top of page

Mheels Privacy Policy
 

Mheels (hereinafter – the "Data Controller") respects your privacy and undertakes to protect it in accordance with this Privacy Policy (hereinafter – the "Policy"). Through this Policy, the Data Controller aims to inform you comprehensively about the processing of your personal data, whether you communicate with the Data Controller in person, by electronic means (for example, using the Data Controller's website or by email), or in any other way you choose.

The Data Controller undertakes to be transparent by providing clear information about which of your personal data are processed, the purposes of processing, the retention period of personal data, as well as the legal basis for data processing and other information that the Data Controller is required to provide under applicable legislation.

Please take the time to review this Policy and, should you have any questions, do not hesitate to contact the Data Controller using one of the methods listed at the end of the Policy.

The Data Controller confirms that your data will be collected in accordance with the requirements of applicable European Union and Republic of Lithuania legislation and the instructions of supervisory authorities, and that all reasonable technical and administrative measures will be applied to protect the data collected by the Data Controller against loss, unauthorised use and/or alteration. The Data Controller's employees have undertaken in writing not to disclose or distribute to third parties any information received in the workplace, including information about visitors to the website/social media accounts.

Persons under 16 years of age may not provide any personal data. If you are under 16 years of age, you must obtain the consent of your parents or other legal guardians before providing any personal information.

The terms used in this Policy shall be understood as defined in the General Data Protection Regulation No. 2016/679 (EU).

The Data Controller is the operator of the website www.itsmheels.com. It is very important that you read this Policy carefully, because each time you visit the Data Controller's website, you agree to the conditions described herein. If you do not agree with these conditions, please do not visit the Data Controller's website, use its content or the Data Controller's services.

Your personal data, i.e. any information about you that allows the Data Controller to identify you, is obtained in various ways:

  • You may provide the information (personal data) yourself (for example, by filling in an enquiry form, calling the Data Controller, subscribing to the newsletter, or contacting the Data Controller in other ways);

  • Information about you may be collected automatically (when you visit the Data Controller's website (by means of cookies and similar technologies), when you visit the Data Controller's social media accounts (Facebook, LinkedIn, Instagram, TikTok, YouTube), when you visit the Data Controller's premises, the dance studio, events, or during trips to events);

You may provide your personal data to the Data Controller directly. This most commonly occurs when:

  • You provide your data in order to obtain information about the Data Controller's services;

  • You submit your requests or complaints;

  • You subscribe to the Data Controller's newsletter or other communications;

  • You take part in surveys.

Information about you may be collected automatically. This most commonly occurs when:

  • You submit enquiries via the Data Controller's social media accounts;

  • You use the website (data collected by means of cookies and similar technologies. More information about the cookies used by the Data Controller can be found below);

  • You make public posts on social media platforms followed by the Data Controller;

To the extent permitted by applicable legislation, the Data Controller may obtain information about you from third parties.

The Data Controller may link information received about you from you, from public and commercial sources, with other information it receives from you or about you.

Although the Data Controller endeavours to collect as little information about you as possible, it collects the following information in order to carry out its activities:

  • information necessary to provide you with the services offered by the Data Controller;

  • information you provide in enquiries;

  • information you provide when calling the Data Controller;

  • information necessary to establish identity and to verify that you have the right to enter into contracts;

  • information about your behaviour on the Data Controller's website;

  • aggregated information about the browsing habits of all website visitors.

Detailed information on how and what data the Data Controller processes is provided below.

You may choose not to provide the Data Controller with certain information (e.g. information requested in the enquiry form); however, in that case the Data Controller will not be able, or will not be fully able, to provide you with the services it offers.

The information provided above is processed for the following purposes:

  • Conclusion and performance of service provision and other contracts;

  • Providing information related to your enquiries and requests regarding services;

  • Marketing purposes, e.g. to provide individually tailored advertisements and sponsored content and to send notifications about promotions, to assess and analyse our market, clients and services (including collecting your opinion about the services, organising client/partner surveys, competitions or promotions to the extent permitted by law);

  • To learn how people use the Data Controller's website and services, in order to improve them and to create new content and services;

  • To defend our interests in court or another institution.

Your personal data are processed on one or more of the following lawful grounds:

  • Compliance with legal requirements;

  • Performance of a contract with you;

  • Legitimate interests of the Data Controller, unless your private interests override them;

  • In certain cases, your consent.

The legal basis on which your personal data are processed, together with the relevant purpose and the personal data processed, is set out below:

Name, surname, personal identification number, telephone, address, email address. Collected for the conclusion and performance of service and other contracts.

Legal basis – performance of a contract with you; compliance with legal requirements.

Name, surname, telephone, email, payment information, other information that may be required during the provision of services.

Collected for marketing purposes, e.g. to provide individually tailored advertisements and sponsored content and to send notifications about promotions and events, to assess and analyse our market, clients and services (including collecting your opinion about the services and organising client surveys). Legitimate interest – to inform about noticed shortcomings/faults and other services, events, news and other relevant information; your consent.

IP address, operating system version and parameters of the device you use to access the content, the time and duration of your session, and any information stored in cookies placed by the Data Controller on your device, or information about the nearest WiFi access points and mobile network towers that may be transmitted to the Data Controller when you use the content of the Data Controller's website.Collected in order to learn how people use the services provided, so that they can be improved and new content and services created. For this purpose, your personal data are processed on the basis of a legitimate interest in monitoring the quality of the services provided, creating and improving the website content, and ensuring the security of the website.

General information about a candidate: candidate's name, surname, date of birth, place of residence or home address, email address and/or telephone number, information about the candidate's work experience (place of work, period of employment, position, responsibilities and/or achievements), information about the candidate's education (educational institution, period of study, education and/or qualification obtained), information about professional development (training attended, certificates obtained), information about language skills, information technology and driving skills, other competencies, and other information you provide in your CV, cover letter or other application documents. References, employer feedback: the person providing the reference or feedback, their contact details, the content of the reference or feedback. Candidate assessment information: summary of the interview with the candidate, insights and opinions of the person(s) conducting the selection, candidate test results. Collected for the assessment of candidates for vacancies and for recruitment. Legal basis – your consent.

Purpose – to defend our interests in court or another institution. Depending on the claim or complaint brought, all of your personal data listed in this Policy may be processed for this purpose. Legal basis – compliance with legal requirements; legitimate interest – to defend against claims and complaints brought.

In cases where the Data Controller cannot rely on one of the legal bases set out above, it will request your consent before starting to process your personal data (such cases will be clear from the circumstances and context).

In cases where the Data Controller processes your personal data for purposes other than those set out in this Policy, you will be informed by means of a separate notice.

If you provide the Data Controller with data about other persons related to you, you should inform them and, if necessary, obtain their consent and familiarise them with this Policy. The Data Controller may also collect your personal data if you are a representative of a client of the Data Controller that is a legal entity.

The Data Controller may transfer your personal data to:

  • Representative offices of the Data Controller;

  • Credit and other financial institutions operating in Lithuania;

  • State, municipal and law enforcement authorities;

  • Companies providing services at the Data Controller's request;

  • Other responsibly selected business partners of the Data Controller;

  • Other parties, where required by law or where necessary to protect the legitimate interests of the Data Controller.

The companies currently providing services at the Data Controller's request are as follows: service providers, couriers, advertising agencies, auditors, lawyers. The ability of these companies to use your information is limited; they may not use this information for purposes other than providing services to the Data Controller. In order to receive direct marketing offers from the Data Controller and/or the Data Controller's business partners, you will be asked for separate consent. Other parties to whom the information held by the Data Controller about you may be provided, where necessary to protect the legitimate interests of the Data Controller, are public authorities, pre-trial investigation officers, courts, etc.

Occasionally, the Data Controller may need to transfer your personal data to other countries where a lower level of data protection policy may apply. In such cases, the Data Controller would do everything within its power to ensure the security of the transferred personal data. In very rare cases (e.g. where you have exceptional requests regarding the Data Controller's services), the Data Controller may be obliged to send your personal data to countries outside the European Economic Area. If the Data Controller transfers your personal data to countries outside the European Economic Area, the Data Controller will inform you and ensure that one of the following safeguards applies:

  • The contract signed with the data recipient would be based on the Standard Contractual Clauses approved by the European Commission.

  • The data recipient would be established in a country recognised by the European Commission as applying adequate data protection standards.

  • Authorisation from the Data Protection Inspectorate.

The Data Controller has implemented reasonable and appropriate physical and technical measures to protect the information collected for the purposes of providing content/services. However, please remember that although appropriate steps are taken to protect your information, no website, online transaction, computer system or wireless connection is completely secure.

The Data Controller will retain your personal data for as long as is necessary to achieve the specified purpose. Once the specified purpose has been achieved, your personal data are deleted, except in cases where legislation obliges the Data Controller to retain the information for tax purposes or where the data may be required for a pre-trial investigation; in any case, the retention period will not exceed 10 years.

Upon expiry of this period, the data will be deleted in such a way that they cannot be reproduced.

Personal data are generally retained for the following periods:

  • Data contained in payment, service provision and other contracts – 10 years after the payment transaction or the end of the contract.

  • Data submitted by candidates for vacancies – 6 months after the end of the selection process.

  • Personal data used for marketing – for as long as you are an active client of the Data Controller and for a further 2 years after your last visit to the Data Controller or your last active action on the Data Controller's website.

  • IT system records (logs) – at least one year.

  • Analytics data – these data are generally collected automatically when you use the website and are anonymised/aggregated shortly after receipt.

Depending on the situation, you have the following rights:

  • To know (be informed) about the processing of your data (the right to know).

  • To access your data and how they are processed (the right of access).

  • To request the rectification or, having regard to the purposes of the processing, the completion of incomplete personal data (the right to rectification).

  • To have your data erased or to have the processing of your data suspended (except for storage) (the right to erasure and the "right to be forgotten").

  • The right to request that the Data Controller restrict the processing of personal data where one of the lawful grounds applies (the right to restriction).

  • The right to data portability (the right to portability).

  • The right to object at any time to the processing of your personal data where such processing is carried out in the public interest or where processing is necessary for the purposes of the legitimate interests pursued by the data controller or a third party. In order to continue processing personal data, the data controller bears the burden of demonstrating that the data are processed for compelling legitimate reasons which override your interests (the right to object).

  • To lodge a complaint with the State Data Protection Inspectorate.

The Data Controller may not enable you to exercise the rights listed above where, in cases provided for by law, it is necessary to ensure the prevention, investigation and detection of crimes or breaches of official or professional ethics, as well as the protection of the rights and freedoms of the data subject or other persons.

Your rights will be exercised after your identity has been verified in person or by electronic signature.

You have the right:

To know (be informed) about the processing of your data (the right to know). Before the processing of your personal data begins, you have the right to receive information about the processing in concise, plain and intelligible language.

To access your data and how they are processed (the right of access). Having established your identity, the Data Controller will provide you with the information, provided that this does not infringe the rights and freedoms of others. This right means:

  • Confirmation of whether the Data Controller processes your personal data;

  • Provision of a list of your personal data being processed;

  • Provision of the purposes and legal basis for the processing of your data;

  • Confirmation of whether the Data Controller transfers data to third countries and, if so, what safeguards have been taken;

  • Provision of the source of your personal data;

  • Information on whether profiling is applied;

  • Provision of the data retention period.

To request the rectification or, having regard to the purposes of processing, the completion of incomplete personal data (the right to rectification). Applies where the information held is incomplete or inaccurate.

To have your data erased (the "right to be forgotten"). Applies where:

  • The information held by the Data Controller is no longer necessary to achieve the specified purposes;

  • the data are processed on the basis of your consent and you withdraw that consent;

  • the data are processed on the basis of legitimate interests and, following your request, it is established that your private interests override them;

  • the information was obtained unlawfully.

To suspend the processing of your data (except for storage). This right may be exercised for the period during which the Data Controller analyses the situation, i.e.:

  • if you contest the accuracy of the information;

  • if you object to the processing of personal data carried out on the basis of legitimate interests;

  • the Data Controller uses the information unlawfully, but you object to its erasure;

  • the Data Controller no longer needs the information, but you require it to be retained for the purposes of a legal dispute.

To request that the Data Controller restrict the processing of personal data where one of the lawful grounds applies (the right to restriction). You may prohibit the Data Controller from using your personal data for direct marketing purposes.

The right to data portability. This right may be exercised if you have provided your data and the Data Controller processes them by automated means on the basis of your consent or a contract concluded with you.

The right to object. This right may be exercised where such processing is carried out in the public interest or where processing is necessary for the purposes of the legitimate interests pursued by the data controller or a third party. In order to continue processing personal data, the data controller bears the burden of demonstrating that the data are processed for compelling legitimate reasons which override the interests of the data subject.

To lodge a complaint with the State Data Protection Inspectorate (www.ada.lt).

You may submit a request regarding the exercise of the rights set out above, as well as complaints, notifications or requests, to the Data Controller using the contact details provided at the end of the Policy. The Data Controller will provide a response to your request no later than within 30 (thirty) calendar days from the date of receipt of the request. In exceptional cases (requiring additional time), the Data Controller, having notified you accordingly, shall have the right to extend the period for providing the requested data or for examining the other requirements set out in your request to up to 60 (sixty) calendar days from the date of your request.

Cookies, beacons and similar technologies

In this Policy, the term "cookies" is used to describe cookies and other similar technologies, such as pixel tags, web beacons and clear GIFs.

When you visit the Data Controller's website, the aim is to provide content and features tailored specifically to your needs. This requires cookies. These are small pieces of information stored in your web browser. They help the Data Controller recognise you as a previous visitor to a particular website, save your browsing history on the website and tailor content accordingly. Cookies also help ensure the smooth functioning of websites, make it possible to monitor the duration and frequency of visits to websites and collect statistical information about the number of website visitors. By analysing these data, we can improve the Data Controller's websites and make them more convenient for you to use.

When you use a browser to access the content provided by the Data Controller, you can configure your browser to accept all cookies, reject all cookies, or notify you when a cookie is sent. Every browser is different, so if you do not know how to change your cookie settings, consult its help menu. Your device's operating system may contain additional cookie controls. If you do not want information to be collected by means of cookies, use the simple procedure available in most browsers that allows you to opt out of the use of cookies. To find out more about managing cookies, visit: http://www.allaboutcookies.org/manage-cookies/

However, please remember that some services may be designed to work only with cookies, and if you disable them, you will no longer be able to use those services or certain parts of them. In addition to the cookies used by the Data Controller, certain third parties are permitted to set and access cookies on your computer on the Data Controller's websites. In such cases, the use of cookies is governed by the privacy rules of those third parties. Please note that the cookie policies of the relevant social network apply to the Data Controller's social media accounts.

When collecting and using the personal data entrusted to the Data Controller by you, as well as data obtained from other sources, the Data Controller adheres to the following principles:

  • Your personal data are processed in a lawful, fair and transparent manner (the principle of lawfulness, fairness and transparency).

  • Your personal data are collected for specified, explicit and legitimate purposes and are not further processed in a manner incompatible with those purposes (the principle of purpose limitation).

  • Your personal data are adequate, relevant and limited to what is necessary for the purposes for which they are processed (the principle of data minimisation).

  • The personal data processed are accurate and, where necessary, kept up to date (the principle of accuracy).

  • Your personal data are kept in a form which permits identification for no longer than is necessary for the purposes for which your personal data are processed (the principle of storage limitation).

  • Your personal data are processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (the principle of integrity and confidentiality).

If you have noticed a discrepancy in this Policy, a security vulnerability on the Data Controller's website, or if you have other questions relating to the processing of your personal data, please contact the Data Controller using the contact details provided at the end of the Policy.

This Policy is reviewed at least once every two years. When the Policy is updated, you will be informed of any changes that the Data Controller considers material by means of a notice published on the Data Controller's website. If you access or use the content and/or services provided by the Data Controller after such a notice has been published, you will be deemed to agree to the new requirements set out in the update.

Data Controller details:

MB "Mheels"
Address: T. Ševčenkos g. 29–16, Vilnius
Studio address: Švitrigailos g. 16, Vilnius
Email: hello@itsmheels.com
Phone: +370 621 06135

[1] Please note that the Data Controller has the right to send its clients/potential clients or persons who have completed an order form advertising information by email about other similar services it provides, and you have the right, now or at any time later, to opt out of receiving direct marketing content by notifying us of your decision using the contact details provided at the end of the Policy or by using the unsubscribe link in the newsletter itself.

In case of any discrepancy between the Lithuanian and English versions of this Policy, the Lithuanian version shall prevail.

bottom of page