PRIVACY POLICY

PRIVACY POLICY

This Privacy Policy (hereinafter referred to as the Policy) gives information on how EPS LT, UAB (hereinafter may be referred to as EPS or we) processes personal data of its customers (the Policy may refer to them as Customers, Data Subjects or You). For the purposes of this Policy, EPS acts as the personal data controller. This Policy applies to us and our Customers who use, have used, intend to use or are otherwise related to our products or services. In provision of services to our Customers, we seek to ensure a high level of personal data privacy and their protection. In compliance with the principle of transparency, in this Policy we explain what Customers’ personal data processing and protection rules and provisions we follow in our activities. All personal data are processed according to the EU General Data Protection Regulation (2016/679) and other EU or national legal acts providing for additional personal data protection requirements.

Terms used in the Policy

Customer shall mean any natural person who uses, has used, stated an intent to use or is otherwise related to EPS products (services, goods), as well as provider of goods/services in respect of EPS (who can be mentioned in the Policy as the Customer (natural person)). Employees or other authorised representatives of legal entities that are EPS clients may also be regarded as Customers (who can be mentioned in the Policy as Customer (legal entity’s employee or another authorised representative)).

Personal data shall mean any information, directly or indirectly related to a Customer, making it possible to identify the Customer.

Personal data processing shall mean operation which is performed upon the personal data: collection, recording, sorting, storage, modification (supplementing and correction), consultation, disclosure, use, erasure, destruction or another operation or set of operations.

What personal data processing principles and legal bases do we follow in processing Your data?

We process Your data in accordance with the following data processing principles:

  • We process personal data in a lawful, fair and transparent manner;
  • We collect and process personal data only for established, clear and legitimate purposes;
  • We ensure that we collect data only to achieve the established purposes;
  • We take measures to ensure that personal data are accurate and, if necessary, we seek to update or correct them;
  • We store personal data no longer than necessary to achieve the purposes for which they are collected;
  • We process personal data by ensuring their confidentiality and security, including protection against unlawful or unauthorized processing and/or access. We also ensure protection against their accidental disclosure, loss, destruction or damage.

We process the Customers’ personal data only if there is a legal basis for such processing, i.e. if processing meets at least one of the following conditions:

  • Your consent has been obtained to process Your personal data for specific purposes (consent);
  • Personal data are processed for the purpose of concluding a contract or fulfilling contractual obligations (contractual obligations);
  • For fulfilment of a statutory legal obligation (legal obligation);
  • In pursuance of our legitimate interests as those of a personal data controller and service provider, save for cases when Your interests are overriding (legitimate interest).

What aims do we seek in processing Your personal data?

Maintaining relationship with Customers and provision and administration of possibilities to use our products:

  • Conclusion and performance of a contract;
  • Data updating to ensure their correctness, using information provided by the Customer himself, external and internal registers, also when that is necessary for the performance of the contract or taking action at the Customer’s request before conclusion of the contract or for the fulfilment of a legal obligation.

Risk assessment:

  • Assessment on what conditions and what products we can offer to our Customers;
  • Performance of duties provided for in legal acts in connection with business conduct risk assessment;
  • Management of the Customer’s debt;
  • Compliance with operational risk management requirements;
  • Performance of internal calculations and analysis, where necessary for the performance of a contract, taking action at the request of the Customer prior to the conclusion of a contract or in the fulfilment of a legal obligation, or pursuing EPS legitimate interest to ensure sound risk management.

Protection of legitimate interests of the Customer and/or EPS:

  • Protection of interests of the Customer and/or EPS;
  • Checking of the quality of services provided by EPS;
  • Ability to provide evidence of a commercial transaction or of other business communication (recording of conversations, storage of e-mails, other correspondence), when that is necessary for contract performance, taking action at the Customer’s request prior to the conclusion of a contract or in the fulfilment of a legal obligation;
  • Legitimate interest of EPS to perform prevention and investigation of any improper or unlawful use of EPS products or their damage, employee training and ensuring the quality of EPS products.
  • Ensuring security of EPS and/or the Customer, defence of other rights of EPS and the Customer (video and/or audio recording), pursuing the legitimate interest of EPS to protect its customers, employees, visitors, their assets and/or EPS assets.

Offering of additional products, asking for the Customer’s opinion, market research and collection of statistical data:

  • For the purpose of offering products of EPS and/or its partners to the Customer, with the Customer’s consent and pursuing a legitimate interest of EPS, in connection with offering of additional products;
  • For the purpose of Customers’ opinion surveys, market research and/or collection of statistical data, organising discounts for Customers, with the Customer’s consent and pursuing a legitimate interest of EPS to improve the quality of EPS products, experience of Customers as service recipients (their representatives), also with the aim to create new products.

Identification:

  • Identification where necessary for the performance of a contract, for the fulfilment of a legal obligation or for the legitimate interest of EPS to ensure adequate risk and organizational management.

Establishment, exercise or defence of legal claims:

  • For the purposes of establishment, exercise, assignment and defence of legal claims, when that is necessary for contract performance, taking action at the Customer’s request prior to the conclusion of a contract or in the fulfilment of a legal obligation, or pursuing a legitimate interest of EPS in connection with exercise of legal claims.

How do we obtain Your personal data?

We can obtain personal data directly from You, from Your actions by making use of our products (services, goods) and from external sources – such as registers administered by the state and/or private persons and from other third parties.

What personal data do we process?

The main categories of personal data of Customers (natural persons) that we process are, without limitation:

  • Person’s identification data: first name, surname;
  • Contact details: address, telephone number(s), e-mail address;
  • Data relating to commercial activities: data relating to Your self-employed activity or other similar economic-commercial activities. Statistical data on turnover, number of points of sale and their location, may be collected. Statistical data are normally collected from external sources and can be used in conjunction with data we have;
  • Financial data: information on account(s) in a credit institution (bank, etc.), the credit institution where an account is opened;
  • Data relating to reliability and performance evaluation: data on debts to the national treasury and the treasury of the State Social Insurance Fund, debts and/or damage caused to EPS;
  • Data obtained and/or created when fulfilling requirements of legal acts: data obtained in reply to requests from law enforcement authorities, notaries public, the tax administrator, courts and judicial officers;
  • Data about the Customer’s code and place of residence for tax purposes: data about the place of performance of commercial activities, personal ID number (as the taxpayer ID);
  • Data collected by means of communications and other technical means: data collected upon Your arrival to the registered office of EPS (including video surveillance data) or in communication with EPS by phone, video and/or audio recording means, e-mail, messages and other means of communication, such as social networks, data related to the Customer’s visits to the EPS website(s) or use of other EPS channels of communication;
  • Other data that You provide to EPS or enable to obtain them in performance of a concluded contract(s).

The main categories of personal data of Customers (legal entity’s employees or other authorised representatives) that we process are, without limitation:

  • Person’s identification data: first name, surname;
  • Contact details: telephone number(s), e-mail address;
  • Data about Your relationship with legal persons: data You have provided or that we obtain from public registers or for the purposes of performance of a third party transaction on behalf of a relevant legal entity (job position, place of work, character of work, etc.);
  • Data obtained and/or created when fulfilling requirements of legal acts: data obtained in reply to requests from law enforcement authorities, notaries public, the tax administrator, courts and judicial officers;
  • Data collected by means of communications and other technical means: data collected upon Your arrival to the registered office of EPS (including video surveillance data) or in communication with EPS by phone, video and/or audio recording means, e-mail, messages and other means of communication, such as social networks, data related to Your visits to the EPS website(s) or use of other EPS channels of communication;
  • Other data that you provide to EPS or enable to obtain them in performance of a concluded contract(s).

All personal data are processed in the territory of the European Union (EU) / the European Economic Area (EEA).

 

Direct marketing

We may process personal data in order to improve the quality of products supplied to You, for example, by adapting the products offered for Your equipment.

If you have agreed to the processing of personal data for direct marketing purposes, we may process personal data in order to provide general and personal offers of our products.

We undertake to stop processing Your personal data for direct marketing purposes if you object to it. You can inform us about Your objection to processing of Your personal data for marketing purposes as indicated below.

To whom can we transfer Your personal data?

When processing Your personal data, where necessary, we may transfer them to the following recipients:

  • Public institutions and authorities, other persons carrying out the functions assigned to them by law (e.g. law enforcement authorities, judicial officers, notaries public, tax administration authorities, authorities supervising EPS);
  • Persons servicing/supporting our IT equipment (service providers), transferring only data necessary for service provision;
  • Auditors, legal, financial, tax advisors, property (business) valuators, authorized data processors;
  • Third parties that administer registers (including the Register of Legal Entities, other registers where personal data are processed) or that intermediate in obtaining personal data from such registers;
  • Debt collection companies or other persons, to which claims to the Customer’s debts are assigned, courts, out-of-court dispute resolution institutions and bankruptcy administrators, persons that secure proper performance of obligations (sureties, guarantors, pledgors);
  • Third parties that provide personnel selection and related services to us;
  • Other persons involved in the performance of our economic-commercial activities, such as archiving, postal and telecommunications service providers, vendors, other authorized/involved persons.

How long do we store Your data?

Personal data storage period is defined with regard to the character of concluded contracts, legitimate interest or requirements of legal acts.

In all cases, personal data is processed for no longer than necessary for those purposes for which they are collected or required by applicable legal acts.

We process Your data. What rights do You have?

  • You have the right to know whether we process Your personal data and, if we do so, to get access to them;
  • You may request the rectification of Your personal data if they are incorrect, incomplete or inaccurate;
  • You have the right to request the erasure of Your personal data if they are no longer necessary to achieve the purpose of data processing, if You withdraw Your consent or object to data processing, if Your personal data are processed illegally or in other circumstances provided for in legal acts on data protection. If the processing of personal data requested to be erased is necessary on another legal basis, such as for the purposes of performance of a contract or legal obligations, we will not be able to erase them;
  • You have the right to request restriction of the processing of Your personal data in the circumstances provided for in legal acts;
  • You have the right to receive personal data that you provided to us in a structured, commonly used and machine-readable format and that are processed on the basis of consent or performance of contractual obligations. You can request that we transmit those data to another controller if that is technically possible;
  • You may object to the processing of personal data where they are processed in our legitimate interest, save for cases when such data are processed for lawful reasons that override the interests of the data subject, or in order to fulfil a legal obligation;
  • You have the right to withdraw Your consent to the processing of personal data;
  • You have the right to lodge a complaint regarding personal data processing with the State Data Protection Inspectorate if You suspect that EPS acts in breach of legal acts on personal data protection.

How can You contact us?

Please always contact us if you have any questions, you wish to apply for the exercise of Your rights as those of a data subject whose data we process, or if you have any complaints about the processing of Your personal data, using the contact details presented on this website.

In order to ensure data security, we accept requests for the exercise of data subject’s rights or complaints in writing – by registered mail or by e-mail.

In order to manage the risks and protect Your personal data against accidental loss, disclosure or misappropriation, when you wish to access or receive Your personal data we process, we are obliged to identify You properly:

  • We can ask you to come to our office at Savanoriu Ave. 123A, Vilnius, Lithuania;
  • We can ask You to produce Your personal identity document or its notarised copy;
  • If another person wants to access Your personal data, he will be required to present a notarised power of attorney You have given him.

We analyse and evaluate requests for the exercise of the data subject’s rights each time individually, and we shall inform You on the decision taken without undue delay, in any case no later than within 1 month as of the receipt of Your request.

Validity of the Policy

We constantly review conformity of the Policy provisions to our activities, therefore, the Policy can be updated and modified. Your rights will not be restricted due to any changes being made.

Once the Policy is updated, its effective version is immediately published on this website.

SUPPORT 24/7