Privacy Policy
Last updated: 18 September 2026
MB XS VENTURES ("we", "RUBIX") is the controller of your personal data. This policy explains what data we collect when you visit rubixsiauliai.lt, buy tickets, book a table, join our guest programme, subscribe or visit our venue — and what rights you have under the EU General Data Protection Regulation (GDPR) and the Lithuanian Law on the Legal Protection of Personal Data (ADTAĮ).
1. Data Controller
| Company | MB XS VENTURES |
| Legal entity code | 306987612 |
| VAT number | LT100017359513 |
| Registered address | Maučiuvio g. 17-4, Nairių k., LT-39380 Pasvalio r., Lithuania |
| Venue | RUBIX, Vasario 16-osios g. 48, Šiauliai, Lithuania |
| [email protected] | |
| Phone | +370 691 99223 |
We are not required to appoint a Data Protection Officer. All data protection questions, requests and complaints go to [email protected] — we answer within one month.
2. Scope of This Policy
This policy covers the website rubixsiauliai.lt, our ticket shop, table reservations, guest accounts, newsletters, job applications, event-related communication and the video surveillance of our venue. Separate agreements (for example a private event or mobile bar contract) may contain additional data protection terms.
3. What Data We Collect and Where It Comes From
- Identity and contact data you give us: first and last name, email address, phone number.
- Ticket and order data: order number, ticket type, quantity, price, currency, QR code, order status, purchase date.
- Reservation data: name, phone number, email, number of guests, requested date and time, comments.
- Guest account data: name, email, phone, hashed password, ticket and reservation history.
- Payment data: payment method, payment provider reference, amount and status. We never receive or store your full card number or CVC — those are processed by the payment provider.
- Marketing data: newsletter subscription status, consent records (what you agreed to and when), and whether you opened our emails.
- Recruitment data: CV, cover letter and contact details you send when applying for a job.
- Enquiry data: private event, mobile bar and corporate party enquiries.
- Technical data: IP address, browser and device type, operating system, pages visited, timestamps (server logs), and analytics identifiers when you consent to analytics cookies.
- Video data: CCTV footage recorded in and around the venue.
- Photo and video material: images and recordings made at events.
Most data comes directly from you (forms, checkout, emails, on-site registration). Technical data is generated automatically when you use the website. When you buy a ticket through an external platform (for example Bilietai.lt or TicketMarket.lt), that platform is the seller for your purchase and we receive ticket-level data from it for admission and accounting purposes.
4. Why We Process Your Data and on What Legal Basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Selling and delivering tickets, taking payment, issuing and validating tickets | Performance of a contract — Art. 6(1)(b) |
| Handling table reservations and your guest account | Performance of a contract — Art. 6(1)(b) |
| Answering enquiries, complaints and support requests | Performance of a contract / legitimate interests — Art. 6(1)(b), (f) |
| Accounting, invoicing, VAT and tax reporting | Legal obligation — Art. 6(1)(c) |
| Newsletter and event marketing | Consent — Art. 6(1)(a); you can withdraw it at any time |
| Website analytics and statistics | Consent (analytics cookies) — Art. 6(1)(a) |
| Safety of guests and staff, protection of property, incident investigation | Legitimate interests — Art. 6(1)(f) |
| Photos and videos of events for promotion on our website and social media | Legitimate interests — Art. 6(1)(f); you can object |
| Recruitment and candidate assessment | Consent / steps before entering a contract — Art. 6(1)(a), (b) |
| Website security, fraud prevention and abuse protection | Legitimate interests — Art. 6(1)(f) |
| Defending and pursuing legal claims | Legitimate interests — Art. 6(1)(f) |
Where we rely on legitimate interests, we have balanced them against your rights: we use the minimum data necessary, keep it short, and you can object at any time (see section 9).
5. Who Receives Your Data
We never sell your personal data. We share it only with processors acting on our instructions, or where the law requires it:
| Recipient | What they do |
|---|---|
| Paysera LT, UAB (Lithuania) | Payment processing for tickets — they handle your payment data as a payment service provider |
| Google Ireland Ltd. / Google LLC | Website analytics (Google Analytics 4, only with your consent), Google Sign-In when you choose it, and the embedded Google map on the contact page |
| Cloudflare, Inc. | DNS, content delivery and traffic security for the website |
| Our hosting and IT infrastructure providers (EEA) | Servers, backups and technical operation of the website and mail |
| Our accounting service provider | Bookkeeping and tax reporting |
| Banks, auditors, legal advisers, debt recovery | Only where necessary for a specific case |
| Police, courts, VDAI and other authorities | Only when legally required or to protect our rights |
Processors are bound by written data processing agreements and may only process your data on our documented instructions.
6. Transfers Outside the EEA
Some providers (Google, Cloudflare) are established in the United States. Where personal data is transferred outside the European Economic Area, we rely on the European Commission's Standard Contractual Clauses under Art. 46 GDPR, and on the EU–US Data Privacy Framework where the recipient is certified. You can request a copy of the safeguards by emailing [email protected].
Our website, database and mail infrastructure are hosted within the EEA. Analytics data is transferred to Google only if you accept analytics cookies.
7. How Long We Keep Your Data
| Data | Retention period |
|---|---|
| Orders, tickets and invoices | 10 years from the end of the financial year (Lithuanian accounting law) |
| Ticket and order records needed for claims and admission (not required for accounting) | 3 years after the event |
| Table reservation records | 2 years after your last visit |
| Guest accounts | Until you delete the account; accounts unused for 3 years are deleted or anonymised |
| Newsletter data | Until you unsubscribe; proof of your consent is kept for 5 years |
| Job applications | 6 months after the recruitment process ends, unless you consent to longer storage |
| CCTV footage | Up to 30 days, unless a specific incident requires longer storage |
| Server and security logs | Up to 90 days |
| Analytics data | Analytics cookies 2 years; aggregated analytics reports 26 months |
| Complaints and disputes | 3 years from the final resolution |
8. How We Protect Your Data
- Stored personal data in our database is encrypted (symmetric encryption with regularly rotated keys); email addresses used for searching are stored as irreversible blind indexes.
- All traffic to the website is encrypted with TLS/HTTPS.
- Access to personal data is limited to authorised staff and administrators, protected by individual logins and permissions, and logged.
- We keep back-ups and monitor our systems for unauthorised access.
- If a personal data breach creates a risk to your rights, we notify the State Data Protection Inspectorate within 72 hours and inform you without undue delay where the risk is high.
9. Your Rights
- Access — to know whether we process your data and get a copy of it.
- Rectification — to have inaccurate or incomplete data corrected.
- Erasure (right to be forgotten) — to have your data deleted, unless we must keep it by law (for example accounting documents).
- Restriction — to have processing limited while a question about your data is being resolved.
- Portability — to receive the data you provided in a structured, commonly used, machine-readable format, or have it transferred to another controller.
- Objection — to object to processing based on our legitimate interests (including CCTV and event photography); we stop unless we have compelling legitimate grounds.
- Withdrawal of consent — at any time, for anything based on consent (newsletter, analytics cookies). Withdrawal does not affect processing carried out before it.
- Not to be subject to a decision based solely on automated processing — we do not use automated decision-making or profiling with legal effects.
To exercise any right, email [email protected]. Exercising your rights is free of charge, and we respond within one month (extendable by two months for complex requests, with an explanation). We may ask you to confirm your identity to protect your data.
If you believe your rights were breached, you can lodge a complaint with the supervisory authority — Valstybinė duomenų apsaugos inspekcija (VDAI), L. Sapiegos g. 17, LT-10312 Vilnius, email [email protected], phone +370 5 271 2804, vdai.lrv.lt — or apply to a court.
10. Cookies and Local Storage
We use technically necessary cookies so the site works, and analytics cookies only with your consent. You can change or withdraw your cookie choice at any time via "Cookie Settings" in the footer or the cookie banner.
| Name | Type / purpose / duration |
|---|---|
| guest_token | Essential — keeps you logged into your guest account; 30 days |
| rubix_lang | Essential — remembers the language (EN/LT) you chose; 1 year |
| _ga | Analytics (Google Analytics) — distinguishes visitors; 2 years; only with consent |
| _ga_CR8ZE145C3 | Analytics (Google Analytics) — session/visitor state; 2 years; only with consent |
| rubix_cookie_consent (local storage) | Essential — stores your cookie choice so we don't ask again |
| rubix_cart (local storage) | Essential — your ticket cart before checkout; cleared when the session expires |
| rubix_buyer (local storage) | Optional — your name, surname and email from your last purchase, so the checkout form is prefilled on this device. Never shared; delete it any time via Cookie settings. |
| rubix_admin_token (local storage) | Essential, staff only — admin session token; 7 days |
We do not use advertising or social-media tracking cookies. Google Analytics scripts load only after you accept analytics cookies, and the analytics cookies are deleted again as soon as you reject or withdraw your consent — withdrawal is just as easy as giving it.
11. Video Surveillance (CCTV)
Our venue is monitored by video cameras for the safety of guests and staff and for the protection of property (legitimate interest, Art. 6(1)(f) GDPR). Information signs are displayed at the venue entrance and in monitored areas. Recordings are viewed only when needed for a specific incident and are stored for up to 30 days; if an incident or legal claim requires it, the relevant clip may be kept longer and shared with the police, insurers or courts.
You can object to video surveillance by contacting us, but where safety and security require it we may continue processing; in that case we will explain our grounds.
12. Photos and Videos at Events
We photograph and film our events (including the crowd) to promote RUBIX on our website and social media. This is based on our legitimate interest. If you do not want to appear in published material, tell our staff at the event or email us afterwards and we will remove the material where technically possible. We do not use your image to advertise third-party products, and we never publish material that is defamatory or that focuses on an individual in a negative way.
13. Minors
The venue operates an age policy (events are generally 18+ unless stated otherwise). Tickets for minors may only be bought by an adult, and we do not knowingly collect personal data from children. If you believe a child's data reached us, contact us and we will delete it.
14. Third-Party Websites
Our website links to external services (social networks, ticket platforms, map provider). Their own privacy policies apply once you leave our site, and we are not responsible for their processing.
15. Changes to This Policy
We may update this policy when our processing or the law changes. The current version is always published on this page with the date it was last updated. In case of a conflict between language versions, the Lithuanian version prevails.
Questions about this document? Email [email protected]
We use cookies to improve your experience. Analytics cookies load only with your consent.Details