FREE SHIPPING OVER €75KNITTED IN LITHUANIA100% PURE LINENMADE TO LASTMADE TO ORDERFREE SHIPPING OVER €75KNITTED IN LITHUANIA100% PURE LINENMADE TO LASTMADE TO ORDERFREE SHIPPING OVER €75KNITTED IN LITHUANIA100% PURE LINENMADE TO LASTMADE TO ORDERFREE SHIPPING OVER €75KNITTED IN LITHUANIA100% PURE LINENMADE TO LASTMADE TO ORDER

Privacy Policy

Last updated: 25 April 2026

EGLESNA respects your privacy. This Policy explains what personal data we collect when you visit eglesna.design, place an order, or contact us — and how we protect it under the EU General Data Protection Regulation (GDPR) and Lithuanian law.

1. Who is the data controller?

The data controller (per GDPR Art. 4(7)) is:

  • Trader: Eglė Česnauskienė, individual business activity (individuali veikla), trading as EGLESNA
  • Individual activity certificate No.: 042024 (issued 2012-02-29)
  • VAT (PVM) ID: LT100006684913
  • Registered address: Platelių g. 17, Babrungo km., Babrungo sen., LT-90108 Plungės raj. sav., Lithuania
  • Privacy & data-subject requests: [email protected]

EGLESNA is a sole trader and is not required to appoint a Data Protection Officer under GDPR Art. 37. The trader is the single point of contact for all privacy matters.

2. What personal data we collect

  • When you place an order: first and last name, billing and shipping address, email, phone number (if provided), order contents, IP address, browser/device user-agent.
  • When you contact us by email: your email address and the contents of your message.
  • When you visit the site: standard server access logs (IP, URL, timestamp) and strictly-necessary cookies. See our Cookie Policy.

We do not collect special-category data (health, religion, political opinions etc.). We do not see or store your card number — Stripe handles all payment data directly and we receive only a non-sensitive transaction reference.

3. Why we process it (legal basis under GDPR Art. 6)

  • To fulfil your order — Art. 6(1)(b): contract performance.
  • To meet Lithuanian and EU tax / accounting law (invoicing, VAT records) — Art. 6(1)(c): legal obligation.
  • To prevent fraudulent transactions — Art. 6(1)(f): legitimate interests, balanced against your rights.
  • To analyse site security events (failed login attempts, attack patterns) — Art. 6(1)(f): legitimate interests.

4. Sub-processors (third parties handling your data on our behalf)

ProviderPurposeLocation
Stripe Payments Europe Ltd.Payment processing (we never see your full card data)Ireland (EU)
Sendinblue SAS / BrevoOrder confirmation and admin notification emailsFrance (EU)
Cloudflare Ireland Ltd.Site delivery, DDoS protection, email routing for our domainIreland (EU)
Hetzner Online GmbHVM hosting and automated infrastructure backupsGermany (EU)
Defiant Inc. (Wordfence)Site security monitoring and brute-force protectionUSA (EU Standard Contractual Clauses)

Transfers to the United States are covered by the EU Standard Contractual Clauses adopted by the European Commission. EU-based providers do not transfer your data outside the EEA in the ordinary course of business.

5. How long we keep your data

  • Order records: 24 months after order completion the personal-data fields are anonymised in our shop database. The minimum information required by Lithuanian accounting law (invoice records) is retained for the legally-required 10 years and then deleted.
  • Email correspondence: 12 months from the last reply, then deleted unless an active matter requires longer retention.
  • Server access logs (IPs): rotated daily and deleted after 14 days.
  • Application backups: 14 days locally on the server.
  • Infrastructure backups (Hetzner): 7-day rolling, then automatically overwritten.
  • Strictly-necessary cookies: session-only or up to 12 months — see Cookie Policy.

6. Your rights under GDPR

You have the right to:

  • Access your personal data we hold (Art. 15)
  • Have inaccurate data corrected (Art. 16)
  • Have your data erased (Art. 17) — note that orders required by tax law cannot be erased before the legal retention period ends
  • Restrict our processing (Art. 18)
  • Receive your data in a portable format (Art. 20)
  • Object to processing based on legitimate interests (Art. 21)
  • Withdraw consent at any time where processing is based on consent (Art. 7(3))

To exercise any of these rights, email [email protected] with your request and (if applicable) your order number. We respond within 30 days.

You also have the right to lodge a complaint with the Lithuanian Data Protection Authority — Valstybinė duomenų apsaugos inspekcija (vdai.lrv.lt).

7. Security measures

  • All traffic is encrypted with TLS 1.2+ via Cloudflare; HSTS is enforced.
  • Card data is tokenised by Stripe and never reaches our servers.
  • Administrator accounts use two-factor authentication.
  • The site is protected by Wordfence and Cloudflare WAF rules.
  • The server runs in an EU data centre (Germany) with automated backups.

8. Cookies

We use only strictly-necessary cookies by default — these are required to operate the cart and checkout. Any analytics or marketing cookies are loaded only after you give explicit consent via our cookie banner. See the Cookie Policy for the full list.

9. Changes to this Policy

We may update this Policy to reflect changes to our services or to comply with new law. The “last updated” date at the top will reflect any change. Material changes will be announced on our homepage.

Scroll to Top