PRIVACY POLICY
This Privacy Policy (hereinafter – the Policy) sets out and explains how we process your personal data.
Your personal data controller is UAB “SPA-ABC”, legal entity code 306968747, which you can contact by phone at +370 610 29617, by email at uab.spa.abc@gmail.com, or in writing at Gamyklos g. 52, Mažeikiai (hereinafter – the Data Controller or We, Us, Our).
The Data Controller is the operator of the website https://www.spa-abc.lt/ (hereinafter – the Website).
I. GENERAL PROVISIONS
This Policy applies to all persons visiting the Website, and the conditions set out herein apply whenever you purchase our goods or services, regardless of the device you use (computer, mobile phone, tablet, etc.).
By purchasing our goods and services or continuing to browse the Website, you confirm that you have read and understood this Policy, including the purposes, methods, and procedures of processing your personal data.
When processing your personal data, we ensure the implementation of the following fundamental principles:
3.1. We process personal data lawfully, fairly, and transparently (lawfulness, fairness, and transparency principle);
3.2. We collect personal data for specific, explicit, and legitimate purposes and do not process them in ways incompatible with those purposes;
3.3. Further processing for archiving in the public interest, scientific or historical research, or statistical purposes is not considered incompatible with the initial purposes (purpose limitation principle);
3.4. Personal data are adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed (data minimization principle);
3.5. We make every effort to ensure that personal data are accurate and, where necessary, kept up to date within a reasonable time after a change;
3.6. We take all reasonable steps to ensure that inaccurate personal data, having regard to the purposes for which they are processed, are erased or rectified without delay (accuracy principle);
3.7. Personal data are kept in a form that permits identification of the data subject for no longer than necessary for the purposes for which the personal data are processed;
3.8. Personal data may be stored for longer periods if processed solely for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes, provided that appropriate technical and organizational measures are implemented to safeguard the rights and freedoms of the data subject (storage limitation principle);
3.9. Personal data are processed in a manner that ensures appropriate security, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage (integrity and confidentiality principle);
3.10. We are responsible for and must be able to demonstrate compliance with the above principles (accountability principle).
This Policy has been prepared in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (the General Data Protection Regulation – GDPR), the Law on the Legal Protection of Personal Data of the Republic of Lithuania, and other applicable legal acts of the European Union and the Republic of Lithuania.
II. DEFINITIONS
The terms used in this Policy are defined as follows:
5.1. Personal data – any information relating to an identified or identifiable natural person;
5.2. Data processing – any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, sorting, organizing, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction;
5.3. Cookie – a small text file stored by the Website [https://www.spa-abc.lt/] on your end device;
5.4. End device – any device used to access the Website, such as a computer, mobile phone, or tablet;
5.5. Other terms are used as defined in the General Data Protection Regulation (GDPR), the Law on the Legal Protection of Personal Data of the Republic of Lithuania, and other applicable legal acts regulating personal data protection and processing.
III. PURPOSES AND LEGAL GROUNDS FOR PROCESSING PERSONAL DATA
We process your personal data for the following purposes:
6.1. To create your user account on the Website;
6.2. To deliver your orders and manage product returns;
6.3. To send you news, special offers, and general information about our goods and services;
6.4. To respond to your inquiries;
6.5. To conduct internal data analysis, identifying Website usage trends and the effectiveness of advertising campaigns.
We process your personal data on the following legal grounds:
7.1. Based on your consent (Article 6(1)(a) of the GDPR);
7.2. For the performance of a contract (Article 6(1)(b) of the GDPR);
7.3. For the purposes of our legitimate interests (Article 6(1)(f) of the GDPR).
IV. METHODS OF PROCESSING PERSONAL DATA
We process your personal data on the Website in the following ways:
8.1. When you fill in the registration form on the [https://www.spa-abc.lt/lt/mano-paskyra] section;
8.2. When you place orders for goods and services on the [https://www.spa-abc.lt/callback/checkout] section;
8.3. When you subscribe to our newsletters;
8.4. When you submit an inquiry via the dedicated form in the [https://www.spa-abc.lt/lt/kontaktai] section;
8.5. When cookies used on the Website are stored on your end device.
V. REGISTRATION ON THE WEBSITE, PLACING ORDERS, AND MANAGING RETURNS
If you wish to order goods and services from the Website, you may do so either by creating a user account in advance or by placing an order without prior registration. Please note that after placing an order, your account will be created automatically.
You may modify, update, or delete your user account at any time. To delete your account, you must contact us in writing via email at uab.spa.abc@gmail.com.
To create a user account, you must provide your first name, last name, email address, phone number, and password. When placing an order, you must also provide your parcel terminal address (unless you choose to collect the goods in person).
If you place an order without creating an account, you must still provide your first name, last name, phone number, email address, and parcel terminal address (unless choosing local pickup).
Payments for goods and services are processed via Stripe and Paysera platforms. Through these platforms, we may have access to your bank account number, which is necessary for issuing refunds if requested.
The personal data you provide in the registration form and in your order will be processed only to the extent necessary to properly fulfill and deliver the services related to your order.
We process this personal data on the basis of a contract concluded between you and us.
Your personal data provided during registration and ordering is stored in the Dashboard data center.
VI. SUBMITTING INQUIRIES ON THE WEBSITE
If you wish to submit an inquiry regarding the assortment of goods or services or for any other matter of interest, you can do so using the dedicated inquiry form on the Website in the following section:
[https://www.spa-abc.lt/lt/kontaktai].To submit an inquiry, you are required to provide us with your first name, last name, email address, and phone number.
We process this personal data based on our legitimate interest, i.e., to respond to your inquiries as quickly and efficiently as possible and to provide the appropriate consultation regarding our products and services.
Once a response is sent to your inquiry via the email address you provided, your personal data is stored for 10 years, after which it is automatically deleted.
The personal data you submit in the inquiry form is stored in the Dashboard data center.
VII. COOKIES USED ON THE WEBSITE
When using cookies, we process the following personal data:
23.1. The type of browser, operating system, and device used;
23.2. Browsing history;
23.3. The IP (Internet Protocol) address assigned to your device;
23.4. The number of visits to the Website;
23.5. The duration of browsing the Website;
23.6. The sections of the Website viewed;
23.7. Other information regarding your activity on the Website.We use cookies for the following purposes:
24.1. To ensure the functionality of the Website;
24.2. To improve and develop the Website to meet your browsing needs;
24.3. To implement new functions that facilitate the use of the Website, the search of information, and improve accessibility for a wider audience;
24.4. To analyze user behavior while browsing the Website;
24.5. To offer you products that match your browsing behavior and needs;
24.6. To link the Website with social networks such as Facebook and Instagram;
24.7. To collect statistical data on how the Website is used.The Website uses the following categories of cookies:
25.1. Strictly necessary (essential) cookies – ensure the operation of the Website and enable the use of all its functions. These cookies collect general information about users’ use of the Website;
25.2. Functional cookies – help recognize and remember returning users, the sections visited, functions used, changes made, and other choices made on the Website. When you return, the site will reflect your prior settings unless you manually delete cookies or they expire;
25.3. Analytical cookies – allow us to recognize and count users, track which sections they use, and collect other data to improve the Website and implement new features. They also help identify personalized marketing offers;
25.4. Marketing or advertising cookies – used to offer advertisements and promotions tailored to your browsing behavior and preferences on other websites.The Website also uses trackers and digital fingerprinting – advanced technologies that work without cookies.
Each time a user visits a specific Website element, a 1-pixel image is loaded to notify the server that a specific user with a particular IP address visited that element. This data is stored on the server. Digital fingerprinting uses device-specific information to generate unique IDs that allow the user to be recognized upon returning.
Technologies such as web beacons, uXDT, and ultrasonic tracking work by emitting ultrasonic signals when visiting the Website. These signals, inaudible to humans, can be detected by other smart devices running certain apps simultaneously.
The Website is integrated with Facebook and Instagram, where we publish information about our activities. Cookies used by these platforms provide us with aggregated statistics and insights into how visitors interact with the Website and our content.
Cookies are used based on your consent. Upon first visiting the Website, you can agree to the use of all cookies in the pop-up window. If you do not want to consent to all cookies, you can adjust your preferences in the cookie settings panel.
Strictly necessary cookies are stored regardless of your consent, as the Website would not function properly without them. If you do not consent to other cookies, your preferences will not be saved during future visits.The Website uses Google Analytics cookies. More information about data transfer to Google can be found here:
https://business.safety.google/adsdatatransfers/?sjid=1218907052053697014-EUYou may also delete cookies from your browser at any time. The procedure depends on the browser used. For example:
Internet Explorer:
How to delete cookie files in Internet ExplorerSafari:
Delete cookies in SafariGoogle Chrome:
Delete cookies in ChromeMicrosoft Edge:
Manage cookies in Edge
More information about cookies and how to manage or delete them can be found at
www.allaboutcookies.org and in your browser’s help section.You can also download the Google Analytics opt-out browser add-on, which is compatible with Google Chrome, Safari, Firefox, and Microsoft Edge. It prevents data from being sent to Google Analytics.
The personal data we process is not disclosed to third parties, except in cases where disclosure is required under the laws of the Republic of Lithuania or necessary for fulfilling contractual obligations.
Categories of data recipients (the list is not exhaustive):
36.1. Courier service providers;
36.2. The EveryPay payment platform (LHV Group);
36.3. Data processors contracted by us (e.g., IT service providers, accounting service providers, etc.);
36.4. Courts, law enforcement, and other state institutions;
36.5. Google.
Data processors are authorized to process personal data only in accordance with our instructions and only to the extent necessary. When engaging data processors, we take all necessary measures to ensure that they have implemented appropriate organizational and technical measures to protect personal data.
IX. YOUR RIGHTS
By providing your personal data when placing orders on the Website, creating a user account, submitting inquiries, or consenting to the use of cookies on your device, you acquire the following rights:
40.1. The right to access your personal data being processed;
40.2. The right to request the rectification, supplementation, or deletion of your personal data;
40.3. The right to restrict the processing of your personal data;
40.4. The right to receive the personal data concerning you, which you have provided to us, in a structured, commonly used, and machine-readable format, and the right to transmit those data to another data controller (right to data portability);
40.5. The right to withdraw your consent at any time;
40.6. The right to object to the processing of your personal data;
40.7. The right to lodge a complaint with the State Data Protection Inspectorate (address: L. Sapiegos g. 17, Vilnius, or by email: ada@ada.lt) if you believe that our processing of your personal data does not comply with the Regulation, the Law on Legal Protection of Personal Data of the Republic of Lithuania, or other legal acts regulating personal data protection, or otherwise violates your rights and freedoms.
To exercise your rights, submit requests, complaints, or demands to us in writing via email at: uab.spa.abc@gmail.com.
If there is any non-compliance with the Regulation, the Law on Legal Protection of Personal Data, or other applicable Lithuanian legislation, please contact us. If we are unable to assist or if our response is unsatisfactory, you may contact the State Data Protection Inspectorate under the procedure established by law.
X. FINAL PROVISIONS
We reserve the right to update or amend this Privacy Policy at any time.
Such updated or amended Policy shall take effect from the date it is published on the Website.
We recommend that you periodically review this Policy to ensure that you are aware of and satisfied with the current version of the Privacy Policy.
For any questions related to this Policy and/or data protection in general, you may contact us in writing via email at: uab.spa.abc@gmail.com.