Privacy Policy

Last updated: July 2026

This policy explains how we collect, use, store and protect your personal data in compliance with the General Data Protection Regulation and other applicable EU data protection law, when you visit our website, read our educational content, or book and attend a Live Session.

1. Who we are

1.1 Data controller

Brains On Duty, UAB, trading as Ticking Biology, is the data controller responsible for your personal data.

Company code: 307333551

Address: Manufaktūrų g. 6, LT-11342 Vilnius, Lithuania

Email: support@tickingbiology.com

We are not required to appoint a Data Protection Officer and have not appointed one. Data questions go to the address above.

2. Personal data we collect

2.1 Categories of personal data

Identity data. Your first name and surname.

Contact data. Email address. Billing address and country where required for tax purposes. Telephone number only if you choose to give it.

Booking and transaction data. Which session you booked, the amount paid, the date and time of payment, and the reference issued by our payment provider. We do not receive or store your full card number. Card details are entered directly into Stripe and are never visible to us. We see only the last four digits, the card brand and the country of issue.

Session participation data. Whether you attended, questions you submit before or during a session, messages you post in the chat, and your image and voice if you choose to switch on your camera or microphone. See section 4.3.

Support group data. Anything you post in the private group that runs for three weeks after a session, including comments and replies.

Technical data. IP address, browser type and version, time zone setting, operating system, device type and screen size.

Usage data. Pages viewed, time on page, referring source, and how you move through the website, collected through cookies and analytics as described in section 10.

Marketing data. Your preferences for receiving email from us and your record of consent or withdrawal.

2.2 Health related data

If you write to us, submit a question at booking, speak during a session or post in the support group, you may choose to tell us about your symptoms, your treatment or your health. That is special category data under Article 9 of the GDPR and it receives additional protection.

You are not required to share anything about your health, and you can take part fully without doing so. Where you do share it, we process it only on the basis of your explicit consent, given at the point you submit the question or post the message. You may withdraw that consent at any time by writing to support@tickingbiology.com. We will stop using the material, remove it from our systems, and delete it where deletion is technically possible. Withdrawal does not undo processing that already took place lawfully, and we cannot recall material that has already been shown in a live session or shared with other participants. We may retain a minimal record where the law requires it, for example in accounting records.

We never use health information you share to target advertising, and we never pass it to advertising or analytics providers.

Questions submitted at booking are anonymised before they are discussed in a session. We remove your name and any identifying detail.

2.3 How we collect it

Directly from you, when you book a place, fill in a form, submit a question, join a session or write to us.
Automatically, through cookies, analytics and server logs, as described in section 10.
From our payment provider, which confirms your payment and passes us your email address and limited card metadata.

3. Legal basis for processing

What we processWhyLegal basis
Name, email, booking recordTo confirm your place, send joining instructions and give you access to the recording and the groupPerformance of a contract
Payment and billing dataTo take payment and issue receiptsPerformance of a contract
Payment and billing data, retainedTo meet accounting and VAT obligationsLegal obligation
Session recordingsTo supply the recording that forms part of your purchasePerformance of a contract
Health information you choose to shareTo answer your question and run the sessionExplicit consent, Article 9 (2) (a)
Marketing emailTo send you news about future sessionsConsent, or legitimate interest where you are an existing customer and have not opted out
Analytics cookiesTo understand how the website is used and improve itConsent
Security logs and fraud preventionTo protect the website and our businessLegitimate interests

Where we rely on consent you may withdraw it at any time, and withdrawal does not affect processing carried out before you withdrew.

4. How we use your personal data

4.1 Running your booking

We use your name and email to confirm your booking, send joining instructions and reminders, give you the recording and the written guide, admit you to the support group, and answer any question you send us about your place.

4.2 Payments, invoices and tax

We use your payment and billing data to take payment, issue a receipt, calculate VAT correctly and keep the records that Lithuanian accounting law requires.

4.3 Recording sessions

Live Sessions are recorded so that the recording can be supplied to everyone who booked. If you keep your camera and microphone off and do not type in the chat, you will not appear in the recording.

Recordings are hosted on a private link available only to people who booked, for 30 days after the session. If you appear in a recording and want your contribution removed, write to us and we will edit or remove that part where it is technically possible to do so.

4.4 The support group

The group is private and open only to people who booked. Anything you post there is visible to other participants and to our moderators. Other participants are not under our control, so please share only what you are comfortable for them to read. The group closes three weeks after the session and its content is deleted.

4.5 Marketing

We send email about future sessions only if you asked us to, or if you bought from us and have not opted out. Every email carries an unsubscribe link. We do not sell your data and we do not share it with third parties for their own marketing.

4.6 Improving the website and our content

We use aggregated analytics to understand which pages are read and where people leave, and to plan future session topics. This is aggregate reporting, not decisions about individuals.

4.7 No automated decision making

We do not carry out automated decision making or profiling that produces legal or similarly significant effects for you.

5. Data sharing and our processors

We share your personal data only with the providers listed below and with legal authorities where the law requires it. The providers in the first table act as our processors under a data processing agreement, meaning they handle your data on our instructions and not for their own purposes.

Our processors

ProviderWhat it doesData involvedTransfers outside the EEA
Stripe Payments Europe, Ltd., with Stripe, LLC as sub-processorProcesses payments and issues receiptsName, email, card data entered directly with Stripe, billing country, amountYes, to the United States, under the EU to US Data Privacy Framework
Google Ireland Limited, Google Analytics 4Website analyticsPseudonymous identifier, truncated IP address, pages viewed, device and browser dataYes, to the United States, under the EU to US Data Privacy Framework
Google Ireland Limited, Google Tag ManagerLoads and manages the tags we useIP address processed to serve the container. The container itself sets no cookiesYes, to the United States, under the EU to US Data Privacy Framework
Hostinger International, Ltd.Hosts the website and stores form submissionsAll data submitted through the siteYes, to the United States, under the EU to US Data Privacy Framework
Zoom Communications, Inc.Hosts the live session and produces the recordingName entered on joining, email address, IP address, and your image, voice and chat messages if you choose to take partYes, to the United States, under the EU to US Data Privacy Framework
OmnisendSends joining instructions, reminders and newslettersName, email, open and click dataYes, to the United States, under Standard Contractual Clauses

Joint and independent controllers

ProviderWhat it doesData involvedTransfers outside the EEA
Meta Platforms Ireland Ltd. and Meta Platforms, Inc.Tracks ad performance and delivers targeted marketing through the Meta PixelIP address, browser type, pages visited, button clicks and purchase actionsYes, to the United States
WhatsApp Ireland Limited, part of the Meta groupHosts the private support groupYour telephone number, your WhatsApp profile name and photo, and metadata about your messages. Message content is end to end encrypted, so WhatsApp cannot read what you postYes, to the United States

Meta is not our processor. For the Meta Pixel we and Meta act as joint controllers for the collection and transmission of the data described above, and Meta acts as an independent controller for what it does with that data afterwards. WhatsApp acts as an independent controller under its own privacy policy, which you accepted when you created your WhatsApp account, and we have no data processing agreement with it. Meta’s terms are at meta.com and WhatsApp’s are at whatsapp.com/legal.

Important, before you join the WhatsApp group. Every member of a WhatsApp group can see the telephone number and profile name of every other member, and can save those numbers. You cannot hide your number from the group. If you would rather not share your number with other participants, tell us at support@tickingbiology.com and we will send you the group materials, exercises and office hours by email instead.

We also use professional advisers such as accountants and lawyers, who are bound by confidentiality. If our business is sold or merged, data may transfer to the buyer, who would be bound by this policy.

5.1 Use of the Meta Pixel for analytics and advertising

We use the Meta Pixel, formerly the Facebook Pixel, on our website. This tracking technology is operated by Meta Platforms Ireland Ltd. and Meta Platforms, Inc.

The Meta Pixel allows us to see what visitors do on our website after they arrive by clicking on a Meta advertisement. This helps us measure how well our advertising works for statistical and market research purposes, improve our campaigns, and build custom audiences for future remarketing.

The data collected through the Meta Pixel, such as your IP address, browser type, pages visited and actions taken on our site, is shared with Meta. Meta stores and processes this data in accordance with its own privacy policy. Meta may link the information to your Facebook or Instagram account and use it for its own promotional purposes.

The Meta Pixel is only loaded if you accept marketing cookies through our cookie banner.

Cookie set by the Meta Pixel

CookieSet byPurposeDuration
_fbpMetaIdentifies the browser so that advertising can be measured and delivered3 months

6. International transfers

Some of our providers are based in, or transfer data to, the United States. Where that happens we rely on one of the following safeguards.

The EU to US Data Privacy Framework, where the recipient is certified under it. Stripe and Google are certified participants.
Standard Contractual Clauses approved by the European Commission, with supplementary measures where needed. This applies where a provider is not DPF certified, and in some cases alongside DPF certification.

You may ask us which safeguard applies to a specific transfer by writing to support@tickingbiology.com.

7. Data security

We use appropriate technical and organisational measures to protect your personal data against accidental loss, unauthorised access, alteration or disclosure. These include encryption in transit, access controls limiting who on our side can see booking data, and private links for recordings and group access.

We have procedures for handling suspected personal data breaches, and we will notify you and the supervisory authority where the law requires it.

No transmission over the internet is completely secure. Please do not send us sensitive health information by email when a private route is available.

8. Data retention

8.1 How long we keep things

DataRetention period
Name and contact data2 years after your last booking or interaction
Payment and transaction records10 years, as required by Lithuanian accounting law
Session recordings30 days after the session, then deleted
Questions submitted at bookingUntil the session has taken place, then anonymised or deleted within 30 days
Support group contentAfter 2 years of inactivity
Health information you sharedDeleted with the material it appeared in, or sooner on request
Marketing preferencesUntil you withdraw consent, or after 2 years of inactivity
Technical and usage data in analytics14 months in Google Analytics
Server and security logs12 months

We review these periods regularly.

8.2 Anonymisation

We may anonymise data so that it can no longer be linked to you, for example to count how many people attended a session or which topics drew the most questions. Once anonymised it is no longer personal data and we may keep it indefinitely.

9. Your rights

Under the GDPR you have the right to:

Access. Request a copy of the personal data we hold about you.

Rectification. Have inaccurate or incomplete data corrected.

Erasure. Have your data deleted where there is no good reason for us to keep it. Note that we cannot delete payment records before the ten year accounting period ends.

Restriction. Ask us to pause processing while a dispute about accuracy or lawfulness is resolved.

Portability. Receive the data you gave us in a structured, commonly used, machine readable format, or have it sent to another controller.

Objection. Object to processing based on our legitimate interests, and object to direct marketing at any time with no reason needed.

Withdrawal of consent. Withdraw any consent you gave, including consent to health related processing and to cookies, at any time.

Rights relating to automated decisions. We do not carry out such decision making, so this right does not arise in practice.

To exercise any of these, write to support@tickingbiology.com. We answer within one month. There is no fee unless a request is manifestly unfounded or excessive.

10. Cookies and tracking

10.1 How we handle consent

Our cookie banner lets you accept or reject non-essential cookies before they are set. Only strictly necessary cookies run before you choose. You can change your choice at any time through the Cookie Settings link in the website footer.

We use Google Tag Manager to load our tags. The container itself sets no cookies. It is configured so that analytics tags fire only after you have given consent through the banner.

10.2 Cookies we use

Strictly necessary. Required for the site and the checkout to work. These run without consent because the service cannot be delivered without them.

CookieSet byPurposeDuration
Session cookieOur websiteKeeps your session and secures form submissionsUntil you close the browser
Cookie consent recordOur consent toolRemembers your cookie choice12 months
__stripe_midStripeFraud prevention, identifies the browser across payment attempts12 months
__stripe_sidStripeFraud prevention within a single checkout30 minutes

Analytics, consent required. These help us understand how the site is used.

CookieSet byPurposeDuration
_gaGoogle Analytics 4Distinguishes one visitor from another2 years
_ga_[container id]Google Analytics 4Maintains session state2 years

10.3 What Google Analytics does with the data

Google Analytics 4 collects a pseudonymous identifier, the pages you view, roughly where you are based on a truncated IP address, and technical details of your device. IP addresses are truncated before storage and we do not receive your full IP address through Analytics.

We have not enabled Google Signals, advertising personalisation or data sharing with other Google products. Analytics data is retained for 14 months.

You can opt out of Google Analytics across all sites using the browser add-on published by Google, in addition to rejecting analytics cookies here.

10.4 Third parties on the payment page

When you go to pay, checkout is hosted by Stripe. Stripe sets its own cookies for fraud prevention and processes your data as a controller for its own compliance purposes. Its privacy policy applies to that page and is published at stripe.com/privacy.

11. Children

Our services are intended for adults. You must be at least 18 to book a Live Session, and we do not knowingly collect data from anyone under 18. If we learn that we have, we delete it promptly.

12. Changes to this policy

We may update this policy. Where a change is significant we will post the new version here and, where appropriate, tell you by email. The date at the top shows when it was last revised.

13. Contact and complaints

Questions, requests and complaints go to support@tickingbiology.com.

You also have the right to complain to a supervisory authority, in particular in the EU member state where you live or work, or where you believe the infringement occurred.

In Lithuania this is the State Data Protection Inspectorate, Valstybinė duomenų apsaugos inspekcija:

Website: vdai.lrv.lt

Telephone: +370 5 271 2804

Email: ada@ada.lt

We would appreciate the chance to resolve the matter first.

No results