Sia 'Finansum'

Registration number: 50103723851

Tax number:

LV50103723851

Company adress:

Plūdu iela 10, Jūrmala, LV-2015

logo

finansum

Limited Liability Company 'Finansum'

Privacy Policy

General information

In accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), the Controller ensures a transparent and fair processing of personal data, which simultaneously complies with the regulatory enactments of the Republic of Latvia.

This Privacy Policy, hereinafter referred to as the Policy, describes the procedure under which Limited Liability Company 'Finansum', reg. No 50103723851, hereinafter referred to as the Controller, processes the data of natural persons.

The Controller of your Personal Data is Limited Liability Company 'Finansum', reg. No 50103723851, to whom you have submitted your Personal Data, whose Services you intend to use, or have used.

When processing data, the Controller complies with the following principles of personal data processing:

• Legitimacy;

• Good faith;

• Purpose limitations;

• Accuracy;

• Minimization;

• Integrity and confidentiality;

• Storage restrictions;

Definitions:

Processing: any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

Customer: a natural person who uses, has used, or has expressed a wish to use any services provided by the Controller or is related to them in any other way.

Personal Data: any information relating to an identified or identifiable natural person ('data subject'); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

Data Subject: an identified or identifiable natural person (Customers).

Service: any service provided by Limited Liability Company 'Finansum', reg. No 50103723851.

The legal basis for personal data processing is as follows:

• Application of a natural person (Customer) for the receipt of the Service and provision of the Service;

• Return of money to the Customer;

• Handling of Customer complaints;

• Compliance with regulatory enactments of the Republic of Latvia;

• Consent of the Data Subject (Customer);

• Contractual obligations with the Data Subject;

• Performance of commercial activities, provision of rental services to Data Subjects (Customers)

Legal (legitimate) grounds:

• Protection of the vital interests of the Data Subject or any other natural person: ensuring security on the premises of the Controller.

Purposes of personal data processing:

To identify the Customer and provide the appropriate Service, as well as the process of calculating and making payments, to communicate with the Customer about the provision of the Service and/or the performance of the contract on related issues (incl. also for sending invoices), in some cases also to ensure the recovery of unpaid payments, Personal Data of Data Subjects are processed for the following purposes:

• To take commercial activities, to provide vehicle rental services;

• To establish labor relations and manage human resources;

• Accounting;

• Marketing, Customer acquisition, and Customer data collection;

• Reporting, accounting, approvals, surveys;

• Service advertising;

• Sending commercial notifications;

• Customer payment administration;

• Protection of the Controller's legal interests;

• To provide security.

Categories of Personal Data: Personal Data processed by the Controller includes the following information

Identification data and, specifically: name, surname, personal identity number (national identification number), passport or ID card details, bank account details.

Contact details and, specifically: address of the place of residence or address for communication purposes, address of correspondence, telephone number (for example, landline and mobile), e-mail address, language of communication.

The Controller transfers the Customer's Personal Data to the following recipients of Personal Data, if this does not contradict the applicable laws and regulations:

• Parties related to the business activities of the Controller on the basis of the cooperation agreements concluded, including but not limited to data storage service providers, IT service providers, accounting service provider, banks, debt collection companies, etc., if there is a reasonable need;

• Law enforcement authorities or other third parties, if it is deemed necessary in accordance with applicable laws and regulations to protect the rights and interests of the Controller.

Scope and period of Personal Data processing, storage of Personal Data:

Personal Data is processed to the extent necessary and in accordance with the specified purposes (intentions) of Personal Data processing, in compliance with the requirements of the current laws and regulations of the Republic of Latvia.

The Controller will store Personal Data within the period specified in laws and regulations, as well as until the purposes of processing Personal Data has been achieved (Personal Data are necessary for the purpose for which they have been received) and until there are legal grounds for storing the data.

When assessing the duration of storage of Personal Data, the Controller takes into consideration the requirements of current regulatory enactments, aspects of performance of contractual obligations, instructions of the Customer (e.g., in case of consent), as well as the legitimate interests of the Controller. If the Customer's Personal Data is no longer needed for the specified purposes, the Controller will erase or destroy them.

Periods of storage of Personal Data:

• Personal Data necessary for the performance of contractual obligations are stored until the contract is executed and until other storage periods are met (see below);

• Personal Data that must be stored in order to comply with the requirements of the legislation – for periods specified in the relevant regulatory enactments, for example, the Accounting Law states that the supporting documents must be kept as long as they are necessary to establish the beginning of each economic transaction and track its progress, but not less than 5 years;

• Data to prove the fulfilment of the obligations of the Controller – for the general limitation period of the claim in accordance with the limitation periods for claims specified in regulatory enactments, namely, 10 years under the Civil Law, 3 years under the Commercial Law, and other periods, considering also the periods specified in the Civil Procedure Law for filing claims.

Periods for the storage of Personal Data are set out in the Controller's Personal Data Processing Register.

Cookie Policy

A cookie is a small text string (information) sent by a web server that is stored on the user's computer or other devices in the user's browser file directory.

This helps the site to remember the settings chosen by the Customer to browse the site, so that they no longer need to be re-entered each time, and to make it easier to browse the site (for example, the language used). Cookies (after saving the IP address) do not identify the user as a person, only recognize the user as a previous visitor to the site. Cookies also help the Controller to collect website attendance statistics and optimize marketing communication.

The Controller collects this information using an automatic Google Analytics tool that allows to see and analyze the pattern of visitors use of this website (this tool is provided by the US company Google Inc.).

Here is more information about how Google Analytics works and what information this tool allows to collect and analyze: https://support.google.com/analytics/answer/1012034?hl=lv&ref_topic=6157800

The Customer may disable (withdraw) data collected by Google Analytics at any time as described here: https://tools.google.com/dlpage/gaoptout/.

Three types of cookies are used:

1. Session cookies are temporary and disappear as soon as the website or browser is closed. Session cookies can be used to activate certain features and capabilities of the site.

2. Constant cookies do not disappear at the end of the session and remain in the memory of your computer or any other device. They can be used, for example, to identify the Customer as a unique visitor to the site, save a randomly generated number, adapt the content of the site to the needs of the Customer, update previously selected information and settings, or collect statistics.

3. Third-party cookies are used for advertising purposes, such as Google AdWords. They are used to customize advertising content, evaluate its effectiveness and optimize marketing communication.

After changing the browser settings, the Customer can erase the saved cookies at any time and prevent them from being stored on his or her computer or any other device. Learn how to do this by clicking on the link: Mozilla Firefox, Google Chrome, Internet Explorer.

The Controller's website (online store) may use cookies.

When visiting the Controller's website, the user is presented with a window with a notification about the use of cookies on the website. By closing this notification window, the user confirms that he or she has read the information about cookies and agrees using them. The use of cookies helps the Controller to record the number of visitors and collect statistics and information about the viewed Service. All this data is collected anonymously, meaning that the Controller cannot connect the data with an individual user or an authenticated user.

Privacy and data security:

The Controller's company uses appropriate technological and organizational measures to protect Personal Data.

The Controller's security procedures and internal rules of procedure comply with applicable external laws and regulations governing the protection of personal data.

The Controller's employees are trained and comply with confidentiality, security, and personal data protection requirements.

Access to Customers’ Personal Data is provided only to authorized employees of the Controller; in some cases – to cooperation partners of the Controller on the basis of concluded agreements.

The Controller will respond to any Customer objections regarding data processing and will take all steps to address Customer objections, if received.

Rights of Data Subjects:

In accordance with the current regulatory enactments governing the protection of personal data, Data Subjects have the following rights:

• The right to restrict the processing of Personal Data;

• The right to withdraw the consent to the processing of Personal Data;

• The right to access Personal Data;

• The right to rectify or erase Personal Data from the Controller's systems, unless the Controller has legal grounds to continue processing such Personal Data.

• If the Data Subject notifies the Controller of his or her wish to exercise any of these rights, the Controller will respect it and respond to such request within one month of receipt of the request.

The Data Subject has the right to contact the Controller in order to obtain information about the Personal Data held by the Controller regarding the Data Subject, to confirm or correct the Personal Data.

The Data Subject has the right to request the erasure of the personal data held by the Controller, unless this requirement contradicts the laws and regulations in force in the Republic of Latvia.

The Data Subject may make corrections to the submitted Personal Data at any time. In such case, it is necessary to contact the Controller by phone +371 29569626 or by sending a letter to the legal address of the Controller: Limited Liability Company "Finansum", reg. No 50103723851, Plūdu iela 10, Jūrmala, LV-2015, Latvia, or by sending an electronic letter to e-mail address: info@finansum.lv.

The Data Subject has the right to submit a complaint regarding the processing of Personal Data to the supervisory authority, namely, the Data State Inspectorate, contact information: 17 Elijas Street, Riga, LV-1050, phone: +371 67223131, e-mail: info@dvi.gov.lv.

Limited Liability Company ”Finansum" (the Controller) has the right at any time to unilaterally amend this Policy in accordance with the applicable laws and regulations by publishing the amendments and the current version of the Privacy Policy on the website www.finansum.lv.

This Privacy Policy has been updated and approved on 1 June 2023.

This Privacy Policy is applicable to all Customers of Limited Liability Company ”Finansum” (controller) and is available on the website www.finansum.lv.