This Privacy Policy defines the principles and procedures for the processing of personal data carried out by Nemunas Aparthotel, UAB.
1. GENERAL PROVISIONS
1.1. Nemunas Aparthotel, UAB ensures that personal data is processed lawfully, fairly, and transparently, collected for specified and clearly defined purposes, and not further processed in a manner incompatible with those purposes.
1.2. Definitions used in this Policy:
1.2.1. personal data – any information relating to an identified or identifiable natural person (data subject); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person;
1.2.2. data controller – Nemunas Aparthotel, UAB, code: 307171964, registered office address: Liepų g. 1-314, LT-66116 Druskininkai;
1.2.3. data subject – a client of the Company – any natural person whose personal data is processed by the Data Controller;
1.2.4. data processing – any operation or set of operations performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination, or otherwise making available, alignment or combination, restriction, erasure, or destruction.
1.3. The terms, principles, and other provisions used in this Policy comply with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, GDPR), the Law on Legal Protection of Personal Data of the Republic of Lithuania, and other applicable legal acts.
1.4. A data subject shall be deemed to have read and familiarized themselves with this Policy when voluntarily providing their data (email address and phone number) by signing the guest registration form.
1.5. The Data Controller ensures that:
1.5.1. personal data is processed lawfully, fairly, and transparently (principle of lawfulness, fairness, and transparency);
1.5.2. personal data is collected for specified, explicit, and legitimate purposes and not further processed in a manner incompatible with those purposes (purpose limitation principle);
1.5.3. only such personal data is collected that is adequate, relevant, and limited to what is necessary in relation to the purposes for which it is processed (data minimization principle);
1.5.4. only accurate personal data is processed and, where necessary, kept up to date; every reasonable step is taken to ensure that inaccurate personal data, having regard to the purposes for which it is processed, is erased or rectified without delay (accuracy principle);
1.5.5. personal data is kept in a form permitting identification of data subjects for no longer than is necessary for the purposes for which the personal data is processed (storage limitation principle);
1.5.6. personal data is processed in a manner that ensures appropriate security, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, using appropriate technical or organizational measures (integrity and confidentiality principle);
1.5.7. the Data Controller is responsible for compliance with the above principles and must be able to demonstrate compliance (accountability principle).
1.6. When using third-party services, for example by visiting the Data Controller's social media accounts, third-party terms may apply. Therefore, it is recommended to also review the terms applied by such third parties when using their services.
2. COLLECTION, PROCESSING AND STORAGE OF PERSONAL DATA
2.1. For the purposes of the Company's activities, including the provision and performance of services/works, purchase, sale, participation in other activities, issuance of invoices, and data analysis, the Data Controller has the right to process the following personal data of the Data Subject:
2.1.1. name, surname;
2.1.2. personal identification number or date of birth;
2.1.3. telephone number, email address;
2.1.4. residential address;
2.1.5. bank account number (for payment of services);
2.1.6. data about the real estate purchased/sold/owned by the data subject (extract from the Real Estate and Cadastre Register of the State Enterprise Centre of Registers);
2.1.7. correspondence by email and on social media (non-public posts).
2.2. For direct marketing purposes, the Data Controller has the right to process the Data Subject's:
2.2.1. name, surname;
2.2.2. telephone number, email address;
2.3. For the purposes of handling customer inquiries and ensuring quality of services, the Data Controller has the right to process the Data Subject's:
2.3.1. comment;
2.3.2. name, surname;
2.3.3. telephone number, email address.
2.4. Storage of personal data:
2.4.1. personal data related to the main activities of the Company (short-term rental, maintenance, and management of real estate and related areas) shall be stored for 10 (ten) years. This term is set due to possible inspections by state institutions (e.g., State Tax Inspectorate, Social Insurance, etc.), which may be initiated after 5 years from the conclusion of a specific contract and may require data for the previous 5 years;
2.4.2. data collected for direct marketing purposes (offering rentals, purchases, etc.) shall be stored for 5 (five) years from the date of collection;
2.4.3. personal data collected for the purpose of handling inquiries shall be stored for 1 (one) year from the date of collection;
2.4.4. personal data collected for invoicing purposes shall be stored in accordance with legal requirements applicable to accounting.
2.5. The Data Subject may submit a request to withdraw consent for the processing of their personal data at any time by sending an email to info@nemunasaparthotel.lt or by visiting the Company's office at Liepų g. 1-314, LT-66116 Druskininkai.
2.6. The Data Controller may collect personal data:
2.6.1. directly from the Data Subject;
2.6.2. from publicly available sources, i.e., data of business partners and/or their representatives available in public systems (social networks, public databases, etc.).
2.7. The Data Controller undertakes not to disclose processed personal data to third parties, except in the following cases:
2.7.1. where the Data Subject has consented to such disclosure;
2.7.2. where the data is provided to data processors providing accounting, IT, payment, or other services;
2.7.3. where the data is provided to processors related to the Data Controller or cooperating with the Data Controller in real estate short-term rental, maintenance, management, purchase-sale, and related areas, or providing services/works at the request of the Data Controller (e.g., banks/companies assisting in payment operations). These parties’ ability to use the data is limited to the purposes of providing services/works to the Data Controller;
2.7.4. to other parties when required by law or necessary to protect the provision of information society services;
2.7.5. when data is provided for other necessary actions in compliance with legal obligations.
2.8. Cases when the Data Controller may disclose the Data Subject’s information to other parties:
2.8.1. in order to comply with the law or respond to a mandatory court order;
2.8.2. to confirm the lawfulness of its actions;
2.8.3. to protect the Data Controller, its rights, property, or ensure their safety;
2.8.4. to any third party in the event of a merger, transfer, or bankruptcy;
2.8.5. in other cases with the Data Subject’s consent or a legitimate request.
2.9. By providing personal data, the Data Subject grants the Data Controller the right to collect, accumulate, systematize, use, and process all personal data provided directly or indirectly while visiting the Website, for the purposes specified in this Policy.
2.10. The Data Subject is responsible for ensuring that the data provided is accurate, correct, and complete. Providing knowingly false data is considered a violation of the Policy. If the provided data changes, the Data Subject must promptly correct it or inform the Data Controller. The Data Controller shall not be liable for any damage caused to the Data Subject and/or third parties due to incorrect and/or incomplete data provided or failure to request data updates.
2.11. The Data Controller does not collect sensitive data of the Data Subject.
2.12. The Data Controller does not engage in automated decision-making or profiling based on Data Subject information.
2.13. The Data Controller does not share the Data Subject’s personal data with entities located outside the European Economic Area.
3. DATA SUBJECT RIGHTS
3.1. The Data Controller guarantees the implementation of Data Subject rights and the provision of any related information at the Data Subject's request:
3.1.1. to be informed about the processing of their personal data;
3.1.2. to access their personal data and information on how it is processed;
3.1.3. to request rectification, deletion, or suspension (except storage) of processing of their personal data;
3.1.4. to object to the processing of personal data, including for direct marketing;
3.1.5. to request deletion of personal data (the 'right to be forgotten');
3.1.6. to request data portability, i.e., to access their personal data in a commonly used, machine-readable format;
3.1.7. to lodge a complaint with the State Data Protection Inspectorate.
3.2. The Data Controller may restrict the exercise of the above rights in cases provided by law, in order to ensure the prevention, investigation, and detection of crimes, breaches of professional or ethical standards, as well as to protect the rights and freedoms of the Data Subject or others.
3.3. By presenting an identity document or verifying identity as required by law or via electronic communication (if sufficient for proper identification), the Data Subject has the right to access the personal data processed by the Company free of charge and obtain information on the sources, purposes, and recipients of their data for the past year. The Data Subject also has the right to request rectification of inaccurate, incomplete, or incorrect data, and to request suspension of unlawful data processing, except for storage.
3.4. Requests regarding the exercise of these rights may be submitted at the Company's office (Liepų g. 1-314, LT-66116 Druskininkai) by filling out a request form, or by email to info@nemunasaparthotel.lt.
3.5. Where data processing is based on consent, the Data Subject has the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
3.6. The Data Controller’s website(s) or social media accounts may contain links to third-party websites and services, which are not controlled by the Data Controller. The Data Controller is not responsible for the security and privacy of information collected by third parties. The Data Subject should carefully review the privacy policies applicable to such third-party websites and services.
3.7. If dissatisfied with the Data Controller’s response or believing that their personal data is being processed unlawfully, the Data Subject has the right to lodge a complaint with the State Data Protection Inspectorate of the Republic of Lithuania.
4. FINAL PROVISIONS
4.1. Legal relations related to this Policy are governed by the law of the Republic of Lithuania.
4.2. The Data Controller shall not be liable for damages, including those caused by website interruptions, data loss, or damage arising from the actions or omissions of the Data Subject or third parties acting with the knowledge of the Data Subject, including incorrect data entry, errors, deliberate harm, or other improper use of the Website. The Data Controller is also not responsible for disruptions or damage caused by third parties unrelated to the Data Controller or the Data Subject, including power outages, internet access disruptions, etc.
4.3. The Data Controller has the right to amend the Policy in whole or in part. This Privacy Policy is reviewed once every two (2) years and updated as necessary.
4.4. Amendments or supplements to the Policy shall take effect from the date of publication on the Website.
4.5. If, after amendments or supplements, the Data Subject continues to use the Company’s services, it shall be deemed that the Data Subject does not object to such changes.