Skip to main content

Inga Barkauskaite

Privacy

How this website handles personal data.

This Privacy Policy explains what information the company collects when you visit this website, submit the contact form, or make contact by email, telephone, LinkedIn or WhatsApp, and what rights apply to that information.

Last updated10 August 2026
Applies toingabarkauskaite.com
Governing lawIreland
Contents
  1. Introduction
  2. Data controller
  3. Personal data that may be collected
  4. How personal data is used
  5. Legal bases for processing
  6. Whether providing personal data is obligatory
  7. Comments
  8. Media uploads
  9. Cookies and similar technologies
  10. Embedded content from other websites
  11. Contact forms and communications
  12. Email, telephone, LinkedIn and WhatsApp
  13. Analytics, security and website tools
  14. Fonts and third-party assets
  15. Who personal data may be shared with
  16. International transfers
  17. Data retention
  18. Security of personal data
  19. Your data protection rights
  20. Your right to object
  21. How to exercise your rights
  22. Complaints
  23. Children's privacy
  24. Automated decision-making and artificial intelligence
  25. External links
  26. Business transfers
  27. Updates to this Privacy Policy
  28. Contact

Section 01

Introduction

This Privacy Policy applies to the website operated at ingabarkauskaite.com, together with any staging or development domain used while the website is being built or maintained.

This website is operated by Mega Commercial Enterprises Limited, a company registered in Ireland. It publishes written content, background information and a record of professional experience, and provides means of making contact. Nothing is sold through this website, no payment is taken through it, and no visitor account exists on it.

This Privacy Policy is intended to comply with the General Data Protection Regulation (Regulation (EU) 2016/679), the Irish Data Protection Act 2018, and the European Communities (Electronic Communications Networks and Services) (Privacy and Electronic Communications) Regulations 2011 (S.I. 336/2011) as they apply to cookies and similar technologies.

Using this website means personal data may be processed by the company as described below. Where consent is required, including for non-essential cookies, that consent is requested separately and is not assumed.

Section 02

Data controller

For the purposes of data protection law, the data controller is the person or organisation determining the purposes and means of processing personal data.

The data controller for this website, and for all personal data processed through it, is:

Mega Commercial Enterprises Limited

A private company limited by shares, registered in Ireland under number 726999, with its registered office in Dublin, Ireland.

Email: [email protected]
Telephone: +353 87 148 3870
Company website: megacommercialenterprises.com

This website is operated by Mega Commercial Enterprises Limited, which determines why and how personal data submitted through it is processed and which is accountable for that processing under Article 5(2) GDPR.

All requests, objections and complaints relating to personal data are handled by the company, and correspondence should be addressed to it using the details above.

No data protection officer is appointed. The company does not carry out large-scale monitoring of individuals through this website and does not process special category data on a large scale through it, so the conditions requiring appointment under Article 37 GDPR are not met.

Section 03

Personal data that may be collected

Personal data means any information relating to an identified or identifiable individual. What is collected depends on how the website is used.

3.1 Information provided directly

Where contact is made through the website contact form, by email, by telephone, by LinkedIn or by WhatsApp, the following may be collected:

  • Name.
  • Email address.
  • Telephone number, where provided in a message.
  • Company name or website, where provided.
  • The subject and content of the message.
  • Any files, links or further information voluntarily included.
  • Communication preferences.

3.2 Contact form submissions

Information entered into the contact form is processed in order to receive, review, respond to and manage the enquiry. The form also processes limited technical information necessary for security, spam prevention and reliable delivery.

3.3 Technical information collected automatically

Certain technical information is recorded automatically when the website is visited:

  • IP address.
  • Browser type and version.
  • Device type and operating system.
  • Pages visited and time spent on the website.
  • Referring website or source.
  • Approximate location derived from IP address.
  • Date and time of access.
  • Server, error and security logs.

3.4 Cookies and similar technologies

Cookies and comparable technologies may be used to operate the website, record consent choices, provide security, and — where consent is given — to understand how the website is used. Full detail appears in the Cookie Policy.

3.5 Social media and external platforms

Following a link to LinkedIn, Instagram, Facebook, TikTok, X or WhatsApp takes you to a platform operated by a third party, which processes personal data under its own privacy policy. This website does not control that processing.

What this website does not collect

There is no visitor account, no login, no newsletter subscription, no shop, no payment processing, no booking system and no comments section. No special category data is sought. Personal data is not knowingly collected from children.

Section 04

How personal data is used

Personal data may be used for the following purposes:

  • To receive and respond to enquiries submitted through the website or other listed channels.
  • To continue correspondence about a message, request, introduction or collaboration.
  • To direct an enquiry to the relevant business within the group where the enquiry concerns that business.
  • To manage professional correspondence and keep reasonable records of it.
  • To operate, secure and maintain the website.
  • To prevent spam, abuse, unauthorised access and other security threats.
  • To understand how the website is used and improve its content, where consent to analytics has been given.
  • To comply with legal, regulatory and administrative obligations.
  • To establish, exercise or defend legal claims where necessary.

Personal data is not sold

Personal data is not sold, rented or traded, and is not shared for the marketing purposes of any third party. It is used only for the website, communication, security, compliance and operational purposes described in this policy.

Section 05

Legal bases for processing

Every use of personal data requires a lawful basis under Article 6 GDPR. The bases relied on are as follows.

PurposeLegal basisExplanation
Responding to enquiries and correspondenceLegitimate interests (Art. 6(1)(f))It is necessary to review and respond to a message that has been voluntarily sent.
Passing an enquiry to the relevant businessLegitimate interests (Art. 6(1)(f))It is necessary so that an enquiry reaches the business able to answer it.
Website security, spam prevention and maintenanceLegitimate interests (Art. 6(1)(f), recital 49)It is necessary to keep the website secure, available and protected from misuse.
Analytics and non-essential cookiesConsent (Art. 6(1)(a))Analytics is used only where consent has been given, and consent may be withdrawn at any time.
Recording a consent choiceLegal obligation (Art. 6(1)(c))A record must be kept to demonstrate that consent was sought and what was chosen.
Legal and regulatory obligationsLegal obligation (Art. 6(1)(c))Processing may be required in order to comply with applicable law.
Legal claims and disputesLegitimate interests (Art. 6(1)(f))Information may be processed to establish, exercise or defend legal rights.

Where legitimate interests are relied on, a balancing assessment has been carried out to establish whether those interests are overridden by the interests, rights and freedoms of the individual. Where processing is based on consent, that consent may be withdrawn at any time, without affecting the lawfulness of processing carried out beforehand.

Section 06

Whether providing personal data is obligatory

Providing personal data through this website is entirely voluntary. It is neither a statutory nor a contractual requirement, and there is no obligation to enter into any arrangement in order to use the website.

The only consequence of not providing a name and an email address through the contact form is that no reply can be sent, because there would be no means of sending one. No other consequence follows, and the rest of the website remains fully accessible.

Section 07

Comments

This website does not currently operate a comments section, and no comment data is collected.

Were comments to be enabled, the data entered into the comments form would be collected, together with the commenter's IP address and browser user agent string, in order to assist with spam detection.

An anonymised string created from the email address, known as a hash, may in that case be provided to the Gravatar service to determine whether the service is in use. After a comment is approved, the profile picture associated with that account may be visible to the public alongside the comment, depending on the Gravatar settings of the account holder. The Gravatar privacy policy would apply to that processing.

Comments and their related metadata would be retained for moderation, anti-spam and record-keeping purposes. This policy would be updated before any comments function is enabled.

Section 08

Media uploads

This website is informational and does not permit visitors to upload images or other files. No visitor-uploaded media is collected or stored.

Were an upload function to be enabled, visitors should avoid uploading images containing embedded location data, including EXIF GPS coordinates, because other visitors could download such an image and extract that location data from it.

Additional privacy and security controls would be applied to any upload function, and this policy would be updated before such a function is enabled.

Section 09

Cookies and similar technologies

Cookies are small text files placed on a device when a website is visited. Comparable technologies include pixels, tags, scripts, local storage and session storage. This policy and the Cookie Policy treat all of them the same way.

7.1 Consent is requested before anything non-essential is stored

This website uses its own consent tool. Until a choice is made, the only cookie set is ib-consent, which records that choice. No analytics tag is loaded and no non-essential cookie is written before consent is given.

7.2 Categories

  • Strictly necessary — required for the website to function and to record the consent choice. Exempt from consent under the ePrivacy Regulations.
  • Preferences — would remember display choices. Currently unused; nothing is set under this category.
  • Analytics — Google Analytics 4, used only where consent is given.
  • Marketing — would support measurement of advertising. Currently unused; nothing is set under this category.

7.3 Withdrawing or changing consent

A choice may be changed or withdrawn at any time through Cookie Settings, linked in the footer of every page. Withdrawal takes effect immediately and is as straightforward as giving consent. The consent record is retained for 12 months, after which the choice is requested again.

7.4 Google Consent Mode

Google Consent Mode v2 is implemented. All storage types are set to denied before any tag runs and are updated only where consent is given. Where analytics consent is declined, the Google Tag Manager container is not loaded at all, so no request is made to Google.

Section 10

Embedded content from other websites

This website does not embed third-party video players, social media feeds, maps, booking tools or advertising. No third-party content loads in the background beyond what is described in this policy.

Where embedded content is introduced in future, it will behave as though the external website had been visited directly: the third party may set cookies, collect data and monitor interaction with that content, particularly where you are logged in to an account with that service. This policy would be updated before any such content is added.

Section 11

Contact forms and communications

Information submitted through the contact form is used to respond to the enquiry and manage the resulting correspondence. Submissions are stored in this website's own database and sent by email to the company.

Contact form submissions are handled by the website's form software, hosting provider, an email delivery service, and a bot-detection service that verifies the submission came from a person. Those providers process the data only as necessary to deliver the website and email functions. Providers are identified by function rather than by product name, for security reasons; details are available on request.

Sensitive personal data should not be submitted through the contact form unless strictly necessary for the enquiry. This includes health information, financial account details, government identification numbers, data relating to criminal offences, and highly confidential business information.

Section 12

Email, telephone, LinkedIn and WhatsApp

This website provides means of making contact by email, through LinkedIn, and through WhatsApp.

Contact made through a third-party platform is processed by that platform under its own privacy policy and terms. Depending on the platform this may include profile information, telephone number, message content, metadata, device details and interaction data. WhatsApp is operated by Meta Platforms Ireland Limited; LinkedIn is operated by LinkedIn Ireland Unlimited Company.

The privacy notice of any external platform should be reviewed before it is used to communicate. This website does not control how those platforms process personal data.

Section 13

Analytics, security and website tools

This website uses tools for analytics, security, performance, spam prevention, search optimisation, form handling and site management. These may process technical data including IP address, browser type, device information, pages visited, referral source, time of visit and interaction data.

These tools are used to:

  • understand website traffic and improve content, where consent to analytics has been given;
  • protect the website against spam, malware, brute-force attempts and unauthorised access;
  • maintain loading speed and technical performance;
  • detect errors and diagnose faults;
  • manage contact form submissions and email delivery.

Analytics is provided by Google Analytics 4, delivered through Google Tag Manager, and operates only where consent has been given. Analytics data is retained by Google for 14 months.

Section 14

Fonts and third-party assets

The typefaces used on this website are loaded from Google Fonts. As a result, a request is made to servers operated by Google when a page loads, and an IP address is disclosed to Google as part of that request. This occurs for technical delivery of the typeface and is not used to identify visitors of this website.

Google is a separate controller in respect of that request and processes it under its own privacy policy.

No other third-party asset is loaded from an external source.

Section 15

Who personal data may be shared with

Personal data is shared only where necessary to operate, secure and maintain the website, to respond to correspondence, or to comply with the law. Providers act on documented instructions under written data processing terms.

Categories of recipient:

  • Website hosting provider.
  • Domain, DNS, content delivery and security providers.
  • Website maintenance and technical support providers.
  • Form processing software operating on this website.
  • Email hosting and email delivery providers.
  • Spam prevention and security services.
  • Analytics providers, where consent has been given.
  • Professional advisers, where necessary.
  • Regulators, courts, public authorities or law enforcement, where legally required.
  • Businesses operated by the company, where an enquiry concerns one of them.

Personal data is not sold to third parties.

Section 16

International transfers

Some providers used to host the website, deliver email, provide security or supply analytics operate outside Ireland and the European Economic Area, including in the United States.

Where personal data is transferred outside the EEA, the transfer relies on one of the following safeguards:

  • an adequacy decision of the European Commission;
  • the EU–US Data Privacy Framework, where the provider is certified under it;
  • the European Commission's Standard Contractual Clauses, together with any supplementary measures applied;
  • explicit consent, where no other mechanism applies.

Details of the safeguard applying to a particular provider, and a copy of the relevant clauses where applicable, are available on request.

Section 17

Data retention

Personal data is retained only for as long as necessary for the purpose for which it was collected, unless a longer period is required or permitted by law.

DataRetained forThen
Contact form entries stored on the website12 monthsDeleted
Email and message correspondence24 monthsDeleted
Correspondence relating to an ongoing matter6 yearsDeleted — matching the Statute of Limitations 1957
Server, error and security logsUp to 12 monthsOverwritten automatically
Analytics data held by Google14 monthsDeleted automatically
Record of a cookie consent choice12 monthsExpires; consent is requested again

Where a longer statutory retention period applies to a particular document, that period applies instead. When personal data is no longer required it is deleted or anonymised.

Section 18

Security of personal data

Technical and organisational measures are applied to protect personal data against unauthorised access, misuse, loss, alteration, disclosure and destruction.

These include TLS encryption across the whole website, a content delivery and security layer, firewall and malware protection, restricted administrative access, current software, and regular backups.

No website, email system or internet transmission can be guaranteed fully secure. Highly sensitive or confidential information should not be sent through a contact form or other unsecured channel.

Should a personal data breach occur that is likely to result in a risk to the rights and freedoms of individuals, the Data Protection Commission will be notified within 72 hours as required by Article 33 GDPR, and affected individuals will be informed directly where Article 34 requires it.

Section 19

Your data protection rights

The following rights apply under Articles 15 to 22 GDPR. No fee is charged for exercising them, and no reason need be given for most of them.

  • The right to be informed about how personal data is used — which this policy is intended to satisfy.
  • The right of access — to confirmation of whether personal data is held, and a copy of it.
  • The right to rectification — to correction of inaccurate or incomplete data.
  • The right to erasure — to deletion, where no overriding ground for retention applies.
  • The right to restrict processing — to suspension of processing while accuracy or legitimate interests are disputed.
  • The right to object — to processing based on legitimate interests. See the section below.
  • The right to data portability — to receive data provided, in a structured, commonly used and machine-readable format.
  • The right to withdraw consent — at any time, where processing is based on consent.
  • The right not to be subject to a decision based solely on automated processing producing legal or similarly significant effects.
  • The right to lodge a complaint with a supervisory authority.

These rights are not absolute. They may be subject to legal limitations, exemptions, verification requirements and competing legal obligations, and any refusal will be explained with its reason.

Section 20

Your right to object

This notice is given expressly and separately

As Article 21(4) GDPR requires, this right is brought to your attention separately from the other information in this policy.

You have the right to object at any time to processing of your personal data that is based on legitimate interests. On this website that means the handling of your enquiry, the retention of correspondence, and the keeping of technical and security records.

Where an objection is made, processing will stop unless compelling legitimate grounds can be demonstrated which override your interests, rights and freedoms, or unless the processing is necessary for the establishment, exercise or defence of legal claims.

An objection may be sent to [email protected] and requires no particular form of words. No direct marketing is carried out through this website, so there is no marketing to object to.

Section 21

How to exercise your rights

Requests should be made in writing and sent to [email protected], so that they are recorded and can be answered within the statutory period.

A response will be provided within one month of receipt, as Article 12(3) GDPR requires. Where a request is complex or where several requests have been received, that period may be extended by up to two further months; notice of any extension and the reason for it will be given within the first month.

Information sufficient to verify identity and locate the relevant data may be requested first, in order to prevent disclosure of personal data to a person impersonating the data subject.

Where a request concerns data processed by a third-party platform — LinkedIn, WhatsApp, Instagram, Facebook, TikTok, X or Google — that platform may also need to be contacted directly, as it acts as controller in respect of its own processing.

Section 22

Complaints

A person who considers that their personal data has been processed unlawfully has the right to lodge a complaint with a supervisory authority.

Data Protection Commission

The supervisory authority for Ireland. Complaints are made in writing, using the webform on its website.

dataprotection.ie

A data subject resident in another EEA state may instead lodge a complaint with the supervisory authority of that state.

Raising the matter directly first is welcome, so that it can be reviewed and resolved where possible, but there is no obligation to do so before complaining.

Section 23

Children's privacy

This website is intended for business, professional and general informational purposes. It is not directed at children and personal data is not knowingly collected from them.

Under section 29 of the Data Protection Act 2018, the digital age of consent in Ireland is 16. Where it becomes apparent that personal data has been provided by a child, it will be deleted.

Where you believe a child has provided personal data through this website, please make contact so that appropriate steps can be taken.

Section 24

Automated decision-making and artificial intelligence

No decision producing legal or similarly significant effects is made about any individual on the basis of automated processing alone. No profiling within the meaning of Article 22 GDPR is carried out.

Automated tools are used for website security, spam detection, analytics and technical maintenance. These operate to protect and run the website, not to make decisions about visitors.

22.1 No AI system operates on this website

There is no chatbot, virtual assistant or automated agent on this website. Messages are read by a person.

22.2 Personal data is not used for AI

Personal data submitted through this website is not used to train any AI model, is not entered into a generative AI tool, and is not shared with any AI provider.

How AI tools are used in producing the content of this website is a separate matter, disclosed in full in the Terms of Service having regard to Article 50 of the EU AI Act.

Section 25

External links

This website links to external websites, including megacommercialenterprises.com, LinkedIn, Instagram, Facebook, TikTok, X and WhatsApp.

External websites are not controlled by this one. Their own privacy policies, cookie policies, terms and data practices apply, and those should be reviewed before submitting personal data or interacting with them.

Section 26

Business transfers

Where website ownership, business assets or related interests are reorganised, transferred, merged or sold, personal data may be transferred as part of that transaction where necessary and lawful.

Any such transfer would be carried out in accordance with data protection law and subject to appropriate safeguards, and individuals with an open matter would be notified.

Section 27

Updates to this Privacy Policy

This Privacy Policy may be updated to reflect changes to the website, to the tools it uses, to legal requirements, or to data protection practices. Where this website begins any new processing of personal data, this policy will be updated before that processing starts.

The date shown at the top of this page indicates when the policy was last revised. Where a change materially affects how personal data is handled, individuals with an open matter will be notified directly. Where a change alters the purpose of any cookie, consent will be requested again rather than carried over.

Section 28

Contact

Questions about this Privacy Policy, or about how personal data is handled, may be directed to the data controller:

Mega Commercial Enterprises Limited

Registered in Ireland, number 726999 · Registered office: Dublin, Ireland

Email: [email protected]
Telephone: +353 87 148 3870
Website: megacommercialenterprises.com

This website, ingabarkauskaite.com, is operated by the company named above.