This is a translation provided for convenience. The Lithuanian version is legally authoritative.
MB “Vienu yriu prieky” (hereinafter “we”, “our”), which operates the website https://upemis.lt, respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store and share your personal data in accordance with the General Data Protection Regulation (GDPR), the ePrivacy Directive and other applicable legislation. If you have any questions, please contact us by email at: info@upemis.lt.
1. Data Controller
The data controller is: MB “Vienu yriu prieky” Company registration number: 306658403 Address: Juknaičių g. 25, Lygumai, LT-83306 Pakruojo District, Lithuania Email: info@upemis.lt Telephone: +370 638 87353 Head: Rimgaudas Jurgaitis, Director
2. What personal data do we collect and why?
We collect only the data necessary to ensure the smooth operation of the website and the booking process. Our website is intended for a general audience, and whilst we do not verify users’ ages, it is not intended for children. Below is a breakdown of what data we collect, why we collect it, and the legal basis for doing so:
2.1. Device information
Data: Browser type, IP address (anonymised), time zone, device settings and essential cookies.
Purpose: To ensure the website’s functionality and security, and to analyse website usage (via PostHog).
Legal basis: Legitimate interest (ensuring the website’s operation and security, anonymous statistics).
Note: PostHog uses anonymised IP addresses, so your identity is not disclosed. For further information, see PostHog’s privacy policy: https://posthog.com/privacy.
2.2. Account and booking information
Data: First name, surname, email address, telephone number, payment details (processed via Neopay).
Purpose: To fulfil bookings, process payments, communicate regarding bookings and provide customer service.
Legal basis: Compliance with the website’s terms and conditions (Article 6(1)(b) of the GDPR).
2.3. Newsletters and contact form
Data: Email address, first name (if provided).
Purpose: To send newsletters or respond to your enquiries via the contact form.
Legal basis: Your consent (Article 6(1)(a) of the GDPR). You may withdraw your consent at any time by unsubscribing from the newsletter or by contacting us.
2.4. Cookies
We use only the strictly necessary cookies required for the website to function (e.g. session cookies for logging in). PostHog cookies are used to collect anonymous statistics, but only with your consent via the cookie management tool. Neopay, our payment processing partner, may also set cookies during the payment process. Further information about cookies:
Essential cookies: These enable you to browse the website and use its core features (e.g. logging in). These cookies do not store any personal information that could be used to identify you. Legal basis: legitimate interest.
Analytical cookies (PostHog): Collect anonymous information about website usage (e.g. pages viewed, session duration). These cookies are only enabled with your consent. Legal basis: consent. See PostHog’s privacy policy: https://posthog.com/privacy.
Neopay cookies: Used for payment processing and may include consents relating to payment services.
Consent management: Before enabling non-essential cookies (e.g. PostHog), we ask for your consent via the cookie management tool. Neopay also requests consent at the time of payment in accordance with their privacy policy.
2.5. Event registration and photo data
Data: When registering for an event – first name, surname, email address, phone number, year of birth or age, gender, team or club, chosen category, boat crew members (where applicable), results and times, and event photos in which you may be identifiable.
Purpose: To process the registration, compile start lists, publish results, communicate with participants, and promote the event (including photo galleries).
Access: The event organizer receives access to the data of their event’s participants (start lists, results, contacts) and may use it only to organize and run the event. The organizer is responsible for processing the data available to them in accordance with the GDPR.
Legal basis: Performance of the registration contract (GDPR Art. 6(1)(b)). Publishing event photos in which participants are identifiable is based on the legitimate interest of promoting the event or on your consent; you may request the removal of a photo in which you are identifiable by contacting info@upemis.lt.
3. How do we share your data?
Your data may be transferred to the following recipients:
PostHog: Anonymous statistics on website usage (only with your consent). See PostHog’s privacy policy: https://posthog.com/privacy.
Hostinger: Website hosting services ensuring the website’s operation and data security.
Mailgun: Email services used for newsletters and customer support.
Event organizers: If you register for an event, your registration data (start lists, results, contacts) is available to that event’s organizer so that they can organize and run the event.
Other recipients: Data may be disclosed where required by law (e.g. to tax authorities) or to protect our rights, security or to investigate criminal offences.
4. International data transfers
Your data (e.g. via Mailgun) may be transferred outside the EU/EEA, for example to the USA. In such cases, we use standard contractual clauses (Article 46 of the GDPR) to ensure the protection of your data.
5. Data retention period
Device information: Stored for as long as the cookies remain valid (session cookies are deleted after 30 minutes of inactivity; PostHog analytics cookies are stored for up to 2 years, provided you have given your consent).
Account and booking data: Stored for 7 years in accordance with Lithuanian tax legislation, or until you submit a request for deletion.
Newsletters: Stored until you withdraw your consent.
Event registration data: Stored for 7 years in accordance with Lithuanian tax legislation. Event results and photos may be published indefinitely for the purposes of event history and sporting results, unless you request their removal.
Neopay payment data: Stored in accordance with Neopay’s privacy policy (usually for 3 years after payment, see https://neopay.online/privacy-policy).
Inactive accounts: Upon receipt of a request to delete an account, it is marked as inactive (data is no longer processed but is stored with restricted access). To have your data completely deleted, please submit a clear request by email to info@upemis.lt. Data will be deleted within 30 days, unless we are required by law to retain it (e.g. for tax purposes).
6. Your rights
If you are a resident of the EU/EEA, you have the following rights under the GDPR:
To be informed: About how we process your data.
Access: To obtain a copy of your data.
Rectification: To have inaccurate or incomplete data corrected.
Erasure: To request that your data be erased (‘the right to be forgotten’).
Restriction: To restrict the processing of your data in certain circumstances.
Data portability: To receive your data in the format in which it is stored on the server.
Objection: Object to the processing of your data (e.g. for direct marketing).
Withdrawal of consent: Withdraw your consent at any time (e.g. for newsletters or cookies).
Complaint: To lodge a complaint with the State Data Protection Inspectorate (vdai.lrv.lt).
7. Data protection
We use state-of-the-art technical solutions to protect your data:
The website uses SSL encryption for data transmission.
Only authorised personnel have access to the servers.
We regularly check our systems for potential breaches or cyber attacks.
In the event of a data breach, we will notify the State Data Protection Inspectorate within 72 hours and, where necessary, the affected users.
8. Automated decision-making
We do not use automated decision-making or profiling that would have legal consequences for you.
9. Children’s data
Our website is not intended for persons under the age of 16 and is not aimed at children. We do not verify the age of users, but our services require payment by card in advance, so purchases by children are not anticipated. If we become aware that we have collected data from a person under the age of 16, we will delete it immediately. Please contact us if you believe this has happened.
10. Links to third-party websites
Our website may contain links to third-party websites (e.g. Neopay, PostHog). We are not responsible for their privacy practices. We recommend that you read their privacy policies:
Rental providers’ websites (accessible via the rental provider’s profile)
11. Website accessibility for people with disabilities
We aim to ensure that upemis.lt is accessible to all users in accordance with the European Accessibility Act (from 28 June 2025). Our website does not yet comply with WCAG 2.1 AA standards.
12. Policy updates
This Privacy Policy may be updated. We will notify you of any material changes by email or on the website at least 14 days before they come into effect. The updated policy is published at: https://upemis.lt/privatumo-politika.
13. Contact details
If you have any questions about this policy or your data, please contact us: Email: info@upemis.lt Telephone: +370 638 87353