Privacy Policy

Last updated: February 13, 2025

1. Introduction

This Privacy Policy describes how UAB Pirmas Ragas ("we", "us", "our", or the "Company") collects, uses, shares, and protects your personal data when you visit our website https://apostolicdiet.com (the "Service") or use our mobile applications and related services.

We are committed to protecting your privacy and handling your data in an open and transparent manner. This Privacy Policy is provided in a layered format so you can navigate to the specific areas set out below.

Data Controller:
UAB Pirmas Ragas
Gedkanto g. 13, LT-14188 Vilnius, Lithuania
Email: hello@apostolicdiet.com

2. Data We Collect

We may collect the following categories of personal data:

2.1 Data You Provide to Us

  • Account and Profile Data: Name, email address, date of birth, gender, and other information you provide when creating an account or completing our personalization quiz.
  • Health and Wellness Data: Height, weight, dietary preferences, health goals, activity level, food allergies, and other wellness-related information you provide through the quiz or during your use of the Service.
  • Payment Data: Billing address, payment card details (processed by our third-party payment providers; we do not store full card numbers).
  • Communications: Any information you provide when contacting our support team, including email content and attachments.

2.2 Data Collected Automatically

  • Device and Technical Data: IP address, browser type and version, operating system, device type, unique device identifiers, time zone, and language preferences.
  • Usage Data: Pages viewed, links clicked, time spent on pages, referring URLs, and other actions taken on the Service.
  • Cookies and Similar Technologies: We use cookies, pixels, and similar tracking technologies. See Section 8 for details.

2.3 Data from Third Parties

  • Payment Providers: Transaction confirmation, subscription status.
  • Analytics Providers: Aggregated and anonymized usage data.
  • Advertising Partners: Information about your interactions with our advertisements on other platforms.

3. How We Use Your Data

We use your personal data for the following purposes:

  • Service Delivery: To provide, personalize, and improve our Service, including creating your customized diet and wellness plans.
  • Account Management: To create and manage your account, process payments, and manage subscriptions.
  • Communication: To respond to your inquiries, send service-related notices, and provide customer support.
  • Marketing: To send promotional emails and offers (with your consent, where required). You can opt out at any time.
  • Analytics and Improvement: To understand how users interact with our Service, identify trends, and improve our products and features.
  • Legal Compliance: To comply with legal obligations, resolve disputes, and enforce our agreements.
  • Security: To detect, prevent, and address fraud, abuse, and security issues.

4. Legal Basis for Processing (GDPR)

If you are located in the European Economic Area (EEA), United Kingdom, or Lithuania, we process your personal data based on the following legal grounds:

  • Contract Performance: Processing necessary to fulfill our contract with you (e.g., delivering your personalized plan, managing your subscription).
  • Consent: Where you have given us consent to process your data (e.g., marketing communications, health data processing). You may withdraw consent at any time.
  • Legitimate Interests: Where processing is necessary for our legitimate business interests (e.g., analytics, fraud prevention, service improvement), provided these interests are not overridden by your rights.
  • Legal Obligation: Where processing is necessary to comply with a legal obligation (e.g., tax records, regulatory requirements).

5. Data Sharing and Disclosure

We may share your personal data with the following categories of recipients:

  • Payment Processors: Stripe, Braintree, PayPal, Primer, and other payment service providers who process your transactions. They are independent data controllers for payment data.
  • Analytics and Advertising Partners: Google Analytics, Facebook Pixel, and similar services for analytics and advertising purposes.
  • Email Service Providers: To send you transactional and marketing emails on our behalf.
  • Cloud Hosting Providers: Our Service is hosted on secure cloud infrastructure.
  • Legal and Regulatory Authorities: When required by law, court order, or to protect our legal rights.
  • Business Transfers: In connection with a merger, acquisition, or sale of all or a portion of our assets.

We do not sell your personal data to third parties.

6. International Data Transfers

Your personal data may be transferred to and processed in countries outside of the European Economic Area (EEA). When we transfer data outside the EEA, we ensure adequate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission.
  • Adequacy decisions by the European Commission for certain countries.
  • Other appropriate safeguards as required by applicable data protection laws.

You may request a copy of the safeguards we use by contacting us at hello@apostolicdiet.com.

7. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including to satisfy any legal, accounting, or reporting requirements.

Specific retention periods:

  • Account data: Retained for the duration of your account plus 3 years after deletion or last activity.
  • Payment and transaction data: Retained for up to 7 years as required by tax and accounting regulations.
  • Marketing data: Retained until you withdraw consent or unsubscribe.
  • Technical logs: Retained for up to 12 months.

8. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to collect and track information about your use of our Service. Cookies are small data files stored on your device.

Types of cookies we use:

  • Strictly Necessary Cookies: Required for the Service to function properly (e.g., session management, security).
  • Performance/Analytics Cookies: Help us understand how visitors interact with the Service (e.g., Google Analytics).
  • Marketing Cookies: Used to deliver relevant advertisements and track advertising campaign performance (e.g., Facebook Pixel).
  • Functional Cookies: Remember your preferences and settings for a better experience.

You can control cookies through your browser settings. Disabling certain cookies may affect the functionality of our Service.

9. Your Rights (GDPR)

If you are located in the EEA, UK, or Lithuania, you have the following rights under the General Data Protection Regulation (GDPR):

  • Right of Access: You can request a copy of the personal data we hold about you.
  • Right to Rectification: You can request correction of inaccurate or incomplete personal data.
  • Right to Erasure ("Right to be Forgotten"): You can request deletion of your personal data in certain circumstances.
  • Right to Restrict Processing: You can request that we limit the processing of your personal data.
  • Right to Data Portability: You can request to receive your personal data in a structured, commonly used, machine-readable format.
  • Right to Object: You can object to the processing of your personal data based on legitimate interests or for direct marketing purposes.
  • Right to Withdraw Consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
  • Right to Lodge a Complaint: You have the right to lodge a complaint with your local data protection supervisory authority.

To exercise any of these rights, please contact us at hello@apostolicdiet.com. We will respond to your request within 30 days.

10. Data Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:

  • Encryption of data in transit (TLS/SSL) and at rest.
  • Access controls limiting who can access personal data.
  • Regular security assessments and monitoring.
  • Secure payment processing through PCI-DSS compliant providers.

While we strive to protect your personal data, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.

11. Children's Privacy

Our Service is not intended for individuals under the age of 18. We do not knowingly collect personal data from children under 18. If you are a parent or guardian and believe your child has provided us with personal data, please contact us at hello@apostolicdiet.com and we will take steps to delete such data.

12. Third-Party Links

Our Service may contain links to third-party websites, services, or applications. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party services you access through our Service.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last updated" date above. For significant changes, we may also notify you by email.

Your continued use of the Service after changes are posted constitutes your acceptance of the revised Privacy Policy.

14. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data processing practices, please contact us:

UAB Pirmas Ragas
Gedkanto g. 13, LT-14188 Vilnius, Lithuania
Email: hello@apostolicdiet.com

If you are not satisfied with our response, you have the right to lodge a complaint with the State Data Protection Inspectorate of the Republic of Lithuania (https://vdai.lrv.lt) or your local supervisory authority.