About us

Privacy Notice

1. What is provided in this Privacy Notice and who is it intended for?

UAB TETAS (hereinafter referred to as the Company or we), in the course of its activities, processes (collects, stores, etc.) your personal data. When processing this information, the Company follows the General Data Protection Regulation of the European Union (hereinafter referred to as the GDPR) and other applicable legal acts regulating the protection of personal data.

This Privacy Notice (hereinafter referred to as the Privacy Notice) is intended for you. It provides essential information about how your personal data is processed by the Company – where we obtain your personal data from, to whom we may disclose it, the purposes and legal bases for processing it, the rights you have, how you can exercise them, and other relevant information. Please read this important information carefully and visit our website from time to time to review the latest version of this Privacy Notice.

To find out when the Privacy Notice was last updated, please refer to the date indicated under “Last Updated”.

2. Who is responsible for the protection of your personal data?

UAB TETAS
Legal entity code: 300513148
Registered office address: Senamiesčio g. 102B, Panevėžys, Lithuania Mailing address: V. Krėvės pr. 120, Kaunas, Lithuania Email: [email protected] Phone: +370 640 38334 +370 640 38334

3. Why and what personal data about you do we collect?
No . Why do we collect information about you? What information do we collect about you? Why are we entitled to collect your information? Why are we entitled to collect your information?

1

We conduct employee search and selection

Name, surname, date of birth, telephone number, email address, etc. postal address, place of residence (address), details of education, desired position (function), date of receipt of CV, personal characteristics, experience: employer, length of service, position held, other work experience; knowledge of foreign languages: language, reading, writing, speaking levels; ability to work with computer programmes, desired salary, other information contained in the CV, letter of recommendation and/or covering letter.

We have your consent (Article 6(1)(a) GDPR).

After the selection has been completed and the candidate agrees to the storage of his/her data for future selections, his/her personal data will be kept for 1 year.

After the selection has ended and if the candidate does not agree to the storage of his/her personal data for future selections, his/her personal data will be deleted within 30 days of the end of the selection (the end of the selection is considered to be the candidate’s notification of the end of the selection).

The data on LinkedIn or another professional social network is stored for 30 days from the date of the person’s consent (in the case of recruitment carried out by the parent company EPSO-G using the SmartRecruiters system).

Personal data is stored in SmartRecruiters for 1 year from the date of creation of the account and the date of application for the position (when the selection is carried out by the parent company EPSO-G using SmartRecruiters).

If a person applies for a position outside the SmartRecruiters system and an account is created in the SmartRecruiters system by the recruiter, the system will ask for the person’s consent no later than 30 days after the account is created. Once consent has been obtained, the personal data will be stored in SmartRecruiters for 1 year (when the selection is carried out by the parent company EPSO-G using SmartRecruiters).

2
We carry out security checks on candidates applying for office.

Name, surname, residential address, position applied for, personal data referred to in Article 16 of the Law of the Republic of Lithuania on Prevention of Corruption (the scope of personal data depends on the information provided to the Company by the relevant authorities).

For this purpose, special categories of personal data may also be processed if they have been provided to the Company by the authorities carrying out the screening of the candidate (Special Investigation Service of the Republic of Lithuania).

We have an obligation to process your personal data in accordance with the law (Article 6(1)(c) GDPR).

Where a security check of a candidate provides information leading to a decision not to appoint a person to a post, the personal data will be kept for 3 months after the selection has been completed.

When a security check on a candidate provides information that leads to an employment decision, the candidate’s personal data (obtained prior to the conclusion of the employment contract) is stored for the duration of the employment contract and for 1 year after the termination of the employment relationship.

3
We manage an internal whistleblowing channel (helpline).

The name, surname, telephone number, personal identification number, e-mail address (if provided by the data subject) of the persons providing information on possible infringements, the circumstances of the notification, the date of the notification (the actual circumstances, when, by whom and how the infringement was committed) and the decision of the person providing the notification to inform him/her of the actions carried out and the decisions taken.

The personal data of the persons to whom the information concerning the possible infringement is provided may be processed as indicated by the notifying person in the notification of the possible infringement: name, surname, etc.

We have a legitimate interest in processing your personal data (Article 6(1)(f) of the GDPR) (to prevent fraud, corruption, other criminal offences, breaches of the law, breaches of employment obligations and other breaches of the law – to prevent the commission of offences, to take measures to prevent future offences, etc.).

We have an obligation to process your personal data in accordance with the law (Article 6(1)(c) GDPR).

If an infringement has been detected, 5 years after the end of the investigation. If no irregularity has been detected or it was decided not to open an internal investigation, 3 years after the end of the investigation.
4
Organising and executing procurement.
Name, surname, date of birth, address, telephone number, job title, bank account number, individual activity certificate number, business licence number, copies of diplomas, certificates, work experience, number of contracts completed.
We have a legitimate interest in processing your personal data (Article 6(1) of the GDPR) (to ensure the proper organisation and performance of procurement).
5 years from the end of the purchase.
5
We make and enforce contracts.
Name, surname, personal identification number or date of birth, telephone number, e-mail address, bank account number, signature, basis of representation (power of attorney, articles of association, etc.), authorisation number, term of the authorisation, duties, settlement information, settlement period, other information relevant to the conclusion and performance of the contract, depending on the nature of the contract.

We have a legitimate interest in processing your personal data (Article 6(1) of the GDPR) (to collect personal data necessary both for pre-contractual activities and to ensure the proper performance of these contracts).

We enter into and perform a contract with you (Article 6(1)(b) GDPR).

During the term of the contract and for 10 years after the end of the contract.

6

Legal activities.

Name, surname, personal identification number, date of birth, employment data, e-mail address, other data contained in documents and their annexes, procedural documents, court orders, judgments, decisions, rulings, including special categories of personal data.

We have a legitimate interest in processing your personal data (Article 6(1) GDPR) (to defend the Company’s rights in legal proceedings).

The data is needed to enable us to assert, exercise or defend legal claims.

10 years after the end of legal proceedings.
7
We look into the suggestions, complaints and requests you make.
Name, surname, email address, telephone , signature, date of referral, referral number (registration number) and the information contained therein, the outcome of the proceedings, if the person making the request, complaint or proposal has been contacted by e-mail. by email, the personal data contained in these communications.

We have a legitimate interest in processing your personal data (Article 6(1)(f) of the GDPR) (to process requests, complaints or suggestions submitted to the Company).

3 years from the date of receipt of the request, complaint or proposal.

8
Video surveillance.
Image.
We have a legitimate interest in processing your personal data (Article 6(1) GDPR) (to ensure the security of property and persons).
30 days, unless they need to be kept for a longer period as part of the investigation of the incident.
9
Ensuring effective management of corruption and international sanctions risks
Business partner’s name, surname, date of birth, nationality, place of residence, registration address, country, percentage of owned shares, information about connections with politically exposed (influential) persons, information about investigations related to corruption, competition, anti–money laundering, and terrorist financing, violations of employee health and safety, information about business partners and clients.
Personal data of the business partner’s shareholders (members), beneficial owners (name, surname, date of birth, nationality, place of residence).
Business partner’s representative’s name, surname, position, and email address.
Other information provided by the business partner or its representative in the questionnaire.

We are required to collect this information under the law (Article 6(1)(c) of the GDPR) and have a legitimate interest (to ensure that business partners comply with the requirements set out in the Group’s Partner Code of Ethics and to manage potential financial and reputational risks) (Article 6(1)(f) of the GDPR).

Retention period: 5 years after the termination of contractual relations.

You can read the Candidates’ Privacy Policy for this selection process run by EPSO-G Ltd. here.

4. Where do we obtain your personal data from?

Most of the information is provided by you, but certain personal data may also be obtained from legal entities you work for (e.g., companies within the UAB “EPSO-G” group) or represent (e.g., suppliers with whom we contract).

When providing your personal data, please only submit the information necessary to achieve the purposes listed in section 3. Do not provide information such as political views, ethnicity, religion, etc.

5. What personal data are you required to provide and why?

Please review section 3 above – you must provide the information necessary for us to:

5.1. Conduct employee search and selection;

5.2. Conduct reliability checks for candidates;

5.3. Organize and conduct procurement;

5.4. Conclude and execute contracts with you.

If you do not provide the specified information, you will not be able to participate in the selection, and we will not be able to conclude employment or other contracts with you and fulfill contractual obligations.

6. To whom may we disclose your personal data?

We may disclose information related to you to our partners, service providers, and other entities listed below, only as necessary to achieve the purposes listed in section 3 and as permitted by applicable law:

6.1. Banks performing transaction operations;

6.2. Courts, supervisory, law enforcement, and other state institutions;

6.3. Lawyers, notaries, bailiffs, auditors, consultants, data centers, hosting, cloud, website administration, software development and support companies, IT infrastructure service providers, communication service providers, insurance companies, archiving services, and other service providers to the Company.

We ensure that these third parties apply appropriate technical and organizational measures to ensure the secure processing of personal data and an adequate level of data protection according to EU legislation.

7. Will your personal data be transferred outside the European Economic Area?

In most cases, personal data are processed and transferred within the European Union and the European Economic Area (EEA) territory.

If necessary for certain services, data may be transferred outside these areas, ensuring an appropriate level of personal data protection. When permitted by law and necessary for the reasons specified in section 6, we disclose your data:

7.1. on the basis of an adequacy decision of the European Commission, which means that the European Commission has recognised the country in which the third party is established and/or carries out its activities as ensuring an adequate level of protection of personal data;

7.2. We have signed a contract with a third party based on the Standard Contractual Clauses approved by the European Commission;

7.3. we have obtained permission from the State Data Protection Inspectorate;

7.4. making use, where possible, of other available safeguards and derogations for the protection of personal data.

8. How do we protect your personal data?

We implement appropriate technical and organizational measures to ensure that your information is protected against unauthorized access, disclosure, accidental loss, alteration, or destruction, and other illegal processing.

9. What rights do you have?

The GDPR and other laws give you rights, the cases in which you can exercise them, the procedures you must follow, and the exceptions in which cases you cannot exercise the rights granted. Where permitted by law, you can:

9.1. access to your personal data, i. e. to receive a notice confirming whether the Company processes your personal data and, if it does, to request access to the processed data and related information;

9.2. to ask us to correct inaccurate, incorrect or incomplete personal data or to complete personal data;

9.3. request us to erase the personal data we hold about you if this can be justified on one of the grounds set out in Article 17 of the GDPR. ;

9.4. request us to restrict the processing of your personal data in our possession where one of the cases provided for in Article 18 of the GDPR applies. ;

9.5. to object to the use of your data where we process your data in the legitimate interests of the Company and/or third parties;

9.6. request us to transfer/receive data that you have provided to us under a contract or consent to processing and that we process by automated means in a commonly used electronic format;

9.7. to object to a fully automated decision, including profiling, where such decision-making may have legal consequences or similar significant effects on you;

9.8. withdraw the consents given to us to process your personal data where we use the data on the basis of your consent;

9.9. lodge a complaint with a supervisory authority, in particular in the Member State where you are domiciled or where the alleged infringement of the GDPR took place, and seek judicial remedies. In the Republic of Lithuania, the supervisory authority is the State Data Protection Inspectorate (L. Sapiegos str. 17, Vilnius; e-mail. Mail: [email protected]), but we recommend that you contact us first and we will try to work with you to resolve all your requests.

10. How can you exercise your rights?

In order to exercise your rights as set out in section 9 of this Privacy Notice, you must:

10.1. personally deliver the request to exercise the rights of the data subject (hereinafter referred to as the “Request”) to the Company at V. Krėvės pr. 120, LT-51119 Kaunas, Lithuania (the application must be accompanied by a personal identification document for consultation);

10.2. send a Request to the Company or the Personal Data Protection Expert by email to [email protected] (The Request submitted by email must be signed with a secure electronic signature);

10.3. submit to the Company or to the Personal Data Protection Expert by post, at the address V .Krėvės pr. 120, LT-51119 Kaunas (a copy of the personal identity document certified by a notary public or other procedure established by law must be attached to the Application)

11. How will we inform you of changes to this notice?

We may update or change this Privacy Notice at any time. Such updated or amended Privacy Notice will be effective from the date of its posting on our website.

When we update the Privacy Notice, we will inform you of what we consider to be material changes by posting them on the website. You can look at the “Date Updated” date at the top to see when the Privacy Notice was last updated.

12. Does your website leave cookies on my computer or device?

Yes, we use cookies, you can read more about the cookies we use Cookie Policy.

13. How do I contact the Company or a personal data protection expert?

If you have any questions, comments or complaints about how we collect, use and store information about you, or if you wish to exercise your rights as a data subject, you can contact:

13.1. The company’s address is V. Krėvės pr. 120, Kaunas, telephone : +370 640 38334, email [email protected];

13.2. Company’s personal data protection expert, email [email protected]