KML TRADING MB PERSONAL DATA PRIVACY POLICY

CHAPTER I

GENERAL PROVISIONS

The Personal Data Security Policy (hereinafter – the Policy) is intended to ensure the security of the collection and processing of personal data of employees and third-party employees (partners, customers and public authorities) carried out by KML TRADING MB, company code 305643170, Saulėtekio al. 15-1, LT-10224 Vilnius (the Data Controller, the Company), and the proper protection and implementation of data subjects’ rights.

Ši Politika reglamentuoja pagrindinius asmens duomenų rinkimo, tvarkymo ir saugojimo principus bei tvarką, kuria remdamasis Duomenų valdytojas tvarko asmens duomenis.  Ši Politika parengta vadovaujantis Lietuvos Respublikos asmens duomenų teisinės apsaugos įstatymu bei kitais teisės aktais, reglamentuojančiais asmens duomenų rinkimą, tvarkymą ir saugojimą, taip pat ES Bendruoju duomenų apsaugos reglamentu (BDAR arba Reglamentas).

Sąvokų aprašymas:

SąvokaAprašas
Asmens duomenysAny information relating to an identified or identifiable natural person (data subject) who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, a personal identification number, location data and an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
BendrovėKML TRADING MB, legal entity code 305643170, Saulėtekio al. 15-1, LT-10224 Vilnius
Darbuotojų saugos darbe ir sveikatos būklės duomenų administravimasDarbuotojų saugos darbe ir sveikatos būklės duomenų kaupimas, tvarkymas, siekiant įgyvendinti atitinkamų teisės aktų reikalavimus saugos darbe ir sveikatos srityje.
Duomenų subjektasFizinis asmuo, kurio tapatybę galima nustatyti tiesiogiai arba netiesiogiai.
Duomenų subjekto sutikimasA freely given, specific and unambiguous indication of the data subject’s free will, by means of a declaration, by which he or she consents to the processing of personal data concerning him or her.
Duomenų tvarkytojasFizinis arba juridinis asmuo, valdžios institucija, agentūra ar kita įstaiga, kuri duomenų valdytojo vardu tvarko asmens duomenis, t.y. atlieka bet kokius veiksmus su asmens duomenimis – renka, apdoroja, kaupia, tvarko, tikslina, sistemina, keičia, naikina ir t.t..
Duomenų valdytojasFizinis arba juridinis asmuo, kuris vienas ar drauge su kitais nustato duomenų tvarkymo tikslus ir priemones. Šiuo atveju – Bendrovė.
Išorinė komunikacijaCollection and processing of contact information of officials, officers and employees of public authorities in order to have relevant and accurate information for the purpose of keeping records of visits, inspections, as well as other actions carried out by public authorities in relation to the Company. As well as informing state authorities (VMI, Sodra) about the Employees’ income and taxes paid and social benefits. It also includes the processing of personal data of guests and representatives of public authorities for the purpose of keeping records of visits to the Company; the provision of the Employee’s personal data to public authorities and law enforcement authorities for the purpose of the performance of the functions performed by the public authorities in respect of the Employee.
KlientaiFiziniai ir juridiniai asmenys, kurie perka iš Bendrovės prekes, paslaugas, darbus (pvz., pirkėjai, užsakovai, nuomininkai, kt.).
PartneriaiFiziniai ir juridiniai asmenys, kurie parduoda Bendrovei prekes, paslaugas, darbus, bendradarbiauja su Bendrove (pvz., rangovai, subrangovai, pardavėjai, nuomotojai, paslaugų teikėjai, kt.)
Valstybinės institucijosValstybinės institucijos, kurios atlieka priežiūros, kontrolės, kitas teisės aktais nustatytas valstybinės valdžios funkcijas Bendrovės atžvilgiu.
Verslo komunikacijaCollection and processing of business contact information of partners, customers’ employees for the purpose of having up-to-date and accurate information in the Company’s possession necessary to maintain business relations; provision of business contact information of the Company’s employees to the Company’s partners, customers (as defined in the Company’s Personal Data Processing Rules) necessary to maintain business relations, to execute contracts with partners, customers, including production and distribution of business cards to the Company’s partners, customers.
Vidaus administravimasDarbuotojų asmens bylų sudarymas ir tvarkymas, Darbuotojų darbo laiko apskaitos vedimas, Darbo užmokesčio pervedimas į asmeninę darbuotojo banko sąskaitą, mokesčių, susijusių su darbo santykiais, mokėjimas valstybinėms institucijoms, mokėjimų pagal vykdomuosius dokumentus mokėjimas teisėsaugos institucijoms.
Vidinis komunikavimasOrganising the work process (drafting orders and documents governing work organisation). Administration of the list of staff members’ work telephone numbers and work e-mail addresses, Preparation of the monthly newsletter and posting it on the Intranet portal in electronic format and on the news stand in hard copy.

ICHAPTER I

PURPOSES AND PRINCIPLES OF PERSONAL DATA PROCESSING

Personal data are processed for the following purposes:

  • Personalo atranka;
  • Vidaus administravimas
  • Vidinis komunikavimas;
  • Darbo saugos administravimas;
  • Klientų aptarnavimas
  • Garantinių įsipareigojimų registravimas;
  • Žalos atlyginimo paslaugos;
  • Draudimo tarpininkavimo paslaugos;
  • Lizingo tarpininkavimo paslaugos;
  • Tiesioginė rinkodara;
  • For targeted marketing and convenient browsing by website visitors (use of cookies);
  • Bandomojo važiavimo administravimas;
  • Potencialių klientų registracija;
  • Nuosavybės teisės apsauga, turto saugumo ir neliečiamumo garantija (vaizdo stebėjimas);
  • ICT administration;
  • Bendrovės veiklos viešinimas;
  • Darbuotojo artimojo funkcijų įgyvendinimas.

The personal data processed by the Company for each specific purpose are specified in the Company’s Personal Data Processing Rules. Personal data are retained only to the extent and for the period necessary to achieve the established purposes.

Personal data processed for direct marketing purposes may be subject to profiling.

Principles of personal data processing:

Personal data:

  • duomenų subjekto atžvilgiu tvarkomi teisėtu, sąžiningu ir skaidriu būdu (teisėtumo, sąžiningumo ir skaidrumo principas);
  • renkami nustatytais, aiškiai apibrėžtais bei teisėtais tikslais ir toliau netvarkomi su tais tikslais nesuderinamu būdu (tikslo apribojimo principas);
  • adekvatūs, tinkami ir tik tokie, kurių reikia siekiant tikslų, dėl kurių jie tvarkomi (duomenų kiekio mažinimo principas);
  • tikslūs ir prireikus atnaujinami; turi būti imamasi visų pagrįstų priemonių užtikrinti, kad asmens duomenys, kurie nėra tikslūs, atsižvelgiant į jų tvarkymo tikslus, būtų nedelsiant ištrinami arba ištaisomi (tikslumo principas);
  • kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be retained for longer periods if the personal data are to be processed solely for archiving purposes in the public interest after appropriate technical and organisational measures have been put in place (the principle of limitation of the duration of storage);
  • tvarkomi tokiu būdu, kad taikant atitinkamas technines ar organizacines priemones būtų užtikrintas tinkamas asmens duomenų saugumas, įskaitant apsaugą nuo duomenų tvarkymo be leidimo arba neteisėto duomenų tvarkymo ir nuo netyčinio praradimo, sunaikinimo ar sugadinimo (vientisumo ir konfidencialumo principas).

Duomenų valdytojas atsako už tai, kad Bendrovėje būtų laikomasi nurodytų principų, ir turi visas reikiamas priemones įrodyti, kad jų laikomasi (atskaitomybės principas).

Taking into account the nature of the personal data to be protected and the risks arising from their processing, the Company implements organizational and technical measures appropriate to the required level of security of the personal data processed.

IICHAPTER I

STORAGE AND PROCESSING OF PERSONAL DATA

Within the Company, the protection and processing of personal data is organized, ensured and carried out by the head of the Data Controller or by person(s) appointed by the head’s order, who:

  • privalo saugoti darbuotojų asmens duomenų paslaptį ir laikytis asmens duomenų apsaugos teisės aktų reikalavimų;
  • tvarkyti asmens duomenis vadovaujantis Lietuvos Respublikos įstatymais, kitais Lietuvos Respublikos ir Europos Sąjungos teisės aktais, reglamentuojančiais asmens duomenų apsaugą, ir šiuo Aprašu;
  • užtikrinti, kad būtų vadovaujamasi principu „Būtina žinoti“, t. y. neatskleisti, neperduoti ir nesudaryti sąlygų bet kokiomis priemonėmis susipažinti su asmens duomenimis nė vienam asmeniui, kuris nėra įgaliotas tvarkyti asmens duomenų;
  • siekiant, kad būtų užkirstas kelias atsitiktiniam ar neteisėtam asmens duomenų sunaikinimui, pakeitimui, atskleidimui, taip pat bet kokiam kitam neteisėtam tvarkymui, saugoti dokumentus bei duomenų rinkmenas tinkamai ir saugiai bei vengti nereikalingų kopijų darymo. Dokumentų kopijos, kuriose nurodomi darbuotojų asmens duomenys, turi būti sunaikintos taip, kad šių dokumentų nebūtų galima atkurti ir atpažinti jų turinio;
  • užtikrina, kad Duomenų valdytojo darbuotojai nedelsiant praneš Duomenų valdytojo vadovui ar jo paskirtam asmeniui apie bet kokią įtartiną situaciją, kuri gali kelti grėsmę asmens duomenų saugumui, arba apie asmens duomenų saugumo pažeidimą, ir imtis priemonių tokiai situacijai išvengti ar dėl asmens duomenų saugumo pažeidimo galinčiai kilti ar kilusiai žalai sumažinti ar išvengti.

Personal data may be processed only by persons who require them to perform their functions and only when such processing is necessary to achieve the relevant purposes.

Staff members who, in the exercise of their assigned functions, handle personal data of staff members or other persons shall respect the principle of confidentiality and shall keep secret any information relating to personal data of which they have knowledge in the performance of their duties, unless such information is public information in accordance with the provisions of applicable laws or regulations. The obligation of confidentiality of personal data shall also apply to transfers of duties, employment or contractual relationships.

Employees’ personal data contained in relevant documents (contracts, orders, applications, etc.) are retained for the periods specified in the General Index of Document Retention Periods approved by order of the Chief Archivist of Lithuania.

To ensure the security of personal data, the Company has implemented organizational and technical personal-data security measures detailed in the Company’s Personal Data Processing Rules.

CHAPTER IV

RIGHTS OF DATA SUBJECTS

Data subjects have the right to:

  • be aware of the collection of your personal data – you must be informed of what personal data you are required to provide, the purpose for which it is collected, to whom it may be provided and for what purpose, and the consequences of failing to provide it;
  • susipažinti su surinktais savo asmens duomenimis ir kaip jie tvarkomi – turi teisę prašyti pateikti informaciją apie tai, kokie ir kokiu tikslu jo asmens duomenys yra tvarkomi;
  • reikalauti ištaisyti, patikslinti ar papildyti neteisingus ar neišsamius jo asmens duomenis, sunaikinti savo asmens duomenis arba sustabdyti savo asmens duomenų tvarkymą;
  • nesutikti, kad būtų tvarkomi darbuotojo tam tikri neprivalomi jo asmens duomenys;
  • pateikti skundą priežiūros institucijai;
  • independently opt out of the use of cookies.

CHAPTER V

POLICY COMPLIANCE RULES

The policy compliance audit is carried out during the risk analysis of the Company’s activities, analyzing documents related to personal data processing and receiving feedback from direct personal data processors.

Failure to comply with this policy may, depending on the severity of the violation, be considered a violation of employment responsibilities for which employees may be held liable under applicable law.

The company carries out employee education in the field of personal data security.

VI CHAPTER

RELATED DOCUMENTS

The Law on Legal Protection of Personal Data of the Republic of Lithuania, other legal acts regulating the protection of personal data.

General requirements for organizational and technical personal data security measures.

European Union General Data Protection Regulation (EU 2016/679).

The Company’s Personal Data Processing Rules.

Information security policy of the company.

The Company’s Information Security Incident Management Plan.

Video surveillance procedure of the company.

VII CHAPTER

FINAL PROVISIONS

The policy applies to all employees of the Data Controller, data processors, external parties, i.e. i.e. those who have access to the personal data managed and processed by the Data Controller and their processing tools.

The policy applies to all personal data managed by the Data Controller.

The policy is approved and changed by the head of the Company by his decision, after completing the consultation procedure with the works council, if one is elected in the Company. The policy is reviewed and updated in the event of changes in the legal acts that regulate the processing of personal data, as well as in the event of a change in the existing or emergence of a new purpose for the processing of personal data.

The Company’s employees are introduced to the Policy in accordance with the procedure for familiarization with the Company’s internal legal acts, and the Policy is also published on the Company’s intranet website.