IV Discover Privacy Notice
This is the formal privacy notice for IV Discover. The short “Your data” page and the notice shown before registration summarise it; this document is the full version.
Version 0.4 · Last updated 15 September 2026 · Effective 15 September 2026
Shorter summary: Your data
1. Who we are
Industrial Visibility is an independent, industry-led initiative operated by Darius Užkuraitis under individual activity registered in Lithuania. Industrial Visibility is not a separate legal entity.
Industrial Visibility is not a government institution, and IV Discover is not a government-operated information system, a Ministry of National Defence system or a Lithuanian Armed Forces system.
IV Discover is a service operated within the initiative. The current IV Discover Open Pilot is a non-commercial pilot iteration used to validate the concept and improve the service with real organisations. This describes the current iteration and does not define any future commercial model.
Organisations that participate in, support or advise the initiative are not data controllers merely because of that participation.
2. Who is legally responsible (Data Controller)
The Data Controller is Darius Užkuraitis. You can reach the controller at contact@industrialvisibility.org, which is the contact route for all privacy and data-protection matters.
- Legal operating form
- Individual activity registered in Lithuania
- Registration document
- Certificate of Registration of Resident's Individual Activity FR0468
- Registration No.
- 1406969
- Registered activity
- Computer infrastructure, data processing, hosting and related activities
- EVRK / NACE activity code
- 631000
- Country
- Lithuania
- Jurisdiction
- European Union
3. What this notice covers
Information processed in the IV Discover application and in the operation of the IV Discover Open Pilot. It does not cover your own systems, third-party websites linked from organisation profiles, or information your organisation publishes elsewhere.
4. Organisation information and personal data
IV Discover is mainly a service for describing and discovering organisations. Most of what you enter — organisation name, website, description, products and services, capabilities, affiliations, cooperation interests, country and administrative area — is information about an organisation, not about you personally.
Some information is personal data: your account and profile details, and organisation information that identifies a person, such as a named contact or a personal e-mail address. Where information relates to an identifiable person, this notice applies to it.
Where a contact person is needed, please use a role-based or general organisation e-mail address wherever possible rather than a named individual's personal contact details. If you do provide the professional contact details of another person, we process them in our legitimate interest in operating a functioning organisation-discovery service, and that person may contact us at the address above to ask what we hold, to object, or to have the details corrected or removed. Information being publicly available elsewhere is not by itself our legal basis for processing it.
Capability classification against the Industrial Visibility taxonomy describes what an organisation can do. It is not used to build a profile about you as an individual.
5. What we process
- Your account and profile — e-mail address, authentication data (your password is stored only as a hash, or a link to your Google account if you sign in with Google), sign-in times, and the profile details you provide: name, job title, headline, interface language, time zone and notification preferences. Profile photo upload is not available during the Open Pilot.
- Organisation information you provide — identification and registration data, contact e-mail, website, description, market presence, cooperation interests, declared activity classification, declared country and administrative area (no street address or precise coordinates are required), capabilities, services, affiliations, and files you upload such as a logo, cover image or documents.
- Registration and review records — your drafts, submitted versions and their status history; the Organisation Declaration and Administrative Review Acknowledgement (which account, which organisation, which version and when — no IP address is recorded); administrative review decisions and notes.
- Connect records — participation opt-in, connection requests and their progress, including which account acted.
- Accountability records — append-only provenance and audit entries showing which account performed which action, on what, and when.
- Enquiries — the name, e-mail address, organisation, role and message you send us.
- Usage measurement — internal measurement of how IV Discover is used. Raw usage records contain only the event type, time, the acting organisation, a coarse result-size band, whether a search text was present (never the text itself), the filters chosen and a salted day-scoped session value. They contain no account identifier, no search text, no result identifiers, no IP address, no device information and no location beyond the filters you selected. We also keep aggregate figures that cannot be traced to an individual.
We do not operate advertising or ad-tracking technology, we do not use third-party behavioural analytics, and we do not sell participant or organisation data.
6. Why we process it, and on what legal basis
| Purpose | Legal basis |
|---|---|
| Operating your account and giving you access to IV Discover | Article 6(1)(b) — necessary to provide the service you asked for |
| Registering, classifying, reviewing and publishing your organisation | Article 6(1)(b). Where we process the professional contact details of a person who is not the account holder: Article 6(1)(f) — our legitimate interest in a usable organisation-discovery service |
| Discover and Connect functionality | Article 6(1)(b) |
| Administrative review, security, accountability (provenance and audit) | Article 6(1)(f) — our legitimate interest in governed access, security and accountability |
| Evaluating the Open Pilot and minimal internal usage measurement | Article 6(1)(f) — our legitimate interest in understanding and improving the service, using non-identifying records |
| Answering your enquiries and sending service messages | Article 6(1)(b) and/or Article 6(1)(f), depending on the nature of the request |
We do not rely on consent (Article 6(1)(a)) as a general basis for IV Discover. Your Organisation Declaration and Administrative Review Acknowledgement is a declaration made on behalf of your organisation and an acknowledgement that administrative review may take place. It is not GDPR consent and is not treated as such.
Where we rely on legitimate interests, we have assessed the interest, its necessity and the balance with your rights, and you can object at any time using the contact address in this notice.
You control what your organisation publishes: information becomes visible in Discover only through your own submission and your organisation's publication state.
7. Who else processes information
We use a small number of service providers to run IV Discover. They process information on our instructions, or as independent providers where that is indicated:
- the managed backend platform that hosts the database, authentication and file storage;
- the application hosting and edge platform that serves IV Discover;
- the managed e-mail service used for enquiry acknowledgements and administrative notifications;
- Google, only if you choose to sign in with Google;
- our own business e-mail service, used to receive and answer enquiries and privacy requests;
- an AI service used only for internal, administrator-triggered analysis of organisation and public source material — participant account data are not sent to it.
Administrative access to participant information is limited to authorised IV Discover administrators, and individual review findings are not published.
8. Where information is stored
IV Discover's primary application data — your account, your organisation record, capabilities, connection records and uploaded files — are stored in the European Union, in the Ireland (AWS eu-west-1) region.
Supporting service providers, such as e-mail delivery, hosting and edge operation, or sign-in with Google, may process limited information through their own infrastructure, which is not necessarily located only in Ireland. Where a provider processes information outside the European Economic Area, appropriate data-protection arrangements apply where required. You can ask us about a specific provider at any time.
9. How long we keep information
| Information | How long we keep it |
|---|---|
| Account, profile and organisation information | while you use IV Discover; removed on a verified request, or after 24 months of account inactivity |
| Unfinished registration drafts | 12 months after your last meaningful activity |
| Connection records | 24 months after a connection is closed, terminated or expires |
| Enquiries | 12 months after the enquiry is resolved |
| Organisation Declaration and administrative review records | while your organisation participates, and for 3 years afterwards as evidence of the basis on which access and publication were authorised |
| Provenance and audit records | 5 years. These records are append-only: we never alter or delete individual entries |
| Raw usage records | maximum 180 days; only non-identifying aggregate figures are kept longer |
| Uploaded files | as long as the organisation profile they belong to |
Inside longer-lived accountability records we apply data minimisation separately: we keep the record of what happened, and we reduce direct personal identifiers, such as an account identifier, once they are no longer needed to hold an individual accountable.
10. Security
The controls in place today are:
- authenticated access to all participant functions;
- database-level access rules on every read and write;
- organisation records bound to the owning account;
- administrator-restricted functions and role-based access;
- append-only provenance and audit records for governance actions;
- organisation information controlled and published by the participant;
- location detail limited to country and administrative area.
No service can be described as completely secure and we make no absolute security guarantee. Our infrastructure providers hold their own security certifications; those belong to the providers and are not certifications held by Industrial Visibility.
12. Your rights
Subject to the conditions in the GDPR, you may ask for access to your personal data, correction of inaccurate data, erasure, restriction of processing, portability where applicable, and you may object to processing based on our legitimate interests.
Requests are handled manually by the controller. IV Discover does not offer automated data export or self-service account deletion, and no such functionality is implied.
If you ask us to erase your data, we remove your account and profile information. Accountability records showing that an action took place are kept for the period stated above, because they are needed for the integrity of the register; where we keep such a record, we reduce the personal identifiers in it where we can and we will explain what was kept and why.
To make a request, write to contact@industrialvisibility.org. This is our single channel for privacy and data-protection requests. We may ask you to confirm your identity — normally by writing from the e-mail address registered to your account — and we will respond within one month, as the GDPR allows.
13. Automated decision-making
We do not make decisions about you producing legal or similarly significant effects solely by automated means. Eligibility, publication and review decisions are made by an authorised person. Search and filtering simply order information that organisations have themselves published.
14. Complaints
You can contact us first at contact@industrialvisibility.org. You may also lodge a complaint with the supervisory authority: Valstybinė duomenų apsaugos inspekcija (State Data Protection Inspectorate of the Republic of Lithuania), L. Sapiegos g. 17, LT-10312 Vilnius, Lithuania; e-mail ada@ada.lt; telephone +370 5 271 2804; website vdai.lrv.lt.
15. Changes to this notice
Each published version carries a version number, an effective date and a last-updated date. If we make a material change, we will inform registered participants by e-mail to the address held on their account.
16. Contact
Questions about Industrial Visibility, IV Discover, registration, your data, privacy or security: contact@industrialvisibility.org.
