GROW BEYOND 2026
Privacy policy
Last updated on 24 September 2026.
This privacy policy explains how we collect, use, store and otherwise process your personal data when you visit the GROW BEYOND website, buy tickets to our events, subscribe to the newsletter or contact us in any other way. We respect your privacy and process your data in line with the General Data Protection Regulation (EU) 2016/679 and other applicable laws of the Republic of Lithuania and the European Union.
1. Who is the data controller
The organiser of GROW BEYOND and the controller of your personal data:
- VšĮ VIP GRUPĖ, company code 306256002
- VAT number LT100015790519
- Address: E. Andrė g. 14-5, Vilnius, Lietuva
- Email: info@growbeyond2026.com
- Website: www.growbeyond2026.com
If you have questions about how your data is processed, write to the address above.
2. What data we collect
Depending on how you use the website and our services, we may process:
- When you buy a ticket: your name, surname, email address, company name and details, the ticket you chose, the order and its payment status.
- When you subscribe to the newsletter: your email address and any other data you provide voluntarily.
- When you contact us: your name, surname, email address and the information in your enquiry.
- When you use the website: technical data needed for the site to work and general audience statistics that carry no identifier of you (see section 9).
3. Purposes and legal grounds
- Selling tickets and administering attendance. To accept the order, administer payment, identify the attendee and provide event information. Legal ground: conclusion and performance of a contract.
- Communication before and after the event. Information about the programme, venue, organisational changes, practical details and a request for feedback. Legal ground: performance of a contract and our legitimate interest in improving the quality of our events.
- Newsletters and marketing. Only if you separately agreed to receive them. Legal ground: your consent, which you can withdraw at any time using the link at the bottom of every email.
- Handling enquiries. So that we can answer your question. The legal ground depends on the enquiry: performance of a contract, steps prior to a contract, or our legitimate interest in handling enquiries properly.
- Legal and accounting obligations. Where we must keep data under accounting, tax or other laws. Legal ground: legal obligation.
4. Payments
Payments for tickets are handled by third party payment providers: Stripe, PayPal and Paysera. When you pay, part of your data is passed to the chosen provider to the extent needed to make and confirm the payment, prevent fraud and meet legal obligations.
We do not store card details ourselves: they are entered in the payment provider's environment. Those providers also process data under their own privacy policies.
5. Newsletters
We use MailerLite to administer our newsletters, acting as a data processor on our behalf. MailerLite states that its data centres are in the European Union and that its data processing agreement covers any international transfers.
You can unsubscribe at any time using the link at the bottom of every email or by writing to us.
6. Who we share data with
We share data only as far as needed to provide a service or to meet legal requirements. Recipients or processors may be:
- website hosting and technical maintenance providers (Hostinger);
- ticketing and order administration systems;
- payment providers (Stripe, PayPal, Paysera);
- the newsletter platform MailerLite;
- accounting, legal and IT partners;
- public authorities where the law requires us to provide data.
We do not sell your data and we do not pass attendees' contact details to conference partners for their own marketing, unless you have given separate consent.
Where a provider processes data outside the European Economic Area, this is done under the European Commission's standard contractual clauses or another ground allowed by the GDPR.
7. How long we keep data
- Accounting and payment documents: 10 years, as required by accounting and tax law.
- Attendees' contact details: up to 2 years after the event, so that we can answer questions related to attendance.
- Newsletter subscribers' data: until you unsubscribe or withdraw consent.
- Enquiry correspondence: up to 2 years after the enquiry is closed.
- Website statistics: up to 14 months.
After that the data is deleted or anonymised, unless the law requires us to keep it longer.
8. Photography and filming at the event
The conference is photographed and filmed. The photos and video are used to publicise the event, to report to partners and to communicate about future events. The legal ground is our legitimate interest in documenting and publicising the event.
If you do not want your image to be used, tell us at the registration desk or write to us, and we will act on it: we will inform the photographer and remove any image already published.
9. Cookies and website statistics
Necessary cookies and similar technologies are used so that the website works and its functions can be used. We do not use advertising or tracking cookies.
We collect website statistics in a way that stores nothing on your device: no identifier is kept in your browser and visits are grouped on the server only, using a hash of the IP address and browser data that changes every day. Because of this we cannot recognise the same person across several days and cannot follow you on other websites.
We only collect what shows whether the page is clear: which sections you read, what you clicked, how long you stayed, what device you used and which source you came from. This data is used only to improve the website and never for advertising.
The statistics are processed on our behalf by one of the conference organisers, MB „Growly“ (antanascoach.com), acting as a data processor. The data stays in the European Union.
The website also loads a Google Fonts typeface and a MailerLite newsletter form, so those providers may see your IP address when the page loads. The MailerLite form stores its own identifier (ml_guid) in your browser for its own operation; you can remove it by clearing this site's data in your browser.
10. Your rights
In the cases set out in the GDPR you have the right to:
- access your data and receive information about how it is processed;
- have inaccurate or incomplete data corrected;
- have your data erased;
- have processing restricted;
- object to processing based on legitimate interest;
- withdraw consent you have given;
- data portability, where it applies;
- lodge a complaint with the supervisory authority.
To exercise your rights write to info@growbeyond2026.com. We reply within one month at the latest.
The supervisory authority in Lithuania is the State Data Protection Inspectorate, L. Sapiegos g. 17, 10312 Vilnius, phone +370 5 271 2804, email ada@ada.lt, www.vdai.lrv.lt.
11. Data security
We apply technical and organisational measures that protect data against unauthorised access, loss, alteration or disclosure. When we choose external providers, we look for those who apply appropriate data protection measures.
12. Changes to this policy
We may update this privacy policy from time to time, for example when our providers or legal requirements change. The current version is always published on this page and the date of the last update is shown at the top.