Privacy policy
PRIVACY POLICY
The Privacy Policy (hereinafter – the Policy) regulates the principles of collection, processing, and storage of personal data of visitors to the website https://tauragehotel.lt operated by UAB “Agavos prekyba” (hereinafter – the Company) and establishes the purposes and means of processing their personal data.
This Policy has been prepared in accordance with the provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (hereinafter – the Regulation).
This Policy informs visitors to the Company’s website about the processing of their personal data. By using the services and continuing to browse the website, you confirm that you have read this Policy and understand its provisions.
DEFINITIONS
Personal data – any information relating to an identified or identifiable natural person (data subject); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
Data subject – a natural person – a visitor to the Company’s website and/or social media accounts and/or a recipient of services whose personal data is collected and processed by the Company.
Data subject’s consent – any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.
Data subject’s rights – the data subject’s ability to participate in and control the activities of the data controller and/or processor when processing his or her personal data – to know, to be informed about the processing of his or her personal data; to access his or her personal data and how it is processed; to request the rectification, erasure of his or her personal data or restriction of processing operations, except for storage, when data is processed in violation of legal provisions; to object to the processing of his or her personal data; to request the erasure of his or her personal data; to receive the data concerning him or her which he or she has provided to the data controller; to lodge a complaint with a supervisory authority (the State Data Protection Inspectorate).
Data processing – any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination with other data, restriction, erasure or destruction.
Automated data processing – data processing operations performed wholly or partially by automated means. These include any information and communication technologies that can be used to perform personal data processing operations, for example: computers, communication networks, etc.
Data controller – UAB “Agavos prekyba”, legal entity code: 179250952, registered address: Gedimino St. 44, LT-72336 Tauragė, email: info@tauragehotel.lt, tel. no.: +370 620 55 221, website: https://www.tauragehotel.lt/
Data processor – a natural or legal person, public authority, agency or other body which processes personal data on behalf of the data controller.
Data recipient – a natural or legal person, public authority, agency or other body to which the personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.
Cookie – a small text file that a website saves on your computer or mobile device when you visit it.
Personal data breach – a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed.
Other terms used in this Policy are understood as defined in the Regulation and other legal acts regulating the processing of personal data.
SECTION I
PRINCIPLES OF PERSONAL DATA PROCESSING
- When processing your personal data, the Company is guided by the following principles:
1.1. The Company processes personal data only for lawful purposes as defined in this Policy and does not further process it in a manner incompatible with those purposes (principle of purpose limitation);
1.2. Personal data is processed accurately, fairly and lawfully, in compliance with legal requirements (principle of lawfulness, fairness and transparency);
1.3. The Company processes personal data in such a way that personal data is accurate and, where necessary, kept up to date (principle of accuracy);
1.4. The Company processes personal data only to the extent necessary to achieve the purposes of personal data processing (principle of data minimization);
1.5. Personal data is kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data was collected and processed (principle of storage limitation);
1.6. When processing personal data, the Company applies appropriate technical and organizational measures to ensure appropriate security of personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction or damage (principle of integrity and confidentiality);
1.7. The Company is responsible for compliance with the principles set out in this Policy and must be able to demonstrate compliance (principle of accountability).
SECTION II
PURPOSES OF PERSONAL DATA PROCESSING
- The Company processes your personal data:
2.1. Guest personal data for the purposes of reservation administration, accommodation and provision of other services, customer identification, payment processing, invoice issuance, communication with customers, handling inquiries and complaints, improving service quality, fulfilling obligations established by law, and ensuring the security of the hotel and guests;
2.2. To properly manage and administer the Company’s website, monitor website traffic, ensure its security, improve its performance, facilitate information search and ensure the submission of data subject inquiries;
2.3. For other purposes for which the Company has the right to process the data subject’s personal data when the data subject has given consent, when data needs to be processed due to the Company’s legitimate interest, or when the Company is obliged to process data by relevant legal acts.
- For the purposes specified in Section 2 of this Policy, the Company collects and processes the following data about you:
3.1. For the purpose of implementing legitimate interests (to properly manage and administer the website, monitor its traffic, ensure its security, improve its performance, facilitate information search and ensure the submission of data subject inquiries, etc.), the Company collects and processes the following data: IP address.
3.2. For the purposes of hotel services, the Company collects and processes the following data: name, surname, date of birth, identity document number, citizenship, residential address, arrival/departure date, data of accompanying persons, dietary requirements, bank account details, etc.
3.3. For the purposes of restaurant table reservations, the Company collects and processes the following data: name, surname, phone number, email address, reservation date, time and number of guests, additional information provided by the guest.
3.4. For the purposes of gift card sales, the Company collects and processes the following data: name, surname, phone number, email address, gift voucher validity date, payment details, recipient’s name and contact details.
3.5. Administration of inquiries, comments and notifications. Data processed: name, surname, phone number, email address, message, comment or notification text.
SECTION III
COLLECTION AND PROCESSING OF PERSONAL DATA
- Personal data is obtained from you when such data is required to be provided by law or when you provide such data voluntarily.
- Regardless of how the data is collected, it is stored only to the extent and for as long as necessary to achieve the specified purposes, but no longer than the periods established in the current edition of the General Document Retention Schedule approved by Order V-100 of the Chief Archivist of Lithuania of 9 March 2011 or in other legal acts. Data contained in applications submitted via the website is processed on the basis of legitimate interest to carry out activities and is stored for up to 12 months from the date of submission, after which it is destroyed.
SECTION IV
DATA SUBJECT’S RIGHTS
- You, as a data subject, have the right to:
6.1. Know / be informed about the processing of your personal data;
6.2. Access your personal data and its processing. You have the right to contact the Company with a request to provide information about what personal data is being processed and for what purpose;
6.3. Request the rectification of your personal data. If it is established that the Company is processing inaccurate or incomplete personal data about you, you have the right to submit a request for the rectification or completion of such personal data;
6.4. Request the erasure of your personal data (“right to be forgotten”). You have the right to contact the Company with a request to erase your personal data if one of the following grounds exists:
– the personal data is no longer necessary for the purposes for which it was collected or otherwise processed;
– you have withdrawn consent on which the data processing was based and there is no other legal ground for processing your personal data;
– you object to the processing of data and there are no overriding legitimate grounds for processing it;
– the personal data has been processed unlawfully.
6.5. Request the restriction of processing of your personal data. You have the right to contact the Company with a request to restrict the processing of your personal data if one of the following grounds exists:
– you contest the accuracy of the data for a period enabling the Company to verify the accuracy of the personal data;
– the processing of personal data is unlawful and you oppose the erasure of the data and request instead the restriction of its use;
– the Company no longer needs the personal data for the purposes of processing, but you require it for the establishment, exercise or defense of legal claims;
– you have objected to the processing pending verification of whether the Company’s legitimate grounds override those of the data subject.
6.6. Object to the processing of personal data. You have the right to object to the processing of certain non-mandatory personal data about you. Such objection may be expressed by not completing certain fields in documents, as well as by subsequently submitting a request to cease processing your non-mandatory personal data. Upon your request, the Company will provide you with information about which of your data is processed on a non-mandatory basis. Upon receiving a request to cease processing non-mandatory personal data, the Company shall immediately cease such processing, unless this would be contrary to legal requirements, and shall inform you accordingly;
6.7. Data portability, i.e., you have the right to receive the personal data concerning you which you have provided to the Company in a structured, commonly used and machine-readable format, and you have the right to transmit that data to another data controller, and the Company must not create obstacles to this. - For more information about your rights and/or how to exercise them, you may contact the Company using the contact details specified in this Policy. If you contact the Company in the manner specified in this Policy, the Company may process the following personal data you provide: name, surname, email, date of contact and correspondence text, as well as any other information you voluntarily provide. If there are doubts about the identity of the person submitting a request, complaint or claim, the Company has the right to request an identity document from the person who has contacted them. If the Company is unable to provide you with the required information or if the information provided by the Company does not satisfy you, you have the right to lodge a complaint with the State Data Protection Inspectorate in accordance with the procedure established by law.
SECTION V
PERSONAL DATA SECURITY MEASURES
- When storing personal data, the Company implements and ensures appropriate organizational and technical measures designed to protect personal data from accidental or unlawful destruction, alteration, disclosure, as well as from any other unlawful processing.
- Only those persons who have the right of access to such data may access the personal data collected and processed by the Company, and only when it is necessary to achieve the purposes specified in this Policy.
- The Company guarantees that personal data will not be sold or rented to third parties.
- The Company ensures proper network management, maintenance of information systems and implementation of other technical measures necessary to ensure the protection of your personal data.
SECTION VI
TRANSFER OF PERSONAL DATA TO THIRD PARTIES
- Your personal data may be disclosed to third parties providing services to the Company that ensure the operation and maintenance of the information systems used by the Company. In such cases, your personal data is disclosed to third parties only to the extent necessary for the proper provision of their services.
- The Company may provide personal data to its data processors who provide services to the Company and process personal data on behalf of the Company. Data processors have the right to process personal data only in accordance with the Company’s instructions and only to the extent necessary to properly fulfill the obligations set out in the contract.
- Your personal data may be disclosed to law enforcement authorities in accordance with the procedure established by the legal acts of the Republic of Lithuania.
- In all other cases, your personal data may be disclosed to third parties only with your consent.
SECTION VII
USE OF COOKIES
- Information collected through cookies allows the Company to improve the operation of the website, ensuring convenient and efficient information search for you.
- Main cookies used on the Company’s website:
| Cookie name | Data processing purpose/function | Cookie type | Validity period |
| _ga, _gat, _gid, | This cookie is installed by Google Analytics. The cookies are used to distinguish users, to calculate visitor, session, campaign data, to monitor statistical analysis of website usage, and for online advertising purposes based on user behavior. The cookies store information anonymously and assign a randomly generated number to identify unique visitors. | Statistics cookie / Non-essential | 2 years, until browser closure, 1 day |
- Consent to record cookies is expressed by clicking the “I AGREE” button when a message appears on the website with the text: “In order to improve your browsing experience, for statistical and marketing purposes, this website uses cookies, which you can revoke at any time by changing your browser settings and deleting saved cookies”.
- The consent given may be withdrawn at any time by changing your internet browser settings and deleting saved cookies. How to do this depends on the operating system and internet browser you are using.
- If you delete saved cookies, some functions of the Company’s website may not work as intended.
SECTION VIII
PRIVACY POLICY AMENDMENTS
- This Policy is an integral part of the services provided by the Company. In developing and improving the Company’s activities, the Company has the right to unilaterally amend this Policy at any time.
- The Company has the right to unilaterally amend this Policy in part or in full by announcing it on the website www.tauragehotel.lt.
- Additions or amendments to the Policy shall enter into force from the date of their publication, i.e., from the date they are posted on the tauragehotel.lt website.
SECTION IX
CONTACT INFORMATION
- If you have any questions, comments, complaints or requests related to the personal data collected, used and stored by the Company, please contact us by email at info@tauragehotel.lt

