Updated on 8th of June 2022: updated chapter 9.
Novian guarantees respect for confidentiality of your personal data subject to the requirements of the applicable laws and shall implement the appropriate technical and organisational measures to protect your personal data from unauthorised access, disclosure, accidental loss, alteration or destruction or any other illegal processing.
For the purposes of processing your personal data, Novian is acting in accordance with the provisions of the General Data Protection Regulation, the Law on Personal Data Protection and other governing legislation. Please note that this Policy may be amended to reflect possible changes in the legislation and the operations of Novian and therefore, we strongly advice to read it on a regular basis.
1. CATEGORIES OF PERSONAL DATA
For the purposes of administration of the website, Novian is processing personal data disclosed to the controller by a data subject (you) or the data that is collected automatically by using cookies. You may choose not to provide your personal data and use our website absolutely anonymously, but in certain instances, if you choose not to provide your personal data, we shall not be able to deliver services to you (e. g. in case of recruitment or when using the customer self-service environment).
If a data subject disagrees to disclose his (her) personal data, Novian may refuse services to that individual. If a data subject provides Novian with the personal data of other related individuals, the data subject is required to obtain a consent from these individuals and make this Policy available to them.
The key categories of personal data, including but not limited to:
- Personal identity data (e. g. full name, ID, date of birth, ID document data);
- Contact details, e. g. address, telephone number, email address;
- Background and professional information;
- IP address, a data subject’s data of login to the self-service portal, website browsing history etc.
2. OBJECTIVES AND LEGAL BASIS OF PERSONAL DATA PROCESSING
Novian is processing your personal data to the extent strictly necessary in order to achieve a specific goal.
We process personal data to achieve the blow specific goals:
- Tracking of website traffic and user browsing patterns for statistical purposes. The basis for data processing is your consent for the use of statistical cookies unless otherwise provided for by applicable laws. You may choose not to give your consent or to withdraw your consent at any time by changing your cookie settings. The data are collected by means of cookies and stored subject to a specific cookie configuration. For specific time-limits, please read the section “Cookies” below. For this purpose, personal data are disclosed to the below third parties: Google Inc., Facebook, Leadfeeder.
- Responding to enquiries. The basis for data processing is our legitimate interest (to deliver quality services to our customers). Your data will be stored up to maximum 3 months following the response to your enquiry unless the longer storage period is required for the purposes of a potential dispute or claim.
- Sending newsletters and offers, organising customer satisfaction surveys, games (direct marketing). The basis for data processing is your consent. You may choose not to give your consent and to withdraw your consent at any time without adverse consequences by using a refusal link available in every newsletter we are sending to you. For this purpose, we collect the following personal data: full name, date of birth, gender, demographic information, address, contacts including email address, browsing history, publicly available information from social networks, IP address, cookie data, locations, browser and device information. We shall store your data until you have withdrawn your consent. For this purpose, we shall transfer your personal data to the data processor–the provider of the email newsletter service located in the territory of the European Union that will process your personal data as instructed by us.
- Organisation and administration of events. For this purpose, we shall process the following personal data: full name, institution, email address and telephone number. In case of distance events, we may offer you an option to choose the most convenient self-service parcel terminal for delivery of the event kit. For this purpose, your data shall be processes within the framework of our legitimate interest–to ensure smooth organisation of the event, to remind you about the event and, if necessary, to contact you after the event. We shall disclose your personal data to our partners involved in the event organisation procedures i. e. the administrator of the event venue, express mail services, providers of the event kits etc.
- Recruitment and employment of candidates. There is a possibility to submit a curriculum vitae via our website or a social network account. You may also send us your curriculum vitae by email. The basis for data processing is our legitimate interest (to invite the most suitable candidates for a job interview). We shall store your personal data until the end of the recruitment procedure and three months thereafter until the candidate has completed his (her) probationary period. Following the end of the period, we shall delete all CVs that we have received, including all personal data unless you agree that your personal data will be stored for any longer period for the purposes of job offers. In this case, the basis for data processing is your consent. You may choose not to give your consent or withdraw your consent at any time without any adverse consequences. When you send your CV, please limit the disclosure of your data to your contacts, background, business-like data and the description of your experience. We may contact your former employers and, if permitted by you, with your current employer.
3. THE RIGHTS OF A DATA SUBJECT
A data subject has the right granted by the applicable laws to apply to the Data Controller and request that the Data Controller, having verified the data subject’s identity:
- provides the information on whether the Data Controller is processing the data subject’s personal data and, if so, gives proper familiarisation with the personal data being processed; informs on what personal data, from what sources and for what purposes have been obtained and what methods are used for their processing (including automated decision-making, its effect and outcome for the data subject); how log personal data are stored and to whom they are disclosed (the right to get access to own personal data);
- rectifies incorrect, incomplete or inaccurate data of a data subject (the right to request that incorrect, incomplete or inaccurate data are rectified);
- deletes a data subject’s personal data under specific circumstances defined in GDPR (when personal data have been processed illegally, the basis for processing has expired etc.) (the right to have personal data erased i. e. the right to be forgotten);
- restricts the processing of a data subject’s personal data under specific circumstances defined in GDPR (when personal data have been processed illegally, until a data subject’s request in respect of data accurateness or data processing is pending), except for data storage (the right to restrict the processing of a data subject’s personal data);
- provides a data subject with the data disclosed in writing or in generally used electronic format to the data subject’s personal data controller that are processed by automated means on the basis of the data subject’s consent and, if feasible, transfers these data to any other service provider (the right of data transferability).
- In cases where a data subject’s personal data are processed by Novian with his (her) consent, the data subject is entitled to withdraw his (her) consent and the data processing based on this particular consent shall be suspended immediately. Please note that if you withdraw your consent it may occur that Novian is not able to offer certain products or services to you as a data subject however, it will continue using the data subject’s personal data for the purposes such as the implementation of the agreement concluded with the data subject, or if so required by applicable laws.
A data subject has the right to oppose at any time to:
- the processing of his (her) personal data and undertakes to provide his (her) legally substantiated objection to the personal data controller in writing or in any other method that enables the Personal data controller to identify the data subject, if the basis for personal data processing is legal interests of the Personal data controller;
- the processing of his (her) personal data for direct marketing purposes (including the related data profiling) without giving the causes of this disagreement;
- the automated decision-making, including profiling, if this type of decision-making entails any legal consequences or any similar significant effect on the data subject. This right shall be excluded, if this type of decision-making is obligatory for the purposes of conclusion or performance of the agreement with the data subject, or permitted by applicable laws, or the data subject has given his (her) explicit consent in this respect.
A data subject is entitled to lodge a complaint in respect of personal data processing to the State Date Protection Inspectorate (L. Sapiegos str. 17, 10312 Vilnius, website: https://vdai.lrv.lt/) if the data subject considers that the processing of personal data relating to him (her) is against his (her) interests and in breach of the applicable laws. Should you have any questions, we kindly ask you to primarily contact Novian that we could resolve the issues as soon as possible.
4. PROCEDURE FOR HANDLING THE REQUESTS FOR EXERCISING A DATA SUBJECT’S RIGHTS
The application to exercise a data subject’s rights can be lodged to any of the Data Controllers.
To protect the personal data processed by Novian against the unauthorised disclosure to the third parties, when requested by a data subject to provide personal data or to exercise any other rights, the individual’s identity shall be verified first. If the procedure of identity verification is successful, Novian undertakes, without undue delay but in any case no later than within one month as of the date of a data subject’s request, to provide the information about the actions undertaken as per the data subject’s application.
Depending on complexity of the request or if a data subject has lodged multiple applications, Novian shall be entitled to extend the one month’s period for two extra months by notifying the data subject about it before the end of the first month and by giving the reasons of such extension. A data subject shall not be charged for the information about his (her) personal data being processed (or for exercising any other data subject’s rights). However, Novian may charge a reasonable fee if a data subject’s request is obviously unreasonable, or it has been lodged repeatedly, or is disproportionate.
5. PERSONAL DATA RECIPIENTS
The Data Controller may disclose / transfer a data subject’s personal data for processing by any third party, who, including but not limited to, shall assist the data controller in maintaining and administering the website and delivery of the related services:
- IT service providers (to ensure maintenance, upgrading and development of IT systems);
- The providers of website administration and related service established in Lithuania;
- The electronic communication partner based in Lithuania, who provides assistance in administering the provision of advertisements in cyberspace;
- The companies engaged by Novian for the purposes of assessment of the quality of the services delivered by Novian (including the services of opinion polling in respect of quality and servicing), market research, games and other campaigns targeted to data subjects.
6. TIME LIMITS FOR STORAGE OF PERSONAL DATA
Personal data shall be processed for no longer than it is necessary to attain the goals of data processing.
If for the purposes of lodging a request a data subject uses any contact forms available on the websites of Novian companies, the information disclosed in the forms, including the data subject’s contact information shall be kept until the request has been investigated, but no longer than 3 months after the date of lodging the request, unless any longer period of retention is allowed by applicable laws on any other grounds.
The data shall be processed for marketing purposes and, subject to a data subject’s consent, shall be retained until the consent has been withdrawn. To withdraw his (her) consent, a data subject should lodge the application by email email@example.com.
If a data subject discloses his (her) personal data in seeking job opportunities at any Novian group company without applying for a particular position, these data shall be retained for one year and may be used for the purposes of finding suitable candidates for the vacancies in Novian group companies. If a data subject discloses his (her) personal data in seeking job opportunities at any Novian group company by applying for a particular position and does not give consent to retain his (her) personal data for any longer period, these data shall be retained until the end of the recruitment procedure and three months after its closure. If a data subject discloses his (her) personal data in seeking job opportunities at any company of Novian group by applying for a particular position and gives consent to retain his (her) personal data for any longer period, these data shall be retained for one year and may be used for the purposes of finding suitable candidates for the vacancies in the companies of Novian group.
If a data subject registers for participation in any event and discloses any personal data for the purposes of registration, these data shall be processed exclusively for the purposes of providing information about the event. If a data subject gives consent for processing of his (her) personal data for marketing purposes, these data shall be processed until the consent has been withdrawn. To withdraw his (her) consent for processing a data subject’s personal data, the data subject must apply by email firstname.lastname@example.org and specify which particular data should no longer be processed.
The data collected by using cookies shall be retained for the period referred to in the cookies policy.
7. GEOGRAPHICAL TERRITORY OF PROCESSING
As a rule, Novian is processing personal data in the European Union / European Economic Area (EU/EEA) countries, however, in certain instances, personal data may be transferred outside EU/EEA countries, e. g. the data collected by cookies can be transferred to Google and it cannot be excluded that these data shall be transferred to its parent company in the United States of America. Any personal data shall be transferred outside EU/EEA countries provided that the appropriate safeguards have been implemented.
8. AUTOMATED DECISION-MAKING
To deliver the most appropriate services to a data subject and to provide the marketing offers tailored to the needs of data subjects, and to improve the quality of the services delivered by Novian, Novian may employ automated analysis of data subjects’ personal data, including the information on the use of services, the patterns of browsing the websites of Novian companies and self-service portals.
Please note that the activities of personal data analysis undertaken by Novian do not entail any legal or other significant effects on data subjects. A data subject may at any time object to the processing of his (her) personal data for direct marketing purposes and change the browser settings so as to reject cookies fully or partially.
- Novian UAB (company code: 121998756, address Gynėjų str. 14, Vilnius, tel. (8 5) 219 0000, email: email@example.com, website www.novian.lt.
- Novian Technologies UAB (company code: 301318539, address Gynėjų str. 14, Vilnius, tel. (8 5) 219 00 00, email: firstname.lastname@example.org, website: www.novian.lt, the Data Protection Officer’s email: email@example.com);
- Novian Systems UAB (company code: 125774645, address Gynėjų str. 14, Vilnius, tel. (8 5) 273 41 81, email: firstname.lastname@example.org, website: www.novian.lt, the Data Protection Officer’s email: email@example.com);
- Elsis PRO UAB (company code: 300064148, address Baltupio str. 14, Vilnius, tel. (8 5) 219 0000, email: firstname.lastname@example.org, website www.elsispro.com;
- Novian Eesti OÜ (address Pärnu mnt 186, Tallinn, Estonia, tel. +372 6715 188, email: email@example.com, website: www.novian.ee);
- Andmevara AS (address Pärnu mnt 186, Tallinn, Estonia, tel. +372 6715 188, email: firstname.lastname@example.org, website: www.novian.ee);
- Zissor (address Bragernes Torg 6, 3017 Drammen, Norway, tel. +47 22 83 85 00, email: email@example.com, website: www.zissor.com).
The Data Protection Officer’s email: firstname.lastname@example.org.
Last revision date: 7 December 2021.