Public document · Privacy Policy
Investor dataroomUAB Baltic Freya

Investor dataroom

Privacy Policy

Last Updated: 18 February 2026

1. Introduction

UAB "Baltic Freya" ("we", "us", or "our") operates this investment data room. We are committed to protecting your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and applicable Lithuanian data protection laws.

This Privacy Policy explains how we collect, use, store, share, and protect your personal data when you access our platform. By using this service, you acknowledge that you have read and understood this policy.

2. Data Controller

The controller of your personal data is:
UAB Baltic Freya
Registration Code: 305174399
Address: 19 Tulpiu st., Garliava 53250, Lithuania
General Inquiries: info@freyacultivation.com
Data Protection Contact: Vilmantas Rastutis, vilmantas@freyacultivation.com

3. Information We Collect

To provide access to the confidential Data Room, we collect:

  • Identity Data: Full name.
  • Contact Data: Work email address.
  • Professional Data: Company name, company website.
  • Preference Data: Investment scope and timeline preferences.
  • Authentication Data: Hashed password (never stored in plaintext), session tokens.
  • Usage Data: Logs of documents viewed, access times, and IP addresses (for security auditing).

We may also collect additional information that you voluntarily submit to us via email or other communication channels during the course of your engagement.

4. How We Process Your Data

Your data is processed through our technology infrastructure as follows:

  • Authentication: When you create an account or sign in, your credentials are processed by Supabase Auth, which handles password hashing (bcrypt), session management, and token issuance. Passwords are never stored in plaintext.
  • Database Storage: Your profile data (name, email, company) is stored in a Supabase PostgreSQL database. This data is encrypted at rest and in transit.
  • Email Delivery: Transactional emails (account verification, password resets, magic links, invitations) are sent via Resend's email delivery service.
  • Application Hosting: The platform is hosted on Vercel, which may process your IP address and basic request metadata for CDN routing and security purposes.

5. Purpose and Legal Basis

We process your personal data for the following purposes and legal bases under GDPR Article 6:

Purpose
Account creation and authentication
Legal Basis
Contractual necessity
Purpose
Managing Data Room access
Legal Basis
Contractual necessity
Purpose
Investment-related communications
Legal Basis
Legitimate interest
Purpose
Security monitoring and audit logging
Legal Basis
Legitimate interest

6. Data Sharing

Your personal data may be shared with the following parties:

6.1 Sub-processors (Technology Providers)

We use the following technology providers to process your data:

Provider
Supabase (EU)
Purpose
Authentication, database
Data Processed
Email, password hash, profile data, session tokens
Provider
Vercel
Purpose
Application hosting, CDN
Data Processed
IP address, request metadata
Provider
Resend
Purpose
Email delivery
Data Processed
Email address, email content

We do not sell, trade, or otherwise share your personal data with third parties for marketing or advertising purposes.

7. Data Retention

We will retain your personal data only for as long as you are engaged in researching Freya Farms for an investment opportunity. Once your engagement concludes or you request deletion, your data will be removed from all active systems within 30 days. Backup systems may retain encrypted copies for up to 90 days for disaster recovery purposes.

8. Cookies

This platform uses essential cookies only, required for authentication and session management. These cookies are strictly necessary for the platform to function and cannot be disabled.

  • sb-access-token: Supabase session authentication token
  • sb-refresh-token: Session refresh token for maintaining login state

We do not use analytics cookies, tracking pixels, or any third-party advertising cookies.

9. Data Security

We implement appropriate technical and organisational measures to protect your data:

  • All data is encrypted in transit using TLS 1.2+
  • Database data is encrypted at rest (AES-256)
  • Passwords are hashed using bcrypt with appropriate cost factor
  • Role-based access control limits data access to authorised personnel
  • Regular security audits and dependency updates

10. Your Rights

Under the GDPR, you have the right to:

  • Access: Request a copy of your personal data
  • Rectification: Request correction of inaccurate data
  • Erasure: Request deletion of your profile ("Right to be Forgotten")
  • Restriction: Request restriction of processing
  • Portability: Receive your data in a portable format
  • Objection: Object to processing based on legitimate interest
  • Withdraw consent: Where processing is based on consent

You can exercise your right to erasure directly through Configuration → Profile Deletion in your dashboard. For all other rights or to file a complaint, contact our Data Protection Officer at vilmantas@freyacultivation.com.

You also have the right to lodge a complaint with the Lithuanian State Data Protection Inspectorate (vdai.lrv.lt).

11. International Transfers

Our primary data processing infrastructure (Supabase) is hosted within the European Union. Some sub-processors (Vercel, Resend) may process data in the United States under the EU-US Data Privacy Framework or Standard Contractual Clauses, ensuring an adequate level of data protection as required by GDPR Chapter V.

12. Contact

For any privacy-related questions or requests, please contact:
Vilmantas Rastutis, Data Protection Contact
Email: vilmantas@freyacultivation.com
General inquiries: info@freyacultivation.com