GDPR & Data Processing
Last updated: 13 May 20261. Data Controller
Musės ("we") is the data controller for personal data processed in connection with the Musės Shop Platform. Contact: legal@muses.lt.
2. Lawful Bases for Processing
We rely on the following lawful bases under GDPR Article 6:
- Art. 6(1)(b) — Contract: processing necessary to perform a contract with you (order fulfilment, account management, marketplace transactions)
- Art. 6(1)(c) — Legal obligation: VAT/tax records, DAC7 seller reporting, anti-money-laundering checks
- Art. 6(1)(f) — Legitimate interests: fraud prevention, platform security, service analytics, and abuse detection
- Art. 6(1)(a) — Consent: marketing emails, non-essential cookies (analytics, marketing pixels)
3. Data Processors (Sub-Processors)
We use the following sub-processors who process personal data on our behalf under data processing agreements:
- Stripe, Inc. (USA — Standard Contractual Clauses) — payment processing, payout management
- Vercel, Inc. (USA — SCC) — hosting, CDN, edge compute
- Sentry, Inc. (USA — SCC) — application error monitoring
- Mailchimp / Intuit Inc. (USA — SCC) — transactional and marketing email delivery
4. International Data Transfers
Some sub-processors are based in the United States. Transfers are protected by Standard Contractual Clauses (SCCs) approved by the European Commission under Art. 46(2)(c) GDPR. You may request a copy of the relevant SCC agreements by emailing legal@muses.lt.
5. Your Data Subject Rights
Under GDPR Chapter III you have the following rights:
- Right of access (Art. 15): obtain confirmation of whether we process your data and a copy of it
- Right to rectification (Art. 16): correct inaccurate or incomplete data
- Right to erasure (Art. 17): request deletion of your data subject to legal retention obligations
- Right to restriction (Art. 18): restrict processing in certain circumstances
- Right to data portability (Art. 20): receive your data in a structured, machine-readable format
- Right to object (Art. 21): object to processing based on legitimate interests or direct marketing
- Right not to be subject to automated decisions (Art. 22): we do not make solely automated decisions with legal or similarly significant effects
6. How to Make a Data Subject Request
Email legal@muses.lt with the subject line "Data Subject Request" and describe your request. We will verify your identity and respond within 30 days (extendable to 90 days for complex requests). We will not charge a fee for reasonable requests.
7. Supervisory Authority
If you believe we have not handled your data in accordance with GDPR, you have the right to lodge a complaint with the State Data Protection Inspectorate of Lithuania (Valstybinė duomenų apsaugos inspekcija): www.ada.lt, email: ada@ada.lt.