PRIVACY POLICY
Privacy Notice
In this Privacy Notice, we, UAB FMĮ OSUM Securities, legal entity code 300153084,
registered office at A. Rotundo g. 5-102, Vilnius, Republic of Lithuania
(hereinafter – the “Company” or “we”), provide information on how we process your
personal data when you use our services. We are established and located in Lithuania, therefore this Privacy Policy is governed by the data protection law of the European
Union (“EU”) and Lithuania. If you reside outside the EU, we cannot
confirm that our collection and processing of personal data complies with your local
data protection laws.
1. How do we use your data?
This section provides information on:
- the purposes for which we process your data;
- how we use your personal data;
- the categories of data we process;
- the legal bases for data processing;
- data retention periods.
More detailed information is provided below.
1.1. Implementation of the “Know Your Customer” principle
Purpose. To implement the “Know Your Customer” principle and ensure compliance with legal requirements.
How we use your personal data. We process your personal data to identify you as a client, assess your risk profile, and fulfill anti-money laundering and terrorist financing prevention requirements.
Personal data processed.
When processing personal data of a natural person:
- name, surname;
- personal identification number or date of birth;
- identity document number;
- residential address;
- phone number;
- email address;
- bank account;
- country of residence;
- correspondence address;
- utility bill or other document indicating the person’s address;
- citizenship;
- information on whether the person is considered a beneficial owner;
- information on whether the person is married;
- information about the person’s regular sources of income;
- information on whether the person or other related persons have been or are considered politically exposed persons.
When processing data of a legal entity:
- name;
- legal entity code;
- registration date;
- registered address;
- phone number;
- email address;
- bank account;
- address of actual business operations;
- LEI code;
- name, surname, date of birth, citizenship, residential address, and position of the legal entity’s head;
- information about the legal entity’s regular sources of income and types of activities;
- data on legal entities within the client’s structure holding 25% or more of the legal entity’s shares;
- data on the legal entity’s beneficial owners;
- information on whether persons related to the legal entity have been or are considered politically exposed persons;
- information about the ownership structure of the legal entity.
Legal basis. Legal obligation (GDPR Article 6(1)(c)).
Data retention period.
According to Article 19(10) of the Law on Prevention of Money Laundering and Terrorist Financing of the Republic of Lithuania,
personal data is stored for 8 (eight) years from the end date of transactions or business relations with the client.
1.2. Prevention of Money Laundering and Terrorist Financing
Purpose. To prevent money laundering and terrorist financing.
How we use your personal data. We process your personal data to assess and monitor money laundering and terrorist financing risks, as well as to fulfill legal obligations.
Personal data processed.
When processing personal data of a natural person:
- name, surname;
- personal identification number;
- place of residence;
- citizenship;
- phone number;
- email address;
- average monthly income received;
- primary source of funds;
- ultimate beneficial owner of funds;
- identity document information;
- risk category assigned to the client and/or geographical region risk category;
- data obtained during client identity verification;
- account and/or contract documentation;
- correspondence related to business relations with the client;
- documents and data confirming a monetary operation or transaction, or other legally valid documents and data related to the execution of monetary operations or conclusion of transactions;
- IP address.
When processing data of a legal entity, additionally processed:
- legal entity name;
- legal entity code;
- registration date;
- registered office, country of residence;
- number of employees;
- duration of activity;
- name, surname, personal identification number (or date of birth), citizenship, country of residence of the director (representative), shareholders, beneficial owners;
- number of shares;
- names, codes, and countries of business partner companies.
Legal basis.
Legal obligation (GDPR Article 6(1)(c)).
Special categories of personal data are processed for reasons of substantial public interest (GDPR Article 9(2)(g)).
Data retention period.
According to Article 19(12) of the Law on Prevention of Money Laundering and Terrorist Financing of the Republic of Lithuania,
personal data is stored for 8 (eight) years from the end date of transactions or business relations with the client.
1.3. Identity Verification
Purpose. To establish and confirm your identity.
How we use your personal data. We process your personal data for identity verification and confirmation purposes when contracts are concluded or services are provided.
Personal data processed:
- name, surname;
- date of birth;
- gender;
- personal identification number;
- place of issue of identity document;
- type of identity document;
- identity document number;
- date of issue and validity date of identity document;
- information on whether the identity document has been lost or stolen and found;
- citizenship;
- person’s photograph;
- photograph of identity document;
- IP address;
- residential address;
- video recording.
Legal basis.
Legal obligation (GDPR Article 6(1)(c)).
Special categories of personal data are processed for reasons of substantial public interest (GDPR Article 9(2)(g)).
Data retention period.
According to Article 19(10) of the Law on Prevention of Money Laundering and Terrorist Financing of the Republic of Lithuania,
personal data is stored for 8 (eight) years from the end date of transactions or business relations with the client.
1.4. Ensuring Compliance with International Sanctions Requirements
Purpose. To ensure compliance with international sanctions requirements.
How we use your personal data. We conduct checks and monitor information related to international sanctions and reputational risk.
Personal data processed:
- information on whether you are included in sanctions lists;
- information about your participation in political activities;
- information about negative media coverage concerning you;
- information on whether you are included in lists of financial and other supervisory authorities, disciplinary bodies, and anti-corruption agencies.
Legal basis.
Legal obligation (GDPR Article 6(1)(c)).
Special categories of personal data are processed for reasons of substantial public interest (GDPR Article 9(2)(g)).
Data retention period. During the period of service provision.
1.5. Securities Account Management
Purpose. To professionally manage the accounts of all securities you have issued.
Personal data processed.
When processing personal data of a natural person:
- name, surname;
- personal identification number or date of birth;
- identity document number;
- residential address;
- phone number;
- email address;
- bank account details;
- representative’s name, surname, position, basis of representation.
When processing data of a legal entity:
- name;
- legal entity code;
- registration date;
- registered office address;
- phone number;
- email address;
- bank account details;
- representative’s name, surname, position, basis of representation.
Legal basis. Performance of a contract (GDPR Article 6(1)(b)).
Data retention period. 10 (ten) years from the termination of the contract.
1.6. Administration of Correspondence with Clients
Purpose. To respond to your inquiries and ensure quality communication.
Personal data processed:
- date;
- email address;
- other information provided in the letter.
Legal basis. Consent (GDPR Article 6(1)(a)).
Data retention period.
According to Article 19(11) of the Law on Prevention of Money Laundering and Terrorist Financing of the Republic of Lithuania,
personal data is stored for 5 (five) years from the end date of transactions or business relations with the client.
1.7. Implementation of International Cooperation Obligations for Automatic Exchange of Financial Account Information
Purpose. To process and provide your data to the State Tax Inspectorate to implement international cooperation obligations for the automatic exchange of financial account information.
Personal data processed.
When processing personal data of a natural person:
- name, surname;
- residential address;
- country code;
- date of birth;
- personal identification number;
- account and account balance;
- account holder’s MIN/TIN.
When processing data of a legal entity:
- name;
- registered office address;
- country code;
- legal entity code;
- account and account balance;
- account holder’s MIN/TIN.
Legal basis. Legal obligation (GDPR Article 6(1)(c)).
Data retention period.
The validity period of the agreement for managing personal securities accounts of shareholders and other securities holders.
1.8. Sending Direct Marketing Communications
1.8.1. Marketing to existing clients (legitimate interest)
If you have used the Company’s services and have not objected to receiving direct
marketing communications, the Company will inform you by email about Company news and provide
offers that may be relevant to you.
Personal data processed:
- name, surname;
- areas of investment interest;
- email address (phone number may also be provided if needed).
Legal basis. Legitimate interest (GDPR Article 6(1)(f)) – to provide you with relevant marketing communications.
Data retention period. 5 (five) years after the last login to the website.
1.8.2. Marketing with consent (newsletter subscription)
If you express your consent on our website by subscribing to the investment newsletter,
we will process your data for direct marketing purposes.
Personal data processed:
- name, surname;
- areas of investment interest;
- email address (phone number may also be provided if needed).
Legal basis. Consent (GDPR Article 6(1)(a)).
Data retention period. 5 (five) years from the date of obtaining consent.
1.9. Defense of Legal Claims
Purpose.
The Company, based on its legitimate interest to defend its rights, including in civil disputes,
processes the data of persons involved in the case or their employees.
Personal data processed.
Depending on the claim or complaint filed, all personal data
listed in this policy may be processed for this purpose.
Legal basis. Legitimate interest (GDPR Article 6(1)(f)).
Data retention period.
1 (one) year after the final resolution of the case and full satisfaction of the Company’s claims
(if the claims are satisfied).
1.10. Document Archiving
Purpose. To archive and store documents for a specified period.
Personal data processed:
- contracts for goods, works, services;
- acceptance acts for goods, works, and services.
Legal basis.
Legal obligation (GDPR Article 6(1)(c)) (Order No. V-100 of the Chief Archivist of Lithuania of March 9, 2011,
“On the Approval of the Index of General Document Retention Periods”).
Data retention period.
According to the terms established by Order No. V-100 of the Chief Archivist of Lithuania of March 9, 2011,
“On the Approval of the Index of General Document Retention Periods.”
2. Cookies Collected
Cookies are small text files that are temporarily stored on your device’s hard drive.
Cookies typically do not contain any information that personally identifies the user, but personal
information we store about you may be linked to information stored in and obtained from cookies.
Cookies we use:
- Essential cookies – necessary for the basic functions of the website to operate, and therefore cannot be disabled.
- Analytical cookies – allow monitoring and analyzing visits from various traffic sources and help improve overall website performance.
- Marketing cookies – identify your interests and select advertising content displayed on other websites accordingly.
More detailed information about the cookies we use:
| Cookie Name | Cookie Purpose | Retention Period |
|---|---|---|
| PHPSESSID | This cookie is for the website to function and be usable. | During session |
| _ga | This cookie is used by Google Analytics. | 2 years |
| _ga_XJXGMRKEYB | This cookie is used by Google Analytics. | 2 years |
| $_COOKIE[‘_allowcookies’] | Used to confirm the privacy policy banner. | 1 month |
3. Data obtained from other sources
We may obtain information about you not only directly from you but also from other sources. In certain cases,
we may process your personal data provided to us by our clients, for example, if you are
a family member or a representative, founder, shareholder, participant, owner, etc., of a client – legal entity.
Also, in certain cases, we may obtain information about you from external sources, for example,
from the Bank of Lithuania, commercial banks, the State Enterprise Centre of Registers, and other state and departmental
register managers.
Information on what data we process and how long we store it for this purpose is provided
in the section “How do we use your data?”.
4. To whom do we provide your personal data?
Generally, we do not disclose your personal data, but to ensure the continuous
operation of the Company and proper provision of services, we may disclose your data to persons
involved in the provision of Company services:
- accounting service providers (UAB “Everise Labs”);
- anti-money laundering and terrorist financing prevention service providers (UAB “Ondato”);
- IT, hosting, cloud computing service providers (UAB “IT sistemų priežiūra”);
- accounting service providers (UAB “Malmiga ir partneriai”).
Under certain circumstances, we may be obliged to transfer personal data when:
- we are required to disclose information by law, including cases where personal data must be disclosed to the tax administrator and law enforcement agencies for crime prevention and detection purposes;
- we must disclose personal data due to legal proceedings or to obtain legal advice, or its disclosure is necessary to establish, exercise, or defend our rights;
- disclosure of information is necessary to protect our or third parties’ interests (e.g., to prevent fraud);
- disclosure of information is necessary to protect your vital interests (e.g., if you feel unwell on our premises and we need to seek medical assistance);
- information must be disclosed to another third party providing data processing services on our behalf, i.e., data processors. In such a case, we ensure that data processors protect personal data in the same way we do, and we will inform you about changes to this privacy notice;
- disclosure of information is necessary to a potential buyer of our company’s assets or organization.
Except as provided in this Privacy Policy, we do not provide your personal data to any
third parties.
The list of recipients or categories of recipients specified in the Privacy Policy may change. If you wish
to be informed about changes to the recipients of your personal data, please notify us by email
at the email address provided in this Privacy Policy, stating in the body of the email:
“I wish to receive information about changes to the recipients of my personal data, name, surname.”
5. Transfer of data to third countries
Sometimes we may need to transfer your personal data to other countries outside the European Economic
Area (EEA) that may have lower levels of data protection. In such cases,
we will do our best to ensure the security of the transferred personal data.
If we send your personal data to countries outside the EEA, we will inform you and
ensure that one of the following security measures is applied:
- the contract signed with the data recipient is based on the Standard Contractual Clauses approved by the European Commission;
- the data recipient is located in a country for which an adequacy decision has been adopted by the European Commission;
- permission has been obtained from the State Data Protection Inspectorate to transfer personal data under the contractual clauses of the data controller or data processor and the data controller, data processor, or recipient of personal data in a third country or international organization.
The following service providers are established outside the European Economic Area, so your
data may be transferred outside the EEA:
Microsoft (Standard Contractual Clauses approved by the European Commission apply).
Please contact us by email at info@osumsec.lt,
if you would like more information about the mechanism we use to transfer your personal data from the EU.
6. Direct Marketing
To individuals who have provided their contact details and expressed a desire to receive information about
the Company’s offered products, the Company will send offers regarding
the Company’s services, newsletters, and other promotional materials via electronic communication means, inquire about opinions on
services provided, and announce Company news and/or service provision procedures.
For direct marketing purposes, the Company will process the following personal data of yours:
name, surname, phone number, email address, and your areas of investment interest.
If you have previously used and/or are currently using the Company’s services and do not object,
the Company will inform you by email about other Company services that may be relevant to you, as well as
information related to them, based on the Company’s legitimate interest.
If you object to receiving direct marketing communications, please inform us within 5 business days
by email at info@osumsec.lt from the date of signing the contract with the Company.
Your data for direct marketing purposes will be used for 5 years from the date of consent, and then
deleted. In the event that you are a Company client who has not objected to receiving direct marketing
communications, your personal data will be processed for direct marketing purposes for five years
after your last login to the website.
You can opt out of receiving marketing communications at any time. You can do this by:
- clicking the relevant link in any marketing communication received;
- contacting us by email at info@osumsec.lt.
Upon performing any of the above actions, we will update your profile to ensure that
you no longer receive our marketing communications in the future. Opting out of marketing communications will not stop
communications directly related to the provision of services to you.
7. Security of your personal data
Your personal data will be processed in accordance with the requirements of the General Data Protection Regulation, the Law on Legal Protection of Personal Data of the Republic of Lithuania,
and other legal acts.
When processing your personal data, we implement organizational and technical measures that ensure
the protection of personal data against accidental or unlawful destruction, alteration, disclosure, as well as
any other unlawful processing. Employees performing personal data processing functions store
documents and data files properly and securely and avoid making unnecessary copies. Copies of documents
containing your personal data are destroyed in such a way that the documents can no longer be restored
or their content identified.
The Company ensures the security of premises where personal data is stored, proper technical equipment
arrangement and review, compliance with fire safety rules, proper network management, information
system maintenance, and implementation of other technical measures necessary to ensure personal data protection.
Electronic data is stored on encrypted media, communication between servers and computers
is encrypted, and cloud services comply with the ISO27001 standard. User access to data
is granted based on business need. User access is protected by two-factor authentication,
and a 180-day password policy is applied to user passwords. User computer disks are encrypted.
Backups are encrypted.
8. Processing of children’s personal data
Our website is not intended for children, and we do not knowingly collect personal information from
children under 18 (eighteen) years of age. We will delete any collected personal information
if we discover that it was provided by a user under 18 years of age.
If you are a parent or legal guardian of a child under 18 who has provided us with personal information,
you may request to review or delete this information by
contacting us at info@osumsec.lt.
9. Your Rights
In this section of the notice, we provide an overview of the rights you have under data protection laws.
The exercise of some rights may be complex, so we recommend familiarizing yourself with the relevant
legal acts and guidelines of supervisory authorities.
Your main rights are:
- right to access data;
- right to rectification of data;
- right to erasure of data;
- right to restriction of processing;
- right to object to data processing;
- right to data portability;
- right to lodge a complaint with a supervisory authority;
- right to withdraw consent.
9.1. Right to access data
You have the right to obtain confirmation from us as to whether personal data concerning you is being processed, and, if so,
to access the processed data and additional information (purposes of processing, categories,
recipients). Except where it would adversely affect the rights and freedoms of others, we will provide
a copy of your personal data upon your request. The first copy will be provided free of charge, but for additional copies, we may
request a reasonable fee to cover administrative costs.
9.2. Right to rectification of data
You have the right to request that inaccurate personal data be rectified, and, taking into account the purposes of data processing,
incomplete data be supplemented.
9.3. Right to erasure of data
In certain cases, you have the right to request the erasure of your personal data, for example, when:
- the data is no longer necessary for the purposes for which it was processed;
- you withdraw your consent and there is no other legal basis for processing the data;
- you object to the processing of data on the basis of applicable legal acts;
- the data is processed for direct marketing purposes;
- the data is processed unlawfully.
In certain cases, you will not be able to exercise this right due to applicable exceptions. Such exceptions include cases
where the data is necessary for:
- ensuring freedom of expression and information;
- compliance with legal obligations binding on us;
- the establishment, exercise, or defense of legal claims.
9.4. Right to restriction of processing
In certain cases, you have the right to restrict data processing, for example, when:
- you contest the accuracy of the data;
- the data is processed unlawfully, but you do not want it to be erased;
- we no longer need the data, but you require it for the establishment, exercise, or defense of legal claims;
- you object to data processing on grounds of public interest or legitimate interest, pending verification of the legitimacy of your objection.
If processing is restricted, we will continue to store your data, but will not process it, except:
- with your consent;
- for the establishment, exercise, or defense of legal claims;
- for the protection of the rights of other natural or legal persons;
- for reasons of important public interest.
9.5. Right to object to data processing
You have the right to object to the processing of your personal data, based on your particular situation, when we process data
for public interest purposes or on the basis of our or third parties’ legitimate interest. In such a case,
we will no longer process your data unless we demonstrate compelling legitimate grounds
for the processing which override your interests, rights, and freedoms, or for the establishment, exercise, or defense
of legal claims.
You have the right to object at any time to the processing of your personal data for direct marketing purposes.
In such a case, we will no longer process your personal data for this purpose.
9.6. Right to data portability
To the extent that data is processed based on your consent or for the performance of a contract or for taking steps
at your request prior to entering into a contract, you have the right to receive your personal data in a structured, commonly used, and
machine-readable format. You will not be able to exercise this right if it would adversely affect the rights and freedoms of others
.
9.7. Right to lodge a complaint with a supervisory authority
If you believe that we are violating data protection laws when processing your personal data, you have the right
to lodge a complaint with the State Data Protection Inspectorate (L. Sapiegos g. 17, 10312 Vilnius,
tel. (8 5) 271 28 04, 279 1445, email ada@ada.lt,
website: https://vdai.lrv.lt/).
9.8. Right to withdraw consent
In cases where the legal basis for data processing is your consent, you have the right to withdraw consent
at any time. The withdrawal of consent will not affect the lawfulness of data processing prior to withdrawal.
10. Responsibility
You are responsible for the confidentiality of the data you provide and for ensuring that the data you provide to us
is accurate, correct, and complete. If the data you have provided changes, you must immediately
inform us by email.
In no event will we be liable for damages arising from your provision of incorrect or incomplete
personal data or your failure to inform us of changes to it.
11. Changes to the Privacy Policy
We will inform you by email of any material changes to this notice.
12. Contacts
We will make every effort to answer any questions or quickly resolve any issues related to your
privacy.
We welcome all comments, inquiries, and requests related to the use of your personal information.
You can contact us by email:
info@osumsec.lt.
Be the first.
Get the latest investment offers.
You may unsubscribe at any time. Review our privacy policy.