PRIVACY POLICY OF ŠIAULIŲ BANKAS GROUP COMPANIES IN LITHUANIA
(amending the Personal Data Protection Rules of AB "Šiaulių bankas" in force until 1 December 2023, the Information of UAB "SB lizingas" to the borrowers of consumer credit on the collection, use and storage of information about me, the Personal Data Protection Policy, the Personal Data Processing Rules of life insurance UAB "SB draudimas")
1. Purpose of the Privacy Policy of Šiaulių Bankas Group companies in Lithuania
This Privacy Policy of Šiaulių bankas group companies (hereinafter referred to as "SB Companies" or "We, Our, Us") in Lithuania (hereinafter referred to as " Privacy Policy") provides answers to the most important questions about how SB Companies process Your Personal Data and what rights You have in relation to this.
In the context of this Privacy Policy, Šiaulių Bankas Group companies in Lithuania mean:
AB "Šiaulių bankas" (hereinafter referred to as the Bank), life insurance UAB "SB draudimas" (hereinafter referred to as SB insurance), UAB "SB lizingas" (hereinafter referred to as SB leasing), UAB "SB Asset Management" (hereinafter referred to as SB Asset Management), or all of the following companies together.
This Privacy Policy applies to You - current, future and/or former SB Companies' Clients or persons related to them who have expressed a desire to use Our services, are already using, have previously used or are otherwise related to Our services, i.e. You are an agent, family member, guarantor, security provider, etc. of Our Client, or You are an agent, shareholder, member of the governing bodies of the Legal Clients, the beneficial owner or the real beneficiary of , or any other Data Subject as specified in this Privacy Policy.
You can also get acquainted with the Privacy Policy at the Client Service Departments of SB Companies. Please periodically visit https://www.sb.lt/lt/apie/svarbus-dokumentai/privatumo-politika for the most up-to-date version of our Privacy Policy.
We invite You to familiarize Yourself with this Privacy Policy and to make this Privacy Policy known to Your current or future authorized representatives, persons whom You represent, beneficiaries and other persons who are or may be in any way connected with our services and/or whose Personal Data You provide to us.
2. Terms used in this Privacy Policy
Personal data |
Any information directly or indirectly relating to You and capable of identifying You. |
---|---|
Automated solution |
Our decision, which has legal consequences for You or affects You, is made without the intervention of an employee of SB Companies, i.e. in an automated way. |
Joint controllers |
Where two or more Data Controllers jointly determine the purposes and means of the processing of the Data, they shall be considered as Joint Data Controllers. |
Data protection legislation |
Any Personal Data protection legislation applicable to SB Companies, including but not limited to: Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of Personal Data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (abbreviated to "GDPR"), the Law on Legal Protection of Personal Data of the Republic of Lithuania and national legal acts implementing the GDPR. |
Data recipient |
A natural or legal person, government or other authority to whom SB Companies may disclose Personal Data. |
Data Subject |
The natural person whose Personal Data is processed by SB Companies. SB Companies may process Personal Data of Data Subjects such as: Clients, members of the Client's family, legal representatives, authorised representatives, counterparties, payers, collateral providers, insured persons, policyholders, premium payers, beneficiaries, representatives of SB Companies' Legal Clients, shareholders, members of the management bodies, beneficial owners, final beneficiaries, users of SB Companies' website, self-service portals, participants in SB Companies' events and persons visiting SB Companies' premises, beneficiaries, representatives and employees of SB Companies' business partners, as well as other persons such as followers on social networks, etc. |
Data processing |
Any act (including collection, recording, storage, alteration, transmission, destruction, retrieval or other processing) of Personal Data. |
Data Processor |
A natural or legal person who processes Personal Data on behalf of and for the benefit of the Data Controller. |
Data Controller |
A natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of Personal Data. |
EU/EEA |
European Union/European Economic Area. The European Economic Area is made up of all the member countries of the European Union plus Iceland, Liechtenstein and Norway. |
Legal client |
Means a legal person who uses, has used, has expressed an intention to use the SB Companies services. |
Client (or You)
|
A natural person who has expressed an interest in using Our Services, is already using or has previously used Our Services, or is otherwise connected with the Services provided by SB companies, the users of the Services or the business relationship with SB companies. |
Services |
Any service, advice, product provided or made available by SB Company at a customer service outlet, online bank, self-service, through any SB Company mobile application, telephone, video transmission or other means, through Our intermediaries, as well as services and products of Our carefully selected partners. |
Profiling |
Processing of Personal Data by automated means in order to assess certain of Your personal characteristics and to analyse or predict, for example, Your economic situation, personal preferences, interests. |
Other terms used in this Privacy Policy shall be understood as defined in the GDPR and other legislation on the protection of Personal Data.
3. Data Controller
The Bank acts as a Data Controller of Your Personal Data when it provides You with various banking services, such as day-to-day banking, credit, investment services.
SB leasing acts as a Data Controller of Your Personal Data when providing consumer credit and other services.
SB Asset Management acts as a Data Controller of Your Personal Data when providing management services for Tier II and Tier III pension funds and collective investment undertakings.
SB insurance acts as a Data Controller of Your Personal Data when providing life insurance services.
The Bank also acts as a Data Processor when it offers and manages the provision of services on behalf of other SB Companies that are Data Controllers.
SB Companies may act as joint controllers where this is necessary for financial accounting, auditing, risk assessment, or where we share information systems or hardware (servers), or where this is necessary for the provision of services.
If You have any questions, requests or comments regarding this Privacy Policy, the processing of Personal Data, complaints or any other issues related to the protection of Personal Data in SB Companies, please contact the following contacts:
Regarding the services provided by the Bank |
Joint stock company Šiaulių bankas |
---|---|
Regarding consumer credit and other services provided by SB leasing
|
UAB “SB lizingas” |
Regarding life insurance services provided by SB insurance
|
Life insurance UAB "SB draudimas" |
Regarding SB Asset Management's pension fund and investment fund management services for Tier II and Tier III pension funds
|
UAB „SB Asset Management“ |
4. Categories of Personal Data processed by SB Companies
SB Companies process the following categories of Your Personal Data (including but not limited to):
Personal identity data, such as name, surname, personal identification number, date of birth, facial image in a photograph, signature, details of the identity document (a copy of the document may be processed in certain cases).
Contact details , such as residential and/or mailing address, telephone number, email address.
Identification data for SB Companies' self-service, such as Your login details (Internet Banking user ID or username, email address), Internet Protocol (IP) address, other browsing information, including when, from where and from which device You accessed Our Internet Bank, Self-Service, website or other electronic platforms.
Data about Your financial experience and investment knowledge and objectives, such as the asset classes You invest in, frequency, duration, investment risk tolerance, investment needs and expectations, sustainability preferences, education, field of work, and other data provided prior to the selection and provision of investment or investment life insurance services.
Data about Your transactions, depending on the services provided to You by SB Companies, such as data about the transactions (e.g. bank account, payment card, consumer credit, home credit, leasing, insurance, pension, deposit, investment services or other contracts) that You intend to enter into (by means of requests, applications) or have entered into, and the details of those transactions and related documentation.
Payment data, such as sender/recipient of funds, account number, purpose of payment, amount and currency of payment, payer identification code, payment instruments (e.g. bank card, internet bank, digital wallet, etc.) and the actions taken using them, funds deposits, withdrawals, credit transfers, etc.
Financial status data such as employment income other income and assets (amounts, periods of declaration, types of economic activity), employer, length of service, dates of commencement and termination of employment, self-employment or other performed economic activity, lump-sum or periodic social benefits received or granted, type, amount, nature, sources, periods of receipt, social security insurer, beginning and end of social security insurance period, immovable and movable property owned, property rights and encumbrances, information on existing liabilities, history of indebtedness, etc.
Data about Your behavioural patterns, preferences and satisfaction with the Services, such as data about Your activity in using the Services, the Services provided to You, Your personal preferences in Your online bank, self-service or apport feedback on the Services of SB Companies, etc.
Data necessary for the Bank and SB leasing to assess Your solvency, creditworthiness and risk of performance of obligations, such as information on Your bankruptcy status, credit rating, bank statement data, information on whether You are not included in the list of persons for whom applications have been submitted to refrain from concluding consumer credit agreements, data on incapacity or restriction of capacity, and information on Your marital status, the number of minor children, details of relationships with other related natural and/or legal persons, information on education, profession, occupation, possession of movable and non-movable property and rights thereto, types and amounts of existing or former financial and/or property obligations, the time limits for the fulfilment of these obligations, details of the performance of these obligations and other information relevant for the assessment of Your creditworthiness and financial situation).
Data needed to enforce anti-money laundering, anti-terrorist financing, anti-tax evasion measures and international sanctions, such as nationality, country of residence (for tax purposes), taxpayer identification number, links to Lithuania, other related natural and/or legal persons, sources of funds, activities, planned bank account turnover and/or investments and/or insurance premiums, political positions held and political participation of You or Your family members or close associates, publicly available information in the media, correspondence with You in business dealings, details of documents supporting a monetary operation or transaction, etc.
Data necessary for the protection and defence of rights and interests in the event of legal proceedings or the recovery of debts, such as all of the above information, documents and attachments sent to You by SB Companies, the amount of the debt, the information held by You or by a third party (for example, documents and their attachments sent or submitted by You or third parties, documents and their attachments sent or submitted by notaries, bailiffs, attorneys, heirs, spouses, etc.), procedural documents containing Your Personal Data, information about criminal offences and convictions of You and/or third parties.
Audiovisual data, such as video recordings of You visiting SB Companies' filmed branches or using ATMs, or of You about to become a customer of SB Companies remotely, or audio recordings of You calling customer service numbers or using remote consultations.
Special categories of Personal Data such as:
Biometric data, such as facial image (biometric data unique to the person: 3D projection of the face, result of a comparison between a photograph of the person and a photograph of the person in the ID document (expressed as matching points) when You intend to become/become a Client remotely.
Health data, such as information about Your state of health, any incapacity or restriction of capacity, or disability, medical treatment provided, diagnosed illnesses, injuries sustained, and other health data, is necessary to assess Your ability to enter into transactions, insurance risks, to investigate the circumstances of an insured event or to assess whether You have acquired the right to a pension, to evaluate Your requests for deferment of housing or consumer credit payments on health grounds, etc.
Please note! SB Companies process special categories of Personal Data with Your consent (Article 9(2)(a) GDPR) or if such processing is provided for by legal requirements and/or is based on the necessity to comply with or assert a legal claim (Article 9(2)(g), (f) GDPR).
Please note! In this section, we have set out the main categories of Personal Data that we process. However, due to the specific nature of our activities, it is not possible to provide an exhaustive list of the categories of Personal Data processed in the Privacy Policy, and therefore this list is not exhaustive. The specific amount of Personal Data we process depends on the Services You order and use and Your relationship with SB Companies.
In order to use our Services, You must provide us with the information that is necessary for us to enter into or perform a Service Contract with You or to provide You with a financial or other service, as well as information that we are required to collect by the requirements of law. If You do not provide the information requested by Us, We have the right not to provide the Services to You or to suspend the Services.
5. Information about the purpose for which and the legal basis on which we process Your Personal Data
We process Your Personal Data in accordance with the provisions of the GDPR and other data protection legislation, for clear and specific purposes and on the following legal grounds:
5.1. Legal basis - consent
We process Personal Data on the basis of consent for the following purposes:
- to send You marketing offers, to ask for Your opinion about our Services. For this purpose, SB Companies process Your name, surname, date of birth and contact details. You can find out how SB Companies process Your Personal Data for direct marketing purposes on their website: https://www.sb.lt/lt/apie/svarbus-dokumentai/tr-privatumo-pranesimas;
- organise and execute promotions, campaigns and events for Clients. For this purpose, SB Companies process Your personal identity and contact data. Please note that we may additionally process other necessary Personal Data, such as demographic data, financial data, etc., depending on the promotion, campaign and/or event;
- record video or telephone conversations to ensure the quality of our Services and to protect the interests of SB Companies and You. For this purpose, SB Companies process Your image, voice recording and other information that You provide to SB Companies during the conversation;
- to provide the Bank with payment services related to open banking. The Bank shall provide the payment initiation service provider or the account information service provider with a list of Your accounts, a list of transactions, payment order data, account balance, depending on which service You use; such data is also processed by the Bank on the basis of legal obligation;
- to identify You without Your physical presence at a customer service outlet when You intend to become an SB Companies' Client remotely. For this purpose, SB Companies process Your biometric data on the basis of consent as provided for in Article 9(2)(a) GDPR;
- to enable SB Insurance to underwrite and administer life insurance contracts, assess insurance risks and investigate insured events. For this purpose, SB insurance collects and provides reinsurers with data on Your health, medical examinations and other medical data, life insurance services provided to You by other life insurance companies, data related to the investigation of insured events from law enforcement authorities on the basis of consent as provided for in Article 9(2)(a) of the GDPR;
- In order to enable SB Asset Management to pay the received right to a pension benefit before the minimum retirement age, SB Asset Management processes Your health data on the basis of Your consent as provided for in Article 9(2)(a) of GDPR.
Please note! You may withdraw Your consent at any time, but please note that this does not affect the lawfulness of the processing of Your Personal Data carried out prior to the withdrawal of consent.
5.2. Legal basis - performance of a contract or intention to conclude a contract
For the performance of the contract, we process Personal Data for the following purposes:
- to take action at Your request prior to entering into a contract for Services (e.g. bank account, payment card, pension scheme, home loan, leasing, consumer credit, life insurance, deposits, investment services, internet banking, etc.), to enforce a contract entered into and/or to terminate a contract to which You are party. For this purpose, SB Companies process Your personal identity data, contact data, contractual data, financial data, health data (depending on the contract You are entering into) and other data necessary for the conclusion and performance of the specific contract.
Please note! In some cases, contracts (e.g. bank accounts, debit cards) may be subject to an automated decision. The automated decision to provide You with the requested Service is only made if You meet all the conditions for the provision of the requested Service. In the event that You disagree with the automated decision, it will be reviewed and evaluated by a member of Our staff; - to update the data You provide to Your SB Companies. For this purpose, SB Companies process the personal identity and contact details You update;
- to execute Your payment transactions, including one-off payment transactions where You do not have a bank account agreement (e.g. transferring funds without a bank account, currency exchange, depositing funds into another Client's account). For this purpose, the Bank processes payment transaction data and Personal Identification Data;
- when communicating with You about the Services You have selected and use in SB Companies, providing and administering access to the Services, and monitoring the use and operation of the Services. For this purpose, SB Companies process Your personal identity data, contact data, identification data in SB Companies' self-service and data on Your transactions (Contracts) depending on the services SB Companies provide to You.
5.3. Legal basis - performance of a legal obligation
In order to comply with the legal obligations imposed on SB Companies by law, i.e. on the basis of a legal obligation, we process Your Personal Data for the following purposes:
- to establish and verify Your identity and to maintain a business relationship (physically and remotely). For this purpose, SB Companies process personal identity data, contact data, and, if You are a representative of our client, documents supporting Your representation (including, but not limited to, a representation agreement, power of attorney, court order, other documents supporting representation);
- implementing Know Your Customer requirements and preventing money laundering, terrorist financing, circumvention of international sanctions or other restrictive measures, or tax evasion. For this purpose, SB Companies process Your personal identity data, contact data, as well as data necessary for the enforcement of measures to prevent money laundering, terrorist financing, tax evasion and the implementation of international sanctions. In the event that You are a Client of more than one SB Company, the SB Company shall, on the basis of legitimate interest, transfer the data collected for this purpose to the other SB Company (except for SB Leasing);
- to assess Your solvency, creditworthiness, and risk of default in order to provide or render Services to You. For this purpose, the Bank and SB leasing shall process Your personal identity data, contact data, data on Your financial status, data necessary for the Bank and SB leasing to assess Your solvency, creditworthiness and risk of performance of obligations.
Please note! that Your creditworthiness assessment is carried out in an automated way (i.e. based on Your financial situation and data related to solvency and liability risk, Your credit rating is calculated and You are assigned to a specific Client category). If You disagree with the automated decision, the automated decision will be reviewed and evaluated by a member of our staff at Your request; - for carrying out an insurance risk assessment when taking out a life insurance contract (to properly assess the commitments You are making and the suitability of the product You have chosen). For this purpose, SB insurance processes Your data on Your financial situation, financial obligations, education, experience, investment knowledge and objectives (in the case of investment life insurance) or other data necessary for this purpose;
- to record telephone and/or video conversations with You in order to comply with applicable law relating to the provision of investment services or remote identification. For this purpose, SB Companies shall keep records of telephone and video conversations and/or video recordings;
- to deal with Your complaints and respond to Your requests, claims, contact You and provide advice on the services You use. For this purpose, SB Companies process Your personal identity data, contact data, and other data related to the content of Your inquiry, request, claim. Such data may also be processed by SB Companies on the basis of a contract and/or legitimate interest, depending on the nature of Your request;
- to comply with other legal requirements under applicable legislation in areas such as financial markets, financial services, financial instruments, accounting and tax. For this purpose, SB Companies may process Your personal identity data, financial status data, payment data, data from contracts concluded with You and other data necessary for the implementation of a specific legal requirement imposed on SB Companies.
5.4. Legal basis - legitimate interest
In the legitimate interests of SB Companies and/or third parties to whom Your data is provided, We process Your Personal Data for the following purposes on the basis of legitimate interest:
- to ensure the accuracy and actuality of Your data, if You are a client of more than one SB Company and You update Your contact details in one of the SB Companies, the SB Company where You have updated Your contact details shall transfer Your contact details to the other SB Company of which You are also a Client;
- to provide advice in response to Your requests to SB Companies, SB Companies process Your name and contact details and information about the advice You are seeking;
- when You check in at an SB Companies' Client service point or ask us to register You for a visit and send You reminders of Your scheduled appointment. For this purpose, SB Companies process Your name, surname, telephone number and email address;
- to identify You and provide You with precise information about Your requested question when You call an SB Company, the SB Company processes personal identification data, contact data, other additional information that may help identify You;
- to prevent fraud, identify and investigate potential fraud through the monitoring, review, assessment and remediation of payment transactions, including payment card transactions. For this purpose, SB Companies process personal identity data, contact data, identification data in SB Companies' self-service, data on Your transactions, payment transaction data, data on behavioural habits, preferences, or any other necessary data;
- for fraud prevention purposes, to send fraud alerts to SB Clients. For this purpose SB Companies process Your contact details;
- to manage debts according to concluded contracts (agreements), enforce debt collection and/or transfer/sell a claim on Your debt. For this purpose, SB Companies process personal identification data, contact data, data about Your transactions and data about Your financial situation;
- for bringing, pursuing and defending legal claims against SB Companies, handling disputes and claims in legal proceedings. For this purpose, SB Companies process personal identity data, contact data, data about Your transactions, payment data, data about Your financial situation and other data that may be necessary to protect and defend the rights and interests of SB Companies;
- to ensure the safety of the health, life and property of SB Companies' employees, SB Companies' Clients and other Data Subjects, as well as to ensure public order, to carry out video surveillance. For this purpose, SB Companies keep video recordings of Your image (premises and areas subject to video surveillance are marked with special information notices);
- to carry out internal credit and risk assessment in order to determine what services and under what conditions can be offered to the Client, to make decisions, to monitor the loan portfolio, SB Companies process personal identity data, data on Your transactions, depending on the services provided to You by the SB Companies, data on Your financial situation, data that are necessary for the Bank and SBL to assess Your solvency, creditworthiness, and the risk of fulfilling obligations;
- to enter into and perform contracts and business relationships with SB's corporate partners, intermediaries or other legal entities. For this purpose, SB Companies may process the personal identity and contact details of legal entity representatives and beneficiaries;
- to maintain, develop, evaluate and improve the operations and Services of SB Companies through Client data analysis and statistics. For this purpose, SB Companies may process personal identity data, contact data, revenue, products available, and activity in using the Services;
- to ensure information security, improve, develop and maintain SB Companies websites, internet bank, mobile app, technical systems and IT infrastructure. For this purpose, SB Companies process data on behavioural habits, preferences, satisfaction with the Services, identification data in SB Companies' self-services and online bank;
- to communicate with You in the public space (on SB's social media accounts). For this purpose, SB Companies process Your account name, profile picture, information about communication on SB Companies' accounts (clicks (reactions) likes, follow, share, comment, sent/received messages), collected consents to participate in organised promotions/competitions, and this data is obtained directly from You (on Your social network account) when You communicate with us (via the social network tools). Personal data provided on social networks is processed jointly with the social network operator (e.g. Facebook, YouTube, LinkedIn and/or Instagram platform), so we suggest that You consult the privacy policies of the specific social network operator.
Under the conditions of the applicable law, one or more of the above legal substantiations may apply to the processing of the same Personal Data about You.
6. Data sources
We receive Personal Data directly from You, but depending on the Services provided or requested, we may also receive data from external data sources such as:
- Registers managed by the State Enterprise Centre of Registers (e.g. Population Register, Register of Legal Entities, Securities Register, Real Estate Register, etc.);
- from state bodies and institutions, other persons exercising functions conferred on them by law, supervisory authorities, tax authorities, bailiffs, notaries, courts, other law enforcement authorities (e.g. Bank of Lithuania, Informatics and Communications Department; State Social Insurance Fund Board; State Patients' Fund; National Paying Agency; Lithuanian State Science and Study Fund; State Enterprise Regitra; State Tax Inspectorate; State Enterprise Lithuanian Agricultural Advisory Service, State Data Agency, municipalities, etc.);
- from other banks and financial institutions, payment service provider institutions and organisations, including the Depositary, Nasdaq Vilnius Stock Exchange, financial services intermediaries, the Central Securities Depository, third parties involved in the execution, settlement and reporting cycle of trading in investment instruments;
- Personal Data on financial commitments and their fulfilment, and debts of persons acting as intermediaries for financial institutions (UAB "Creditinfo Lietuva" and UAB "Scorify");
- healthcare institutions or other insurance companies if You use the services provided by SB insurance;
- from natural or legal persons who provide services to Us, such as call handling, fraud prevention, remote identification, debt collection, financial counselling, insurance brokerage, contract administration, etc;
- our Clients, when they provide Your Personal Data as spouses, children, other persons related by family or affinity, guarantors, collateral providers, etc;
- legal persons, where You are an agent, employee, founder, shareholder, participant, beneficiary, governing body, etc. of those legal persons;
- when business sellers or their advisers decide to buy, merge or otherwise restructure SB Companies or parts of their businesses;
- From legal entities belonging to the SB Group;
- Facebook, Instagram, YouTube, Linkedln and/or other social network administrators.
Please note! The list of external data sources is not exhaustive, depending on the specifics of our activities and services, we may obtain data from other sources.
7. Data recipients
SB Companies may disclose information, or part of it, about You to other data recipients where permitted by law and for the reasons set out in Section 5 of this Privacy Policy.
Here is a list of the categories of recipients who may receive Personal Data in certain cases:
- Legal entities belonging to the SB Group;
- public bodies and authorities, other persons exercising functions conferred on them by law, such as supervisory authorities, tax administrations, law enforcement authorities, bailiffs, notaries, courts, out-of-court dispute resolution bodies (e.g. State Tax Inspectorate, State Social Insurance Fund Board, Financial Crimes Investigation Service, Competition Council, etc.);
- The Bank of Lithuania, the European Central Bank, correspondent banks or other intermediaries (e.g. clearing houses, settlement intermediaries, brokerage firms, collective investment undertakings, management companies providing investment services, etc.) that participate in and/or are involved in the processing of payment operations executed in payment or securities settlement systems;
- legal entities that act as intermediaries for financial institutions in obtaining Personal Data on financial commitments and their fulfilment and indebtedness (such as UAB "Creditinfo Lietuva" and UAB "Scorify");
- natural or legal persons taking over rights and obligations under contracts, persons administering insolvency proceedings;
- financial and payment institutions or other payment service providers
- insurance companies, insurance intermediaries, reinsurers;
- healthcare institutions if You use the services of SB Insurance;
- persons providing financial and legal advice, audits of SB Companies or other services;
- consumer credit intermediaries if You use SB leasing services;
- natural or legal persons who guarantee the proper performance of obligations to the SB Group, such as guarantors, warrantors, collateral providers;
- business sellers or their authorised advisers (in the event of a decision to buy, merge or otherwise restructure SB Companies or parts of their business);
- other legal persons involved in the provision of services, such as postal services, contract drafting and administration, debt collection, mediation, cooperation, services quality assessment, market research, promotion organization, remote identification, fraud prevention, IT implementation, maintenance, administration, archiving, printing, technical experts, etc.
SB Companies shall not disclose Personal Data beyond what is necessary for the specific purpose of processing Personal Data. Recipients may process Personal Data in their capacity as Data Processors and/or Data Controllers.
8. Transfer of information about You outside the European Economic Area
In most cases, Your Personal Data is processed in Lithuania and only in specific cases is transferred within the territory of the European Union and the European Economic Area (usually when the external service provider hired by SB Companies is established in another country). However, where necessary for the provision of certain services, data may be transferred and processed outside the aforementioned territories (e.g. in the context of debt collection processes), subject to an adequate level of protection of Personal Data where there is a lawful basis for the transfer of the Personal Data and at least one of the following conditions:
- the non-EU/EEA country in which the Data Recipient is located ensures an adequate level of protection of Personal Data as determined by the European Commission;
- The Data Controller or Data Processor implements appropriate data security measures, such as, for example, the transfer of Personal Data is carried out in accordance with a contract containing standard terms and conditions approved by the European Commission or other standard terms and conditions approved in accordance with the established procedure, an approved code of conduct, or a certificate has been issued to the recipient of the Data;
- provisions allowing derogation apply, for example, where You have expressly consented to the transfer of Personal Data, the transfer of Personal Data is necessary for the performance of a contract concluded with You, or the transfer of Personal Data is necessary for the exercise or defence of legal claims or for important reasons of public interest.
9. Time limits for keeping information about You
We keep Personal Data for no longer than is necessary to achieve the purposes of processing the Personal Data or for such period as may be prescribed/allowed by law, for example:
Storing of Business relationship information:
- We process and store Your Personal Data collected in the course of providing the Services for as long as You use the SB Companies Services and for a period of 10 (ten) years after You stop using the Services;
- SB leasing and the Bank shall process Your Personal Data for 30 (thirty) months if the provision of the financial service is refused and/or if a home loan or consumer credit agreement is not concluded for other reasons (e.g. after Your creditworthiness assessment);
- In the case of life insurance, the Personal Data of the persons who have received an offer of insurance are kept for 5 (five) years after the offer has been made, if no insurance contract has been concluded after the offer. In the absence of an insurance contract, the health data provided will be kept for 90 (ninety) calendar days;
- where the Personal Data is necessary for the purpose of preventing money laundering and terrorist financing - 10 (ten) years from the end of the business relationship.
Information collected for direct marketing purposes is stored:
- for as long as any contract You have with any SB Company is in force, or for 5 (five) years from the date of giving consent to direct marketing, whichever is longer, unless You withdraw Your consent earlier.
Telephone records are kept:
- for the purpose of ensuring the services provided - 5 (five) years from the date of their recording;
- for the purpose of securing investment services rendered, for a period of 10 (ten) years from the date of their recording (from the date of placing the order);
- SB leasing - for the purpose of ensuring the quality of service to Data Subjects - 6 months after their recording.
Video recordings are stored:
- if the surveillance is carried out in the premises or territories of the SB Companies, the video recordings shall be kept for up to 40 (forty) calendar days from the date of the recording;
- 40 calendar days if the video is taken during the provision of the Services (to identify or consult You remotely).
Consultation requests are stored:
- until the enquiry has been processed, but for a maximum period of 6 (six) months, except for enquiries relating to pensions and investment funds and life insurance, which shall be kept for a maximum period of 2 (two) years from the date of enquiry.
Please note! Personal data may be retained for longer in the event of a dispute with You, legal proceedings or pre-trial investigation. In this case, Personal Data may be kept for as long as the dispute, investigation or legal proceedings are ongoing.
10. Security of Personal Data
In order to protect Your Personal Data from unauthorised access, use or disclosure, we use a variety of organisational and technical security measures to ensure its security. These include firewalls, high-security data encryption methods and secure equipment, access control and rights restriction, "need-to-know" principle application (we only allow processing of Personal Data by employees who need it to perform their tasks and are committed to ensuring the confidentiality of the data), ongoing training of employees, and careful selection of Service Providers. By signing an Agreement, Service Providers undertake to comply with the requirements of the applicable laws, the data protection principles and the guidelines for the processing of Personal Data set out by SB Companies. However, the security of information transmitted by email or mobile phone may sometimes be compromised for reasons beyond the control of SB Companies, so You should take care when submitting confidential information to us outside the electronic systems used by SB Companies.
For more information on the possible frauds and how to avoid them, please visit Our website at: https://www.sb.lt/lt/apie/naudinga/sukciavimo-budai-ir-kaip-ju-isvengti.
11. Your rights regarding the processing of Personal Data
If Your Personal Data is processed by SB Companies, You have the right to:
- request access to Personal Data processed by SB Companies;
- request the rectification of inaccurate or incomplete Personal Data;
- require the restriction of the processing of excessive, inaccurate or unlawfully processed Personal Data in SB Companies;
- request the erasure of Personal Data that are excessive and/or unlawfully processed ("Right to be forgotten");
- object to the processing of Personal Data concerning You by SB Companies, where the processing is carried out on the basis of legitimate interest;
- object to a decision based solely on automated processing, including profiling, which may lead to legal consequences for You or similarly significantly affect You. Where an automated decision is applied and You disagree with it, You have the right to request a review and evaluation of that decision by a member of our staff.
- withdraw Your consent at any time where processing is based on Your consent, e.g. for direct marketing. Withdrawal of consent shall not affect the lawfulness of the processing prior to the withdrawal of consent;
- receive the Personal Data relating to You that You have provided to the Data Controller
in a structured, commonly used and computer-readable format and to request the transfer of that data to another controller ("right to data portability"); - lodge a complaint with the State Data Protection Inspectorate (see. State Data Protection Inspectorate (lrv.lt))if You believe that Your Personal Data has been processed in breach of the GDPR and other Personal Data protection legislation, but we recommend that You contact us first and we will try to resolve all of Your requests together with You.
12. Information on how You can exercise Your rights as set out above
You may exercise Your rights by submitting a written request to SB Companies (i.e. to each of the SB Companies at the contacts specified in Section 3 "Data Controller" of this Privacy Policy) in the following ways:
- Visit Your nearest Client service point. You will need to prove Your identity by presenting a valid identity document to the employee at the time of application;
- By post to the addresses indicated by the SB Companies, enclosing a copy of a valid identity document, certified in accordance with the procedure laid down by law.
- By sending a request by email to the contacts listed in Section 3 of the Privacy Policy. This request must be authenticated by electronic means of communication that allow the person to be properly identified (e.g. by mobile signature, qualified electronic signature, etc.);
- By sending a request by logging into the Bank's Internet Bank.
In order for us to assess Your request and provide You with a response, we must identify You in one of the ways set out above. This is done for the security of Your data, to ensure that Personal Data is not disclosed to any person who is not entitled to receive it. We may also contact You to request additional information to help us identify You and/or implement Your request (e.g. to clarify information related to Your request, etc.).
13. Deadlines for responding to Your requests
SB Companies will provide, no later than 1 month after receipt of Your request, information on the action they have taken in response to Your request for the exercise of the data subject's rights, or the reasons for not taking any action. The time limit for providing the requested information may be extended by a further 2 months if necessary, depending on the complexity of the requests, the volume of data processed and the number of services provided.
Please note! SB Companies may refuse to process a request received from You for the exercise of the data subject's rights, or may charge an appropriate fee if the request is manifestly unfounded or disproportionate, in particular due to its repetitive nature, as well as in other cases provided for by the Data protection legislation in effect.
14. Changes and current version of the Privacy Policy
This version of the Privacy Policy is effective as of 1 December 2023.
This Privacy Policy replaces the Personal Data Protection Rules of AB "Šiaulių bankas" in force until 1 December 2023, the Information for Consumer Credit Recipients of UAB "SB lizingas" on the collection, use and storage of information about me, the Personal Data Protection Policy, and the Personal Data Processing Rules of life insurance UAB "SB draudimas". All references to previous SB Company rules and/or policies are to this Privacy Policy.
Please note that SB Companies reserve the right to amend this Privacy Policy in the future to reflect changes in legislation and business practices. You will be informed of the changes on the website www.sb.lt and/or by private messages. However, we encourage You to review this Privacy Policy regularly if You have any questions about the processing of Personal Data by SB Companies.
The latest version of the Privacy Policy is also available at SB Companies Client service centres and SB leasing consumer credit intermediaries.
The Privacy Policy is available in Lithuanian and has been translated into English. In case of any disputes or claims regarding the interpretation of the language of the text, the text of the Privacy Policy in the Lithuanian language shall prevail.