How we handle your data
This policy explains how Ex Genesis, UAB processes personal data when you visit fatburn.quest, join the waitlist, or place a preorder.
1) Who we are (Data Controller)
Data Controller: Ex Genesis, UAB (Lithuania).
We currently do not list a DPO contact. For privacy requests, contact us via Instagram: @founder_log.
2) What personal data we collect
- Device and usage data (IP address, device/browser, pages viewed, timestamps, referrer).
- Security logs for abuse prevention and reliability.
- Email address (and optional name if you provide it).
- Signup metadata (timestamp and source/UTM, if present).
- Order details (tier, currency, amount, order status).
- Contact details required for the order (email; later shipping details if needed).
- Payment processing is handled by Stripe. We do not store full card details.
- Your message content and basic contact metadata.
3) Why we process personal data
- To operate the Website and keep it secure.
- To manage preorders: payments, confirmations, refunds (if applicable), and customer support.
- To send product updates if you request them (waitlist/newsletter).
- To measure and improve Website performance (only if optional analytics cookies are enabled).
4) Legal bases (GDPR Art. 6)
- Contract (Art. 6(1)(b)) — to process your preorder and provide related support.
- Legal obligation (Art. 6(1)(c)) — accounting/tax compliance for orders.
- Legitimate interests (Art. 6(1)(f)) — Website security, fraud prevention, minimal operational logs.
- Consent (Art. 6(1)(a)) — marketing emails and non-essential cookies/analytics.
7) International transfers
Some service providers (e.g., Stripe, hosting, email tools) may process data outside the EEA. Where applicable, we rely on appropriate safeguards such as EU Standard Contractual Clauses (SCCs) and/or adequacy decisions.
8) Data retention
- Waitlist / updates: until you unsubscribe or request deletion.
- Orders and payment records: retained as required by accounting/tax laws.
- Support messages: kept as long as needed to resolve your request and handle follow-ups.
- Security logs: kept for a limited period unless needed to investigate abuse or incidents.
9) Your rights (GDPR)
You have the right to access, rectify, erase, restrict processing, object to processing (where applicable), and request data portability. You can withdraw consent at any time for consent-based processing.
To exercise your rights, contact us via Instagram: @founder_log. We aim to respond within one month.
You also have the right to lodge a complaint with your supervisory authority. In Lithuania, this is the State Data Protection Inspectorate (VDAI): vdai.lrv.lt.
10) Security
We use reasonable technical and organisational measures to protect personal data, including HTTPS in transit, access controls, and least-privilege access. No system is 100% secure.
11) Children
The Website is not intended for children under 16. We do not knowingly collect personal data from children.
12) Changes to this policy
We may update this policy from time to time. The latest version will always be published on this page with the updated date.
13) Contact
Data Controller: Ex Genesis, UAB
Privacy requests / support via Instagram: @founder_log
Note: This privacy policy covers personal data processing. Product renders on the Website are conceptual visualizations; final product may differ.