Privacy Policy
Procedure for the processing, use, and storage of personal data.
This procedure regulates the processing, use, and storage of personal data at VŠĮ "Savitri", establishes the rights of data subjects, risk factors of personal data protection violation, personal data protection implementation measures, and other issues related to the processing of personal data.
This procedure regulates the processing, use, and storage of personal data at VŠĮ "Savitri", establishes the rights of data subjects, risk factors for personal data protection breaches, measures for the implementation of personal data protection, and other issues related to the processing of personal data.
1. TERMS USED IN THE RULES
1.1. Authorized persons – employees of the Data Controller (i.e. persons with whom the Data Controller has concluded employment contracts) and / or other physical persons who, based on contracts or other grounds, have the right to process the Processed Personal Data.
1.2. Personal data – any information related to an individual – a data subject whose identity is known or can be directly or indirectly identified, using such data as a personal identification number, one or more physical, physiological, psychological, economic, cultural, or social characteristics characteristic of the person.
1.3. Information system – a set or part of a set of hardware and software in which and through which personal data is processed.
1.4. Processing of personal data – means any operation performed on personal data: collection, recording, accumulation, storage, classification, grouping, combining, changing (supplementing or correcting), provision, publishing, use, logical and/or arithmetic operations, searching, dissemination, destruction, or any other action or set of actions.
1.5. Data recipient – a legal or physical person to whom personal data is provided.
1.6. Data subject – a physical person whose personal data is processed by the Data Controller.
1.7. Data controller – VŠĮ "Savitri", legal entity code 301487578, registered office address Savičiaus g. 13, Vilnius.
1.8. Rules – these Rules for the Processing of Personal Data.
2. PRINCIPLES, PURPOSES, AND MEANS OF DATA PROCESSING
2.1. The Data Controller processes Personal Data in strict compliance with the Law on Legal Protection of Personal Data of the Republic of Lithuania and other requirements of legal acts, as well as the following principles:
2.1.1. Personal data is collected only for defined and legitimate purposes and is processed only for purposes compatible with those established before the collection of Personal Data;
2.1.2. Personal data is processed accurately, fairly, and lawfully;
2.1.3. Personal data is accurate and, if necessary for the processing of Personal Data, constantly updated; inaccurate or incomplete data must be corrected, supplemented, destroyed, or its processing must be suspended;
2.1.4. Personal data is appropriate, relevant, and limited to what is necessary for their collection and further processing;
2.1.5. kept in a form which permits identification of Data Subjects for no longer than is necessary for the purposes for which such data was collected and processed.
2.2. The Data Controller processes the following Personal Data and for the following purposes:
2.2.1. registration for classes, lectures, courses, and other training. Processed data: name, surname, date of birth, place of residence (address), telephone number, email address;
2.2.2. to issue financial documents (e.g., invoices). Processed data: name, surname, personal identification number or date of birth, place of residence (address), bank account number;
2.2.3. direct marketing. Processed data: telephone number and email address.
2.3. Only Authorized Persons who are appointed to process Personal Data have the right to process Personal Data.
2.4. An Authorized Person must:
2.4.1. safeguard the confidentiality of Personal Data;
2.4.2. process Personal Data in accordance with the laws of the Republic of Lithuania, other legal acts, and these Rules;
2.4.3. not disclose, transfer, or create conditions by any means for any person who is not authorized to process Personal Data to access the Personal Data;
2.4.4. immediately notify the head of the Company or their designated person about any suspicious situation that may pose a threat to the security of Personal Data.
2.5. The computers of Authorized Persons who process Personal Data must be password-protected. Passwords must be changed periodically, as well as under certain circumstances (e.g., when the Authorized Person changes, in the event of a hacking threat, if there is a suspicion that the password has become known to third parties, etc.). An Authorized Person working on a specific computer can only know their own password.
2.6. An Authorized Person loses the right to process Personal Data when the employment or similar contract of the Authorized Person with VŠĮ "Savitri" terminates, or when the company's head revokes the Authorized Person's appointment to process Personal Data.
3. PROCEDURE FOR THE IMPLEMENTATION OF DATA SUBJECT RIGHTS
3.1. The Data Subject has the following rights:
3.1.1. to know (be informed) about the processing of their Personal Data;
3.1.2. to gain access to their Personal Data and how it is processed;
3.1.3. to demand the correction, destruction of their Personal Data, or suspension of their Personal Data processing operations, except for storage, when the data is processed in violation of this and other laws;
3.1.4. to object to the processing of their Personal Data;
3.1.5. to receive information from the Data Controller about them (i.e., the Data Controller): name, registered office address, code, place of processing of personal data;
3.1.6. to know for what purposes the Data Subject's Personal Data is processed;
3.1.7. to receive other additional information from the Data Controller (to whom and for what purposes the Data Subject's Personal Data is provided; what Personal Data the Data Subject must provide and what the consequences of not providing the data are, about the Data Subject's right to access their Personal Data and the right to demand correction of incorrect, incomplete, or inaccurate Personal Data), to the extent necessary to ensure proper processing of Personal Data without prejudice to the Data Subject's rights;
3.1.8. The Data Subject, having presented a document proving their identity to the Data Controller, has the right to receive information indicating from which sources and what Personal Data has been collected, for what purpose it is processed, and to which Data Recipients it is and has been provided at least during the last year;
3.1.9. The Data Controller, having received the Data Subject's inquiry regarding the processing of their Personal Data, must answer whether Personal Data related to them is processed and provide the Data Subject with the requested data no later than within 30 calendar days from the date of the Data Subject's request. Upon the Data Subject's request, such data must be provided in writing. The Data Controller provides such data to the Data Subject free of charge once per calendar year.
3.1.10. if the Data Subject, having familiarized themselves with their Personal Data, determines that their Personal Data is incorrect, incomplete, or inaccurate, and applies to the Data Controller, the Data Controller must immediately verify the Personal Data and, upon the Data Subject's request (expressed in written, oral, or other form), immediately correct incorrect, incomplete, or inaccurate Personal Data and/or suspend the processing operations of such Personal Data, except for storage.
3.1.11. if the Data Subject, having familiarized themselves with their Personal Data, determines that their Personal Data is processed unlawfully or unfairly, and applies to the Data Controller, the Data Controller must immediately check the legality and fairness of the processing of Personal Data free of charge and, upon the Data Subject's request (expressed in writing), immediately destroy the unlawfully and unfairly accumulated Personal Data or suspend the processing operations of such Personal Data, except for storage.
3.1.12. if the processing operations of the Data Subject's Personal Data are suspended at their request, the Personal Data, the processing of which has been suspended, must be stored until it is corrected or destroyed (at the Data Subject's request or upon expiry of the data storage period). Other processing actions with such Personal Data may only be performed: for the purpose of proving the circumstances due to which the processing actions were suspended; if the Data Subject gives consent to further process their personal data; blockages necessary to protect the rights or legitimate interests of third parties.
3.1.13. The Data Controller must immediately notify the Data Subject of the correction, destruction, or suspension of the processing operations of Personal Data performed or not performed at their request.
3.1.14. Personal Data is corrected and destroyed, or its processing activities are suspended on the basis of the Data Subject's identity and documents confirming their Personal Data, upon receipt of the Data Subject's request.
3.1.15. if the Data Controller doubts the accuracy of the Personal Data provided by the Data Subject, they must suspend the processing of such data, verify, and correct the data. Such Personal Data may only be used to verify its accuracy.
3.1.16. The Data Controller must immediately inform the Data Recipients about the Personal Data corrected or destroyed at the request of the Data Subject, or suspended processing actions of Personal Data, except where providing such information would be impossible or excessively difficult (due to a large number of Data Subjects, data period, disproportionate costs). In such a case, the State Data Protection Inspectorate must be notified immediately.
3.1.17. The Data Subject also has all other rights granted to them under the Law on Legal Protection of Personal Data of the Republic of Lithuania and other legal acts.
3.2. The Data Controller undertakes in all cases to create appropriate conditions for the Data Subject to exercise the rights specified in Clause 3.1 of these Rules, except as provided by law when it is necessary to ensure: state security or defense; public order, prevention, investigation, detection, or prosecution of criminal offenses; important economic or financial interests of the state; prevention, investigation, and detection of violations of official or professional ethics; protection of the rights and freedoms of the Data Subject or other persons.
3.3. The Data Controller, having received the Data Subject's request to exercise the rights specified in Clause 3.1 of the Rules, shall examine and satisfy it within 30 calendar days from the date of the Data Subject's request, or provide reasoned refusal to satisfy it. If the Data Subject's request is expressed in writing, the Data Controller shall provide a response in writing.
3.4. The Data Subject may appeal against the actions (inaction) of the Data Controller to the State Data Protection Inspectorate within 3 months from the date of receipt of the response from the Data Controller or within 3 months from the day when the period specified in Clause 3.3 of these Rules to provide an answer expires.
4. RECIPIENTS OF PERSONAL DATA AND THE PROCEDURE FOR PROVIDING PERSONAL DATA
4.1. Data collected by the Data Controller is generally used only by the Data Controller themselves to achieve the purposes for which they were collected.
4.2. The Data Controller generally does not provide the collected Processed Personal Data to anyone. Available Personal Data is generally processed only by the Data Controller themselves.
4.3. The Data Controller transfers the Processed Personal Data only in exceptional cases, for a legitimate purpose, and only in the event that the person receiving the Processed Personal Data undertakes to ensure a level of Personal Data protection no less than that ensured by the Data Controller themselves.
5. PROCEDURE FOR GRANTING, REVOKING, AND CHANGING ACCESS RIGHTS AND AUTHORIZATIONS TO PROCESS PERSONAL DATA
5.1. Authorized Persons who are employees of the Data Controller have the right to process Personal Data from the beginning to the end of their employment relations.
5.2. Authorized Persons who are not employees of the Data Controller have the right to process Personal Data from the moment the Data Controller grants them such right until this right is revoked or expires.
6. RISK FACTORS FOR PERSONAL DATA PROTECTION BREACHES
6.1. A breach of personal data protection refers to actions or omissions that may cause or cause unwanted consequences, as well as violate the mandatory norms of laws regulating Personal Data protection. The degree of impact, damage, and consequences of a breach of personal data protection is determined in each specific case by the director of VŠĮ "Savitri" or a commission formed by them.
6.2. Risk factors for personal data protection breaches:
6.2.1. unintentional, when Personal Data protection is breached due to accidental reasons (data processing errors, deletion, destruction of information media, data records, incorrect routing (addresses) during data transmission, etc., or system disruptions due to power outages, computer viruses, etc., breach of internal rules, lack of system maintenance, software tests, improper maintenance of data media, inadequate line capacity and protection, computer networking, lack of computer program protection, insufficient supply of fax materials, etc.);
6.2.2. intentional, when Personal Data protection is breached deliberately (unauthorized intrusion into the premises of VŠĮ "Savitri", information systems, computer network, malicious violation of established rules in processing Personal Data, deliberate distribution of a computer virus, theft of Personal Data, illegal use of another Authorized Person's rights, etc.);
6.2.3. unexpected accidental events (lightning, fire, flood, water damage, storms, combustion of electrical wiring, influence of temperature and/or humidity changes, influence of dirt, dust, and magnetic fields, accidental technical accidents, other force majeure and/or uncontrollable factors, etc.).
7. PERIOD OF PERSONAL DATA PROCESSING
7.1. The processing of Personal Data begins after the Data Subject has given their consent to the processing of their Personal Data.
7.2. VŠĮ "Savitri" stores Personal Data for no longer than required by the purposes of data processing, and upon expiration of the terms specified in legal acts, all Personal Data is destroyed.
8. FINAL PROVISIONS
8.1. For Authorized Persons who violate the Law on Legal Protection of Personal Data of the Republic of Lithuania, other legal acts regulating the processing and protection of Personal Data, or these Rules, the liability measures provided for in the laws of the Republic of Lithuania shall apply.
8.2. Supervision of compliance with the Rules and, if necessary, their review at least once every 2 years is entrusted to the director of VŠĮ "Savitri" or their authorized person.
8.3. Responsible Authorized Persons are introduced to the Rules under signature.

