Privacy Policy

Last updated: April 2026 — Version 2026-04

1. Data Controller

WeldLit UAB, registered in the Republic of Lithuania, is the data controller for all personal data processed through the WeldLit Marketplace platform. Contact: privacy@weldlit.eu

2. What Data We Collect

  • Company registration details: company name, VAT number, address, country
  • Contact person information: full name, position, phone, email
  • Account credentials: email address and bcrypt-hashed password
  • Session data: authentication tokens stored in HTTP-only cookies
  • Consent record: timestamp and IP address at registration, terms version accepted
  • Marketing preference: whether you opted in to receive product updates
  • RFQ and project data: uploaded files, messages, proposal details
  • Equipment and photo uploads associated with your company profile

3. Legal Basis for Processing

  • Contract performance (Art. 6(1)(b)) — account management, RFQ delivery, invoicing
  • Legitimate interest (Art. 6(1)(f)) — fraud prevention, platform security
  • Consent (Art. 6(1)(a)) — marketing emails (opt-in only, withdrawable at any time)
  • Legal obligation (Art. 6(1)(c)) — tax and accounting records retention

4. Cookies

We use only essential cookies:

  • mp_session — authentication session (HTTP-only, expires on logout)
  • mp_ui_lang — your preferred UI language (30 days)

We do not use analytics, advertising, or third-party tracking cookies.

5. Data Retention

  • Active accounts: data retained for the duration of the account
  • Deleted accounts: soft-deleted immediately, purged after 30 days
  • Financial records: retained 7 years per Lithuanian tax law (Buhalterinės apskaitos įstatymas)
  • Uploaded files: configurable per category (see File Retention Rules)

6. Your Rights (GDPR)

You have the right to:

  • Access your data — visit Account & Privacy → Download Data Export
  • Rectify data — edit your profile at any time
  • Erasure (right to be forgotten) — delete your account at Account & Privacy
  • Data portability — JSON export available in Account & Privacy
  • Withdraw consent — unsubscribe from marketing at any time
  • Lodge a complaint with the State Data Protection Inspectorate of Lithuania (VDAI): vdai.lrv.lt

To exercise any right, email privacy@weldlit.eu. We respond within 30 days.

7. Data Transfers

All data is stored on servers located in the European Union. We do not transfer personal data to third countries.

8. Third Parties

We do not sell or share personal data with third parties for marketing. Email delivery is handled by a transactional email provider operating under GDPR-compliant data processing agreements.

9. Changes to This Policy

We will notify registered users by email when material changes are made. The version date at the top of this page reflects the last update.