Privacy Policy
Effective and last updated: 1 October 2026
DataSurfer (operated by Mažoji Bendrija “Dekma”) helps social-ad creative teams and agencies find the right footage. Customers connect their cloud storage, DataSurfer indexes their videos and images with AI, and users search that library in plain language to find matching scenes, with timestamps, and open the original files. The website datasurfer.ai, the DataSurfer web application, and related services are together the “Services”. This Privacy Policy explains what personal data we collect, how we use it, and how we protect it. It covers website visitors, our customers and their users, and the people who may appear in the footage and images our customers index.
1. Data Controller
The data controller for the processing described in this policy is Mažoji Bendrija “Dekma”, legal entity code 307544235, registered at Sodžiaus g. 34, Macenių k., LT-90100 Plungės r., Lithuania. Data about the Company are collected and stored in the Register of Legal Entities; the register manager is the state enterprise Centre of Registers.
For the footage, images, and other files our customers connect to or upload into the Services (“Customer Content”), the customer is the data controller and DataSurfer acts as a data processor on the customer's behalf (see Section 6). The customer's own privacy notice applies to that processing.
2. Who This Policy Covers
- Website visitors and business contacts: people who visit datasurfer.ai, book a demo, contact us, or whom we contact for business-to-business purposes (Section 3).
- Customers and their users: companies, agencies, and the team members who create an account or use the web application (Sections 4 and 5).
- People appearing in Customer Content: individuals who may be visible or audible in the videos and images our customers index (Section 6).
Our Services are intended for business and professional use. We do not knowingly collect personal information from children under the age of 18 as users of the Services.
3. Website Visitors and Business Contacts
3.1 Information we collect
- Information you provide directly: when you contact us or book a demo, we collect details such as your name, work email address, company, job title, and the contents of your message. Demo bookings are made through Cal.com (cal.com/silvestras/30min), which collects the booking details you enter and processes them under its own privacy policy as well as this one.
- Technical data: like any website, our hosting provider receives standard technical information when you load a page (such as your IP address, browser type, and the page requested) in server logs used to deliver and secure the site.
- Google Fonts: our website loads the Inter typeface from Google Fonts. When a page loads, your browser connects to Google's servers (fonts.googleapis.com and fonts.gstatic.com), which receive your IP address and browser information. Google's processing is governed by Google's privacy policy.
- Business contact data: we may obtain business contact details (such as name, role, company, and work email) directly from you or from reputable third-party providers for business-to-business outreach.
The datasurfer.ai marketing website does not set cookies and does not use analytics, advertising, or tracking tools. See our Cookies Policy.
3.2 How we use this information
- To operate, deliver, and secure our website.
- To respond to your enquiries, hold demos, and provide support.
- To send product updates and business communications, which you can opt out of at any time.
- To contact prospective business customers.
- To comply with legal obligations and prevent fraud or abuse.
3.3 Legal bases (GDPR)
- Legitimate interests (Article 6(1)(f)): responding to business enquiries, business-to-business outreach, and keeping the website secure and available.
- Consent (Article 6(1)(a)): marketing communications where consent is required by law. You may withdraw consent at any time.
- Performance of a contract (Article 6(1)(b)): steps taken at your request before entering into a contract, such as preparing a proposal after a demo.
3.4 Retention
- Marketing and business contact data: until you unsubscribe, object, or ask us to delete it.
- Server logs: kept for a short period for security and troubleshooting, in line with our hosting provider's log retention.
- Enquiry correspondence: for as long as needed to handle the enquiry and any follow-up.
4. Customer and Account Data
When you create an account or purchase the Services, we collect and process your name, email address, company details, billing information, account and team settings, and your communications with us. Sign-in is handled by our authentication provider (Clerk), and payments are handled by our payment processor (Stripe); we do not store full card numbers ourselves. We process this data to provide the Services under our Terms of Service (performance of a contract), to invoice and collect payment (legal obligation and contract), and to provide support.
We also collect usage data about how you use the web application, such as features used, searches run, actions taken, and diagnostic logs, based on our legitimate interest in operating, securing, and improving the Services.
We retain customer and account data for as long as your account is active and afterwards as necessary to comply with legal obligations (for example, accounting and tax laws), resolve disputes, and enforce our agreements.
5. Connected Storage (Google Drive, Dropbox, and Other Sources)
To index your library, you connect storage sources such as Google Drive, Dropbox, or other custom storage you configure. Google Drive and Dropbox are connected through OAuth: you sign in with the provider directly, we never see your password, and we receive an access token limited to the permissions you approve on the provider's consent screen.
- What we access: only the files and folders you authorise DataSurfer to access, and only for indexing, search, preview, and opening the original file from DataSurfer. We do not access other parts of your account.
- What we read: file contents (video, image, and audio data) and file metadata such as names, folder paths, sizes, formats, durations, and modification dates.
- What we store: the index we create (for example scene descriptions, timestamps, tags, embeddings, and thumbnails or preview frames) together with references to the original files. Original files stay in your storage; any temporary copies made for processing are deleted after indexing.
- Revoking access: you can disconnect a source in DataSurfer at any time, or revoke access from your Google or Dropbox account settings. After disconnection we stop accessing that source (see Section 6.4 for deletion).
5.1 Google API Services — Limited Use
DataSurfer's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, data we receive from Google Drive is used only to provide and improve the user-facing indexing and search features of DataSurfer; it is not transferred to third parties except as necessary to provide those features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to users; it is not used for advertising, and it is not sold. Humans at DataSurfer do not read this data unless you give us affirmative permission for specific files (for example, for support), it is necessary for security purposes such as investigating abuse, or it is required to comply with applicable law. We do not use data received from Google Workspace APIs to develop, improve, or train generalised or non-personalised AI or machine learning models.
6. Customer Content and People Appearing in It
6.1 Roles: the customer is controller, DataSurfer is processor
Our customers decide which footage and images to connect to DataSurfer and why. For Customer Content, including any personal data of people who appear in it, the customer is the data controller and DataSurfer is a data processor: we process Customer Content only on the customer's documented instructions and only to provide the Services to that customer. A data processing agreement governing this processing is available on request and forms part of our Terms of Service.
6.2 What the processing involves
To make a library searchable, we use AI models to analyse the visual and audio content of videos and images: describing scenes, actions, objects, products, settings, and visible text; transcribing speech; and creating searchable representations with timestamps. Where a customer uses features such as search by face, people visible in the footage may be detected and grouped so the customer can find other clips of the same person within that customer's own library.
- Face-related data is kept within the customer's workspace only. We do not match, link, or identify people across different customers' libraries, we do not build a cross-customer database of faces or identities, and we do not use face data to identify people against any external source.
- We do not attach names or identities to faces unless the customer chooses to label them within its own workspace.
- We do not use Customer Content to infer special category data (such as health, ethnicity, religion, or political opinions).
6.3 Customer responsibilities
Customers are responsible for having the rights, licences, releases, and consents needed for the footage and images they connect, including for any people who appear in them, and for having a lawful basis (and, where applicable law requires it, explicit consent) for any processing of facial data, such as when they enable face-based search. If you appear in footage indexed by one of our customers, please direct requests about that data to the company or agency that holds the footage. If you contact us instead, we will forward your request to the relevant customer where we can identify it.
6.4 Retention and deletion of Customer Content
- When a source is disconnected: we stop accessing it and delete the index, thumbnails, preview frames, and other derived data created from that source within 30 days, unless the customer asks us to delete it sooner.
- When a file is removed from an authorised source: its index entries are removed the next time the source is synced.
- When an account is closed: we delete Customer Content and derived data within 30 days of closure, except where we are legally required to keep something. Backups are overwritten on their normal rotation cycle.
6.5 No training of general models
We do not use Customer Content, including footage, images, transcripts, faces, or the indexes derived from them, to train general-purpose or third-party AI models, and we contractually require our AI model providers not to use it for training either. Customer Content is used only to provide the Services to the customer it belongs to.
7. Sub-processors and Data Sharing
We do not sell personal data. We share personal data only with:
- Service providers (sub-processors) who help us run the Services under confidentiality and data-processing terms, in these categories: cloud hosting, storage, and database providers; AI model providers that analyse footage and images and process search queries; our payment processor (Stripe); our authentication provider (Clerk); our scheduling tool for demos (Cal.com); and email and customer-support tools. A current list of sub-processors is available on request.
- Storage providers you connect (such as Google and Dropbox), to the extent needed to read files you have authorised and to open originals.
- Authorities, if required by law or to protect our rights and the safety of our users.
- A successor business, in connection with a merger, acquisition, or sale of assets, in which case this policy will continue to apply to your data.
8. International Data Transfers
DataSurfer is based in Lithuania and we host the Services within the European Union where practicable. Some of our service providers, such as AI model providers, may process data outside the European Economic Area, for example in the United States. Where personal data is transferred to a country that does not provide an adequate level of protection, we put appropriate safeguards in place, such as the EU–US Data Privacy Framework where the provider is certified, or the Standard Contractual Clauses approved by the European Commission. You may request a copy of the relevant safeguards by contacting us.
9. Security
We implement technical and organisational measures designed to protect personal data against unauthorised access, disclosure, alteration, or loss. These include encryption in transit, encrypted storage of access tokens, access controls, separation of each customer's data, and the principle of least privilege. No method of transmission or storage is completely secure. If we become aware of a security incident affecting personal data, we will notify affected customers and the relevant authorities as required by applicable law.
10. Your Rights
Under the GDPR you have the right to:
- Access: confirm whether we process your data and receive a copy of it.
- Correction: have inaccurate or incomplete data corrected.
- Deletion: have your data erased.
- Restriction: restrict processing in certain circumstances, for example while a correction is verified.
- Objection: object to processing based on legitimate interests, including direct marketing.
- Portability: receive data you provided to us in a structured, machine-readable format.
- Withdraw consent: where processing is based on consent, withdraw it at any time.
To exercise any of these rights, contact us at silvestras@adpunk.ai. We may ask you to verify your identity before acting on a request, and we will respond within 30 days. If your request concerns Customer Content controlled by one of our customers (Section 6), we will direct it to that customer where applicable.
You also have the right to lodge a complaint with your local data protection authority. In Lithuania, this is the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija, vdai.lrv.lt).
If you are located outside the EEA, including in US states with privacy legislation, you may have similar rights under your local law, such as the right to know, delete, correct, and opt out of certain processing. We will honour valid requests regardless of where you live.
11. Changes to This Policy
We may update this policy from time to time to reflect changes to the Services, legal requirements, or our processing practices. If we make significant changes, we will give prominent notice on our website or in the web application. The date at the top of this page shows when the policy was last revised.
12. Contact Us
If you have any questions about this Privacy Policy or how we handle personal data, please contact the Data Controller:
Legal entity code 307544235
Sodžiaus g. 34, Macenių k.
Plungės r., Lithuania, LT-90100
Email: silvestras@adpunk.ai
Phone: +370 662 17071