Data Controller information. Overview information.
MB “Tvirtas baitas” / Toughlex, with headquarters and address of management: Pušų g. 36, LT-45319, Kaunas, Lithuania. (“Toughlex“) is a personal data Controller and is responsible for compliance with the provisions of the General Regulation on Protection (Regulation (EC) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46 / EC).
Legal grounds for processing. Processing Purposes. Principles.
Toughlex only processes personal data if it is absolutely necessary. The purposes of processing and the legal grounds for doing so are the following:
- For performance of a contract or in the context of pre-contractual relationships (lawful grounds for processing under Article 6 (1) (b) of the General Data Protection Regulation);
- To implement statutory obligations applicable to Toughlex (lawful grounds for processing under Article 6 (1) (b) “c” of the General Data Protection Regulation); and
- With the explicit consent of the subject to provide the data for one or more specific purposes (lawful grounds for processing pursuant to Article 6 (1) (a) and Article 7 of the General Data Protection Regulation). Marketing is part of the purposes for consent processing of data, including sending information about events, trainings, and publications.
- We may use your information where there is a legitimate reason to do so. For example, we may use your information where it would help achieve our business objectives or to facilitate a benefit to you or someone else.
- We only rely on legitimate interests if the reason for using your information is fair and lawful. Where we want to rely on legitimate interests as a legal basis, we will carry out a balancing test between our legitimate interests and your privacy rights.
When data processing is based on “explicit consent”, on the grounds of Article 6 (1) (a) and Article 7 of the General Data Protection Regulation, the provision of personal data for this purpose is optional. Lack of consent may result in Toughlex not being able to respond to a request or an application.
Toughlex as personal data Controller follows the following principles when processing your personal data:
- legality, acting in good faith and with transparency;
- limitation of processing purposes;
- relevance to processing purposes and minimization of data collection;
- accuracy and updates of the data;
- restriction of data storage in order to achieve the processing purposes;
- integrity and confidentiality of the processing, ensuring an adequate level of security of personal data.
Processing of personal data
Toughlex as Controller executes the following operations and processes personal data for the following purposes:
- Creating an account and signing up for use of a service – the purpose of this operation is to identify the person in order to provide him / her with the service / order;
- Processing of payment for a service and accounting, if any – the purpose of this operation is to enable payment and bookkeeping;
- Individualized data (eg name, personal ID, address, e-mail, telephone, etc.) – for marketing purposes, incl. sending information about events, trainings, and publications;
- Collecting information on the type and duration of provided services – for marketing purposes, incl. sending information about events, trainings, and publications.
- Processing of data when necessary for the performance of contractual or pre-contractual obligations or in case such data is required by law;
When you visit our website and you are asked for personal information, you share and provide this information with Toughlex.
Information We Collect
When you access or use our Website, we collect information about you automatically as you use our Website or as you provide it to us, including:
- Website activity, including data about your browsing activity on our Website, such as which pages you visit, links you click, and when;
- Technical information about the device or browser you use to access our Website, such as your device’s IP address, cookie string data and (in the case of mobile devices) your device type and mobile device’s unique identifier such as the Apple IDFA or Android Advertising ID;
- Contact information, if you choose to provide via a form submission: your name, email address;
- Customer service information you may provide to Toughlex representatives including survey responses, email messages, or phone conversations.
Recipients and categories of recipients of personal data
Toughlex provides personal data to persons outside the European Union only with the explicit consent of the data submitter and an adequately high level of protection of personal data, by requiring contractual provisions or other instruments to ensure high protection of such data. All personal data collected on our website may be stored and processed in the United States if you have provided us with your consent.
The received personal data is stored and processed for the following terms:
- For a period of 2 years – when personal data is received for the purposes of performance of contracts or pre-contractual relationships. The 2-year period starts from the latter of the two dates: the date of correspondence on the possible conclusion of the contract or the date of execution of the contract;
- For the relevant statutory period – if the personal data is collected and processed on the basis of the fulfillment of a statutory obligation by Toughlex;
- For 2 years – when personal data is received for marketing purposes, incl. information about events, trainings and publications or for job applicants if they have provided us with an explicit consent.
Toughlex uses technical and organizational security measures to provide the most comprehensive protection of personal data from unwanted access. Along with providing safe work environment, we use an encryption procedure in some areas to prevent misuse of data by third parties. Our data security is in accordance the present day technology. We make every reasonable effort to protect your personal information.
Personal data is stored in the Atlassian, which comply with the EU-U.S. Privacy Shield Framework and the Privacy Shield Principles (https://www.atlassian.com/legal/privacy-policy) regarding the collection, use, and retention of personal information transferred from the European Union to the U.S. Toughlex also uses Google’s Universal Analytics tracking on our Website. Learn more about how Google handles your data here (https://www.google.com/policies/privacy/partners/).
Rights of data subjects
Right to information
You may at any time request from us information about your personal data that we store and process, as well as about the origin, recipients or categories of recipients to whom we transmitted it and the purpose of processing it.
Right of Withdrawal
If you have provided us with your consent to process your data, you can withdraw it at any time without giving any reasons.
If your personal data processed by Toughlex is incorrect, you can ask us to correct it at any time.
Erasure and blocking rights
You have the right to delete and block your personal data that Toughlex processes. Deleting can be done at any time by contacting us. In general, your data will be deleted immediately, at the latest 30 days after exercising this right as a data subject. If deletion is contrary to legal, contractual, criminal or commercial law, or other legitimate reasons, instead of deletion, only blocking of your data may take place. After deleting your data, it is no longer possible for us to recover it.
Right to data portability
If you require us to provide you with your personal data, we will transfer the data to you or another controller in a structured, widely used and machine-readable format. We will only transfer the data directly if it is technically feasible.
Right of objection
You have the right at any time and without giving any reason to object to our processing of your data, including if we processes it for the purposes of marketing or application for a job position.
Advanced rights in automated data processing, including profiling
Toughlex does not perform automated data processing including profiling. Notwithstanding the above, with respect to automated data processing including profiling, you have the additional right to request human intervention from the Controller, the right to challenge the decision and the right to express your point of view.
Contact (for the exercise of your rights as a data subject)
When contacting us by e-mail at [email protected] or by mail at: MB “Tvirtas baitas”, Pušų g. 36, LT-45319, Kaunas, Lithuania, the reported data (including e-mail address, name and telephone number, if any) are stored by us in order to respond to your questions and respond to your case. We will delete the retained data as soon as the storage is no longer necessary or will restrict its processing if there are statutory obligations.
Right of Complaint
You are entitled to file a complaint against the processing of personal data before the competent control body if you believe that your personal data protection rights have been violated.
Use of Toughlex’s website by children
We do not intend our Web sites or online services to be used by anybody under the age of 18. If you are a parent or guardian and you think we may have collected information about a child, please contact us at [email protected]
Sharing Your Information
- In response to legal process;
- In order to investigate or remedy potential violations of our user agreements or policies, or to protect the rights, property and safety of Toughlex, our users or others;
- With our subsidiaries and related companies;
- In connection with, or during negotiations of, any merger, sale of company assets, financing or acquisition of all or a portion of our business to another company; and
- With your consent or at your direction.
We may also share aggregated or de-identified information, which cannot reasonably be used to identify you.
Your Access and Control Over Your Information
- If you are located in the European Economic Area you may opt out of online advertising via the European Interactive Advertising Digital Alliance (EDAA Your Online Choices website here (http://www.youronlinechoices.com/).
- If you are located in the European Economic Area you may also have the right to access, correct or update some of the information we hold about you. You can also request that we delete your information. If you wish to exercise any of these rights, please contact us at [email protected].
- You may opt out of Google Analytics tracking by visiting this website: https://tools.google.com/dlpage/gaoptout/
Links to Other Websites
Our Website may contain links to third party websites. These links are provided solely as a convenience to you. By linking to these websites, we do not create or have an affiliation with, or sponsor such third party websites. The inclusion of links within our Website does not constitute any endorsement, guarantee, warranty, or recommendation of such third party websites. Toughlex has no control over the legal documents and privacy practices of third party websites; as such, you access any such third party websites at your own risk.