Privacy Policy

A notice for website visitors:

By visiting this website and (or) using the information or services contained here, You acknowledge and agree that you are familiar with the following Personal Data Processing Rules and understand them. We reserve the right, in our sole discretion, to change the Personal Data Processing Rules, therefore, when visiting this website, make sure you are familiar with the updated version of the Personal Data processing Rules, which will apply each time You visit this website and (or) use our services.

 


APPROVED
by Order of General Director
of UAB "Click2Sell"
No. 2014/12/22/1
as of  22 December 2014

 


PERSONAL DATA PROCESSING RULES

I. GENERAL PROVISIONS

1. The purpose of the Personal Data Processing Rules (hereinafter – the Rules) – to regulate the processing of personal data by UAB “Click2Sell”, by ensuring the compliance and enforcement of the Law on Legal Protection of Personal Data of the Republic of Lithuania, internal procedures of UAB “Click2Sell” for the implementation of the money laundering and terrorist financing preventive measures, and other legal acts regulating the processing and protection of personal data.

2. The Rules purpose are intended to provide key conditions for the processing of personal data and measures and inform data subjects of the processing of their personal data and related rights.

3. The Rules shall apply to all employees of UAB “Click2Sell” (hereinafter – the Administrative staff) who process personal data available in UAB “Click2Sell” or get to know them while performing their duties.

4. Definitions used:

4.1. Data subject – a user of payment services provided by UAB “Click2Sell” whose personal data are processed by UAB “Click2Sell”.

4.2. Data Controller – UAB “Click2Sell”, company code 300110581, correspondence address – Ateities 77-27, Vilnius, LT-06324, Republic of Lithuania, e-mail address – [email protected] UAB “Click2Sell” is registered in the Register of Personal Data Controllers, registration code P6316.

4.3. Data recipient – a legal or a natural person to whom personal data are disclosed.

4.4. Data processor – a legal or a natural person, other than an employee of the Data Controller, processing personal data on behalf of the Data Controller.

4.5. Data processing - any operation, which is performed with personal data such as collection, recording, accumulation, storage, classification, grouping, combining, alteration (supplementing or rectifying), disclosure, making available, use, logical and/or arithmetic operations, retrieval, dissemination, destruction or any other operation or a set of operations.

4.6. Data processing by automatic means - any operation performed with personal data carried out in whole or in part by automatic means.

4.7. Website – website www.cardinity.com managed by UAB “Click2Sell”.

5. Other terms used in these Rules match the definitions, laid down in the Law on Legal Protection of Personal Data of the Republic of Lithuania and Law on Payments of the Republic of Lithuania.

6. The Rules have been prepared in accordance with the Law on Legal Protection of Personal Data of the Republic of Lithuania and other legal acts regulating legal protection of personal data.

II. KEY PERSONAL DATA MANAGEMENT AND PROTECTION PRINCIPLES

7. Administrative staff, in performing its duties and processing personal data, must comply with the following personal data processing and protection principles:

7.1. Personal data are collected for specified and legitimate purposes, laid down in legal acts, and later are processed in a way compatible with the purposes determined;

7.2. Collection and processing of personal data are carried out in compliance with the principles of expediency and proportionality, data subjects are not required to submit the data that are not necessary. Excessive data are not stored or processed either;

7.3. Personal data are processed accurately, fairly and lawfully;

7.4. Personal data must be accurate and, where necessary, for purposes of personal data processing, kept up to date; inaccurate or incomplete data must be rectified, supplemented, erased or their further processing must be suspended;

7.5. Personal data are kept in a form which permits identification of data subjects for no longer than it is necessary for the purposes for which the data were collected and processed.

8. Personal data are collected only in accordance with legal acts, by obtaining them directly from a data subject, by applying officially to entities that manage the necessary information and are entitled to transfer it, or to contracts, as well as by logging to separate data collecting databases, registers, and information systems pursuant to legal acts.

9. Personal data shall not be stored longer than it is necessary for data processing purposes. Personal data must be destroyed when they are no more needed for their processing purposes, with the exception of data which must be transferred to State archives in the cases laid down in laws.

10. UAB “Click2Sell” shall ensure that any necessary information is disclosed to a data subject clearly and properly.

11. In cases and pursuant to the procedure laid down in legal acts, UAB “Click2Sell” shall have the right to transfer personal data processed by it to third parties. Personal data may be transferred to member states of the European Union and states of the European Economic Area.

12. Goal of UAB “Click2Sell” – to ensure the maximum security degree of personal data and related information. It has adopted appropriate organisational, administrative, and technical security measures to protect personal information against accidental or illegal destruction, alteration, disclosure, and against all other illegal forms of data processing.

III. PERSONAL DATA PROCESSING

13. Personal data shall be processed and disclosed to relevant authorities in accordance with the Law on Legal Protection of Personal Data of the Republic of Lithuania, rules of payment card organisations, PCI DSS (Payment Card Industry Data Security Standard), and other laws and legal acts of the Republic of Lithuania.

14. The Data Controller shall collect and use a data subject's personal data, which the latter discloses while using the Data Controller’s services, only in accordance with the procedure and for the purposes laid down in the Rules.

15. When using the Data Controller services, a data subject agrees the data, specified by him/her, to be processed for the indicated data collection and use purposes. In case of the data subject’s disagreement, expressed in accordance with the procedure laid down in clause 27.4.1 of the Rules, the Data Controller shall not be entitled to use such personal data (except for personal data storage), while the data subject shall not be entitled to use the Data Controller’s services.

16. UAB “Click2Sell” processes personal data for the following purposes:

16.1. When a data subject is a customer (a merchant) of UAB “Click2Sell”, with whom a service contract is concluded, the data subject’s personal data shall be processed for the purpose of concluding or performing contracts with customers on payment and/or other related services as well as for client identification purposes.

16.2. When a data subject is a payment card holder, the data subject’s personal data shall be processed for the purpose of authorising payment transactions made by payment cards.

17. UAB “Click2Sell” processes the following personal data of data subjects:

1) For the purpose of concluding or performing contracts with customers on payment and/or other related services as well as for client identification purposes: name, surname, personal identification number, date of birth, place of residence (address), data of identity document, workplace, position, phone number, e-mail address;

2) For the purpose of authorising payment transactions made by payment cards: name, surname, payment card number, payment card security code (CVV), card expiration date, phone number, e-mail address.

18. Data subjects' personal data are stored in databases managed by UAB “Click2Sell”.

19. Data subjects' personal data may be processed solely by persons authorised by General Director of UAB“Click2Sell”.

20. The data subject's personal data are stored:

1) For the purpose of concluding or performing contracts with customers on payment and/or other related services as well as for client identification purposes: 10 years following the closure of transactions or business relations with the customer;

2) For the purpose of authorising payment transactions made by payment cards: 10 years following the closure of transactions or business relations with the payment card holder.

21. Upon any change in data subjects’ personal data or data inaccuracy, such data subjects must immediately notify UAB “Click2Sell” thereof in writing. On a request of the data subject, personal data are corrected, revised, and updated based on the data subject's identity and personal data supporting documents. Authorised employees of UAB “Click2Sell” must promptly update and/or revise the data in relevant databases. Processing of the updated personal data is subject to all provisions of the Rules.

22. Transfer of personal data to data recipients. Authorised employees of UAB “Click2Sell” may transfer a data subject's personal data to payment service users, i.e., recipients (merchants engaged in e-commerce, whose goods or services are paid by a payment card holder) and payers, payment card organisations and partners of UAB "Click2Sell" for identification of the data subject and authorisation of payment transactions, as well as to other persons, as far as necessary for the performance of a service contract between the data subject and UAB “Click2Sell”. Personal data shall be disclosed under a personal data disclosure contract between the Data Controller and the data recipient in the case of a multiple disclosure or in response to a request of the data recipient in the case of a single disclosure. The contract must specify the purpose for which personal data will be used, the legal basis for disclosure and receipt, the conditions, the procedure of use, and the extent of personal data that is disclosed. The request must specify the purpose for which personal data will be used, the legal basis for disclosure and receipt, and the extent of personal data requested. When personal data are processed in an automated manner and appropriate data safety measures are applied in transferring of personal data under the personal data disclosure contract between the Data Controller and the data recipient, priority shall be given to the automatic data transfer, while in transferring of personal data under the request of the data recipient - to the data transfer by electronic means.

23. Data processors. An authorised data processor of UAB “Click2Sell” is a server rental services company with the functions including data collection, storage, backup, and other related activities; as well as partners of UAB “Click2Sell” and financial institutions, with the functions covering the use of data for provision of services and authorisation of payment cards.

IV. PERSONAL DATA PROCESSING BY AUTOMATIC MEANS

24. Personal data by automatic means shall be processed for the purposes under clauses 16.1, 16.2.
25. The following personal data shall be processed by automatic means:
25.1. Name and surname of a person;
25.2. Personal identification number
25.3. Date of birth;
25.4. Place of residence (address);
25.5. Phone number;
25.6. E-mail address;
25.7. Data of identity document;
25.8. Workplace;
25.9. Position;
25.10. Payment card details (payment card number, payment card security code (CVV), payment card expiration date).

V. RIGHTS OF DATA SUBJECTS

26. Responsible employees of UAB “Click2Sell” shall ensure that a data subject's rights are properly exercised and all the necessary information is presented to the data subject in a clear, understandable, and acceptable form.

27. The data subject's rights and ways of exercising them:

27.1. To know (be informed) about the processing of the one’s personal data.

27.1.1. UAB “Click2Sell”, while collecting personal data either directly from a data subject or other sources, must provide the following information: its requisites; the purposes of the processing of the data subject’s personal data; the recipient and the purposes of disclosure; particular personal data that the data subject must provide, and the consequences of his/her failure to provide the data.

27.1.2. UAB “Click2Sell” must provide a data subject with information about his/her right of access to his/her personal data, his/her right to request rectification of incorrect, inaccurate and incomplete personal data, and his/her right to object to the processing of his/her personal data. This information is posted on the website of UAB “Click2Sell” www.cardinity.com.

27.2. To have an access to the one’s personal data and to be informed of how they are processed:

27.2.1. A data subject presenting to UAB “Click2Sell” a document certifying his/her identity shall have the right to obtain information on the sources and the type of his/her personal data that has been collected, the purpose of their processing and the data recipients to whom the data are disclosed or have been disclosed.

27.2.2. An authorised employee of UAB “Click2Sell” shall prepare a response and disclose the requested data or justify the refusal to grant the request of the data, no later than within 30 calendar days of the date of the enquiry. On a request of a data subject, such data must be disclosed in writing. Only the requests for personal data processing that are presented in writing shall be considered (by e-mail [email protected] or by post Ateities 77-27, Vilnius, LT-06324, Republic of Lithuania).

27.2.3. Once a calendar year, the Data Controller shall disclose such data free of charge. If a data subject applies not for the first time per calendar year, the amount of the fee for the data, disclosed not for the first time per calendar year, shall not exceed the cost of disclosure of the data.

27.3. To request rectification or destruction of the one’s personal data or suspension of further processing of the one’s personal data, where the data are processed not in compliance with the provisions of this Law and other laws.

27.3.1. Where a data subject, after familiarizing with his/her personal data, finds that his/her personal data are incorrect, incomplete and inaccurate and applies to UAB “Click2Sell” by presenting a document certifying his/her identity, a responsible employee  of UAB “Click2Sell” must check the personal data concerned without delay and, at a written, oral or any other request of the data subject, rectify the incorrect, incomplete and inaccurate personal data and (or) suspend processing of such personal data, except storage, without delay, as well as inform the data recipient of the rectification, destruction or suspension of processing of the data subject’s personal data, at the request of the data subject, or the failure to do so without delay.

27.3.2. A data subject must send the request on rectification or destruction of his/her personal data or suspension of further processing of his/her personal data in writing or by e-mail at the addresses specified in the Rules.

27.4. Right to withhold a consent to the processing of personal data.

27.4.1. A data subject objecting against the processing of his/her personal data must notify UAB “Click2Sell” and stop using its services. The data subject, not willing his/her personal data to be processed or used for the purposes specified, shall have the right to object to the processing of his personal data by notifying UAB “Click2Sell” thereof by e-mail: [email protected], provided that the data subject loses the right to use services of UAB “Click2Sell”.

27.5. The right to change the one’s personal data.

27.5.1. A data subject, if necessary (for example, upon change of personal data) shall have the right to change and (or) to update the personal data.

VI. COOKIES

28. UAB “Click2Sell” uses cookies on this website. Cookies are small files which are sent to a data subject’s web browser or the other website access equipment and stored in the data subject’s device. At present, UAB “Click2Sell” uses PHPSESSID, Java Session ID, and Google Analytics cookies.

29. Cookies are used to collect statistical information about website traffic and identification of the data subject’s device, facilitate the data subject’s access to this website and the information contained therein, and ensure smooth operation. Cookies are not used for collecting personal data. Third parties are not able to identify the data subject, by using cookies collected within UAB “Click2Sell”.

30. UAB “Click2Sell” shall use cookies only with the prior and voluntary consent of a data subject. The data subject gives his/her consent to the use of cookies in the way specified on the website. Cookies shall not be stored without the data subject's consent.

31. The data subject may revoke his/her consent and delete the stored cookies at any time. The data subject may revoke his/her consent by changing his/her device’s settings so that not to accept cookies or by notifying UAB “Click2Sell”about it by e-mail [email protected] Once the data subject revokes his/her consent to the use of cookies, some features of our website may not work or operate correctly.

VII. AMENDMENTS OF THE RULES

32. UAB “Click2Sell”shall be entitled to amend the Rules, in whole or in part, by notifying thereof on the website of UAB “Click2Sell” and by e-mail specified by a data subject.

33. Supplements or amendments to the Rules shall be effective upon publication of them, i.e., on the date they are posted on the website www.cardinity.com or sent to a data subject by e-mail.

34. If a data subject continues to use services of UAB “Click2Sell” after the Rules have been supplemented or amended, the data subject shall be considered as having consented to the updated version of the Rules.

VIII. FINAL PROVISIONS

35. All notifications related to the processing of personal data shall be sent to the Data Controller by e-mail [email protected] or by post to UAB “Click2Sell”, Ateities 77-27, Vilnius, LT-06324, Republic of Lithuania.

36. The Data Controller shall provide an answer in the same form in which the notification was received from the data subject within the time limit set out by the Rules.

37. UAB “Click2Sell” shall not be responsible for a data subject's privacy or a compliance with the personal data rules on third-party websites even in the case the data subject accesses third-party websites using links on this website. UAB “Click2Sell” recommends a data subject to review personal data processing rules of each of the websites not belonging to UAB “Click2Sell”.

38. These Rules and relations of a data subject and the controller are subject to laws of the Republic of Lithuania. Any disputes arising from the Rules or relations of a data subject and the controller shall be resolved through negotiations, and upon failure – in a competent court of the Republic of Lithuania at the place of location of UAB “Click2Sell”.