Contractual Clauses; the underlying activity’s safeguards otherwise apply.
- Retention
- The request and response record is kept for five years after closure as accountability and legal-claim evidence. Additional identity evidence is deleted when verification is complete unless it remains necessary for a dispute or binding legal requirement.
- Rights for this activity
- Access, rectification and restriction may apply. Erasure and objection apply only to the legal-claim portion based on legitimate interests, not where retention is required to comply with a legal obligation. Portability does not apply.
Cookies and browser storage
The reviewed website does not load an advertising or audience-analytics runtime and does not use browser storage to build an advertising profile or follow visitors across websites. The security technology below is limited to the contact and demonstration-booking forms.
_GRECAPTCHA
- Technology
- Cookie and associated device access
- When used
- When reCAPTCHA executes for a contact-form or demonstration-booking submission
- Purpose
- Security, fraud and automated-abuse prevention
- Consent position
- Strictly-necessary security exemption for the requested protected submission; consent would be required before any broader use
- Lifetime
- Google-controlled service lifetime; removable through browser controls
Recipients, transfers and safeguards
Access is limited by role and purpose. Legiscope uses Amazon Web Services for website and booking infrastructure, Google Workspace for professional correspondence and appointments, and Google reCAPTCHA to protect the contact and booking forms. Their operational boundaries are described in the public provider register.
Legiscope does not sell the personal data covered by this notice. A professional adviser or public authority receives information only where advice, a legal claim or a binding legal requirement makes the disclosure necessary.
For a restricted transfer under Chapter V GDPR, the provider terms identified for the applicable processing activity incorporate the relevant 2021 EU Standard Contractual Clauses. A person may use the contact page to ask for information about the safeguard and a copy of the applicable clauses, subject to protection of confidential information.
How to exercise your rights
The final row of each processing-activity card identifies the rights relevant to that activity. Where processing is based on legitimate interests, you may object on grounds relating to your particular situation; Legiscope will stop unless it demonstrates overriding compelling grounds or needs the data for a legal claim.
None of the activities described here relies on consent as its GDPR legal basis. If Legiscope later introduces an optional terminal technology requiring consent, it must remain disabled until a valid choice is made and withdrawing that choice must be as easy as giving it.
Legal framework and changes
This notice applies the transparency requirements of the GDPR and Lithuania’s supplementary data-protection rules. The controller and publisher section identifies the legal entity, registration, office, publication director and website host. Terminal access is assessed under the Lithuanian Electronic Communications Law and, for users in France, Article 82 of the French Data Protection Act.
If Legiscope intends to use personal data for a materially different purpose, it will provide the information required for that further processing before it begins. This notice will also be updated when a provider, purpose, data category, transfer or retention rule changes materially. The review date at the top identifies the current version.