ABOUT US AND OUR PRIVACY POLICY
Acting as your personal data controller, ExpertLab Consulting, UAB, legal entity code 306409658, registered office at Konstitucijos Ave. 7, LT-09308 Vilnius, whose data is collected and processed in the Register of Legal Entities managed by the State Enterprise Centre of Registers (hereinafter – ExpertLab or we), places a high value on your privacy and the security of your data. Therefore, we have prepared this Privacy Policy (hereinafter – the Privacy Policy), which provides you with information about how ExpertLab processes your personal data, ensures its security, and other related matters.
This Privacy Policy applies to you when:
-
you visit our website at www.expertlab.lt (hereinafter – the Website), or our social media accounts;
-
you contact us via email, telephone, or other electronic communication channels (for example, by submitting an inquiry form on our Website);
-
you enter into a contract with us under which we provide services to you;
-
you are our partners, suppliers, or other persons with whom we have entered into contracts or cooperate on other grounds;
-
you register for and participate in events organized by us or subscribe to our newsletters;
-
you apply for an open job position offered by us or wish to undertake an internship;
-
you contact us regarding other matters.
In this Privacy Policy, the term "personal data" (hereinafter – Personal Data) refers to any information or set of information that allows us to directly or indirectly identify your identity, such as your name, surname, email address, and so on.
Our Website may contain links to external websites (for example, links to social networks). Please note that this Privacy Policy does not apply when you visit such external websites. Before submitting your Personal Data to these websites or using their services, we encourage you to review their privacy policies and other applicable terms.
ExpertLab ensures the confidentiality of Personal Data in accordance with applicable legal requirements and implements appropriate technical and organizational measures to protect Personal Data against unauthorized access, disclosure, accidental loss, alteration, destruction, or any other unlawful processing.
ExpertLab processes Personal Data in accordance with this Privacy Policy and in compliance with the General Data Protection Regulation (Regulation (EU) 2016/679) (hereinafter – GDPR) as well as other applicable data protection laws.
This Privacy Policy may be amended in the future to reflect changes in legislation or in the operations of ExpertLab. Therefore, we recommend reviewing it periodically to stay informed.
THE PERSONAL DATA WE COLLECT, PURPOSES OF PROCESSING, AND STORAGE PERIODS
Depending on the services provided or the nature of our cooperation, we process different categories of Personal Data. In all cases, we ensure that we process only the data that is necessary. Your Personal Data is processed for the following purposes:
For the Provision of Consulting Services
In order to fulfill our obligations to you and to ensure smooth cooperation throughout the process – from initial contact to full contract execution – we may process the following categories of your Personal Data, depending on the stage:
Name, surname, date of birth, personal identification number, taxpayer identification number, address/workplace address, phone number, email address, data from other communication channels (e.g., social media account information, etc.), correspondence data, workplace, job title, data of client representatives, employees, clients, beneficiaries, and other data related to pre-contractual relations or to the execution of a contract between you and us.
We do not process special categories of personal data, such as information about health, religious beliefs, sexual orientation, or criminal records. However, in certain exceptional cases where it is strictly necessary for the provision of our services or in accordance with mandatory legal requirements, we may process such data.
Personal Data processed for the purpose of providing consulting services is retained for 10 (ten) years following the expiration of your most recent service agreement with us, unless a longer storage period is required by law and/or other legal acts.
For Administrative and Accounting Purposes
In order to record and store the contracts we have entered into, process payments, manage debts, and maintain proper accounting records, we process the following categories of your Personal Data:
Name, surname, personal identification number (if required to be collected by law), taxpayer identification number, job title, workplace, address/workplace address, email address, phone number, bank account number, information specified in other accounting documents, and any other mandatory data required for fulfilling our functions (including employer obligations, if applicable).
Personal Data processed for administrative and accounting purposes is retained for the periods established by law, and where the law does not specify a storage period, such data is kept for 10 (ten) years following the expiration of your most recent service agreement with us.
For the Prevention of Money Laundering and Terrorist Financing
To fulfill our legal obligations and verify identities, we may be subject to requirements set out in the Law on the Prevention of Money Laundering and Terrorist Financing (hereinafter – the Law). When providing services, we process Personal Data to comply with our statutory obligations and to implement the "know your customer" principle.
For the purposes of anti-money laundering and counter-terrorist financing, we may collect (depending on the specific case) Personal Data about clients, their representatives, employees, ultimate beneficial owners, and their family members: Name, surname, email address, phone number, personal identification number, nationality, residential address, identification document details (document name, number, expiry date, issuing country, photograph used in the document, signature sample), information on whether the client or their family members are politically exposed persons, source of income, and other data processed based on legal obligations.
Storage periods for Personal Data processed for anti-money laundering and terrorist financing prevention purposes are as follows:
Registration log data (in paper or electronic format): kept for 8 years from the end of the transaction or business relationship with the client.
Copies of identity documents, data of beneficial owners, recipient of payment data, video recordings of live identity verification, and account/contract documentation (originals): retained for 8 years from the end of the transaction or business relationship with the client.
Business correspondence with the client: retained for 5 years from the end of the transaction or business relationship, in paper or electronic format.
Documents and data confirming financial transactions or contracts, or other legally binding records related to financial operations: stored for 8 years from the date of the transaction or contract.
Reports documenting investigation results: retained for 5 years, in paper or electronic format.
For the Purpose of organizing, managing, and Inviting to Events
We may invite you to trainings, seminars, and other events organized by us. Please note that during events, you may be photographed or filmed. If you do not agree to the use of your image, we kindly ask you to inform us before the event or at any time afterward.
For the purpose of organizing, managing, and inviting to events, we process the following categories of your Personal Data:
Name, surname, email address, phone number, job title, or other data you may voluntarily provide.
Personal Data processed for these purposes is retained until your consent is withdrawn, or for 5 years from the date of consent.
For Direct Marketing Purposes
We may send you notifications, newsletters, offers, and other information about the services we provide.
For direct marketing purposes, we may process the following categories of your Personal Data:
Name, surname, email address, phone number, job title, or other data you may voluntarily provide.
Personal Data processed for direct marketing purposes is retained until your consent is withdrawn, or for 5 years from the date of consent.
For the Purpose of Employment or Internship Placement
We process the Personal Data of candidates who have submitted their CVs and/or cover letters directly to us via the email address provided on our website, through a link on our website, via job advertisement portals, or by other means. This data is processed for the purpose of selecting candidates for an open job or internship position. Such candidate data is processed based on consent, which you provide by submitting your data to us in your interest to gain employment or an internship position.
For employment or internship placement purposes, we may process the following Personal Data:
Name, surname, date of birth, phone number, current employer, email address, residential address, education, foreign language proficiency, preferred position, desired salary, personal characteristics, work experience: last employer, duration of employment, job title, other work experience, and any additional information provided in the CV, reference, and/or cover letter.
Personal Data processed for employment or internship purposes is stored until the end of the selection process and the date the employment or internship agreement is signed with the selected candidate. If the candidate has given consent to participate in future selections, the data will be stored for no longer than one year after the end of the selection process.
For the Purpose of Inquiry Administration
We process your Personal Data when you contact us via email, submit an inquiry through the Website, call us by phone, or visit our office.
For the purpose of handling inquiries received via electronic communication channels, we may process the following Personal Data:
Name, surname, IP address, phone number, email address, address/workplace address, name of the represented company, or any other data you have provided to us.
Personal Data processed for the purpose of inquiry administration is retained for 2 (two) years from the date your inquiry is received.
For the Purpose of Social Media Management
To manage and administer our social media accounts (i.e., Facebook and LinkedIn), we collect the data you voluntarily provide as a social media user through comments, messages, reactions such as “like,” “share,” and other forms of engagement, as well as other forms of communication.
Currently, we manage the following social media accounts:
LinkedIn https://www.linkedin.com/company/expertlab-consulting/
Facebook https://www.facebook.com/expertLabconsulting
For the purpose of social media management, we may process the following categories of your Personal Data:
Data that you voluntarily provide in accordance with the privacy policies of the respective platforms: your social media profile name, profile picture, public comments posted on our accounts, as well as inquiries sent to us.
Please note that information on Facebook and LinkedIn is stored in accordance with the terms set by the owners of these platforms, based on their privacy policies and your selected privacy settings. We recommend reviewing the privacy policies of the aforementioned third parties and contacting them directly if you have any questions regarding how they process your Personal Data.
Storage of your Personal Data on our social media accounts: We will have access to your Personal Data on our social media accounts for as long as we maintain these accounts, unless you delete your data, request us to delete it, or we remove it ourselves as part of content management on our pages.
GROUNDS FOR THE PROCESSING OF YOUR PERSONAL DATA
Contract. An agreement/contract concluded by and between you and us that provides a legal ground for the processing of your Personal Data.
Consent. A consent signed by you whereby you grant us the right to process your Personal Data for the purpose specified in the consent, and only for such purposes (e. g. direct marketing purposes).
Legitimate interest. In certain cases we may process your Personal Data on the ground of legitimate interest in order to perform tasks arising from out activities, provided that such interest prevails over your interests and fundamental rights.
Legal obligation. Processing of the Personal Data is necessary for the fulfilment of a legal obligation we are subject to.
THIRD PARTIES TO WHOM WE MAY TRANSFER YOUR PERSONAL DATA
We have the right to transfer your Personal Data for processing to third parties that assist us in the performance of contracts concluded with you, such as external consultants, translators, notaries, lawyers etc. as well as to personal data processors hired by us, e. g. IT companies, database administration service providers, cloud service providers, companies providing accounting, advertising and marketing services etc. We request that the data processors store, process and treat the Personal Data responsibly and according to our instructions.
Your Personal Data may be disclosed to third parties also when this is required by applicable laws, e. g. to law enforcement bodies (the police or supervisory bodies) or in order to secure our rights or rights of our clients as well as security of our staff and resources.
We normally process the Personal Data within the territory of the European Union and the European Economic Area (EU/EEA) but in certain cases your Personal Data may be transmitted beyond the EU/EEA. Your Personal Data can be transmitted beyond the EU/EEA provided that the following conditions are fulfilled:
-
The data can only be transferred to our reliable partners with whom we have concluded agreements the standard terms and conditions of which have been approved by the European Commission and which ensure security of your Personal Data;
-
We have received a specific permission for such transfer from the State Data Protection Inspectorate of the Republic of Lithuania;
-
The European Commission has taken a decision on the suitability of the state of establishment of our partner, i. e. security of appropriate level is ensured; or
-
You have given your consent to the transfer of your Personal Data beyond the EU/EEA.
RIGHTS OF A DATA SUBJECT
Information about your rights related to the processing of your Personal Data by ExpertLab, and the exercise of such rights is provided below. For more information about the exercise of your rights please contact us using the email address provided in this Privacy Policy.
Right of access. You have the right to request access to your Personal Data processed by us. This right includes, e. g. the right to be informed about who processes your Personal Data, what categories of the Personal Data are processed and for what purpose.
Right to rectify data. You have the right to request that ExpertLab rectifies any incorrect or incomplete data.
Right to delete data. You may also request deletion of your Personal Data if they are no longer necessary for the purposes for which they were collected, or if you believe that the data processing is unlawful or that the Personal Data must be deleted to prevent a breach of a legal requirement. In cases where legal acts in a certain jurisdiction prohibit us from deleting the data stored and processed by us, we will not be able to honour your request but we will inform you about the relevant obligations.
Right to restrict data processing. You have the right to request that ExpertLab restricts processing of your Personal Data. You may exercise this right when:
-
You contest accuracy of the data (restriction will apply to a period during which we can check accuracy of the data);
-
Processing of the Personal Data is unlawful but you disagree with the deletion of the data and request restriction of their processing instead;
-
The Personal Data are no longer necessary to us for processing purposes but are necessary to you in order to make, satisfy or defend legal claims;
-
You object to the data processing on the ground of legitimate interest (until we check whether our legitimate interest prevails over the reasons provided by you).
Right to data portability. If your Personal Data are collected automatically or under a mutual legal relationship, you may request that we provide your Personal Data in a structured, commonly used and machine-readable format. You have the right to request to transmit those data to another controller, however, this is only possible subject to a technical feasibility.
Right to object to data processing. In cases prescribed by the law you have the right to object to the processing of your Personal Data including e. g. processing for marketing purposes.
Right to withdraw your consent. If the data processing is performed on the ground of your consent, you have the right to withdraw your consent to such data processing at any time.
Right to object to the processing for direct marketing purposes. You may refuse, at any time, from notices sent by us in which we inform you about our events or provide any other information which, in our opinion, may be of interest to you. You can express your objection at any time by contacting us.
YOUR OBLIGATIONS TO US
You are responsible for ensuring that the data provided by you are accurate, correct and complete. You must inform us without delay about any change in the Personal Data provided to us.
If you disclose to us any Personal Data related to a third party (e. g. your employee, board member, colleague, counterparty etc.), you must ensure that they familiarise themselves with this Privacy Policy and that you obtain their consent prior to presenting their data to us.
We do not assume liability for any damage suffered by you due to the fact that you had provided incorrect or incomplete Personal Data or had failed to inform us about changes therein.
INFORMATION SOURCES
You have the right to approach us in order to put queries, withdraw consents, submit applications for the exercise of the data subject‘s rights and complaints concerning processing of the Personal Data.
Our contact details are published on www.expertlab.lt; you can also write us an email to labas@expertlab.lt.
If you are concerned about a potential breach of privacy or another offence, please write us to labas@expertlab.lt or using any other contact details provided on the Website. The person in charge will consider your complaint and provide information about further steps.
If you are dissatisfied with the outcome of consideration of your complaint, you have the right to file a complaint to the State Data Protection Inspectorate and to apply to a competent court.
Details of the institution responsible for compliance with legal acts on the protection of personal data:
State Data Protection Inspectorate
L. Sapiegos g. 17, Vilnius
Tel. + 370 5 279 14 45
Email: ada@ada.lt
AMENDMENTS TO THE PRIVACY POLICY
We can update or amend this Privacy Policy at any time. The updated/amended Privacy Policy will enter into effect on the day of its publication on the Website.
The updated Privacy Policy will be visible on the Website immediately. The date of the last update specified below shows when the Privacy Policy was last updated.
Last update: 17 July 2025.