This Privacy Policy (the Policy) explains how Aliona Varec, a natural person and the operator of the website (the Administration, we, us) collects, uses, stores and processes personal data when natural and legal persons (Users) use the website ntsel.lt (the Platform). By using the Platform, the User agrees to this Policy.
1. General provisions
1.1. This Policy has been prepared in accordance with Regulation (EU) 2016/679 (GDPR), the Law of the Republic of Lithuania on Legal Protection of Personal Data, and other applicable legislation.
1.2. The Administration undertakes to process personal data lawfully, fairly, transparently and only for clearly defined purposes.
1.3. This Policy applies to all Users regardless of their registration status.
2. Definitions
2.1. ‘Platform’ – the ntsel.lt website (including its app-like version installed on a device – PWA) used by Users to publish and browse real estate listings.
2.2. ‘User’ – a natural or legal person using the Platform.
2.3. ‘Personal Data’ – information that directly or indirectly identifies a User.
2.4. ‘Processing’ – any operation performed on personal data: collection, storage, use, transfer, deletion.
2.5. ‘Payment System’ – Stripe, used to process payments for services on the Platform.
2.6. ‘Rules’ – the rules for using the Platform, published at ntsel.lt/taisykles.
3. Data controller
Aliona Varec, natural person — operator and rights holder of the Platform
Location: Vilnius, Republic of Lithuania
Email: [email protected] · Tel.: +370 699 03777 · Website: https://ntsel.lt
4. Data processing principles
- Data is processed only to the extent necessary for the stated purposes
- Data is accurate and kept up to date
- Appropriate technical and organisational protection measures are applied
- Data is not retained longer than necessary
5. Data we collect
5.1. Registration data: email address and password; at the User's option – name, surname, phone number, photo (avatar).
5.2. Listing data: real estate descriptions, photographs, addresses, prices, contact information.
5.3. Financial data: payment card data processed by Stripe (stored solely within Stripe's systems under the PCI DSS standard).
5.4. Technical data: IP address, browser type, operating system, login time, cookies and similar technologies (localStorage), device data, security check (Cloudflare Turnstile) results; where the User has granted browser permission – browser notification (web push) subscription data.
5.5. Communication data: correspondence with the Administration, complaints, enquiries, messages between Users.
5.6. Publicly available data: from public sources, where necessary to verify listing authenticity.
5.7. Special categories of data: The Administration does not knowingly seek to collect special categories of personal data (data revealing racial or ethnic origin, political opinions, religious beliefs, health, sex life or sexual orientation) and asks Users not to include such data in listings or correspondence. If a User voluntarily publishes such data in a publicly accessible listing, it is treated as data manifestly made public by the User (Art. 9(2)(e) GDPR) and is processed only to the extent necessary for operating the Platform and enforcing content restrictions; the Administration does not use such data for profiling or any other purpose and may remove it from a public listing where necessary. If such data appears incidentally in private correspondence with the Administration or another User, this is not treated as the User's consent to its processing, and it is deleted as soon as technically feasible.
6. How we collect data
- Directly from the User – during registration, listing publication, or payment
- Automatically – via cookies and log files
- From third parties – Stripe, hosting providers, Google (sign-in with a Google account)
7. Purposes and legal bases
- Account creation and administration – performance of contract (Art. 6(1)(b) GDPR)
- Listing publication and management – performance of contract (Art. 6(1)(b) GDPR)
- Payment processing – performance of contract (Art. 6(1)(b) GDPR)
- Fraud prevention and security (including Cloudflare Turnstile checks) – legitimate interest (Art. 6(1)(f) GDPR)
- Prohibited content control (moderation) – legitimate interest (Art. 6(1)(f) GDPR)
- Notifications about account and listing events (by email and, where browser permission has been granted, via web push) – performance of contract (Art. 6(1)(b) GDPR)
- Marketing and newsletters – consent (Art. 6(1)(a) GDPR)
- Fulfilment of legal obligations – legal obligation (Art. 6(1)(c) GDPR)
8. Data retention
- Registration data – 1 year after the last login (before an account is removed for inactivity, the User is warned by email at least 30 days in advance)
- Listing content – while the account is active and up to 6 months after closure
- Payment data – 3 years after the transaction (within Stripe – per Stripe's policy)
- Communication data – up to 2 years after resolution
- Accounting records – 10 years under Lithuanian law
9. Prohibited content and consequences
9.1. It is prohibited to publish content related to political propaganda, extremism, terrorism, pornography, illegal trafficking of weapons or drugs, or any other content in violation of applicable law. A detailed list of prohibited content is provided in the Rules.
9.2. Upon detection of prohibited content, the account is immediately suspended and data may be passed to law enforcement authorities.
10. Profiling and automated decision-making
10.1. Listing content is currently reviewed by the Administration's moderators (humans). In the future, automated tools, including AI technologies, may be used for content review – Users will be informed of this through an update to this Policy.
10.2. The final decision to reject a listing or suspend an account is in all cases made by a human.
10.3. The Administration does not use automated decision-making that produces legal effects on the User and does not carry out profiling.
11. Third parties
- Stripe – payment processing (stripe.com/privacy)
- Hetzner Online GmbH (Germany) – server and data hosting services
- Cloudflare, Inc. – network security, traffic protection and automated request verification (Turnstile)
- Resend – sending transactional emails (registration confirmations, notifications)
- Google – where the User chooses to sign in with a Google account
- Google Ireland Limited – Google Analytics 4 audience statistics, only with the User's consent (see section 13)
- Law enforcement authorities – on lawful requests or court orders
- Debt collection agencies – if unpaid invoices for paid services arise, for debt administration and collection purposes
No marketing, profiling or advertising tracking tools are used. The only analytics tool is Google Analytics 4, enabled solely after the User consents in the cookie banner; consent can be withdrawn at any time (clause 13.4).
All data processors are bound by GDPR requirements and confidentiality obligations.
Some of the data processors listed above (for example, cloud service providers) may process data outside the European Economic Area (EEA). In such cases, the Administration ensures that the transfer is based on an adequacy decision of the European Commission, the European Commission's Standard Contractual Clauses (SCCs), or other appropriate safeguards under Chapter V of the GDPR.
12. Your rights
- Right to be informed about how data is processed
- Right of access to your data (a copy of your data can be downloaded in the account settings)
- Right to rectification of inaccurate data
- Right to erasure (‘right to be forgotten’)
- Right to restriction of processing
- Right to object to processing
- Right to data portability
- Right to withdraw consent at any time (including disabling web push notifications in browser or account settings)
- Right to lodge a complaint with the State Data Protection Inspectorate (www.vdai.lrv.lt)
Submit requests to: [email protected]
The Administration responds to User requests regarding the exercise of the rights listed in this section without undue delay, and in any event within 1 (one) month of receiving the request. Where necessary, taking into account the complexity and number of requests, this period may be extended by a further 2 (two) months, with the User informed in advance.
13. Cookies
13.1. The Platform uses necessary cookies and similar technologies (e.g., localStorage) required for its proper operation: maintaining the login session, security (Cloudflare) and remembering the User's preferences (language, theme). Necessary cookies do not require consent – the User is informed of their use.
13.2. With the User's consent, analytical cookies are used – Google Analytics 4 (provider: Google Ireland Limited). Their purpose is to understand how the Platform is used (number of visits, pages viewed, traffic sources, interactions with listings) and to improve the service. Data is processed in aggregate and the IP address is not stored; data may be transferred to the USA under safeguards approved by the European Commission (EU–US Data Privacy Framework, standard contractual clauses).
13.3. No analytical cookie is stored until the User selects "Accept" in the cookie banner. If "Essential only" is selected, none are stored.
13.4. Consent may be withdrawn at any time – the "Cookie settings" link in the site footer brings the banner back.
13.5. Advertising and profiling cookies are not used. The User can also manage or delete cookies in browser settings.
14. Data security
14.1. We apply technical and organisational measures: data encryption, restricted server access, secure transmission protocols.
14.2. Payment card data is processed exclusively through Stripe under the PCI DSS standard – the Administration does not store card data on its own servers.
14.3. Despite the measures taken, absolute data security cannot be guaranteed.
15. Minors
ntsel.lt is intended for persons aged 18 and over. We do not knowingly collect data from minors. If we discover that a minor has submitted data without parental consent, it is deleted immediately. This provision applies to natural person Users. Where the User is a legal entity, its authorised representative, by using the Platform, confirms that they are of legal age and duly authorised to act on the entity's behalf.
16. Policy changes
16.1. The Administration reserves the right to amend this Policy. Each version of the Policy is numbered and published with its effective date.
16.2. Users will be notified of material changes by email or platform notice at least 14 days before they take effect.
16.3. Continued use of the Platform after changes take effect constitutes acceptance of the updated Policy.
17. Contact
Aliona Varec | Vilnius, Lithuania
Email: [email protected] · Tel.: +370 699 03777
State Data Protection Inspectorate: www.vdai.lrv.lt