Privacy Policy

  • General Provisions

    The following terms are used in the Personal Data Protection Policy:

    Personal data – any information relating to an identified or identifiable natural person (data subject); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

    Category of personal data – a group of personal data processed for a specific legal basis and purposes.

    Processing of personal data – any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

    Data controller – VILNIUS TECH, which alone or jointly with others determines the purposes and means of the processing of personal data.

    Data processor – a natural or legal person, public authority, agency or other body which processes personal data on behalf of the data controller.

    When processing personal data, VILNIUS TECH adheres to the following principles of personal data processing:

    Personal data are processed lawfully, fairly and in a transparent manner in relation to the data subject. They are collected for specified, explicit and legitimate purposes and are not further processed in a manner that is incompatible with those purposes.
    Personal data are adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (principle of data minimisation).
    Personal data are accurate and, where necessary, kept up to date. All reasonable steps are taken to ensure that personal data which are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay (principle of accuracy).
    Personal data are kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed. Personal data may be stored for longer periods if the personal data are processed only with the application of appropriate technical and organisational measures required to safeguard the rights and freedoms of the data subject (principle of storage limitation).
    Personal data are processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (principle of integrity and confidentiality).
    The data controller is responsible for compliance with the above principles and must be able to demonstrate compliance with them (principle of accountability).

  • How long do we process personal data?

    When processing personal data, VILNIUS TECH follows the principle that data are processed for no longer than is necessary for the purposes for which they are processed. The retention periods for personal data vary depending on the legal basis and purposes of processing for each category of data.

    The specific retention period applicable to particular categories of personal data is communicated to data subjects in the relevant privacy notice, either at the time the data are collected (for example, when entering into a contract) or, where the data are obtained from other sources, without undue delay after their receipt.

    Once the retention period has expired, VILNIUS TECH deletes and destroys the personal data in such a way that they cannot be restored or altered to allow re-identification of the specific natural person.

  • Data Subjects’ Rights

    VILNIUS TECH undertakes to respect the rights of data subjects as set out in the General Data Protection Regulation (GDPR). These rights include:

    – the right to be informed about the processing of personal data (right to be informed);
    – the right to access personal data and information about how they are processed (right of access);
    – the right to request rectification of inaccurate personal data, or to have incomplete personal data completed, taking into account the purposes of processing (right to rectification);
    – the right to request erasure of personal data or the restriction of processing (except for storage) (right to erasure and the right to be forgotten);
    – the right to request restriction of processing of personal data;
    – the right to data portability;
    – the right to object to the processing of personal data when the processing is based on consent;
    – other rights provided for by the legal acts applicable to personal data processing.

    Data subjects may submit any request related to the processing of their personal data:

    – by email to vilniustech@vilniustech.lt,
    – by post to Saulėtekio al. 11, LT-10223 Vilnius, or
    – in person at the university.

    VILNIUS TECH undertakes to respond to all requests concerning the processing of personal data within one month of receipt, in accordance with the procedure laid down in the General Data Protection Regulation.

  • Final Provisions

    The legal relations related to this Personal Data Protection Policy are governed by the laws of the Republic of Lithuania.

    VILNIUS TECH reserves the right to amend this Personal Data Protection Policy in part or in full.