Privacy Policy
Last updated: July 2026
This policy explains how we collect, use, store and protect your personal data in compliance with the General Data Protection Regulation and other applicable EU data protection law, when you visit our website, read our educational content, or book and attend a Live Session.
1. Who we are
1.1 Data controller
Brains On Duty, UAB, trading as Ticking Biology, is the data controller responsible for your personal data.
Company code: 307333551
Address: Manufaktūrų g. 6, LT-11342 Vilnius, Lithuania
Email: support@tickingbiology.com
We are not required to appoint a Data Protection Officer and have not appointed one. Data questions go to the address above.
2. Personal data we collect
2.1 Categories of personal data
Identity data. Your first name and surname.
Contact data. Email address. Billing address and country where required for tax purposes. Telephone number only if you choose to give it.
Booking and transaction data. Which session you booked, the amount paid, the date and time of payment, and the reference issued by our payment provider. We do not receive or store your full card number. Card details are entered directly into Stripe and are never visible to us. We see only the last four digits, the card brand and the country of issue.
Session participation data. Whether you attended, questions you submit before or during a session, messages you post in the chat, and your image and voice if you choose to switch on your camera or microphone. See section 4.3.
Support group data. Anything you post in the private group that runs for three weeks after a session, including comments and replies.
Technical data. IP address, browser type and version, time zone setting, operating system, device type and screen size.
Usage data. Pages viewed, time on page, referring source, and how you move through the website, collected through cookies and analytics as described in section 10.
Marketing data. Your preferences for receiving email from us and your record of consent or withdrawal.
2.2 Health related data
If you write to us, submit a question at booking, speak during a session or post in the support group, you may choose to tell us about your symptoms, your treatment or your health. That is special category data under Article 9 of the GDPR and it receives additional protection.
You are not required to share anything about your health, and you can take part fully without doing so. Where you do share it, we process it only on the basis of your explicit consent, given at the point you submit the question or post the message. You may withdraw that consent at any time by writing to support@tickingbiology.com. We will stop using the material, remove it from our systems, and delete it where deletion is technically possible. Withdrawal does not undo processing that already took place lawfully, and we cannot recall material that has already been shown in a live session or shared with other participants. We may retain a minimal record where the law requires it, for example in accounting records.
We never use health information you share to target advertising, and we never pass it to advertising or analytics providers.
Questions submitted at booking are anonymised before they are discussed in a session. We remove your name and any identifying detail.
2.3 How we collect it
Directly from you, when you book a place, fill in a form, submit a question, join a session or write to us.
Automatically, through cookies, analytics and server logs, as described in section 10.
From our payment provider, which confirms your payment and passes us your email address and limited card metadata.
3. Legal basis for processing
| What we process | Why | Legal basis |
| Name, email, booking record | To confirm your place, send joining instructions and give you access to the recording and the group | Performance of a contract |
| Payment and billing data | To take payment and issue receipts | Performance of a contract |
| Payment and billing data, retained | To meet accounting and VAT obligations | Legal obligation |
| Session recordings | To supply the recording that forms part of your purchase | Performance of a contract |
| Health information you choose to share | To answer your question and run the session | Explicit consent, Article 9 (2) (a) |
| Marketing email | To send you news about future sessions | Consent, or legitimate interest where you are an existing customer and have not opted out |
| Analytics cookies | To understand how the website is used and improve it | Consent |
| Security logs and fraud prevention | To protect the website and our business | Legitimate interests |
Where we rely on consent you may withdraw it at any time, and withdrawal does not affect processing carried out before you withdrew.
4. How we use your personal data
4.1 Running your booking
We use your name and email to confirm your booking, send joining instructions and reminders, give you the recording and the written guide, admit you to the support group, and answer any question you send us about your place.
4.2 Payments, invoices and tax
We use your payment and billing data to take payment, issue a receipt, calculate VAT correctly and keep the records that Lithuanian accounting law requires.
4.3 Recording sessions
Live Sessions are recorded so that the recording can be supplied to everyone who booked. If you keep your camera and microphone off and do not type in the chat, you will not appear in the recording.
Recordings are hosted on a private link available only to people who booked, for 30 days after the session. If you appear in a recording and want your contribution removed, write to us and we will edit or remove that part where it is technically possible to do so.
4.4 The support group
The group is private and open only to people who booked. Anything you post there is visible to other participants and to our moderators. Other participants are not under our control, so please share only what you are comfortable for them to read. The group closes three weeks after the session and its content is deleted.
4.5 Marketing
We send email about future sessions only if you asked us to, or if you bought from us and have not opted out. Every email carries an unsubscribe link. We do not sell your data and we do not share it with third parties for their own marketing.
4.6 Improving the website and our content
We use aggregated analytics to understand which pages are read and where people leave, and to plan future session topics. This is aggregate reporting, not decisions about individuals.
4.7 No automated decision making
We do not carry out automated decision making or profiling that produces legal or similarly significant effects for you.
5. Data sharing and our processors
We share your personal data only with the providers listed below and with legal authorities where the law requires it. The providers in the first table act as our processors under a data processing agreement, meaning they handle your data on our instructions and not for their own purposes.
Our processors
| Provider | What it does | Data involved | Transfers outside the EEA |
| Stripe Payments Europe, Ltd., with Stripe, LLC as sub-processor | Processes payments and issues receipts | Name, email, card data entered directly with Stripe, billing country, amount | Yes, to the United States, under the EU to US Data Privacy Framework |
| Google Ireland Limited, Google Analytics 4 | Website analytics | Pseudonymous identifier, truncated IP address, pages viewed, device and browser data | Yes, to the United States, under the EU to US Data Privacy Framework |
| Google Ireland Limited, Google Tag Manager | Loads and manages the tags we use | IP address processed to serve the container. The container itself sets no cookies | Yes, to the United States, under the EU to US Data Privacy Framework |
| Hostinger International, Ltd. | Hosts the website and stores form submissions | All data submitted through the site | Yes, to the United States, under the EU to US Data Privacy Framework |
| Zoom Communications, Inc. | Hosts the live session and produces the recording | Name entered on joining, email address, IP address, and your image, voice and chat messages if you choose to take part | Yes, to the United States, under the EU to US Data Privacy Framework |
| Omnisend | Sends joining instructions, reminders and newsletters | Name, email, open and click data | Yes, to the United States, under Standard Contractual Clauses |
Joint and independent controllers
| Provider | What it does | Data involved | Transfers outside the EEA |
| Meta Platforms Ireland Ltd. and Meta Platforms, Inc. | Tracks ad performance and delivers targeted marketing through the Meta Pixel | IP address, browser type, pages visited, button clicks and purchase actions | Yes, to the United States |
| WhatsApp Ireland Limited, part of the Meta group | Hosts the private support group | Your telephone number, your WhatsApp profile name and photo, and metadata about your messages. Message content is end to end encrypted, so WhatsApp cannot read what you post | Yes, to the United States |
Meta is not our processor. For the Meta Pixel we and Meta act as joint controllers for the collection and transmission of the data described above, and Meta acts as an independent controller for what it does with that data afterwards. WhatsApp acts as an independent controller under its own privacy policy, which you accepted when you created your WhatsApp account, and we have no data processing agreement with it. Meta’s terms are at meta.com and WhatsApp’s are at whatsapp.com/legal.
Important, before you join the WhatsApp group. Every member of a WhatsApp group can see the telephone number and profile name of every other member, and can save those numbers. You cannot hide your number from the group. If you would rather not share your number with other participants, tell us at support@tickingbiology.com and we will send you the group materials, exercises and office hours by email instead.
We also use professional advisers such as accountants and lawyers, who are bound by confidentiality. If our business is sold or merged, data may transfer to the buyer, who would be bound by this policy.
5.1 Use of the Meta Pixel for analytics and advertising
We use the Meta Pixel, formerly the Facebook Pixel, on our website. This tracking technology is operated by Meta Platforms Ireland Ltd. and Meta Platforms, Inc.
The Meta Pixel allows us to see what visitors do on our website after they arrive by clicking on a Meta advertisement. This helps us measure how well our advertising works for statistical and market research purposes, improve our campaigns, and build custom audiences for future remarketing.
The data collected through the Meta Pixel, such as your IP address, browser type, pages visited and actions taken on our site, is shared with Meta. Meta stores and processes this data in accordance with its own privacy policy. Meta may link the information to your Facebook or Instagram account and use it for its own promotional purposes.
The Meta Pixel is only loaded if you accept marketing cookies through our cookie banner.
Cookie set by the Meta Pixel
| Cookie | Set by | Purpose | Duration |
| _fbp | Meta | Identifies the browser so that advertising can be measured and delivered | 3 months |
6. International transfers
Some of our providers are based in, or transfer data to, the United States. Where that happens we rely on one of the following safeguards.
The EU to US Data Privacy Framework, where the recipient is certified under it. Stripe and Google are certified participants.
Standard Contractual Clauses approved by the European Commission, with supplementary measures where needed. This applies where a provider is not DPF certified, and in some cases alongside DPF certification.
You may ask us which safeguard applies to a specific transfer by writing to support@tickingbiology.com.
7. Data security
We use appropriate technical and organisational measures to protect your personal data against accidental loss, unauthorised access, alteration or disclosure. These include encryption in transit, access controls limiting who on our side can see booking data, and private links for recordings and group access.
We have procedures for handling suspected personal data breaches, and we will notify you and the supervisory authority where the law requires it.
No transmission over the internet is completely secure. Please do not send us sensitive health information by email when a private route is available.
8. Data retention
8.1 How long we keep things
| Data | Retention period |
| Name and contact data | 2 years after your last booking or interaction |
| Payment and transaction records | 10 years, as required by Lithuanian accounting law |
| Session recordings | 30 days after the session, then deleted |
| Questions submitted at booking | Until the session has taken place, then anonymised or deleted within 30 days |
| Support group content | After 2 years of inactivity |
| Health information you shared | Deleted with the material it appeared in, or sooner on request |
| Marketing preferences | Until you withdraw consent, or after 2 years of inactivity |
| Technical and usage data in analytics | 14 months in Google Analytics |
| Server and security logs | 12 months |
We review these periods regularly.
8.2 Anonymisation
We may anonymise data so that it can no longer be linked to you, for example to count how many people attended a session or which topics drew the most questions. Once anonymised it is no longer personal data and we may keep it indefinitely.
9. Your rights
Under the GDPR you have the right to:
Access. Request a copy of the personal data we hold about you.
Rectification. Have inaccurate or incomplete data corrected.
Erasure. Have your data deleted where there is no good reason for us to keep it. Note that we cannot delete payment records before the ten year accounting period ends.
Restriction. Ask us to pause processing while a dispute about accuracy or lawfulness is resolved.
Portability. Receive the data you gave us in a structured, commonly used, machine readable format, or have it sent to another controller.
Objection. Object to processing based on our legitimate interests, and object to direct marketing at any time with no reason needed.
Withdrawal of consent. Withdraw any consent you gave, including consent to health related processing and to cookies, at any time.
Rights relating to automated decisions. We do not carry out such decision making, so this right does not arise in practice.
To exercise any of these, write to support@tickingbiology.com. We answer within one month. There is no fee unless a request is manifestly unfounded or excessive.
10. Cookies and tracking
10.1 How we handle consent
Our cookie banner lets you accept or reject non-essential cookies before they are set. Only strictly necessary cookies run before you choose. You can change your choice at any time through the Cookie Settings link in the website footer.
We use Google Tag Manager to load our tags. The container itself sets no cookies. It is configured so that analytics tags fire only after you have given consent through the banner.
10.2 Cookies we use
Strictly necessary. Required for the site and the checkout to work. These run without consent because the service cannot be delivered without them.
| Cookie | Set by | Purpose | Duration |
| Session cookie | Our website | Keeps your session and secures form submissions | Until you close the browser |
| Cookie consent record | Our consent tool | Remembers your cookie choice | 12 months |
| __stripe_mid | Stripe | Fraud prevention, identifies the browser across payment attempts | 12 months |
| __stripe_sid | Stripe | Fraud prevention within a single checkout | 30 minutes |
Analytics, consent required. These help us understand how the site is used.
| Cookie | Set by | Purpose | Duration |
| _ga | Google Analytics 4 | Distinguishes one visitor from another | 2 years |
| _ga_[container id] | Google Analytics 4 | Maintains session state | 2 years |
10.3 What Google Analytics does with the data
Google Analytics 4 collects a pseudonymous identifier, the pages you view, roughly where you are based on a truncated IP address, and technical details of your device. IP addresses are truncated before storage and we do not receive your full IP address through Analytics.
We have not enabled Google Signals, advertising personalisation or data sharing with other Google products. Analytics data is retained for 14 months.
You can opt out of Google Analytics across all sites using the browser add-on published by Google, in addition to rejecting analytics cookies here.
10.4 Third parties on the payment page
When you go to pay, checkout is hosted by Stripe. Stripe sets its own cookies for fraud prevention and processes your data as a controller for its own compliance purposes. Its privacy policy applies to that page and is published at stripe.com/privacy.
11. Children
Our services are intended for adults. You must be at least 18 to book a Live Session, and we do not knowingly collect data from anyone under 18. If we learn that we have, we delete it promptly.
12. Changes to this policy
We may update this policy. Where a change is significant we will post the new version here and, where appropriate, tell you by email. The date at the top shows when it was last revised.
13. Contact and complaints
Questions, requests and complaints go to support@tickingbiology.com.
You also have the right to complain to a supervisory authority, in particular in the EU member state where you live or work, or where you believe the infringement occurred.
In Lithuania this is the State Data Protection Inspectorate, Valstybinė duomenų apsaugos inspekcija:
Website: vdai.lrv.lt
Telephone: +370 5 271 2804
Email: ada@ada.lt
We would appreciate the chance to resolve the matter first.