Personal Data Processing Rules

  1. General provisions
    • UAB "Water Filtration Systems" (hereinafter referred to as "Company) of personal data processing rules (hereinafter referred to as "Rules) the aim is to regulate the processing of personal data in the Company, ensuring compliance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter referred to as the 'Regulation (EU) 2016/679) and other legislation governing the processing and protection of personal data, compliance and implementation.
    • The purpose of these rules is to define the general and special requirements for the processing of personal data and the organisational and technical measures implemented by the Company.
    • The rules have been drawn up in accordance with Regulation (EU) 2016/679, the Republic of Lithuania Law on Legal Protection of Personal Data (hereinafter referred to as "ADTAĮ) and other legal acts governing the processing and protection of personal data.
    • All persons employed by the Company under employment contracts (hereinafter referred to as "Company employeesand who are entrusted with processing or finding out personal data in the course of their duties.
  2. Concepts
    • Data controller – UAB „Vandens Filtravimo Sistemos“, company code 15835005, registered office address Sierakausko 15A, Vilnius.
    • Data subject – natural persons whose personal data are processed by the Company: employees, clients and other natural persons whose personal data are processed by the Company.
    • Personal data – any information relating to an identified or identifiable natural person (data subject); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name and surname, an identification number, location data and an online identifier or by one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
    • Data processing – any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
    • Data recipient – A natural or legal person, public authority, agency or other body, to which the personal data are disclosed, whether a third party or not.
    • Data handler – a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
    • Health data – personal data relating to the physical or mental health of a natural person, including the provision of health care services, which reveal information about the health status of that natural person.
    • Direct marketing – an activity whose purpose is to offer goods or services to individuals by post, telephone or other direct means and/or to ask for their opinion on the goods or services offered.
    • The terms used in these Terms and Conditions are defined in Regulation (EU) 2016/679, the Law of the Republic of Lithuania on Electronic Communications, and other legal acts of the Republic of Lithuania regulating the processing and protection of personal data.
  3. Principles of personal data processing
    • When processing personal data, the company performs the following functions:
      • establishes the purposes and means of processing personal data;
      • ensures that personal data are collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes;
      • ensures that personal data are processed lawfully, fairly and in a transparent manner;
      • ensures that personal data are adequate, relevant and not excessive for the purposes for which they are processed;
      • ensures that personal data are accurate and, where necessary, kept up to date; inaccurate personal data are erased or rectified without delay;
      • ensures that personal data is kept in a form which permits the identification of Data Subjects for no longer than is necessary for the purposes for which the personal data are processed;
      • ensures that personal data are processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage.
      • ensures the exercise of data subject rights in accordance with Regulation (EU) 2016/679.
  1. Purposes of personal data processing and list of personal data processed
    • Personal data is processed by the Company by automated means and in systematised sets, with personal data being obtained from Data Subjects or third parties.
    • The company processes personal data for the following purposes:
      • For the purposes of product ordering/sales administration, it handles the following customer personal data:
        • The personal data of the person purchasing goods through the Company's website: name, surname, email, telephone number, address(es), password, bank account number, and bank name.
        • Personal data of the person purchasing goods with delivery: first name, last name, address, phone number, email address.
        • The personal data of the person who submitted a request on the Company's website: first name, surname, city, phone number, email address.
      • For internal administration and personnel management purposes, it processes the following personal data:
        • employee personal data: personal name, surname, personal identification code, place of residence or address, contact details (telephone number and/or email address); bank account number and bank name; special categories of personal data: health data, personal medical book; other data.
      • For direct marketing purposes, the following personal data is processed:
        • Name, contact details (phone number and/or email address).

 

 

  1. Key requirements for processing and protecting personal data
    • Personal data is collected in the Company only in accordance with the law, by obtaining it:
      • directly from the Data Subject or from other sources (with the Data Subject's consent);
      • under a personal data provision agreement, concluded between the data controller and the data provider, which must specify the purpose of personal data usage, the legal basis for provision and receipt, the conditions, procedure, and scope of personal data provided (in the case of multiple personal data collections);
      • when the data controller submits a request, which must specify the purpose of the use of personal data, the legal basis for its provision and receipt, and the scope of the personal data requested (in the case of one-off data collection).
    • Personal data may be disclosed to third parties if necessary for the performance of a contract with the Data Subject or for other legitimate reasons. Information may also be provided to other parties at the request of the Data Subject or in accordance with the Data Subject's contractual obligations to other parties, e.g. banks or other financial institutions.
    • Personal data may be provided to third parties upon the recipient's request (in case of one-off transfer) or under a personal data transfer agreement concluded between the Company and the data recipient (in case of multiple transfers).
    • Personal data is provided:
      • To the State Social Insurance Fund Board;

 

 

 

 

  • The Company may disclose the Data Subject’s personal data to data processors who provide services (carry out work) for the Company and process the Data Subject’s personal data on behalf of the Company, as the data controller, having first entered into a data processing agreement with them.
  • Data processors are only authorised to process personal data in accordance with the Company’s instructions and only to the extent necessary to properly fulfil the obligations set out in the service provision contract. The Company engages only those data processors who provide sufficient assurance that appropriate technical and organisational measures will be implemented in such a way that the processing of data complies with the requirements of Regulation (EU) 2016/679 and that the protection of the data subject’s rights is ensured.
  • The data processors are:
    • Information technology companies – which process personal data to ensure the development, improvement, and maintenance of information systems.

 

 

 

  1. Specific requirements for the processing of personal data
    • The company implements the organisational and technical measures set out in the regulations to ensure the appropriate security of personal data, including protection against the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or unauthorised access to, data that has been collected, stored or otherwise processed, including protection against unauthorised or unlawful destruction, loss, alteration, disclosure or access.
    • Where the Data Subject's personal data changes and the Data Subject has informed the Company in writing of this change, the Company, after verifying the accuracy of the personal data, shall, without undue delay, take action to update the data in the information systems managed by the Company by correcting inaccurate personal data relating to them, supplementing incomplete personal data, or deleting personal data relating to them, except in cases where exceptions are provided for in Regulation (EU) 2016/679.
    • Personal data shall be kept in a form which permits the identification of the Data Subject for no longer than is necessary for the purposes for which the personal data are processed, or as required by the Data Subject and/or stipulated by legislation.
    • The company processes only the personal data that is necessary for each specific purpose of data processing set out in point 2 of the policy.
    • The company must ensure the security of premises where personal data is stored (e.g., restricting access for unauthorised individuals).
    • Documents containing personal data, or copies thereof, must be stored in designated areas, locked cupboards, safes and the like. Documents containing personal data must not be kept in a visible place accessible to everyone, where unauthorised persons could easily gain access to them.
    • Documents containing personal data are stored in accordance with the Law on Documents and Archives of the Republic of Lithuania, the General List of Document Retention Periods, approved by Order No. V-100 of the Chief Archivist of Lithuania of 9 March 2011 "On the Approval of the General List of Document Retention Periods". Upon expiry of the retention period, documents containing personal data are destroyed.
    • When destroying documents whose retention period has expired, any documents containing personal data, or copies thereof, must be destroyed in such a way that their content cannot be recovered or identified.
    • Company employees whose computers store personal data, or from whose computers it is possible to access areas of the local network where personal data is stored, must use passwords. Passwords must be changed periodically at least once every 2 (two) months, as well as under certain circumstances (when an employee changes, in the event of a breach, if there is a suspicion that the password has become known to third parties, etc.). These computers must use a password-protected screen saver. Passwords are issued, changed and stored in a manner that ensures their confidentiality. Passwords must be unique, consist of at least 8 (eight) characters, and must not contain any personal information. They must be changed by the user upon first login.
    • Computer files on company employees' computers that contain personal data must not be accessible to users of other computers, except for users to whom the Company has granted such access.
    • Access to personal data in the Company’s information systems must be granted only to those Company employees who require such data to perform their duties.
    • Company employees must only carry out those actions involving personal data for which they have been granted authorisation.
    • To ensure the protection of computer hardware and the personal data contained within, computers must have antivirus software installed, which should be regularly updated.
    • The company must implement data security measures designed to protect its information systems against unauthorised access via electronic means of communication.
    • Personal data stored in backups and archives, and personal data transmitted over external data transmission networks, must be encrypted.
  2. Requirements for company employees who process personal data
    • The Company ensures that access to personal data is granted only to those Company employees who require such data to perform their duties.
    • Company employees who process the personal data of data subjects must:
      • comply with the principles and security requirements relating to the processing of personal data laid down in Regulation (EU) 2016/679, the rules and other legislation governing the processing and protection of personal data;
      • to observe the principle of confidentiality and to keep secret any information relating to personal data to which they have gained access in the course of their duties, unless such information is public in accordance with the provisions of applicable laws or other legislation. The obligation to maintain confidentiality shall remain in force even after the termination of the employment relationship with the Company;
      • comply with the organisational and technical measures set out in these rules in order to ensure the appropriate security of personal data, including protection against the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or unauthorised access to, stored or otherwise processed;
      • not to disclose, not to disclose, transfer or otherwise allow access to and/or familiarisation with personal data to any person who is not authorised to work with and/or familiarise themselves with personal data within the Company or outside it;
      • notify the Company Director without delay, but no later than within 4 (four) working hours from the moment of detection of a suspicious situation or a personal data security breach, of any suspicious situation which may pose a threat to the security of personal data processed in the Company, or of a personal data security breach;
      • to store documents containing personal data and data files properly and securely, avoiding unnecessary copies;
      • comply with the other requirements set out in these rules and in the legislation governing the protection of personal data.
    • Company employees who perform personal data processing functions and who have access to the personal data processed by the Company must sign a standard confidentiality undertaking before commencing the processing of personal data, which is kept in the employee’s personnel file.
    • An employee of the Company loses the right to process the Personal Data of Data Subjects when their employment relationship with the Company ends or when they are assigned to perform functions unrelated to the processing of Personal Data of Data Subjects.
  3. Direct marketing
    • A data subject's personal data may be processed for direct marketing purposes, with or without their consent to the processing of personal data for direct marketing purposes.
    • The data subject has the right to object to the processing of personal data relating to him or her for such marketing purposes at any time.
    • The company shall no longer process (destroy immediately) the Data Subject's personal data for direct marketing purposes as soon as the Data Subject objects to the processing of data for such purposes.
    • For direct marketing purposes, the Company processes the Data Subject’s personal data for a period of 5 years from the date on which consent is given, or until the date on which the Data Subject objects to the processing of their personal data for direct marketing purposes.
    • The use of electronic communications services, including the sending of electronic mail messages, for direct marketing purposes is permitted only with the prior consent of the subscriber or registered user of electronic communications services (Data Subject). In such cases, the Data Subject's consent must be obtained in advance, i.e. before making a call or sending an electronic mail.
    • The company may use the customer's (Data Subject's) email address for marketing its own similar products or services, provided that customers (Data Subjects) are given a clear, free, and easily implementable option to object or opt-out of such use of contact details for the aforementioned purposes when this data is collected and, if the customer (Data Subject) has not initially objected to such use of data, in every message sent.
  4. Procedure for exercising data subject rights
    • Data subject rights are exercised within the Company in accordance with Regulation (EU) 2016/679.
  5. Final provisions
    • All company employees are informed of these rules in writing and acknowledge receipt.
    • For compliance monitoring and control, the responsibility lies with [ ].
    • These rules are reviewed periodically, at least once every 2 (two) years, and updated as necessary.
    • Company employees who violate the requirements of these rules shall be liable in accordance with the procedure established by the laws of the Republic of Lithuania.
Updating...
  • No products in the basket.
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.