← Back to home
Legal

Privacy Policy

Effective and last updated: 1 October 2026

DataSurfer (operated by Mažoji Bendrija “Dekma”) helps social-ad creative teams and agencies find the right footage. Customers connect their cloud storage, DataSurfer indexes their videos and images with AI, and users search that library in plain language to find matching scenes, with timestamps, and open the original files. The website datasurfer.ai, the DataSurfer web application, and related services are together the “Services”. This Privacy Policy explains what personal data we collect, how we use it, and how we protect it. It covers website visitors, our customers and their users, and the people who may appear in the footage and images our customers index.

1. Data Controller

The data controller for the processing described in this policy is Mažoji Bendrija “Dekma”, legal entity code 307544235, registered at Sodžiaus g. 34, Macenių k., LT-90100 Plungės r., Lithuania. Data about the Company are collected and stored in the Register of Legal Entities; the register manager is the state enterprise Centre of Registers.

For the footage, images, and other files our customers connect to or upload into the Services (“Customer Content”), the customer is the data controller and DataSurfer acts as a data processor on the customer's behalf (see Section 6). The customer's own privacy notice applies to that processing.

2. Who This Policy Covers

Our Services are intended for business and professional use. We do not knowingly collect personal information from children under the age of 18 as users of the Services.

3. Website Visitors and Business Contacts

3.1 Information we collect

The datasurfer.ai marketing website does not set cookies and does not use analytics, advertising, or tracking tools. See our Cookies Policy.

3.2 How we use this information

3.3 Legal bases (GDPR)

3.4 Retention

4. Customer and Account Data

When you create an account or purchase the Services, we collect and process your name, email address, company details, billing information, account and team settings, and your communications with us. Sign-in is handled by our authentication provider (Clerk), and payments are handled by our payment processor (Stripe); we do not store full card numbers ourselves. We process this data to provide the Services under our Terms of Service (performance of a contract), to invoice and collect payment (legal obligation and contract), and to provide support.

We also collect usage data about how you use the web application, such as features used, searches run, actions taken, and diagnostic logs, based on our legitimate interest in operating, securing, and improving the Services.

We retain customer and account data for as long as your account is active and afterwards as necessary to comply with legal obligations (for example, accounting and tax laws), resolve disputes, and enforce our agreements.

5. Connected Storage (Google Drive, Dropbox, and Other Sources)

To index your library, you connect storage sources such as Google Drive, Dropbox, or other custom storage you configure. Google Drive and Dropbox are connected through OAuth: you sign in with the provider directly, we never see your password, and we receive an access token limited to the permissions you approve on the provider's consent screen.

5.1 Google API Services — Limited Use

DataSurfer's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, data we receive from Google Drive is used only to provide and improve the user-facing indexing and search features of DataSurfer; it is not transferred to third parties except as necessary to provide those features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to users; it is not used for advertising, and it is not sold. Humans at DataSurfer do not read this data unless you give us affirmative permission for specific files (for example, for support), it is necessary for security purposes such as investigating abuse, or it is required to comply with applicable law. We do not use data received from Google Workspace APIs to develop, improve, or train generalised or non-personalised AI or machine learning models.

6. Customer Content and People Appearing in It

6.1 Roles: the customer is controller, DataSurfer is processor

Our customers decide which footage and images to connect to DataSurfer and why. For Customer Content, including any personal data of people who appear in it, the customer is the data controller and DataSurfer is a data processor: we process Customer Content only on the customer's documented instructions and only to provide the Services to that customer. A data processing agreement governing this processing is available on request and forms part of our Terms of Service.

6.2 What the processing involves

To make a library searchable, we use AI models to analyse the visual and audio content of videos and images: describing scenes, actions, objects, products, settings, and visible text; transcribing speech; and creating searchable representations with timestamps. Where a customer uses features such as search by face, people visible in the footage may be detected and grouped so the customer can find other clips of the same person within that customer's own library.

6.3 Customer responsibilities

Customers are responsible for having the rights, licences, releases, and consents needed for the footage and images they connect, including for any people who appear in them, and for having a lawful basis (and, where applicable law requires it, explicit consent) for any processing of facial data, such as when they enable face-based search. If you appear in footage indexed by one of our customers, please direct requests about that data to the company or agency that holds the footage. If you contact us instead, we will forward your request to the relevant customer where we can identify it.

6.4 Retention and deletion of Customer Content

6.5 No training of general models

We do not use Customer Content, including footage, images, transcripts, faces, or the indexes derived from them, to train general-purpose or third-party AI models, and we contractually require our AI model providers not to use it for training either. Customer Content is used only to provide the Services to the customer it belongs to.

7. Sub-processors and Data Sharing

We do not sell personal data. We share personal data only with:

8. International Data Transfers

DataSurfer is based in Lithuania and we host the Services within the European Union where practicable. Some of our service providers, such as AI model providers, may process data outside the European Economic Area, for example in the United States. Where personal data is transferred to a country that does not provide an adequate level of protection, we put appropriate safeguards in place, such as the EU–US Data Privacy Framework where the provider is certified, or the Standard Contractual Clauses approved by the European Commission. You may request a copy of the relevant safeguards by contacting us.

9. Security

We implement technical and organisational measures designed to protect personal data against unauthorised access, disclosure, alteration, or loss. These include encryption in transit, encrypted storage of access tokens, access controls, separation of each customer's data, and the principle of least privilege. No method of transmission or storage is completely secure. If we become aware of a security incident affecting personal data, we will notify affected customers and the relevant authorities as required by applicable law.

10. Your Rights

Under the GDPR you have the right to:

To exercise any of these rights, contact us at silvestras@adpunk.ai. We may ask you to verify your identity before acting on a request, and we will respond within 30 days. If your request concerns Customer Content controlled by one of our customers (Section 6), we will direct it to that customer where applicable.

You also have the right to lodge a complaint with your local data protection authority. In Lithuania, this is the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija, vdai.lrv.lt).

If you are located outside the EEA, including in US states with privacy legislation, you may have similar rights under your local law, such as the right to know, delete, correct, and opt out of certain processing. We will honour valid requests regardless of where you live.

11. Changes to This Policy

We may update this policy from time to time to reflect changes to the Services, legal requirements, or our processing practices. If we make significant changes, we will give prominent notice on our website or in the web application. The date at the top of this page shows when the policy was last revised.

12. Contact Us

If you have any questions about this Privacy Policy or how we handle personal data, please contact the Data Controller:

Mažoji Bendrija “Dekma”
Legal entity code 307544235
Sodžiaus g. 34, Macenių k.
Plungės r., Lithuania, LT-90100
Email: silvestras@adpunk.ai
Phone: +370 662 17071