Last update:
10 September 2026

This page explains what personal data Fiddle.Digital collects, why we hold it, and what you can ask us to do with it. It covers our website and the business emails we send.

We have tried to write it in plain language. If anything here is unclear, write to us and we will explain it.

Privacy Policy

Who is responsible for your data

The data controller is Dmytro Troshchylo, operating under the business name Fiddle.Digital.

Individuali veikla pagal pažymą
Pažymos Nr. 1350640
Laumenų g. 4-23, Vilnius, Lithuania

Email: hello@fiddle.digital

We have not appointed a Data Protection Officer (DPO), as we are not required to do so under the GDPR.

If you have any questions about how we handle your personal data, or want to exercise any of your data protection rights, contact us at hello@fiddle.digital.

Who is responsible for your data
Server Logs

Our hosting provider records standard server logs, which may include your IP address and other basic technical information. These logs are used for security, troubleshooting and reliable operation of the website.

Analytics

We use two analytics tools on this site.

  • PostHog (EU hosting, eu.i.posthog.com) records information about how the website is used, such as the pages you visit, your referrer, browser and device type, and an approximate location derived from your IP address. It is configured to minimise the collection of personal data and does not intentionally identify you as an individual.
  • Google Analytics (measurement ID G-M7JNWG18P3) records statistics about website usage. It is only activated after you consent to analytics cookies through the cookie banner. If you decline analytics cookies, Google Analytics is not initialised and its cookies are not set.

The legal basis for analytics is your consent under Article 6(1)(a) GDPR.

You can change or withdraw your cookie choices at any time through the Cookie preferences link in the footer.

Cookies and Local storage
WhatPurposeType
fiddle_localeRemembers your selected languageNecessary
cookies-accept, cookieConsent, gaAcceptRemembers your cookie preferencesNecessary
PostHog identifiersDistinguishes visits for usage statisticsAnalytics
Google Analytics cookies (_ga, _ga_*)Website usage statisticsAnalytics

The consent record is stored in your browser's local storage rather than in a cookie. It serves the same purpose of remembering your choice so that we do not ask you again.

We do not use advertising or cross-site tracking cookies, and we do not run third-party advertising scripts.

Other things the site loads

The cookie banner loads fonts from Google Fonts (fonts.googleapis.com, fonts.gstatic.com). Your browser may therefore send a request to Google that includes your IP address.

Images and video on the site are served from our own media server at media.fiddle.digital.

If you contact us

If you write to us, or fill in the form on our Connect page, we hold the information you choose to provide.

This may include your name, email address, company name, project description, deadline, selected service and budget range, answers you provide in the project configurator, and any files you attach.

We use this information to respond to you, discuss your enquiry, and, where relevant, take steps towards working together.

The legal basis is our legitimate interest in responding to correspondence and handling enquiries. If you are considering entering into a contract with us, processing may also be necessary to take steps at your request before entering into that contract under Article 6(1)(b) GDPR.

If we sent you an email

If we contact you by email, we may process the following information:

What we hold

Your name, business email address, company name, company's public website, and a note identifying the source from which we obtained your contact details. We may also keep a brief note about your company or website that we prepared while assessing whether our services may be relevant to you.

We do not intentionally collect or maintain sensitive personal information as part of this outreach.

Where we found you

We use publicly available business sources, which may include your company's website, public company directories, public professional profiles, industry publications, or public award listings.

We identify the source of your contact details in the email where practicable.

We only use contact details published in a professional or business context. We do not use private or personal contact details, and we do not guess or generate email addresses.

What we do not do
  • We do not buy, rent or exchange contact lists.
  • We do not use data enrichment services.
  • We do not build profiles or score leads.
  • We do not track your behaviour across websites or over time.
  • We do not add you to a mailing list or send you a sequence of automated marketing emails.
Our legal basis

We rely on legitimate interest under Article 6(1)(f) GDPR to introduce our professional services to businesses that may reasonably benefit from them.

Before sending an email, we consider whether the contact is appropriate, whether the message is relevant to the recipient's professional role, and whether our interests are outweighed by the recipient's rights and freedoms.

You have the right to object to this processing at any time. If you object, we will stop contacting you.

How to make it stop

Reply to the email with "no". No reason is required. You can also write to hello@fiddle.digital.

If you object, we will keep your email address on a suppression list solely to ensure that we do not contact you again.

If you become a client

If you become a client, we process information necessary to provide our services and manage our business relationship.

This may include your name, contact details, company details, correspondence, project materials, project-related information, and billing records.

We use this information to provide and manage our services, communicate with you, deliver project work, and manage billing and accounting.

The legal basis is the performance of our contract under Article 6(1)(b) GDPR. For invoices, accounting records and other information we are legally required to retain, the legal basis is our legal obligation under Article 6(1)(c) GDPR.

Who else sees your data

We use third-party providers to operate our website, communicate with you, manage projects, and provide our services.

PurposeProvider
Website hosting and mediaDigitalOcean
Contact form deliverySlack Technologies, LLC
Product analyticsPostHog
Website analyticsGoogle Analytics
Web fontsGoogle Fonts
Email and business accountsGoogle

When you submit the contact form, the information you provide may be sent to our private Slack workspace, where it is accessed by the people responsible for handling enquiries.

These providers process personal data on our behalf where applicable. We do not sell, rent, or otherwise disclose your personal data for their own marketing or advertising purposes.

Some providers may process data outside the European Economic Area (EEA). Where required, we use appropriate safeguards for international data transfers in accordance with the GDPR.

How long we keep it

We keep personal data only for as long as necessary for the purposes described in this policy or to meet our legal obligations.

DataRetention period
Contact details where you did not reply12 months from the date we contacted you
Contact details where you replied24 months from the date of submission
Client records and correspondenceFor the duration of the relationship and 24 months afterwards
Invoices and accounting recordsFor the period required by applicable tax and accounting laws
Suppression list after you objectUntil there is no longer a need to retain it to respect your objection

When the applicable retention period expires, we delete the data unless we have a legal obligation or another lawful reason to retain it.

Your rights

Under the GDPR, you have the right to:

  • Access the personal data we hold about you and request a copy of it.
  • Correct inaccurate or incomplete personal data.
  • Delete your personal data, where the legal requirements for deletion are met.
  • Restrict the processing of your personal data in certain circumstances.
  • Receive your personal data in a structured, commonly used and machine-readable format, where the right to data portability applies.
  • Object to processing based on legitimate interests. You may object to direct marketing at any time.

To exercise your rights, contact us at hello@fiddle.digital.

We will respond to your request within one month. This period may be extended by up to two further months where permitted by the GDPR, in which case we will inform you of the extension.

We do not use personal data for automated decision-making or profiling that produces legal or similarly significant effects.

If you are not satisfied with how we handle your personal data or your request, you have the right to lodge a complaint with a data protection supervisory authority.

You may contact the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija, VDAI) in Lithuania, or the supervisory authority in the country where you live or work.

Security

We take reasonable technical and organisational measures to protect personal data against unauthorised access, loss, misuse, alteration, or disclosure.

Access to personal data is limited to people who need it for their work. Accounts used to access our systems are protected with appropriate security measures, including two-factor authentication where available. Data is encrypted in transit where supported by the relevant service.

No method of storing or transmitting data is completely secure. If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within the timeframe required by the GDPR and notify affected individuals where required by law.

Changes to this policy

We may update this Privacy Policy when our services, website, data processing activities, or legal obligations change.

The latest version will always be published on this page. We will update the date at the top of the policy when changes are made.

Where a change materially affects how we process personal data, we will provide additional notice where required by law.