Политика обработки персональных данных

PRIVACY POLICY

 

GENERAL INFORMATION

Paylar, UAB (Formerly known as UAB «UPLATA EU»), corporate code 305182887, head office address – Žygimanto Liauksmino g. 3A-4, Vilnius, the Republic of Lithuania, Lithuanian Bank authorisation No LB001876 (hereinafter – Data Controller), by this privacy policy (hereinafter – the Privacy Policy) establishes the terms and conditions for personal data processing at the company managed by the Data Controller, when using the electronic payment services provided under trade name PAYLAR.COM and when using the website https://paylar.com  (hereinafter – Website). The terms and conditions established in the Privacy Policy shall apply each time when the website is visited, regardless of the device (computer, mobile phone, tablet, TV, etc.) you use.

It is very important that you read the Privacy Policy carefully, because each time when you use the the electronic payment services of PAYLAR or visit the Data Controller’s Website, you agree with the terms and conditions described in this Privacy Policy.

By submitting his (her) personal data (including data provided directly or indirectly when visiting the Website and using electronic payment services of PAYLAR and other services), the Data Subject agrees and does not object to their control and processing by the Data Controller for the purposes and according to the procedure specified in this Privacy Policy and in the Data Subject’s consent and provided for by legal acts.

Persons younger than 16 years may not submit any personal data through Website of the Data Controller. If you are a person younger than 16, before submitting personal information you must obtain consent of your parents or other lawful guardians.

Paylar — is a trademark registered by Uplata EU in the Patent Office of The Republic of Lithuania and is used to market services as provided.

Personal data – any information relating to an identified or identifiable natural person (‘Data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, an online identifier or to one or more factors specific to the physical, physiological, genetic, religious, economic, cultural or social identity of that natural person.

Representative – a person representing Clients, the Data Controller’s Partners, Service providers, both natural and legal persons.

Data Subject – for the purposes of this Privacy Policy – the Representative, Applicant, Client, Candidate, Partner, Service Provider, Persons calling by phone or any other natural person whose personal data are processed by the Data Controller.

Data Subject’s consent – any freely given, specific, informed and unambiguous indication of the Data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.

Candidate – a person participating or intending to participate in staff selection carried out by the Data Controller.

Client – a person who concludes the agreement (including online) with the Data Controller for use Paylar services.

Partner – a natural or legal person cooperating with the Data Controller or concluding a cooperation agreement with the Data Controller (e.g., on IT tool development).

Service Provider – a natural or legal person who can offer or offers goods, services or works to the Data Controller and who cooperates with the Data Controller or has concluded an agreement with the latter on sale of goods, services or works.

Person calling by phone – a person who calls at the published contact phone number regarding the services administrated by the Data Controller and(or) other matters.

Direct marketing – activities aimed at offering to persons the goods or services by post, phone or directly and/or at obtaining their opinion regarding the offered goods or services.

Personal data processing – any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

The Data Controller shall collect personal data in accordance with requirements of applicable legal acts of the European Union and Republic of Lithuania, as well as instructions of controlling authorities. All reasonable technical and administrative measures shall be applied to protect data collected on Data Subjects against loss, unauthorised use or alterations.

This Privacy Policy has been drawn up in observance of Regulation (EU) 2016/679 of the European Parliament and of the Council (of 27 April 2016) on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter – the General Data Protection Regulation), the Law of the Republic of Lithuania on Legal Protection of Personal Data, other legal acts of the European Union and the Republic of Lithuania. The terms used in the Privacy Policy shall be understood as they are defined in the General Data Protection Regulation and in the Law of the Republic of Lithuania on Legal Protection of Personal Data.

 

WHAT INFORMATION WE COLLECT ABOUT YOU

 

The information directly provided by you.

 

The information about how you use our Website.

If you visit our Website, we also collect the information which discloses the specifics of use of the services provided by us or automatically generated statistics on visits. More information is provided in the ‘Cookies Policy’.

 

Information from sources of third parties

We can obtain information about you from public and commercial sources (to the extent permitted by applicable legal acts) and link it with other information which we receive from or about you. In addition, we can obtain information about you from third parties’ social network services when you connect to them, e.g. thorough Facebook network accounts.

 

Other information collected by us

We can also collect other information about you, your device or your use of our website’s content with your consent.

 

You may decide not to provide to us certain information; however, in such case you may be denied access to the service offered by us.

 

PERSONAL DATA PROCESSING FOR THE PURPOSE OF ELECTRONIC PAYMENT SERVICES

 

Processing of personal data of Clients (Representatives). The Data Controller shall process the following personal data of Clients (Representatives):

  • Forename;
  • Surname;
  • Represented person (connection with the represented person);
  • Personal identification document data;
  • Your image from personal document and video identification procedure;
  • Position (in case of representative of legal person);
  • Workplace;
  • Phone number;
  • E-mail address;
  • Details of your bank account, such as bank account number, IBAN;
  • Bank cards number and issuers, if applicable;
  • Transactions on your bank account with Paylar, including the incoming and outgoing amounts, their time, amount, currency, exchange rate, beneficiary, sender, payment purpose, etc.
  • Ultimate beneficiary of the legal person, including forename, surname, identification data;
  • Other information related with the provision of our services.

 

The purposes of personal data processing are:

  • Identification and verification of the client (its representative) when concluding service agreement;
  • Implementation of “Know your client” requirements, updating of client data;
  • Implementation of service agreement and provision of services of electronic payment;
  • Risk assessment;
  • prevention of money laundering and terrorism financing, prevention of fraud, detection and reporting of potential fraud, blocking of fraudulent activities;
  • establishing of real beneficiary of the account, establishing politically sensitive persons or persons to which the economical sanctions are applied.

 

Data are obtained directly from Clients when concluding the service agreement and during the  performance of the agreement concluded with the Client and/or from other third parties connected with the Data Subject.

 

We undertake not to transfer your personal data to any unrelated parties, except for the following cases:

  • Having obtained the Client’s consent for personal data disclosure;
  • In implementing our, as the Service Provider’s, obligations (e.g., the data may be transferred to companies providing postal, archiving, audit, legal, financial services, service providers and/or parties related with national, European and international payment systems, e.g., SWIFT);
  • In implementing the legitimate interests of the Data Controller (e.g., in the case of debt collection);
  • Disclosure of the data to authorised bodies (e.g., implementing anti-money laundering procedures, supervising authorities such as the Bank of Lithuania) according to the procedure established by legal acts.

 

The Data Controller may transfer personal data of Clients and other Data Subjects to Data Processors not specified in this Policy who provide services (carry out works) to the Data Controller and process personal data of Clients and Data Subjects on behalf of the Data Controller (e.g., companies providing accounting services). Data Processors may process personal data only according to the Data Controller’s instructions and only to the extent necessary for the proper fulfilment of contractual obligations. If the Data Controller involves data processors, the Data Controller shall take all necessary measures to ensure that the data processors have in place appropriate organisational and technical security measures and maintain secrecy of personal data.

 

Personal data processed on the basis of the Data Subject’s consent expressed when submitting personal data, and/or performance of the agreement concluded with the Data Subject and implementation of legal requirements (Article 6(1)(a), (b) and (c) of the General Data Protection Regulation).

 

 

PERSONAL DATA PROCESSING FOR THE PURPOSES OF CONSULTATION OR FULFILMENT OF A QUERY

 

Processing of personal data of Applicants, including Persons calling the Data Controller phone, for the purpose of a consultation, submission of a query and/or for other purposes. The Data Controller shall process the following personal data of Applicants, including Persons calling by phone:

  • Forename;
  • Surname;
  • Phone number;
  • E-mail address;
  • Position;

 

Personal data of Applicants shall not be communicated to third parties.

 

Personal data for the purposes of a consultation, submission of a query shall be processed on the basis of consent expressed when submitting personal data (Article 6(1)(a) of the General Data Protection Regulation).

 

PERSONAL DATA PROCESSING FOR THE PURPOSE OF PERFORMING AGREEMENTS WITH PARTNERS, SERVICE PROVIDERS

 

When cooperating with Partners and Service Providers the Data Controller shall process the following personal data of natural persons or Representatives:

  • Forename;
  • Surname;
  • Personal ID number;
  • Data of the identification document;
  • Address;
  • Data of the document supporting activities (the individual activity certificate number, date of issue, etc.);
  • data of a payment order;
  • Power of attorney;
  • Authorisation term;
  • Represented person (connection with the represented person);
  • Position;
  • Workplace;
  • Phone number;
  • E-mail address;
  • Data Other information provided during cooperation or performance of the contract.

 

Data obtained directly from natural persons, Representatives and/or represented persons.

 

We undertake not to transfer your personal data to any unrelated third parties, except in the following cases:

  • Having obtained the Client’s consent for personal data disclosure;
  • In implementing our, as the Data Controller’s, obligations (e.g., the data may be transferred to (courier), logistics companies providing services of delivery of goods, companies providing postal, archiving, audit, legal, financial services, service providers and/or parties related with national, European and international payment systems, e.g., SWIFT);
  • In implementing the legitimate interests of the Data Controller (e.g., in the case of debt collection);
  • Disclosure of the data to authorised bodies (e.g., the Bank of Lithuania) according to the procedure established by legal acts).

 

The Data Controller may transfer personal data of natural persons, Representatives to Data Processors not specified in this Policy who provide services (carry out works) to the Data Controller and process personal data of natural persons, Representatives on behalf of the Data Controller (e.g., companies providing accounting services)).

 

Processing of personal data in performing agreements with Service Providers and Suppliers shall be carried out on the basis of performance of the agreement and/or of the legitimate interest of the Data Controller (Article 6(1)(b) and (f) of the General Data Protection Regulation).

 

PERSONAL DATA PROCESSING FOR THE PURPOSE OF DIRECT MARKETING

 

The Data Controller seeks to share with recipients of newsletters only relevant news and other useful information in observance of this Privacy Policy.

 

The following personal data of Clients and other Data Subjects may be processed for the purpose of direct marketing:

  • Forename;
  • Surname;
  • E-mail address.

 

Having sent a newsletter, the Data Controller may collect statistics on the Data Subject’s behaviour related to the use and content of the newsletter (e.g., whether the newsletter was read, what links were opened by the Data Subject).

 

The Data Subject’s e-mail address may be used for providing advertising on Facebook, Google and other advertising platforms, adapting the advertising to the targeted audience.

 

Personal data obtained directly from Data Subjects. The Data Controller may transfer Personal data only to third parties who provide specialised services in order to send e-messages, adapt the type of advertising ordered through advertising platforms.

 

Personal data of Clients and other Data Subjects processed on the basis of consent expressed when submitting personal data and agreeing with their processing for the purpose of direct marketing, or on the basis of the Data Controller’s legitimate interest (Article 6(1)(b) and (f) of the General Data Protection Regulation and Article 69(2) of the Law of the Republic of Lithuania on Electronic Communications when personal data are processed on the basis of the Data Controller’s legitimate interest).

 

Please be informed that the Data Subject shall have the right to disagree or to withdraw the consent to process his (her) personal data for direct marketing purposes at any time without specifying the motives of the disagreement, notifying by e-mail: dpo@paylar.com or calling at the phone number: +370 5 246 3506.

 

The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal.

 

PERSONAL DATA PROCESSING FOR THE PURPOSES OF SELECTION OF CANDIDATES TO JOB VACANCIES

 

For the staff selection purposes the Data Controller shall process personal data voluntarily provided by the Candidate to the extent to which such personal data were provided. The Data Controller may process the below specified data of Candidates:

  • Forename;
  • Surname;
  • Date of birth;
  • Phone number;
  • E-mail address;
  • Residence address;
  • Education;
  • Workplace;
  • Completed courses;
  • Language skills;
  • Computer skills;
  • Data on impeccable reputation requirements, if applicable for the position applied for;
  • Person’s photo (only if it is submitted by the Candidate with his (her) CV; the Data Controller shall not require the submission of the photo);
  • Recommendations;
  • Other data voluntarily submitted by the Candidate specified in his (her) CV or other presented documents.

 

Data obtained directly from Candidates and/or third parties providing job search, selection and/or intermediation services (e.g., employment agencies, job search online portals, career social networks (e.g., Linkedin), etc.). These data shall not be transferred to third parties.

 

Data of Candidates shall be processed on the basis of consent declared when submitting personal data and/or on the basis of the Candidate’s request prior to conclusion of the contract (Article 6(1)(b) and (b) of the General Data Protection Regulation).

 

WHAT WE DO TO PROTECT YOUR INFORMATION

 

Personal data shall be protected against loss, unauthorised use and changes. We have implemented organisational and technical measures to protect all information collected by us for the purposes of provision of services. Please be reminded that despite appropriate actions taken by us to protect your information, no website, online transaction, computer system or wireless communication is completely secure.

 

The Data Controller shall apply different periods of storage of Personal data in observance of requirements of legal acts and according to personal data processing purposes.

 

Personal data storage period:

 

Personal data processing purpose Period of storage
Processing of Data Subjects’ personal data for the purposes of consultation, fulfilment of a query 1 (one) year from the day of the consultation, fulfilment of the query, except where the Data Subject applies for provision of the Data Controller’s services. In such case, the general time limit of 10 (ten) years shall apply.
Processing of personal data of Clients or their Representatives or beneficiarie The term of validity of the agreement and 10 (ten) years after its expiration.
Processing of personal data of natural persons, Representatives for the purpose of performance of agreements with Partners, Service Providers The term of validity of the agreement and 10 (ten) years after its expiration.
Processing of personal data of Data Subjects for direct marketing purpose 5 (five) years from the day on which the consent is given, unless the Data Subject requests the extension of this time limit.

When the Data Subject’s personal data are processed for the direct marketing purpose on the basis of consent or legitimate interest of the Data Controller, the Data Controller shall stop processing the Data Subject’s personal data for the direct marketing purpose (shall immediately destroy them) as soon as the Data Subject objects the processing of personal data for such purpose.

Processing of personal data of Candidates for staff selection purposes 6 (six) moths after the end of staff selection. For a longer retention of Candidates’ CVs and other data the Candidate’s consent shall be required

 

Exemptions from the periods of storage may be applied to the extent they do not infringe the rights of Data Subjects and are in compliance with legal requirements.

 

On expiration of the established time limits, unless they have been extended, the data shall be destroyed in a manner which prevents them from being recovered.

 

YOUR RIGHTS

 

The Data Subject whose data are processed in the Data Controller’s activities shall have the following rights:

  • The right to know (be informed) about the processing of his (her) data;
  • Right to access own data and know how they are processed;
  • Right to rectification of personal data or to supplement incomplete personal data having regard to the purposes of their processing;
  • Right to erasure (‘right to be forgotten’), i.e. to stop actions of processing of own data (except for storage);
  • Right to restriction of processing of personal data under a valid reason;
  • Right to data portability, where the Data Subject has provided his (her) personal data to the  Data Controller in a structured, commonly used and machine-readable format;
  • Right to object to processing of personal data when they are processed or intended to be processed for direct marketing purposes including profiling to the extent related to such direct marketing;
  • Right to lodge a complaint with the State Data protection Inspectorate of the Republic of Lithuania.

 

The Data Subject shall have the right to submit to the Data Controller in writing any request or order concerning processing of personal data in one of the following ways: deliver directly to the address: UAB Uplata EU, Žygimanto Liauksmino g. 3A — 4, Vilnius, the Republic of Lithuania; by post: UAB Uplata EU, Žygimanto Liauksmino g. 3A-4, Vilnius, the Republic of Lithuania; by e-mail: dpo@paylar.com .

 

Having received such a request or order the Data Controller shall, not later than within one month from the date of request, submit the answer and carry out or refuse to carry the actions specified in the request. Where appropriate, the specified time limit may be extended for two more months, considering the complexity and number of requests. In such case, the Data Controller shall notify the Data Subject about such extension within one month from the date of request, also specifying the reasons for the refusal.

 

The Data Controller may refuse enabling data subjects to implement the above specified rights, except for disagreement with personal data processing for direct marketing purpose when in the cases established by laws it is necessary to ensure the prevention, investigation and identification of crimes, infringements of business or professional ethics, and the protection of rights and freedoms of the Data Subject or other persons.

 

THIRD PARTY WEBSITES, SERVICES AND PRODUCTS ON OUR WEBSITE

 

The Data Controller’s Website may contain advertising banners of third parties, links to their websites and services which are not controlled by the Data Controller, e.g., a link to the Data Controller’s Facebook profile. The Data Controller shall not be responsible for the safety and privacy of the information collected by third parties. You must read the privacy provisions applicable to third party websites and services which you use.

 

If you provide your personal data using Facebook, we understand that you give your consent to us to get in touch with you by the specified contact phone number or e-mail and to submit the offers of services.

 

FINAL PROVISIONS

 

Supplements or amendments to the Privacy Policy shall enter into force from the day of their publication on the Website.

 

When the Data Subject uses the Website and of services provided by the Data Controller after supplementing or amending the Privacy Policy, it shall be considered that the Data Subject does not object to such supplements and/or amendments.

 

CONTACT US

 

If you have any questions concerning the information provided in this Privacy Policy, you are kindly invited to get in touch with us in any manner convenient for you:

 

Phone: +370 5 246 3506

E-mail: dpo@paylar.com

Post: Paylar, UAB, Žygimanto Liauksmino g. 3A-4, Vilnius, the Republic of Lithuania

 

Updated on 1st of January, 2023