Privacy Policy
PERSONAL DATA PROCESSING RULES
- General Provisions
- UAB „Vandens Filtravimo Sistemos“ (hereinafter – the „Company“) personal data processing rules (hereinafter – the „Rules“) are intended to regulate the processing of personal data within the Company, ensuring compliance with and implementation of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter – the „Regulation (EU) 2016/679“), and other legal acts governing the processing and protection of personal data.
- The purpose of these Rules is to set out the general and special requirements for the processing of personal data, and the organizational and technical measures implemented by the Company.
- The Rules have been prepared in accordance with Regulation (EU) 2016/679, the Law on Legal Protection of Personal Data of the Republic of Lithuania (hereinafter – the „LPPD“), and other legal acts governing the processing and protection of personal data.
- The Rules must be observed by all persons working at the Company under employment contracts (hereinafter – „Company employees“) who are entrusted with processing or who become aware of personal data in the course of performing their duties.
- Definitions
- Data controller – UAB „Vandens Filtravimo Sistemos“, company code 158350052, registered office address Sierakausko 15A, Vilnius.
- Data subject – natural persons whose personal data are processed by the Company: employees, clients, and other natural persons whose personal data are processed by the Company.
- Personal data – any information relating to an identified or identifiable natural person (data subject); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
- Data processing – any operation or set of operations performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
- Data recipient – a natural or legal person, public authority, agency, or other body to which personal data are disclosed, whether or not it is a third party.
- Data processor – a natural or legal person, public authority, agency, or other body which processes personal data on behalf of the data controller.
- Health data – personal data related to the physical or mental health of a natural person, including data on the provision of healthcare services, which reveal information about that natural person’s state of health.
- Direct marketing – activity aimed at offering goods or services to persons by mail, telephone, or other direct means, and/or seeking their opinion on the goods or services offered.
- Other terms used in these Rules are defined in Regulation (EU) 2016/679, the Law on Electronic Communications of the Republic of Lithuania, and other legal acts of the Republic of Lithuania governing the processing and protection of personal data.
- Principles of Personal Data Processing
- When processing personal data, the Company performs the following functions:
- determines the purposes and means of processing personal data;
- ensures that personal data are collected for specified, explicit, and legitimate purposes and are not further processed in a manner incompatible with those purposes;
- ensures that personal data are processed lawfully, fairly, and in a transparent manner;
- ensures that personal data are adequate, relevant, and limited to what is necessary for the purposes for which they are processed;
- ensures that personal data are accurate and, where necessary, kept up to date; inaccurate personal data are erased or rectified without delay;
- ensures that personal data are kept in a form which permits identification of the Data subject for no longer than is necessary for the purposes for which the personal data are processed;
- ensures that personal data are processed in a manner that ensures appropriate security of the personal data through the application of technical and organizational measures, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage.
- ensures the exercise of the Data subject’s rights in accordance with the procedure established by Regulation (EU) 2016/679.
- When processing personal data, the Company performs the following functions:
- Purposes of Personal Data Processing and List of Personal Data Processed
- Personal data are processed by the Company using automated means and in structured filing systems, obtaining personal data from Data subjects or third parties.
- The Company processes personal data for the following purposes:
- For the purposes of administering the ordering/sale of goods, it processes the following personal data of clients:
- personal data of a person purchasing goods via the Company’s website: name, surname, e-mail, phone number, address(es), password, bank account number, and bank name.
- Personal data of a person purchasing goods with delivery: name, surname, address, phone number, e-mail.
- Personal data of a person submitting an inquiry on the Company’s website: name, surname, city, phone number, e-mail.
- For the purposes of internal administration and personnel management, it processes the following personal data:
- personal data of employees: name, surname, personal identification number, place of residence or address, contact details (phone number and/or e-mail address); bank account number and bank name; special categories of personal data: health data, personal health record book; other data.
- For direct marketing purposes, it processes the following personal data:
- the person’s name, contact details (phone number and/or e-mail address).
- For the purposes of administering the ordering/sale of goods, it processes the following personal data of clients:
- Basic Requirements for the Processing and Protection of Personal Data
- Personal data are collected by the Company only in accordance with the procedure established by legal acts, obtaining them:
- directly from the Data subject or from other sources (with the Data subject’s consent);
- under a personal data provision agreement concluded between the data controller and the data provider, which must specify the purpose of using the personal data, the legal basis for provision and receipt, the conditions, procedure, and scope of the personal data provided (in the case of multiple collection of personal data);
- by submitting a request to the data controller, which must specify the purpose of using the personal data, the legal basis for provision and receipt, and the scope of the personal data requested (in the case of a one-off collection of personal data).
- Personal data may be disclosed to third parties if necessary to perform a contract with the Data subject or for other legitimate reasons. Information may also be provided to other parties at the request of the Data subject or in view of the Data subject’s contractual obligations to other parties, e.g., banks or other financial institutions.
- Personal data may be provided to third parties at the request of the data recipient (in the case of one-off provision) or under a personal data provision agreement concluded between the Company and the data recipient (in the case of multiple provision).
- Personal data are provided to:
- the State Social Insurance Fund Board;
- Personal data are collected by the Company only in accordance with the procedure established by legal acts, obtaining them:
- The Company may provide the Data subject’s personal data to data processors who provide services to the Company (perform work) and process the Data subject’s personal data on behalf of the Company, as data controller, having first concluded a data processing agreement with them.
- Data processors have the right to process personal data only in accordance with the Company’s instructions and only to the extent necessary to properly fulfill the obligations set out in the service provision agreement. The Company engages only those data processors that provide sufficient guarantees that appropriate technical and organizational measures will be implemented in such a manner that processing will meet the requirements of Regulation (EU) 2016/679 and ensure the protection of the Data subject’s rights.
- The data processors are:
- information technology companies – which process personal data to ensure the development, improvement, and maintenance of information systems.
- Special Requirements for Personal Data Processing
- The Company implements the organizational and technical measures specified in these Rules in order to ensure appropriate security of personal data, including protection against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to, data received, stored, or otherwise processed.
- If a Data subject’s personal data changes and the Data subject notifies the Company thereof in writing, the Company, having verified the accuracy of the personal data, shall without undue delay take steps to update the data in the Company’s information systems by correcting inaccurate personal data relating to the subject, supplementing incomplete personal data, or erasing personal data relating to the subject, except for the exceptions established in Regulation (EU) 2016/679.
- Personal data are kept in a form which permits identification of the Data subject for no longer than is necessary for the purposes for which the personal data are processed, or as required by the Data subject and/or provided for by legal acts.
- The Company processes only the personal data that are necessary for each specific data processing purpose set out in point 2 of the Rules.
- The Company must ensure the security of the premises in which personal data are stored (restricting access of unauthorized persons to the relevant premises, etc.).
- Documents containing personal data, or copies thereof, are kept in designated premises, locked cabinets, safes, etc. Documents containing personal data must not be kept in a publicly accessible, visible place where unauthorized persons could freely view them.
- Documents containing personal data are kept in accordance with the Law on Documents and Archives of the Republic of Lithuania and the General Document Retention Schedule approved by Order No. V-100 of the Chief Archivist of Lithuania of 9 March 2011 „On the Approval of the General Document Retention Schedule“. Upon expiry of the retention period, documents containing personal data are destroyed.
- When destroying documents whose retention period has expired, documents containing personal data, or copies thereof, must be destroyed in such a way that they cannot be reconstructed and their content cannot be recognized.
- Company employees whose computers store personal data, or from whose computers access can be gained to local network areas where personal data are stored, must use passwords. Passwords must be changed periodically, not less than once every 2 (two) months, and also under certain circumstances (change of employee, emergence of a hacking threat, suspicion that the password has become known to third parties, etc.). These computers must use a password-protected screensaver. Passwords are assigned, changed, and stored in a manner ensuring their confidentiality. Passwords must be unique, consist of at least 8 (eight) characters, and must not use personal information. They must be mandatorily changed by the user upon first login.
- Computer files located on Company employees’ computers in which personal data are stored must not be accessible to other computer users, except for users to whom the Company has granted such a right.
- Access to personal data in the Company’s information systems must be granted only to the Company employee for whom personal data are necessary for the performance of their job functions.
- Company employees may perform with personal data only those actions for which they have been granted rights.
- To ensure the protection of computer equipment and the personal data contained therein, antivirus programs must be installed on computers and must be updated periodically.
- The Company must ensure data security measures designed to protect information systems from unauthorized access via electronic communications.
- Personal data stored in backup copies and archives, and personal data transmitted over external data transmission networks, must be encrypted.
- Requirements for Company Employees Processing Personal Data
- The Company ensures that access to personal data is granted only to those Company employees for whom such data are necessary for the performance of their job functions.
- Company employees who process Data subjects’ personal data must:
- comply with the principles and security requirements relating to the processing of personal data established in Regulation (EU) 2016/679, these Rules, and other legal acts governing the processing and protection of personal data;
- observe the principle of confidentiality and keep secret any information related to personal data which they became aware of in the course of performing their job functions, unless such information is public under the provisions of applicable laws or other legal acts. The obligation to maintain confidentiality continues to apply after the termination of the employment relationship with the Company;
- comply with the organizational and technical measures set out in these Rules in order to ensure appropriate security of personal data, including protection against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to, data received, stored, or otherwise processed;
- not disclose, transfer, or otherwise provide the ability to use and/or access personal data to any person who is not entrusted with working with and/or accessing personal data within the Company or outside it;
- immediately, but no later than within 4 (four) working hours from the moment a suspicious situation or a personal data security breach becomes apparent, notify the Company’s manager of any suspicious situation that may pose a threat to the security of personal data processed by the Company, or of a personal data security breach;
- store documents containing personal data and data files properly and securely, avoiding the making of unnecessary copies;
- comply with other requirements set out in these Rules and in legal acts governing the protection of personal data.
- Company employees performing personal data processing functions and having access to personal data processed by the Company must, before starting to process personal data, sign a confidentiality undertaking in the established form, which is kept in the employee’s personal file at the Company.
- A Company employee loses the right to process Data subjects’ personal data when their employment relationship with the Company ends or when they are assigned functions unrelated to the processing of Data subjects’ personal data.
- Direct Marketing
- A Data subject’s personal data may be processed for direct marketing purposes once they have expressed consent or objection to the processing of their personal data for direct marketing purposes.
- The Data subject has the right, at any time, to object to the processing of personal data relating to them for such marketing purposes.
- The Company ceases processing (immediately destroys) the Data subject’s personal data for direct marketing purposes as soon as the Data subject objects to the processing of data for that purpose.
- For direct marketing purposes, the Company processes the Data subject’s personal data for 5 years from the moment consent is given, or until the day the Data subject objects to the processing of their personal data for direct marketing purposes.
- The use of electronic communications services, including the sending of e-mail messages, for direct marketing purposes is permitted only after obtaining the prior consent of the subscriber or registered user of electronic communications services (the Data subject). In such cases, the Data subject’s consent must be obtained in advance, i.e., before making a call or sending an e-mail.
- The Company may use a client’s (Data subject’s) existing e-mail address for the marketing of its own similar goods or services, provided that clients (Data subjects) are given a clear, free, and easily exercisable opportunity to object to or refuse such use of their contact details for the purposes stated above, at the time these data are collected, and, if the client (Data subject) did not initially object to such use of data, with every message sent.
- Procedure for the Exercise of Data Subjects’ Rights
- The Data subject’s rights are exercised at the Company in accordance with Regulation (EU) 2016/679.
- Final Provisions
- All Company employees are familiarized with these Rules against signature.
- Responsible for the supervision and control of compliance with these Rules: [ ].
- These Rules are reviewed periodically, not less than once every 2 (two) years, and updated as necessary.
- Company employees who violate the requirements of these Rules shall be liable in accordance with the procedure established by the legal acts of the Republic of Lithuania.
