Lithuanian Fintech Association Privacy Policy
INTRODUCTION
This Privacy Policy (the “Privacy Policy”) explains how Lithuanian Fintech Association, registered address Gynėjų g. 14, LT-01110, Vilnius, Lithuania, legal entity code 304701279 (the “Association”, “we”, “us”), processes your personal data. It describes how we collect, use, store, share and protect personal data, as well as outlines your rights as a data subject. It also provides information on the purposes, legal grounds, sources, recipients and retention of personal data processing.
We process personal data in accordance with applicable legislation, including the General Data Protection Regulation (EU) 2016/679 (GDPR), the Law on Legal Protection of Personal Data of the Republic of Lithuania and other applicable legal acts.
In this Privacy Policy, “you” refers to representatives of member organisations, applicants for membership, partners and their representatives, members of governing bodies, event participants, social media users interacting with us, and individuals who contact us or use our website.
When you use our website, communicate with us, interact with us via social media or otherwise provide your personal data, you understand that your personal data may be processed as described in this Privacy Policy.
Contact: info@lfa.lt
Website: https://www.lfa.lt/
1. DATA CONTROLLER
Lithuanian Fintech Association
Legal entity code: 304701279
Address: Gynėjų g. 14, LT-01110, Vilnius, Lithuania
Email: info@lfa.lt
2. PERSONAL DATA AND AGE REQUIREMENTS
Personal data means any information relating to an identified or identifiable natural person. Information that, when combined with other data, can identify a person is also considered personal data.
Our services are intended for individuals who are at least 18 years old. If you are between 14 and 18 years old, you should review this Privacy Policy together with a parent or legal guardian. We do not knowingly collect personal data from individuals under the age of 14.
3. DATA WE PROCESS
| Category | Personal Data |
|---|---|
| Basic personal information | Name and surname |
| Contact details | Email address, phone number, address |
| Professional information | Job title, organisation, represented entity |
| Communication data | Emails, correspondence, requests, meeting notes |
| Cooperation and contract data | Agreements, invoices, payment-related information, cooperation details |
| Event-related data | Registration data, attendance, participation details, image (photo and/or video), event-related communication |
| Technical data | IP address, browser and device information, website usage data |
| Social media data | Profile name, profile photo, public comments, interactions, messages |
We process only the personal data necessary for specific purposes and may not process all of the above data in every case.
4. PURPOSES AND LEGAL GROUNDS
4.1 Membership administration and activities
| Item | Description |
|---|---|
| Purpose | Administration of membership and organisation of Association activities |
| Data subjects | Representatives of member organisations |
| Personal data | Basic personal information; contact details; professional information; communication data |
| Source | Directly from you or your organisation |
| Legal ground | Legal obligation; legitimate interest |
4.2 Membership applications
| Item | Description |
|---|---|
| Purpose | Evaluation of applications and communication with applicants |
| Data subjects | Applicants and their representatives |
| Personal data | Basic personal information; contact details; professional information |
| Source | Directly from you |
| Legal ground | Pre-contractual steps; consent where applicable |
4.3 Partners and contracts
| Item | Description |
|---|---|
| Purpose | Conclusion and performance of contracts |
| Data subjects | Partners and their representatives |
| Personal data | Basic personal information; contact details; professional information; contract data |
| Source | Directly from you |
| Legal ground | Contract; legal obligation; legitimate interest |
4.4 Events
| Item | Description |
|---|---|
| Purpose | Organisation and administration of events |
| Data subjects | Event participants and speakers |
| Personal data | Basic personal information; contact details; professional information; event participation data; images |
| Source | Directly from you |
| Legal ground | Contract; legitimate interest; consent where applicable |
4.5 Communication
| Item | Description |
|---|---|
| Purpose | Responding to inquiries and maintaining communication |
| Data subjects | Individuals contacting the Association |
| Personal data | Basic personal information; contact details; communication data |
| Source | Directly from you |
| Legal ground | Legitimate interest; pre-contractual steps |
4.6 Social media management
| Item | Description |
|---|---|
| Purpose | Management of LinkedIn, YouTube and Facebook accounts and communication with users |
| Data subjects | Social media users interacting with the Association |
| Personal data | Profile name; profile photo; comments; interactions; messages |
| Source | From you and/or social media platforms |
| Legal ground | Legitimate interest |
| Note | The Association administers only its accounts and not the platforms themselves; processing by platforms is subject to their own privacy policies |
5. DATA RECIPIENTS
We may share personal data with:
| Recipient category | Description |
|---|---|
| Public authorities | When required by law |
| Professional advisors | Legal, financial, auditing |
| Service providers | IT, hosting, communication services |
| Partners | Where necessary for cooperation |
All recipients are required to ensure confidentiality and appropriate data protection measures.
6. DATA RETENTION
We retain personal data only for as long as necessary for the purposes for which it was collected and processed, including compliance with legal obligations and defence of legal claims.
| Data type | Retention period |
|---|---|
| Membership and governance data | Duration of relationship and as required by law |
| Contract and partner data | Up to 10 years after contract termination |
| Communication data | Up to 6 months after last contact |
| Event-related data | Up to 2 years after the event |
| Social media data | According to platform rules |
| Legal obligations | As required by law |
7. WEBSITE AND COOKIES
We may collect technical data such as IP address and browsing information. Cookies may be used to ensure proper website functionality and improve user experience. Where required, cookies are used based on your consent.
8. AUTOMATED DECISION-MAKING
We do not use automated decision-making or profiling.
9. YOUR RIGHTS
You have the following rights regarding your personal data:
- the right to access your personal data and obtain a copy of it;
- the right to request correction of inaccurate or incomplete personal data;
- the right to request deletion of your personal data where there is no legal basis for its further processing;
- the right to restrict the processing of your personal data in certain circumstances;
- the right to object to the processing of your personal data where processing is based on legitimate interest;
- the right to receive your personal data in a structured, commonly used and machine-readable format and to transmit it to another controller, where applicable;
- the right to withdraw your consent at any time, where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal;
- the right to lodge a complaint with the State Data Protection Inspectorate of Lithuania.
To exercise your rights, submit a request to us at info@lfa.lt or by other contact means indicated in this Privacy Policy. We will process your request after verifying your identity. Your request will be fulfilled, or a reasoned refusal will be provided, within 30 calendar days from receipt. This period may be extended where necessary in accordance with applicable legislation. Requests are handled free of charge, unless they are manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse to act on the request.
10. OBLIGATION TO PROVIDE DATA
Providing personal data may be necessary in order to:
- enter into or perform a contract;
- comply with legal obligations;
- participate in certain activities or services.
If the required personal data is not provided, we may not be able to establish or maintain the relationship or provide certain services.
11. SECURITY
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage of personal data.
12. COMPLAINTS
If you believe that your personal data is processed in violation of applicable laws or your rights, you have the right to submit a complaint to us using the contact details provided in this Privacy Policy. We will review and respond to your complaint within 30 calendar days from receipt. You also have the right to lodge a complaint with the State Data Protection Inspectorate of Lithuania, which is the supervisory authority responsible for personal data protection.
13. CHANGE TO THIS POLICY
We regularly review this Privacy Policy and may update it from time to time in accordance with applicable laws.
The latest version is published on our website and becomes effective upon publication.