Privacy Policy
Version 1 · in force from 2026-07-02
Last updated: 8 August 2026.
This is a translation of the Lithuanian original for convenience. In case of any discrepancy between the Lithuanian and English versions, the Lithuanian version prevails.
1. General information
VšĮ „ANT Studija“ (the “Data Controller”) respects your privacy and undertakes to protect it in accordance with this Privacy Policy (the “Policy”). Through this Policy the Data Controller aims to inform you comprehensively about the processing of your personal data, whether you interact with the Data Controller in person, by electronic means (for example, using the Data Controller’s website or e-mail) or in any other way you choose.
The Data Controller undertakes to be transparent by providing clear information about what personal data is processed, the purposes of processing, the retention period, the legal basis for processing and other information the Data Controller is required to provide under applicable law.
Please take the time to review this Policy and, if you have any questions, do not hesitate to contact the Data Controller using one of the methods given at the end of the Policy.
The Data Controller confirms that your data is collected in compliance with the requirements of applicable European Union and Republic of Lithuania legislation and the instructions of supervisory authorities, applying all reasonable technical and administrative measures so that the collected data is protected against loss, unauthorised use and/or alteration. The Data Controller’s employees have undertaken in writing not to disclose or distribute information received at the workplace to third parties, including information about visitors to the website and social media accounts.
The terms used in this Policy have the meaning given to them in the General Data Protection Regulation (EU) No. 2016/679 (the “GDPR”).
1.1. Where this Policy applies
The Data Controller operates the website www.antstudija.lt. The Data Controller also uses a studio administration system, which processes dancer (member) registration, attendance, class-credit, payment and correspondence data. This Policy applies to both environments and to every other way in which the Data Controller processes your personal data.
The administration system is intended for studio staff only (administrators, coaches and managers). At present there are no separate self-service accounts for dancers or their parents (guardians) — all data requests are made using the contacts given at the end of this Policy.
It is important that you read this Policy carefully, because each time you visit the Data Controller’s website you become acquainted with the conditions described here. If you do not agree with these conditions, please do not visit the Data Controller’s website, use its content or use the Data Controller’s services.
2. Data of minors
A large proportion of the Data Controller’s members are children and teenagers, so particular attention is paid to their data. Two different rules apply to minors, and it is important not to confuse them: one governs the conclusion of the contract, the other governs consent.
2.1. The contract concerning a minor is concluded by a parent or guardian
Under the Civil Code of the Republic of Lithuania, a child under 14 does not conclude transactions independently — their parents or guardians act on their behalf; a minor aged 14 to 18 has limited capacity and may conclude a contract only with the consent of their parents (curators). Attendance of classes is a paid, contractual service, so the contract concerning a dancer under 18 is concluded with their parent or other legal guardian (curator).
That is precisely why, when a dancer under 18 is registered, the registration form requires the guardian’s first name, last name, e-mail address and telephone number: this is the data of the person who is a party to the contract and is responsible for payment. The minor’s own contact details (their e-mail address and telephone number) are not collected. When registering, the guardian separately confirms that they are the dancer’s parent or guardian and consent to the minor taking part in the classes.
All correspondence concerning a minor’s classes, payments and debts is sent to the e-mail address provided by the guardian.
2.2. The age of consent is a different one — 14
Where data is processed not on the basis of a contract but on the basis of consent (for example, direct marketing or optional cookies), the rule laid down in the Republic of Lithuania Law on Legal Protection of Personal Data applies: a child may give consent to information society services independently from the age of 14, and for a younger child consent is given or authorised by the parents (guardians).
This is a separate matter from concluding a contract. The fact that a fourteen-year-old may consent to receive a newsletter does not mean they may themselves become a party to a contract for a paid service.
3. How we obtain your data
Your personal data — that is, any information that allows the Data Controller to identify you — is obtained in the following ways:
- You provide it yourself — by completing the registration form on the website, submitting an enquiry, calling, writing by e-mail, visiting the studio or taking part in surveys.
- We receive it from parents (guardians) — when a minor dancer is registered.
- Data is created as you use the services — attendance marking at classes, class-credit deductions, and the accounting of payments and debts.
- It is created by photography and filming — photographs and video recordings made during classes, performances, competitions and events (see section 11).
- It is collected automatically as you browse the website — using cookies and similar technologies. Statistics and marketing cookies are used only with your consent (see section 10).
- It is received through social media accounts — when you contact the Data Controller through its “Facebook”, “Instagram”, “TikTok” or “YouTube” accounts, or make public posts that the Data Controller follows. In such cases the privacy policy of the relevant social network additionally applies.
- It is received from bank statements — when you pay by bank transfer, the Data Controller receives the payer’s name, account number, payment reference and amount from the statement in order to match the payment to a specific dancer.
To the extent permitted by applicable law, the Data Controller may obtain information about you from third parties and combine it with other information it holds about you.
You may choose not to provide certain information, but in that case the Data Controller will not be able, or will not be fully able, to provide you with the services it offers.
If you provide the Data Controller with data of other persons connected to you, you should inform them and, if necessary, obtain their consent and make them aware of this Policy.
4. What data we process
The Data Controller tries to collect as little information about you as possible. The categories below are the data actually processed in the Data Controller’s systems.
4.1. Dancer (member) data
- first name, last name, date of birth;
- e-mail address and telephone number (for an adult dancer);
- home address, school;
- photograph (if provided) and member card number;
- preferred language of communication;
- participation status (active, no longer attending, trial class) and membership start date;
- administration notes about the member (for example, arrangements regarding payment or attendance).
4.2. Parent (guardian) data
- the first names, last names, e-mail addresses and telephone numbers of one or two parents (guardians);
- information about which contact is responsible for payment.
4.3. Participation data
- enrolments in groups and their periods, season commitments and contracts;
- attendance marks at classes (present, late, absent), the time of marking and the person who marked it, as well as administration notes about a particular visit;
- movement of class credits (granting, deduction, expiry, adjustments);
- waiting-list entries, apparel sizes, family links between members.
4.4. Payment data
- amounts due and paid, periods, payment method, discounts, debts and their settlement;
- payment line items with a service description and VAT information;
- payer details obtained from bank statements — name, account number (IBAN), payment reference and amount.
4.5. Communication data
- e-mails sent to you — recipient address, subject, message type, time of sending and delivery status;
- notifications and reminders in the system;
- your enquiries and the related correspondence.
4.6. Website usage data
- the address of the page viewed, where you came from (referrer), campaign tags and a randomly generated session identifier. This data is collected only with your consent to Statistics cookies. The Data Controller does not store the IP address or browser identifier in these records;
- the cookie consent state stored in your browser;
- if you consent to Statistics or Marketing cookies — data collected by the relevant third parties (“Google”, “Meta”, “YouTube”) under their own privacy rules.
4.7. Registration and consent records
When the registration form on the website is submitted, a registration record is stored: the data provided, the consent text, the time consent was given, and also the IP address and browser data. This technical data is stored as evidence that consent was given (Article 7(1) GDPR).
4.8. System activity records (audit)
The administration system records which employee changed which record and when, together with the previous and new value of the record, the IP address and browser data. These records serve accountability and security — they make it possible to establish who processed your data and when. Audit records are append-only (they cannot be altered or deleted in the ordinary course).
4.9. Photographs and video recordings
Photographs and video recordings showing dancers, made at classes, performances, competitions, open lessons, camps and other studio events. Where and how this material is published, and how you can object, is described in section 11.
4.10. Data of candidates for job vacancies
General information about the candidate: first name, last name, date of birth, place of residence or address, e-mail address and/or telephone number, information about work experience, education, professional development, language skills, IT and driving skills and other competences, and other information you provide in your CV, cover letter or other application documents. References and employer feedback: the name and contact of the person giving the reference and its content. Candidate assessment information: interview summary, the insights and opinions of the persons conducting the selection, and test results.
5. Purposes and legal bases
Your personal data is processed on one or more lawful bases: performance of a contract with you, compliance with legal requirements, the legitimate interests of the Data Controller (unless your interests override them), or your consent.
- Provision of services and performance of the contract. The dancer’s and guardian’s identity and contact data, enrolment in groups, attendance, credits, payments and debts. The studio concludes a contract on participation in classes with the member (or, in the case of a minor, with their parent or guardian); that contract remains in force until either party terminates it and renews automatically each year. If the member chooses to attend for a whole season, an annex to the contract is signed: the member commits to the whole season and prepays the final month of the season, and a discount is applied in return. Legal basis — performance of a contract (Article 6(1)(b) GDPR); in the case of a minor, the contract concluded with their parent or guardian.
- Accounting and tax obligations. Payment and settlement data. Legal basis — compliance with a legal obligation (Article 6(1)(c) GDPR).
- Communication and handling of enquiries. Answers to your questions, reminders about classes, payments and schedule changes. Legal basis — performance of a contract and the legitimate interest in ensuring the smooth provision of the service.
- Registration on the website and confirmation of a minor’s participation. Legal basis — your consent (Article 6(1)(a) GDPR) together with the conclusion of a contract at your request.
- Direct marketing. Newsletters, offers, event invitations, surveys. Legal basis — the legitimate interest in informing existing customers about similar services (see section 9) or your consent.
- Website statistics and improvement. Legal basis — your consent to statistics cookies.
- Advertising on social networks and search engines. Legal basis — your consent to marketing cookies.
- Internal business analytics. Overviews of group occupancy, attendance and revenue, on the basis of which the studio plans its schedule, group sizes and activities. Legal basis — the legitimate interest in planning and improving the studio’s activities.
- Publicising the studio’s activities. Publication of photographs and video recordings from classes, performances and events (see section 11). Legal basis — the legitimate interest in presenting the studio’s activities and its dancers’ achievements; you have the right to object at any time.
- System security and accountability. Audit records, error logging, abuse prevention. Legal basis — the legitimate interest in protecting data and compliance with legal requirements.
- Recruitment. Candidate data. Legal basis — your consent.
- Defence of interests. When defending its interests in court or another institution, all of your data listed in this Policy may be processed. Legal basis — compliance with legal requirements and the legitimate interest in defending against claims brought.
Where the Data Controller cannot rely on one of the legal bases above, it will ask for your consent before starting to process your personal data. Where data is processed for purposes other than those set out in this Policy, we will inform you by means of a separate notice.
6. With whom we share data
6.1. Data processors
The Data Controller engages service providers who process data on the Data Controller’s instructions and only for the purposes it specifies. The main ones are:
- Supabase — database, authentication and file storage services. Data is stored in the European Union (Frankfurt, Germany).
- Vercel — hosting of the website and the administration system. The European Union (Frankfurt) region is used.
- Resend — e-mail delivery services. The recipient’s e-mail address, the subject and the content of the message are transferred.
- Sentry — software error tracking. The system is configured so that request bodies, cookies, IP addresses and user identity data are not included in error reports.
- Anthropic — the artificial-intelligence assistant used by the studio’s administrators (see section 6.3).
- The accounting services provider — for handling settlements and invoices.
- “Google” and “Meta” (Facebook) — website statistics and advertising services. Their tags are loaded only after you have given the corresponding cookie consent.
6.2. Other recipients
The Data Controller may also transfer your personal data to credit and other financial institutions operating in Lithuania, to state, municipal and law-enforcement authorities, to auditors and lawyers, and to other parties where required by law or where necessary to protect the Data Controller’s legitimate interests. The ability of such persons to use your information is limited — they may not use it for purposes other than providing services to the Data Controller.
The Data Controller does not sell your personal data.
6.3. Transfers outside the European Economic Area
The Data Controller’s main systems operate within the European Union. However, some service providers are established outside the European Economic Area (EEA):
- The artificial-intelligence assistant. The administration system includes an AI assistant used only by studio administrators for everyday questions (for example, finding a member’s card or reviewing a group roster) and for matching bank transfers to members. When such a request is made, the relevant member data — first name, last name, date of birth, contacts, parents’ (guardians’) contacts, address, school, administration notes and payment information — is transferred to the service provider Anthropic (USA). The assistant can only propose actions; every change to data must be confirmed by an administrator, and payment, remuneration, permission-granting and data-destruction actions are not available to it at all. Every request is recorded in the system logs.
- Statistics and marketing tags. If you consent to statistics or marketing cookies, the relevant data is transferred to “Google” and “Meta”, which may process data outside the EEA as well.
Such transfers are carried out on the basis of the standard contractual clauses approved by the European Commission, the recipient’s coverage by a European Commission adequacy decision, or — in the case of cookies — your consent. In any event, the Data Controller takes measures to ensure an appropriate level of protection for the data transferred.
7. How long we keep data
The Data Controller keeps your personal data for as long as is necessary to achieve the purposes for which it was collected. There is no single period that fits all data — it depends on how your relationship with the studio develops and on what the law requires. The criteria by which the retention period is determined are therefore set out below.
- For as long as the contract is in force. The identity and contact data of the member and the guardian, enrolments in groups, attendance, credits and correspondence are processed for as long as the contract on participation in classes remains in force.
- For as long as is needed to complete settlements and to deal with legal claims. After the contract ends, data that may be needed to complete settlements or to bring or defend against claims is kept until the relevant limitation periods have expired.
- Periods laid down by law. The retention of payment, settlement and accounting documents is determined not by the Data Controller but by law — the Republic of Lithuania Law on Financial Accounting and the retention schedule approved by the Chief Archivist of Lithuania (Vidaus administravimo dokumentų saugojimo terminų rodyklė, order No. VE-50 of 24 September 2024, applicable from 1 October 2024). Under those rules, accounting documents and accounting registers are kept for at least 10 years. The Data Controller cannot shorten that period — not even upon a request to erase data (see section 8.1).
- Proof of consent. Registration and consent records are kept for as long as the Data Controller needs them in order to demonstrate that consent was given (Article 7(1) GDPR).
- Marketing. Data is processed for marketing purposes until you object or withdraw your consent. If you unsubscribe from marketing messages, the fact of unsubscribing itself is stored indefinitely — otherwise the messages could be resumed by mistake.
- Recruitment. Data submitted by candidates for job vacancies is kept for 6 months after the end of the selection process.
Some records are by their nature append-only and unalterable: system activity (audit) records, class-credit movement records and the registers of data requests. They are kept for as long as is necessary to ensure accountability and are not deleted individually — upon a request to erase data, their content is redacted as described in section 8.1.
Data that is no longer needed for any of the purposes set out in this Policy, and to which no statutory retention period applies, is deleted or anonymised by the Data Controller. That review is carried out by the studio administration; it is not automatic. Independently of it, you may at any time ask for your (or your child’s) data to be erased — how such a request is carried out, and what remains afterwards, is described in section 8.1.
8. Your rights
Depending on the situation, you have the following rights:
- The right to know (to be informed) about the processing of your data — to receive information in concise, plain and intelligible language before processing begins.
- The right of access to your data and to how it is processed: to obtain confirmation of whether your data is processed, a list of the data processed, the purposes and legal basis of processing, information about recipients and transfers to third countries and the safeguards applied, the source of the data, and the retention periods.
- The right to rectification of inaccurate data or completion of incomplete data.
- The right to erasure (“the right to be forgotten”) — where the data is no longer needed for the purpose, where you withdraw your consent, where it is established that your interests override the Data Controller’s legitimate interest, or where the data was obtained unlawfully.
- The right to restriction of processing — while you contest the accuracy of the data, while your objection is being considered, where processing is unlawful but you oppose erasure, or where the Data Controller no longer needs the data but you require it to be kept for a legal dispute.
- The right to data portability — to receive the data you have provided in a structured, commonly used and machine-readable format, where the data is processed by automated means on the basis of your consent or a contract.
- The right to object to processing based on legitimate interest — including the publication of photographs and video recordings (see section 11). If you object to direct marketing, data is no longer processed for that purpose, unconditionally.
- The right to withdraw consent at any time where processing is based on consent. Withdrawal does not affect the lawfulness of processing carried out before it.
- The right to lodge a complaint with the State Data Protection Inspectorate (vdai.lrv.lt).
8.1. How to exercise your rights
Submit your request using the contacts given at the end of the Policy. Your rights are exercised after your identity has been confirmed — by visiting the studio, by submitting a request signed with a qualified electronic signature, or by another means that reliably establishes identity. A request on behalf of a minor is submitted by their parent or guardian.
The Data Controller will respond no later than within 30 (thirty) calendar days of receiving the request. In exceptional cases requiring additional time, the Data Controller, having notified you, will be entitled to extend the period to 60 (sixty) calendar days from the date of your request.
A copy of your data. Upon receiving a request for access or portability, the Data Controller prepares a copy of all data it holds about you (or your child): in a machine-readable format (JSON) and in a conveniently readable, printable format. The copy contains member data, enrolments in groups, payments, attendance, credit movements, correspondence, registration and consent records, and the history of changes to the data. Every such preparation is recorded in a separate system log.
Erasure of data. Upon receiving a justified erasure request, the Data Controller anonymises your (or your child’s) record: it irreversibly removes the first name, last name, date of birth, contact details, address, school, photograph, card number, notes and all other free-text information, and the record values held in the change history are redacted. This operation is irreversible.
Please note that under Article 17(3) GDPR the right to be forgotten is not absolute. Even after anonymisation the Data Controller retains:
- financial records (payment amounts, dates, periods) — this is necessary to comply with the accounting and tax obligations laid down by law (see section 7);
- attendance and credit accounting records, detached from your identity — these are needed for correct settlement with coaches and for the studio’s accounts;
- the fact of consent (when it was given and with what text), detached from your identity — this is necessary for the Data Controller to demonstrate consent;
- system activity (audit) records of who performed an action and when, without the content of the records themselves.
If a member has no related records at all (no enrolments, payments or attendance), their record can be deleted entirely.
Rectification of data and other requests are currently carried out by the studio administration on the basis of your request — there is as yet no separate self-service environment for dancers and parents (guardians).
The Data Controller may decline to enable the exercise of the rights listed above where, in the cases provided by law, it is necessary to ensure the prevention, investigation and detection of criminal offences or breaches of official or professional ethics, or to protect the rights and freedoms of the data subject or of others.
9. Direct marketing and opting out
The Data Controller is entitled to send its customers, potential customers or persons who have completed the registration form information by e-mail about its services, events, promotions and news.
How to opt out. Every marketing e-mail contains an unsubscribe link. Clicking it stops marketing messages immediately. You may also notify us of your decision using the contacts given at the end of the Policy.
Important for parents (guardians): the opt-out applies to the e-mail address, not to a particular dancer. This means that if several of your children are registered with the same e-mail address, unsubscribing stops marketing messages for all of them. If you later wish to resume marketing messages, please contact the studio administration.
What the opt-out does not cover. The opt-out does not apply to messages directly related to the service (contractual ones) — reminders about payments and debts, information about schedule or class changes, registration confirmations and similar notices. Such messages are necessary for the performance of the contract and are sent for as long as membership of the studio continues.
10. Cookies and consent management
In this Policy the term “cookies” is used to describe cookies and other similar technologies (for example, pixel tags, web beacons, browser local storage). Cookies are small pieces of information stored in your web browser.
10.1. The consent mechanism
On your first visit to the website a cookie consent dialog is shown. Until you make a choice, no optional cookies are stored and no third-party tags are loaded. You can change or withdraw your choice at any time using the “Cookie settings” link at the bottom of the website. The same place, under “Details”, also contains a full declaration of the cookies used.
The consent dialog groups cookies into four categories:
- Necessary — required for the website to function; they cannot be switched off. Currently this is the single cookie ant_consent, which stores your cookie choice (valid for 1 year).
- Preferences — remember choices that change the behaviour or appearance of the website. The Data Controller currently uses no such cookies (the language choice is held in the web address itself).
- Statistics — help us understand how visitors use the website. The Data Controller’s first-party cookie ant_sid (valid for 180 days) is a random session identifier; it contains no personal data. If enabled in the website settings, “Google Analytics” may additionally be used (cookies _ga, _ga_#).
- Marketing — used to tailor advertising and measure its effectiveness. These are the “Meta” (Facebook) cookies _fbc, _fbp and the local storage entries lastExternalReferrer and lastExternalReferrerTime, the “Google” cookie _gcl_au, and the “YouTube” cookies VISITOR_INFO1_LIVE, YSC and __Secure-ROLLOUT_TOKEN, which are set by videos embedded in our pages.
“Google” and “Meta” tags are loaded only if you have given the corresponding consent and only if they are enabled in the website settings. If consent is withdrawn, the page reloads and the tags are no longer loaded.
10.2. Managing cookies in your browser
You can also configure your browser to accept all cookies, reject all cookies, or notify you when a cookie is sent. Every browser is different, so if you do not know how to change cookie settings, please consult its help menu. More information about managing cookies is available at allaboutcookies.org. Please note that some services are designed to work only with cookies, so if you disable them you may no longer be able to use those services or parts of them.
The cookie policy of the relevant social network applies to the Data Controller’s social media accounts.
11. Photography and filming
Classes, performances, competitions, open lessons, camps and other studio events are photographed and filmed. The photographs and recordings are made by studio staff or by photographers and camera operators engaged by the studio. Because a large proportion of the studio’s members are children, minor dancers appear in such material.
This material is used to present the studio’s activities and its dancers’ achievements. It is published:
- on the studio’s website (in the “Foto” and “Video” sections);
- on the studio’s social media accounts — “Facebook”, “Instagram”, “TikTok” and “YouTube”;
- in the studio’s promotional and informational material.
The material may be accompanied by the name of the group, event or competition and the date, and — where the results of competitions or performances are published — by dancers’ first names and surnames.
The legal basis is the legitimate interest of the Data Controller in presenting its activities (Article 6(1)(f) GDPR). This means that you have the right to object at any time to such processing (Article 21 GDPR), and the Data Controller must give effect to that objection.
How to object or ask for removal. If you do not want your (or your child’s) image to be photographed, filmed or published, please tell us using the contacts given at the end of the Policy — you do not need to give a reason. Upon receiving such a notice, the Data Controller stops publishing new material featuring that person and, if you identify a particular photograph or recording, removes it from its website and social media accounts.
Please note two things. First, the Data Controller can only remove material from the channels it controls itself: if a photograph or recording has already been saved or shared by other people, the Data Controller has no control over those copies. Second, in group photographs and in general footage of classes or performances it may be technically impossible to remove an individual — in that case the whole photograph or the whole recording is removed.
The member photograph held in the administration system for identification purposes (see section 4.1) is a different matter: it is kept in closed, non-public storage and is never published.
12. Data security
The Data Controller has implemented reasonable and appropriate physical, technical and organisational measures to protect the information collected, including:
- data is encrypted in transit and at rest;
- row-level access control operates in the database — each employee sees only the data needed for their duties; coaches see only the members of their own groups, and remuneration-related data is accessible only to the studio’s managers;
- all changes to sensitive data are recorded — who changed what and when;
- personal employee accounts are used to log in to the system; employees have undertaken in writing to maintain confidentiality;
- dancers’ photographs are kept in a closed (non-public) storage.
Please remember, however, that although appropriate steps are taken to protect your information, no website, online operation, computer system or wireless connection is completely secure.
13. Data processing principles
In collecting and using the personal data entrusted to it, as well as data obtained from other sources, the Data Controller adheres to the following principles:
- your personal data is processed lawfully, fairly and in a transparent manner (the principle of lawfulness, fairness and transparency);
- your personal data is collected for specified, explicit and legitimate purposes and is not further processed in a manner incompatible with those purposes (the purpose limitation principle);
- your personal data is adequate, relevant and limited to what is necessary for the purposes for which it is processed (the data minimisation principle);
- the personal data processed is accurate and, where necessary, kept up to date (the accuracy principle);
- your personal data is kept in a form which permits identification for no longer than is necessary for the purposes for which it is processed (the storage limitation principle);
- your personal data is processed in a manner that ensures appropriate security, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (the integrity and confidentiality principle).
14. Review of the Policy
This Policy is reviewed at least once every two years. When the Policy is updated, you will be informed of what the Data Controller considers to be material changes by publishing a notice on the Data Controller’s website. If you connect to or use the Data Controller’s content and/or services after such a notice is published, you will be deemed to have acquainted yourself with the updated Policy.
If you have noticed an inconsistency in this Policy, a security vulnerability on the Data Controller’s website, or have any other questions relating to the processing of your personal data, please contact the Data Controller using the contacts below.
15. Data Controller’s details
VšĮ „ANT Studija“
Company code: 124624710
Address: Ratnyčios g. 45-44, Vilnius
The person responsible for personal data processing and for handling data subject requests at the studio:
Dainius Žebrauskas
E-mail: info@antstudija.lt
Studio branch addresses:
Verkių g. 31C, Vilnius / E-mail: info@antstudija.lt / Tel.: +370 610 80118 (+370 610 61721)
Pociūno g. 8, Vilnius / E-mail: vilniusoutlet@antstudija.lt / Tel.: +370 614 22313