Privacy Policy
Information on the processing of personal data pursuant to Articles 13 and 14 of the General Data Protection Regulation (EU) 2016/679.
1. Controller
The controller responsible for the processing described in this policy is:
- Legal entity
- Memel Consult, MB (company code 305625254, VAT LT100019333012)
- Address
- Vivulskio g. 7, LT-03162 Vilnius, Lithuania
- Represented by
- Genadijus Smertjevas
- gs@memelconsult.lt
A data protection officer has not been appointed. Given the size of the organisation and the nature of the processing, the criteria in Article 37 (1) GDPR are not met. Please address all data protection enquiries to the email address above.
2. Scope and principles
This policy covers personal data processed through this website and in the course of MemelCon's business activities, including deal sourcing and outreach carried out on behalf of clients.
Personal data is only processed where a legal basis under Article 6 GDPR applies, only for the purposes described here, and only for as long as necessary. No special categories of personal data within the meaning of Article 9 GDPR are deliberately collected, and no automated decision-making or profiling within the meaning of Article 22 GDPR takes place.
This website does not use cookies, analytics, tracking pixels or advertising technologies. No consent banner is displayed because no consent-requiring technology is in use. If this changes, this policy will be updated and consent will be obtained before any such technology is activated.
3. Website hosting and server logs
This website is hosted by HOSTINGER, UAB, a private limited liability company organised under the laws of the Republic of Lithuania, company code 302710386, registered address Švitrigailos g. 34, LT-03230 Vilnius, Lithuania. Other companies within the Hostinger group may be involved in delivering parts of the service.
Hostinger acts as a processor on MemelCon's behalf under a data processing agreement pursuant to Article 28 GDPR, available at hostinger.com/legal/dpa.
When you access this website, the server automatically records technical information that your browser transmits. This typically includes:
- the IP address of the requesting device
- date and time of the request
- the page or file requested and the volume of data transferred
- the HTTP status code returned
- the referring URL, where transmitted
- browser type, version and operating system
Purpose: delivering the website, ensuring stability and security, and investigating misuse.
Legal basis: Article 6 (1) (f) GDPR. The legitimate interest is the secure and reliable operation of the website.
Retention: server logs are kept only for as long as necessary for the purposes stated above and are then deleted or anonymised by the hosting provider.
This data is not merged with other data sources and is not used to identify individual visitors.
4. Web fonts
This website loads the Inter typeface from Google Fonts, a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. When a page is opened, your browser connects to Google servers in order to download the font files. As a result, your IP address is transmitted to Google and may be transferred to servers in the United States.
Purpose: consistent typography across devices.
Legal basis: Article 6 (1) (f) GDPR, the legitimate interest in a uniform and professional presentation of the website. Transfers to the United States are based on Google's certification under the EU-US Data Privacy Framework and, where applicable, the European Commission's standard contractual clauses.
Further information is available in Google's privacy policy at policies.google.com/privacy.
5. Acquisition target and prospect data
A core part of MemelCon's service is identifying companies that may be suitable acquisition targets for clients, and contacting their owners and managing directors. This necessarily involves processing personal data about people who have not contacted MemelCon themselves.
Categories of data
Business contact data: name, job title, employer, business telephone number, business email address, business postal address, professional profile information, and notes recorded about business conversations and the company's succession or sale intentions.
Source of the data
Data is obtained from publicly accessible sources, including company registers, company websites, imprint pages, professional networks, trade press, industry directories and commercial business databases. Data may also be provided by the client on whose behalf the search is carried out.
Purpose and legal basis
Purpose: identifying and qualifying potential acquisition targets, and initiating business contact with the people authorised to decide on a sale.
Legal basis: Article 6 (1) (f) GDPR. The legitimate interest is the pursuit of MemelCon's and its clients' business activity in mergers and acquisitions, specifically the initiation of business-to-business transactions. The data concerns individuals strictly in their professional capacity, is limited to business contact details, and the contact made is relevant to the recipient's own commercial position as an owner or executive.
Information under Article 14 GDPR
Where personal data has not been obtained from the person concerned, that person is informed of the processing at the latest at the time of first contact, and in any event within one month of the data being obtained. This information includes the identity of the controller, the purposes and legal basis of the processing, the categories of data, the source of the data, the retention period and the rights set out in section 11 below.
Right to object
Anyone contacted may object to this processing at any time under Article 21 GDPR, without giving reasons and without cost, by writing to gs@memelconsult.lt. Following an objection, the data will no longer be processed for outreach purposes. A minimal suppression record, consisting of the name and contact details together with a note of the objection, is retained on the basis of Article 6 (1) (c) and (f) GDPR for the sole purpose of ensuring that the person is not contacted again.
6. Contact by email
This website does not use a contact form. If you write to the email address published on this site, the content of your message together with your email address, your name and any other details you choose to provide will be processed in order to deal with your enquiry.
Legal basis: Article 6 (1) (b) GDPR where the enquiry relates to the conclusion or performance of a contract, otherwise Article 6 (1) (f) GDPR, the legitimate interest in responding to business enquiries.
Retention: correspondence is deleted once the enquiry has been finally dealt with and no statutory retention obligation applies.
Please note that unencrypted email transmission cannot be fully secured against access by third parties. Please do not send confidential financial or transaction information by unencrypted email.
7. Client and supplier data
Where a business relationship is entered into, the personal data of the contact persons involved is processed for the purpose of performing the contract, including project delivery, communication, invoicing and accounting.
Legal basis: Article 6 (1) (b) GDPR for contract performance, and Article 6 (1) (c) GDPR in respect of statutory accounting and tax retention obligations.
Retention: for the duration of the business relationship and thereafter for the statutory retention periods, which under Lithuanian accounting and tax law are generally up to ten years.
8. LinkedIn
This website links to a LinkedIn profile. The link is a plain hyperlink: no LinkedIn content, plugin, script or tracking pixel is embedded in this site, and no data is transmitted to LinkedIn unless you actively click the link.
If you follow the link, LinkedIn Ireland Unlimited Company becomes responsible for any processing that takes place on its platform, under its own privacy policy at linkedin.com/legal/privacy-policy. Where MemelCon contacts you or communicates with you through LinkedIn, the processing described in section 5 applies.
9. Recipients and international transfers
Personal data is disclosed only where necessary. Recipients may include:
- the hosting and email providers named above, acting as processors under Article 28 GDPR
- the client on whose behalf a search or outreach mandate is carried out, in respect of qualified target companies and their contact persons
- tax advisers, accountants and auditors, within the scope of statutory obligations
- legal advisers and public authorities, where required by law or necessary to establish or defend legal claims
Personal data is not sold, rented or otherwise made available to third parties for their own marketing purposes.
MemelCon's hosting provider is established in Lithuania, and processing is intended to take place within the European Economic Area, with the exception of the font delivery described in section 4.
Hostinger operates data centres in several countries outside the EEA. Where the hosting plan used for this website is located outside the EEA, or where a Hostinger sub-processor is established outside the EEA, the transfer is made on the basis of an adequacy decision by the European Commission or on the basis of the standard contractual clauses under Article 46 (2) (c) GDPR, which form part of Hostinger's data processing addendum.
10. Retention
Personal data is deleted as soon as the purpose for which it was collected no longer applies and no statutory retention obligation prevents deletion. Specific periods are stated in the relevant sections above. Prospect data that has not led to a business relationship is reviewed periodically and deleted where no legitimate interest in continued processing remains.
11. Your rights
Under the GDPR you have the following rights in respect of your personal data:
- Access (Article 15): confirmation of whether your data is processed, and a copy of it
- Rectification (Article 16): correction of inaccurate or incomplete data
- Erasure (Article 17): deletion where one of the listed grounds applies
- Restriction (Article 18): limitation of processing in defined circumstances
- Data portability (Article 20): receipt of data you provided, in a structured, machine-readable format
- Objection (Article 21): objection at any time to processing based on legitimate interests, including the outreach described in section 5
- Withdrawal of consent (Article 7 (3)): where processing is based on consent, withdrawal at any time with effect for the future
To exercise any of these rights, write to gs@memelconsult.lt. Requests are answered without undue delay and in any event within one month.
Right to lodge a complaint
You may lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or the place of the alleged infringement. The competent authority for MemelCon is the State Data Protection Inspectorate of the Republic of Lithuania (Valstybinė duomenų apsaugos inspekcija), L. Sapiegos g. 17, 10312 Vilnius, Lithuania, vdai.lrv.lt. Data subjects in Germany and Austria may also contact their own national or regional supervisory authority.
12. Changes to this policy
This policy is updated whenever changes to MemelCon's services or to the applicable law make it necessary. The version published on this page at the time of your visit is the version that applies.