Privacy policy

GENERAL INFORMATION

UAB „Vakarų sportas“, legal entity code 306963497, registered office address Statybininkų g. 5, Gargždai, LT-96155 Klaipėdos r. (hereinafter – the Data Controller), by this privacy policy (hereinafter – the Privacy Policy) establishes the conditions for the processing of personal data when using the sports clubs and premises managed by the Data Controller at: Statybininkų g. 5, Gargždai, LT-96155 Klaipėdos r. and when using the website icongym.lt (hereinafter – the Website).

The conditions set out in the Privacy Policy apply each time you visit the website, regardless of which device (computer, mobile phone, tablet, television or other) you use.

By providing their personal data (including data provided directly or indirectly when visiting the website and using its services), the Data Subject agrees and does not object that the Data Controller manages and processes such data for the purposes and in the manner set out in this Privacy Policy, in the Data Subject’s consent, and as provided for by law.

Persons under 18 years of age may not provide any personal data through the Data Controller’s Website. If you are a person under 18 years of age, you must obtain the consent of your parents or other legal guardians before providing personal information.

Personal data means any information relating to an identified or identifiable natural person (Data Subject); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name and surname, a personal identification number, location data and an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

Representative means a person representing Clients, the Data Controller’s Partners, Service Providers, Suppliers, whether natural or legal persons.

Enquiring Person means a natural person or Representative interested in the goods sold and/or services provided by the Data Controller, or wishing to contact the Data Controller on other matters.

Data Subject – for the purposes of this Privacy Policy, means a Representative, an Enquiring Person, a Client, a Candidate, a Partner, a Service Provider, a Supplier, Telephone Callers, or any other natural person whose personal data are processed by the Data Controller.

Data Subject’s consent means any freely given, specific and unambiguous indication of the duly informed data subject’s wishes by which they, by a statement or by a clear affirmative action, signify agreement to the processing of personal data relating to them.

Candidate means a person participating or intending to participate in a personnel selection process carried out by the Data Controller.

Client means a natural person or Representative purchasing goods or services from the Data Controller or who has concluded a contract with the Data Controller for the sale of goods or the provision of services.

Partner means a natural or legal person cooperating with the Data Controller, or who has concluded a cooperation agreement with the Data Controller (e.g. for the sale of goods).

Service Provider means a natural or legal person able to offer or offering goods, services or works to the Data Controller and cooperating with it, or who has concluded a contract with the Data Controller for the sale of goods, services or works.

Telephone Caller means a person calling the publicly announced contact telephone number regarding the sale of the Data Controller’s goods, the provision of services and/or other matters.

Supplier means a natural or legal person supplying goods to the Data Controller.

Direct marketing means an activity intended to offer goods or services to persons by post, telephone or other direct means and/or to seek their opinion on the goods or services offered.

Processing of personal data means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

The Data Controller will collect personal data in compliance with the requirements of applicable European Union and Republic of Lithuania legislation and the instructions of supervisory authorities. All reasonable technical and administrative measures are applied to protect the data collected about Data Subjects from loss, unauthorised use and alteration.

This Privacy Policy has been drawn up in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter – the General Data Protection Regulation), the Law on Legal Protection of Personal Data of the Republic of Lithuania (Lietuvos Respublikos asmens duomenų teisinės apsaugos įstatymas), and other legal acts of the European Union and the Republic of Lithuania. The terms used in the Privacy Policy shall be understood as they are defined in the General Data Protection Regulation and the Law on Legal Protection of Personal Data of the Republic of Lithuania.

WHAT INFORMATION DO WE COLLECT ABOUT YOU?

Information you provide directly.

Information on how you use our Website.

If you visit our Website, we also collect information that reveals the characteristics of your use of the services we provide, or visit statistics generated automatically. Read more about this in the “Cookie Policy”.

Information from third-party sources

We may receive information about you from public and commercial sources (to the extent permitted by applicable law) and link it with other information we receive from you or about you. We may also receive information about you from third-party social networking services when you connect to them, for example, via accounts on the “Facebook” network.

Other information we collect

We may also collect other information about you, your device or your use of the content of our website with your consent.

You may choose not to provide us with certain information, but in that case you may not be permitted to use the service we offer.

PROCESSING OF PERSONAL DATA FOR THE PURPOSES OF SUBMITTING FEEDBACK, CONSULTATION, AND HANDLING ENQUIRIES

Processing of personal data of Enquiring Persons, including Telephone Callers, who contact the Data Controller regarding the sale of goods, the provision of services and/or other matters. The Data Controller processes the following personal data of Enquiring Persons, including Telephone Callers:

  • Name;
  • Surname;
  • Telephone number;
  • Email address;
  • Position held;
  • Workplace.
  • The personal data of Enquiring Persons are not transferred to third parties.

Personal data for the purposes of consultation and submitting an enquiry are processed on the basis of consent expressed by providing one’s data (point (a) of Article 6(1) of the General Data Protection Regulation).

PROCESSING OF PERSONAL DATA FOR THE PURPOSE OF SELLING GOODS AND PROVIDING SERVICES

Processing of Clients’ personal data. The Data Controller processes the following personal data of Clients or Representatives:

  • Name;
  • Surname;
  • Personal identification number (where a contract for the provision of services is concluded);
  • Date of birth (where a contract for the provision of services is concluded for a minor);
  • Power of attorney (if applicable);
  • Represented person (relationship with the represented person);
  • Position held (if purchasing on behalf of an employer);
  • Workplace (if purchasing on behalf of an employer);
  • Telephone number;
  • Email address;
  • Address;
  • Taxpayer identification number;
  • Payment amount (in the case of electronic commerce – payment order data, invoices);Other information related to the goods purchased or the service provided.

The data are obtained directly from Clients or their Representatives, in the performance of the contract with the Client, and/or from other third parties connected with the Data Subject.

We undertake not to transfer your personal data to any unrelated third parties, except in the following cases:

  • If the Client has consented to the disclosure of personal data;
  • In fulfilling our obligations as a seller of goods or provider of services (e.g., data may be transferred to companies providing goods delivery (courier), logistics, archiving, audit, legal and financial services, to Partners, Service Providers, participants and/or parties related to national, European and international payment systems, e.g., SWIFT);
  • In pursuing the Data Controller’s legitimate interests (e.g. in the case of debt recovery);
  • To authorised institutions, in accordance with the procedure established by the legal acts of the Republic of Lithuania.

The Data Controller may provide the personal data of Clients and other Data Subjects to Data Processors not specified in this Policy, who provide services (perform works) for the Data Controller and process the personal data of Clients and Data Subjects on behalf of the Data Controller. Data Processors have the right to process personal data only in accordance with the Data Controller’s instructions and only to the extent necessary for the proper performance of the obligations set out in the contract. When engaging data processors, the Data Controller takes all necessary measures to ensure that the Data Processors have implemented appropriate organisational and technical security measures and maintain the confidentiality of personal data.

Personal data are processed on the basis of the Data Subject’s consent and/or the performance of a contract with the Data Subject (points (a) and (b) of Article 6(1) of the General Data Protection Regulation).

PROCESSING OF PERSONAL DATA FOR THE PURPOSE OF DIRECT MARKETING

The Data Controller seeks to share with newsletter recipients only relevant news about services, discounts, offers, competitions and other useful information. It implements this in accordance with this Privacy Policy.

The Data Controller processes personal data for the purpose of direct marketing only with the Data Subject’s explicitly expressed consent. The following personal data of Clients and other Data Subjects are processed for the purpose of direct marketing:

  • Name;
  • Surname;
  • Email address.

After sending a newsletter, the Data Controller may collect statistical data on the Data Subject’s behaviour related to the use and content of the newsletter (for example, whether the newsletter was read, which links were opened by the Data Subject).

Personal data are obtained directly from Data Subjects. The Data Controller may transfer personal data only to third parties providing specialised services, in order to send emails and to tailor the nature of advertising ordered through advertising platforms. The personal data of Clients and other Data Subjects are processed on the basis of consent, expressed by providing one’s data and agreeing to the processing of personal data for the purpose of direct marketing (point (a) of Article 6(1) of the General Data Protection Regulation).

  • We inform you that the Data Subject has the right to object or to withdraw at any time their consent to the processing of their personal data for direct marketing purposes, including profiling to the extent that it is related to such direct marketing, without stating the reasons for the objection
  • By clicking the “unsubscribe from the newsletter” link at the end of the newsletter or on the website;
  • By writing to the email address info@icongym.lt

Withdrawal of consent does not affect the lawfulness of consent-based data processing carried out prior to the withdrawal of consent.

PROCESSING OF PERSONAL DATA FOR THE PURPOSES OF ENSURING THE SECURITY OF PERSONNEL AND CLIENTS AND THE PROTECTION OF PROPERTY (VIDEO SURVEILLANCE)

For the purposes of ensuring the security of personnel, Clients and other persons entering the video surveillance area, as well as the protection of property (video surveillance), the Data Controller processes the video data of its personnel and Clients and other persons entering the video surveillance area in order to ensure their safety and the safety of property.

We inform you that your video data are captured by the Data Controller’s video surveillance equipment when you visit the Data Controller’s territory around the buildings and in the premises located at Statybininkų g. 5, Gargždai, LT-96155 Klaipėdos r. Video data may be transferred only to law enforcement authorities in accordance with the procedure established by the legal acts of the Republic of Lithuania, and to insurance companies if an incident occurs which may be recognised as an insured event. Video data are transferred only to the extent related to the incident under investigation.

The Data Controller may provide the video data of personnel and Clients and other persons entering the video surveillance area to Data Processors not specified in this Policy, who provide services (perform works) for the Data Controller and process the video data of personnel and clients and other persons entering the video surveillance area on behalf of the Data Controller.

Personal data for the purpose of video surveillance are processed on the basis of the Data Controller’s legitimate interest (point (f) of Article 6(1) of the General Data Protection Regulation).

STORAGE OF PERSONAL DATA

Personal data are protected from loss, unauthorised use and alteration. We have implemented organisational and technical measures to protect all the information we collect for the purposes of providing our services. We remind you that, although we take appropriate steps to protect your information, no website, online transaction, computer system or wireless connection is completely secure.

The Data Controller applies different retention periods for personal data, in accordance with the requirements of legal acts and taking into account the purposes of the processing of personal data.

YOUR RIGHTS

A Data Subject whose data are processed in the Data Controller’s activities has the following rights:

  • The right to know (to be informed) about the processing of their data;
  • The right of access to their data and to how they are processed;
  • The right to rectify or, taking into account the purposes of the processing of personal data, to complete incomplete personal data;
  • The right to have personal data destroyed and the right “to be forgotten”, i.e. to have the processing of their data suspended (except for storage);
  • The right to restrict the processing of personal data where one of the legitimate grounds exists;
  • The right to data portability, where the Data Subject has provided their personal data to the Data Controller in a structured, commonly used and machine-readable format;
  • The right to object to the processing of personal data where such data are processed or intended to be processed for direct marketing purposes, including profiling to the extent that it is related to such direct marketing;
  • The right to lodge a complaint with the State Data Protection Inspectorate of the Republic of Lithuania (Valstybinė duomenų apsaugos inspekcija).

The Data Subject has the right to submit any request or instruction related to the processing of personal data to the Data Controller in writing in one of the following ways: by delivering it directly or by sending it by post to the address: UAB „Vakarų sportas“, legal entity code 306963497, registered office address Statybininkų g. 5, Gargždai, LT-96155 Klaipėdos r.; by email: info@icongym.lt

Upon receipt of such a request or instruction, the Data Controller shall, no later than within one month from the date of the request, provide a response and carry out the actions specified in the request or refuse to carry them out. Where necessary, the specified period may be extended by a further two months, taking into account the complexity and number of the requests. In such a case, within one month from the date of receipt of the request, the Data Controller shall inform the Data Subject of such an extension, together with the reasons for the delay.

The Data Controller may decline to enable data subjects to exercise the rights listed above, except for the objection to the processing of personal data by way of direct marketing, where, in the cases provided for by law, it is necessary to ensure the prevention, investigation and detection of criminal offences or breaches of official or professional ethics, as well as the protection of the rights and freedoms of the data subject or other persons.

THIRD-PARTY WEBSITES, SERVICES AND PRODUCTS ON OUR WEBSITES

The Data Controller’s website may contain third-party advertising banners and links to their websites and services which the Data Controller does not control, for example a link to the Data Controller’s Facebook profile. The Data Controller is not responsible for the security and privacy of information collected by third parties. You must read the privacy provisions applicable to the third-party websites and services you use.

If you have provided data about yourself via “Facebook”, we understand that you agree that we may contact you using the contact telephone number and email address provided and present offers of services.

COMPLAINTS

If you believe that your rights as a personal data subject are and/or may be violated, please contact us immediately with a complaint at the email address info@icongym.lt. We assure you that, immediately upon receipt of your complaint, we will contact you within a reasonable period and inform you of the progress of the investigation of the complaint, and subsequently of its outcome. If the results of the investigation do not satisfy you, please note that you may lodge a complaint with the supervisory authority – the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija) (contact details at www.ada.lt ).

LIABILITY

You are responsible for the confidentiality of your password and the data you provide, as well as for any actions (data transfer, orders placed, etc.) carried out on our Website and/or the App while logged in using your login details. You may not disclose your password to third parties. If a third party uses the services provided on our Website and/or the App after logging in to the Website and/or the App using your login details, we consider that it was you who logged in. If you lose your login details, you must inform us immediately by post, telephone, fax or email. You are responsible for ensuring that the data you provide to us are accurate, correct and complete. If the data you have provided change, you must inform us immediately by amending the relevant data in the registration form or, if the data are not specified in the registration form, by informing us by email. Under no circumstances shall we be liable for damage caused to you as a result of your having provided incorrect or incomplete personal data or having failed to inform us of changes to them.

CHANGES TO THE PRIVACY NOTICE

We may update or amend this Privacy Notice at any time. Such an updated or amended Privacy Notice will take effect upon its publication on our Website and/or the App. You should check it from time to time and make sure that you are satisfied with the current version of the Privacy Notice. When we update the Privacy Notice, we will inform you of changes we consider material by publishing them on the Website. If you access the Website after such a notice has been published, you agree to the new requirements set out in the update. You can check the “Update date” indicated at the bottom to find out when the Privacy Notice was last updated.

COOKIE POLICY

Cookies are items of information transferred from a website to your computer’s hard drive. They are small information files that allow websites to store and subsequently access information about a user’s browsing habits.

Cookies are used by most websites because they are one of the many tools that help tailor internet content to users’ needs. Cookies allow websites to provide services tailored to users’ needs (for example, by remembering login details, keeping purchases in the shopping cart, or displaying only content of interest to a specific user).

Most browsers are set to accept cookies automatically. Cookies do not allow access to, or the ability to copy, a terminal’s data storage device, such as a hard drive. The user may block cookies by changing their web browser settings, but this may reduce the functionality of the pages and is not recommended. The user may also delete cookies in their web browser at any time.

The cookies used on this website do not violate the privacy of the service user. For example, cookies are used for evaluation and research purposes to determine the type and extent of use of the website. Cookies may also be used in marketing based on user lists and remarketing. The purpose of such marketing is to provide information about relevant services to users who have visited the website previously.

The Company collects and processes personal data for the following purposes: contacting clients, marketing of products and services (including planned email marketing, online advertising and personal sales calls), collecting and handling feedback, providing requested information, and providing products and services requested or ordered from the Company.

In addition, the Company may share such contact data of yours and internet functions, such as website visits and email click-throughs, with channel partners for the purposes of sales and marketing of the Company’s products and services.

This translation is provided for convenience. In case of any discrepancy, the Lithuanian original prevails.

REGISTERED CLIENT

Sign in and exercise freely!

LOG IN

NEW CLIENT

Register and train without limits!

REGISTER