Privacy Policy

RULES FOR THE PROCESSING OF PERSONAL DATA OF CLIENTS, WEBSITE VISITORS AND OTHER EXTERNAL INDIVIDUALS

This personal data processing agreement has been drawn up in accordance with the laws of the Republic of Lithuania and the European Union.

These terms and conditions are subject to change without prior notice to the user. By accessing, browsing and using our website on any platform, you acknowledge and agree to read, understand and agree to the terms and conditions set out below.

This Privacy Policy governs the manner in which UAB “Senasis Lokys” collects, uses, maintains and discloses information collected from users of the lokys.lt website. This Privacy Policy applies to the Site and all goods and services provided by UAB “Senasis Lokys”.

I. General provisions

1. UAB “Senasis lokys”, legal-entity code 121525187, registered-office address Stiklių St. 8, LT-01131 Vilnius (hereinafter – the Company), is the controller of the processing specified in these Rules.

2. These Rules apply to clients, persons who reserve a table or event, purchase goods or gift vouchers, contact the Company, participate in the loyalty programme, visit the Company’s website and, where video surveillance is carried out, persons entering the monitored premises. Employee data is not governed by these Rules.
3. The Company processes only data necessary for a specific purpose, retains it only for the specified period and enables individuals to exercise their rights. When joining the loyalty programme and for the simple accumulation of points, the personal identification number, date of birth, place of employment or identity-document data are not collected. Where the transfer of a specific prize gives rise to a tax-reporting or tax-payment obligation for the Company, only the data mandatory for that specific prize record under item 7 is collected. A copy of the document, its expiry date, date and place of issue are not collected; where necessary, an employee only visually checks the document.
4. Each employee who needs data for their work may process it only within the scope of their functions and must comply with confidentiality requirements. The Company does not appoint a data protection officer unless such appointment is required by law or the nature of the Company’s processing changes.
5. Data-protection questions and requests may be submitted by email at info@lokys.lt, by telephone at +370 661 30703 or by post to Stiklių St. 8, LT-01131 Vilnius. The Company’s Director ensures the implementation of these Rules.
6. These Rules are based on Regulation (EU) 2016/679 (GDPR), the Law of the Republic of Lithuania on Legal Protection of Personal Data, the Law on Electronic Communications and other applicable legislation. Where special legislation applies, it takes precedence over these Rules.

II. Processing purposes, data and retention periods

7. The Company processes the following data and follows these rules:

Purpose

Data and legal basis

Usual retention period

Reservation of a table, event or tasting, enquiries about services and their performance

Name, telephone number or email address, reservation date, time, number of people and only the information necessary for the order. Legal basis – steps taken at the individual’s request prior to entering into a contract or performance of a contract.

2 years after completion of the reservation or enquiry. If a dispute arises, the data is retained until its final resolution.

Sale and delivery of goods, gift vouchers and other services

Name and, where necessary for delivery, the purchaser’s and recipient’s name, contact details, delivery address, order and payment information. Legal basis – the contract and steps taken prior to entering into it; after completion of the order – the Company’s legitimate interest in responding to questions related to the order, handling claims and defending legal claims. The Company does not store all payment-card data.

Order data – 2 years after completion of the order; upon receipt of a claim or if a dispute arises – until its final resolution. Accounting documents – for the period prescribed by law.

Accounting, taxes and obligations established by law

Data contained in accounting documents. Legal basis – a legal obligation applicable to the Company.

For the period prescribed by legislation governing the retention of accounting documents.

Handling enquiries, complaints, requests and feedback

Name, contact details, the content of the communication and related documents. Legal basis – a contract, steps taken prior to entering into a contract or a legitimate interest in responding and defending the Company’s rights.

2 years after the response; in the event of a dispute – until its final resolution.

Loyalty programme, accounting for points and transfer of non-taxable gifts / prizes

Name and surname, loyalty-account identifier, records of points earned and used, the selected and received gift / prize, its value, transfer date and, where necessary, confirmation of receipt. Legal basis – performance of the contract for participation in the loyalty programme. Telephone number, email address, address, place of employment, personal identification number and document data are not collected for this purpose.

2 years after the last points transaction or the end of participation in the programme. An inactive account and unused points expire after 2 years.

Transfer of a taxable or otherwise reportable loyalty prize, calculation and reporting of personal income tax

In addition to the transfer data specified in the preceding row, only the recipient identifier required for the personal-income-tax return and other data established by law. For a permanent resident of Lithuania, this may be the taxpayer identification number or the number of an identity document permitted by the State Tax Inspectorate. Legal basis – a legal obligation applicable to the Company. The data is collected when the specific prize is transferred, not when joining the programme.

Together with the relevant tax and accounting document, for the period prescribed by law.

Website operation and security

Technical log data, such as IP address, browser data, time of activity and information about a security event. Legal basis – the Company’s legitimate interest in ensuring the operation and protection of the website.

30 days, except in relation to a specific security incident or dispute.

Non-essential website analytics, personalisation or marketing

Data from cookies and similar technologies. Legal basis – separate consent given in the consent window.

According to the period of each cookie displayed in the consent tool; consent choices are reviewed at least every 6 months.

Video surveillance, if actually carried out

Video recording, date, time and location of the recording. Legal basis – the Company’s legitimate interest in protecting persons and property. Audio recording is not carried out.

30 calendar days; a recording related to an incident – until the end of the investigation, dispute or proceedings.

8. The Company does not use client data for automated decisions that would produce legal or similarly significant effects for an individual, and does not carry out profiling.
9. The Company does not request data concerning health, allergies, religion, political opinions, sex life, criminal convictions or other special categories of data. If such information is received without a clear request to retain it, it is not entered into the client or loyalty database and is deleted as soon as it is no longer necessary to handle the specific enquiry.
10. If there is reasonable doubt about the age of a person purchasing alcohol or tobacco products, an employee may ask to see an identity document and only visually verify the person’s age. No document data, copy or photograph is made or retained.
11. The Company generally receives data from the individual themselves. When a purchaser provides another person’s delivery details, only the data necessary for delivery is used, and information about the processing is provided to the recipient no later than the first time they are contacted.

3. Privacy information for individuals

12. The Company may transfer data only to the extent necessary to achieve the purpose to the following categories of recipients: providers of IT, website hosting, reservation, email and cookie services; payment and delivery service providers; accounting, legal and document-archiving service providers; and public authorities and law-enforcement institutions where required by law.
13. Before entrusting data processing to a service provider, the Company verifies the provider’s role. A written agreement complying with Article 28 of the GDPR is concluded with a data processor. Where a payment or delivery service provider independently determines the purposes of its processing, it processes the data in accordance with its own privacy information.
14. These Rules do not permit the transfer of data outside the European Economic Area until the Company has established the transfer mechanism required under Chapter V of the GDPR and, before the transfer, clearly updated the information provided to the individual about the recipient, country and safeguards.
15. An individual has the right to:

– access their data and obtain a copy of it;
– request the rectification of inaccurate data or completion of incomplete data;
– request the erasure of data where there is no basis for further processing;
– request restriction of processing;
– object to processing based on a legitimate interest; in the case of marketing, the Company terminates the processing immediately;
– withdraw consent as easily as it was given; withdrawal does not affect the lawfulness of processing carried out before withdrawal;
– receive data concerning them that is processed by automated means and provided by them, in a commonly used machine-readable format, where the right to data portability applies;
– lodge a complaint with the State Data Protection Inspectorate (VDAI) or defend their rights in court.

16. A request may be submitted to the Company by email, post or orally. The Company may request only such additional information as is reasonably necessary to verify the identity of the person making the request; an identity-document copy is not ordinarily required.
17. The Company responds without undue delay and no later than one month after receiving the request. Due to the complexity or number of requests, the period may be extended by a further two months; the individual is informed of this and the reasons within the first month. Ordinary requests are handled free of charge.
18. Information about which data is necessary for a contract or order is provided in the relevant form or during the ordering process. If the contact or delivery details necessary for the service are not provided, the Company may be unable to confirm the reservation, fulfill the order or deliver the goods.

4. Marketing and cookies

19. The Company does not carry out direct marketing: it does not use clients’ contact details for advertising messages and does not send such messages to loyalty-programme participants.
20. If the Company decides to carry out direct marketing in the future, it will update these Rules before commencing it and obtain separate, freely given and not pre-ticked consent, unless the exception under Article 81(2) of the Law on Electronic Communications may lawfully apply in a particular case. For proof of consent, the contact details, choice, date, time and method are sufficient.
21. Each future marketing message would state the Company’s name and provide an operative and straightforward means of unsubscribing from messages. Upon receiving an unsubscribe request, the contact would no longer be used for marketing.
22. Strictly necessary cookies and similar technologies are used to ensure the website, reservations, shopping cart, security and the individual’s choices function properly. Analytics, preference and marketing cookies are enabled only after the individual gives separate consent to the relevant category. The consent tool always provides the provider, purpose, period and method for changing or withdrawing the choice.

5. Security, recipients and incidents

23. Taking into account the risks of processing, the Company applies proportionate measures: access is granted only to employees who need it; individual logins and passwords are used; documents are protected from unauthorised persons; copies are destroyed when no longer needed; and devices and software are kept up to date.
24. An employee who becomes aware of lost data, unauthorised access, incorrect transmission, a suspicious email or another possible security breach must immediately notify the Director or email info@lokys.lt. The Director or a person appointed by them assesses the incident, takes measures to mitigate the damage and documents the decision.
25. If a breach is likely to pose a risk to the rights and freedoms of individuals, the Company notifies the VDAI without undue delay and, where possible, no later than 72 hours after becoming aware of it. If there is a high risk, the Company also informs the affected individuals of the breach in clear language without undue delay.
26. Video surveillance, if carried out, is limited to entrances, passageways, the cash desk and other objectively necessary locations for the security of property and people. It is not carried out in toilets, changing rooms or rest areas. Before entering a monitored area, a clear sign is provided containing the Company’s contact details and a reference to these Rules.

6. Final provisions

27. The Company begins new processing that would materially change the purposes, categories of data, categories of recipients or risks specified in Section II of this document only after updating these Rules. If a data protection impact assessment is required under the GDPR, it is carried out before such processing begins.
28. The Rules are reviewed when the processing or legislation changes. If Section III is amended, the updated version is published on lokys.lt before it begins to apply, except for purely editorial changes.
29. These Rules enter into force on the date they are approved.

The Rules were last updated on 22 July 2026.