duomenys.svietimas.lt — Privacy Policy
Last updated: Sep 7, 2026
Who we are
The duomenys.svietimas.lt data platform is developed and operated by VšĮ Švietimas numeris vienas (Švietimas #1). We are the controller of personal data processed for the purposes described in this policy under the General Data Protection Regulation (GDPR).
VšĮ Švietimas numeris vienas
Legal entity code: 307104937
Konstitucijos pr. 21A, LT-08130 Vilnius, Lithuania
Email: info@svietimas.lt. Website: svietimas.lt. Data platform: duomenys.svietimas.lt.
What our services do
This policy covers the duomenys.svietimas.lt dashboard, its website chatbot and our Model Context Protocol (MCP) service. The dashboard presents Lithuanian education data through charts, maps and other views. The chatbot answers questions using AI models and information retrieved through our tools.
The MCP service lets any compatible chat client or application, including ChatGPT or Claude, retrieve our public datasets, statistics and articles. It is independent of any particular chat client. Your chosen client’s own privacy policy also applies to information it processes.
The conversation storage, AI-provider training and two-year conversation retention described for the website chatbot apply to that chatbot; direct MCP use is described separately under ‘Our MCP service’.
What information we process
-
Chatbot content: your messages, conversation history supplied with a request, AI responses, and tool requests and results used to answer you. Anything you include in a message becomes part of that content.
-
Conversation and request details: randomly generated conversation references, request identifiers, timestamps, the models and providers used, response times, errors, usage volumes and costs.
-
MCP requests: tool names and arguments sent by your client, such as dataset names, school or municipality searches, filters, selected columns and calculations, together with the results returned and technical information needed to handle the request.
-
Website and connection information: IP addresses, browser and device information, requested pages or resources, access times and diagnostic information processed by our infrastructure and the services described below.
-
Contact enquiries: your email address, message and any name you choose to provide, together with subsequent correspondence. Formspree also processes technical information, such as IP addresses and browser information, to deliver submissions and prevent spam or abuse.
You do not need a Švietimas #1 account to use the dashboard, chatbot or MCP service. We do not require a name or email address for chatbot use. However, messages can identify you or someone else through their content, and conversation references can link messages together. The absence of an account does not make all records anonymous.
Please avoid submitting personal, sensitive or confidential information, including identifiable information about pupils or other children. Your email address and message are required if you use the contact form so that we can handle your enquiry; your name is optional.
How we use information
We process information to:
-
Understand questions, retrieve relevant public information and generate answers.
-
Operate the dashboard and MCP service, diagnose errors, monitor performance and costs, and prevent misuse.
-
Improve the chatbot through human review of conversations and answers, prompt changes, automated evaluations, and training or fine-tuning models using conversations.
-
Understand overall website usage and improve the presentation and accessibility of education data.
-
Respond to enquiries, suggestions, error reports and requests concerning personal data.
For service operation, security, handling enquiries and assessing and improving service quality, we rely on legitimate interests under Article 6(1)(f) of the GDPR. Our interests are providing a useful, reliable and financially sustainable public education data service, while respecting individuals’ rights and interests. We also process personal data where necessary to meet legal obligations, including applicable data protection obligations.
We do not use your questions to target advertising. Contact messages are handled as correspondence and are not routinely added to chatbot training records. AI providers’ use of chatbot content for their own model or product improvement is described separately below.
Website chatbot: AI services and conversation storage
The website chatbot sends conversation content through OpenRouter to the AI provider handling the request. This can include earlier messages and tool results needed for context. We may change models and use any AI provider eligible under our OpenRouter routing settings. OpenRouter may route or retry requests among eligible providers, so more than one provider may process a request.
We store chatbot conversations and related request records in Langfuse Cloud’s EU region for monitoring, human review, evaluation and the improvement activities described above.
OpenRouter’s own Input & Output Logging and its optional use of our inputs and outputs to improve its own product are disabled. OpenRouter still processes requests and collects request metadata, such as usage and timing statistics. Its data collection policy also describes limited prompt categorisation for reporting and model rankings. These settings do not disable our storage in Langfuse or the receiving AI provider’s own processing.
Our routing permits AI providers that retain inputs and outputs and use them to train or improve their models and products. This includes Meta when its models, such as Muse Spark, are used under terms allowing that reuse. We permit this provider use of content to access reduced-price AI services and keep the chatbot financially sustainable. This is separate from our own chatbot improvement and from OpenRouter’s disabled own-product reuse setting.
Provider practices differ by service and route. OpenRouter’s provider directory and provider data policies link to the applicable terms and privacy information. The chatbot does not offer a separate mode excluding the storage and training uses described here. You can browse the dashboard without submitting chatbot messages.
AI responses may be incomplete or inaccurate. We use AI to provide information, not to make decisions about individuals that produce legal or similarly significant effects.
Our MCP service
The MCP service provides read-only access to public information. Tools can describe datasets and calculations, search for schools or municipalities, query and aggregate education data, retrieve articles, and provide links for downloading public datasets. Outputs may contain data rows, statistics, descriptions, article text, source links and query details.
When you connect through your own chat client, we receive its tool requests, including search terms, filters and other arguments, together with technical information needed to handle them. Our tools do not request your conversation history. Results are returned to your client, whose own privacy policy applies to its processing.
Direct MCP use does not itself send your client’s conversation through our website chatbot’s OpenRouter and Langfuse storage flow. Our MCP infrastructure does keep operational records, including generated database queries, query identifiers, timings and error details. These technical records are used for troubleshooting and monitoring service performance.
Public education data
Our services aggregate and present public Lithuanian education datasets and published articles. These include information about schools, pupil and teacher numbers, examinations, financing, procurement and other education indicators. We identify original sources where available and are not the original publisher of the underlying information.
For concerns about personal information displayed through our services, contact us with the relevant page, dataset or record. We will assess the concern in relation to our services and, where appropriate, refer it to the source institution.
Service providers and access
Access to stored conversations is limited to authorised staff of VšĮ Švietimas numeris vienas and contracted consultants, including their authorised employees, working on the service. They may access content for the review, development, evaluation, training and support purposes described in this policy.
We use the following services, which receive information relevant to their roles:
-
OpenRouter and the selected AI providers: processing chatbot requests and generating responses, with provider retention and training as described above. OpenRouter also processes request metadata.
-
Langfuse: storing and analysing chatbot content and request records in its EU cloud region, including records used for evaluation and improvement.
-
Fly.io, including its managed monitoring and Grafana interface: hosting the dashboard, chatbot backend and MCP service, handling network requests, and storing operational logs and performance metrics.
-
Formspree and Google email services: receiving, storing and delivering contact enquiries. Email copies are delivered to authorised organisational staff and consultants at @svietimas.lt addresses.
-
Plausible Analytics: measuring aggregate website usage, including pages visited, referral sources, browser and device categories, and approximate location derived from network information. Plausible does not use analytics cookies or persistent visitor identifiers, and states that it does not store raw IP addresses.
-
OpenStreetMap Foundation: delivering map images directly to your browser. Requests disclose network and browser information and the map areas requested.
-
Cloudflare R2: hosting public downloadable datasets. Cloudflare processes connection and request information when you access those files. We do not use this storage for chatbot conversations.
Providers may use subcontractors to deliver their services. Where a provider determines its own purposes, such as its own model training, its own privacy terms govern that processing. We may also disclose information when required by law or where necessary to establish, exercise or defend legal claims.
International processing
We prefer EU processing where it is available for the selected service or model. Our Langfuse conversation storage is in the EU, and our Fly.io applications are configured with Frankfurt as their primary hosting region.
This does not mean that all processing takes place in the EU. We permit global AI routing, including for models such as Muse Spark. AI providers may process and retain content in the United States or other countries. Formspree, email delivery and other service providers may also involve processing outside the European Economic Area (EEA). EU storage of a conversation copy does not prevent the original request or other copies from being processed elsewhere.
International transfers are subject to applicable data protection requirements. Depending on the recipient and destination, relevant transfer mechanisms may include a European Commission adequacy decision or Standard Contractual Clauses, with additional safeguards where required. Contact info@svietimas.lt for information about the safeguards applicable to a particular transfer.
How long we keep information
-
Chatbot records: up to two years from collection. This covers stored conversations, related request records under our control, and copies or extracts used for evaluation, training or fine-tuning that still contain personal data. Creating a derived copy does not restart this period. We use this period to compare chatbot performance across school years, investigate recurring failures, and evaluate improvements against historical questions.
-
Contact enquiries: up to one year after the last substantive correspondence. This applies to submissions retained in Formspree and email copies held in our correspondence mailboxes.
-
Operational monitoring: the records we retain in Fly.io’s managed searchable application logs and managed performance metrics contain no personal information. They are used for troubleshooting and monitoring service performance, separately from the chatbot records stored in Langfuse. The personal-data retention periods above do not apply to these technical records.
-
Browser storage: the chatbot keeps messages, a conversation reference and the selected model in your browser’s session storage so that the conversation can continue during the session. Resetting the chat clears its local message history and creates a new conversation reference. You can also clear website data through your browser.
At the end of the applicable period, personal records under our control are deleted or anonymised. Limited records may need to be kept longer for a specific legal obligation or an active dispute, only for as long as that reason requires. Statistics that no longer identify individuals may be retained longer.
Our retention periods do not set a universal deletion deadline for information that AI providers, external chat clients or other providers retain for their own purposes. Their retention depends on the applicable service and terms. Deleting a stored conversation does not by itself reverse model training already carried out.
Resetting or closing a browser conversation does not delete copies already held in Langfuse or by AI providers. To request deletion of personal data, use the contact details below.
Security
We use technical and organisational measures to protect information against unauthorised access, loss, alteration and disclosure. These include restricted access to administration and conversation records, encrypted connections and operational monitoring. No internet service can guarantee absolute security.
Your rights
Subject to the conditions in applicable data protection law, you can:
-
Request access to your personal data and correction of inaccurate information.
-
Request erasure or restriction of processing.
-
Object to processing based on legitimate interests.
-
Request data portability where the legal conditions apply.
-
Withdraw consent where a particular processing activity is based on consent, without affecting the lawfulness of earlier processing.
Send requests to info@svietimas.lt. You do not need an account to make a request. A conversation or request reference, approximate date and time, relevant excerpt, or details of the personal information involved can help us locate records. We may ask for proportionate additional information to locate the data and verify that you are entitled to receive or change it.
We do not collect additional identity information solely to link all conversations to named users. If we cannot locate the relevant records or establish that they relate to you, we will explain this. We will consider additional information you provide rather than treating the absence of an account as a reason to reject every request.
We normally respond within one month. If a permitted extension is needed because a request is complex or there are multiple requests, we will explain the reason and timing. Requests concerning your chosen external chat client can also be directed to that provider.
You may lodge a complaint with the Lithuanian State Data Protection Inspectorate or the data protection authority in the EEA country where you live or work or where an alleged infringement occurred.
Children’s privacy
The services provide general education information. Please do not submit identifiable information about children through the chatbot. AI services and external chat clients may have their own minimum-age requirements. If you believe a child’s personal information has been submitted or inappropriately displayed, contact us so that we can investigate and take appropriate action.
Changes to this policy
We may update this policy as our services, providers or data practices change. The date at the top identifies the latest version. We will make material changes visible on the website. Changes to models or routing remain subject to the practices described here; materially different uses of personal data will be reflected in an updated notice.
Contact
For questions about this policy or requests concerning personal data, contact VšĮ Švietimas numeris vienas at info@svietimas.lt or write to Konstitucijos pr. 21A, LT-08130 Vilnius, Lithuania.